{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T21:43:45Z","timestamp":1757627025052,"version":"3.44.0"},"publisher-location":"Cham","reference-count":58,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031944475"},{"type":"electronic","value":"9783031944482"}],"license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-031-94448-2_5","type":"book-chapter","created":{"date-parts":[[2025,8,31]],"date-time":"2025-08-31T19:08:15Z","timestamp":1756667295000},"page":"84-107","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Anti-EMP: Encrypted Malware Packets Filtering Algorithm Leveraging Ciphertext Patterns Under Zero Knowledge Setting"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6206-083X","authenticated-orcid":false,"given":"Junggab","family":"Son","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jeehyung","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jemin","family":"Ahn","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Doowon","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Homook","family":"Cho","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daeyoung","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,1]]},"reference":[{"key":"5_CR1","unstructured":"DARKCOMET remote administration tool (2012). http:\/\/www.darkcomet-rat.com\/"},{"key":"5_CR2","unstructured":"Cryptowall ransomware built with rc4 bricks. Tech. rep., McAfee (2014). https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/cryptowall-ransomware-built-with-rc4-bricks\/"},{"key":"5_CR3","unstructured":"Operation blockbuster: unraveling the long thread of the SONY attack. Report, Operation Blockbuster (2015). https:\/\/www.novetta.com\/2016\/02\/operation-blockbuster-unraveling-the-long-thread-of-the-sony-attack\/"},{"key":"5_CR4","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.102985","volume":"183","author":"G Aceto","year":"2021","unstructured":"Aceto, G., Ciuonzo, D., Montieri, A., Pescap\u00e9, A.: Distiller: encrypted traffic classification via multimodal multitask deep learning. J. Netw. Comput. Appl. 183, 102985 (2021)","journal-title":"J. Netw. Comput. Appl."},{"key":"5_CR5","doi-asserted-by":"publisher","unstructured":"Adamov, A., Carlsson, A., Surmacz, T.: An analysis of LockerGoga ransomware. In: Proceedings of the 2019 IEEE East-West Design & Test Symposium (EWDTS), pp. 1\u20135 (2019). https:\/\/doi.org\/10.1109\/EWDTS.2019.8884472","DOI":"10.1109\/EWDTS.2019.8884472"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Anderson, B., McGrew, D.: Identifying encrypted malware traffic with contextual flow data. In: Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, pp. 35\u201346 (2016)","DOI":"10.1145\/2996758.2996768"},{"key":"5_CR7","doi-asserted-by":"publisher","unstructured":"Anderson, B., McGrew, D.: Machine learning for encrypted malware traffic classification: accounting for noisy labels and non-stationarity. In: Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD), pp. 1723\u20131732 (2017). https:\/\/doi.org\/10.1145\/3097983.3098163","DOI":"10.1145\/3097983.3098163"},{"key":"5_CR8","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/s11416-017-0306-6","volume":"14","author":"B Anderson","year":"2018","unstructured":"Anderson, B., Paul, S., McGrew, D.: Deciphering malware\u2019s use of TLS (without decryption). J. Comput. Virol. Hacking Tech. 14, 195\u2013211 (2018). https:\/\/doi.org\/10.1007\/s11416-017-0306-6","journal-title":"J. Comput. Virol. Hacking Tech."},{"issue":"4","key":"5_CR9","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1007\/s11416-011-0152-x","volume":"7","author":"B Anderson","year":"2011","unstructured":"Anderson, B., Quist, D., Neil, J., Storlie, C., Lane, T.: Graph-based malware detection using dynamic analysis. J. Comput. Virol. 7(4), 247\u2013258 (2011)","journal-title":"J. Comput. Virol."},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"Bader, O., Lichy, A., Hajaj, C., Dubin, R., Dvir, A.: MalDIST: from encrypted traffic classification to malware traffic detection and classification. In: 2022 IEEE 19th Annual Consumer Communications & Networking Conference (CCNC), pp. 527\u2013533. IEEE (2022)","DOI":"10.1109\/CCNC49033.2022.9700625"},{"key":"5_CR11","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.118299","volume":"209","author":"E Berrueta","year":"2022","unstructured":"Berrueta, E., Morato, D., Maga\u00f1a, E., Izal, M.: Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic. Expert Syst. Appl. 209, 118299 (2022)","journal-title":"Expert Syst. Appl."},{"key":"5_CR12","doi-asserted-by":"crossref","unstructured":"Canzanese, R., Mancoridis, S., Kam, M.: System call-based detection of malicious processes. In: 2015 IEEE International Conference on Software Quality, Reliability and Security, pp. 119\u2013124. IEEE (2015)","DOI":"10.1109\/QRS.2015.26"},{"key":"5_CR13","doi-asserted-by":"publisher","unstructured":"Chen, J., Song, L., Cai, S., Xie, H., Yin, S., Ahmad, B.: TLS-MHSA: an efficient detection model for encrypted malicious traffic based on multi-head self-attention mechanism. ACM Trans. Priv. Secur. 26(4) (2023). https:\/\/doi.org\/10.1145\/3613960","DOI":"10.1145\/3613960"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Chen, Y.C., Li, Y.J., Tseng, A., Lin, T.: Deep learning for malicious flow detection. In: 2017 IEEE 28th Annual International Symposium on Personal, Indoor, and Mobile Radio Communications (PIMRC), pp. 1\u20137. IEEE (2017)","DOI":"10.1109\/PIMRC.2017.8292316"},{"key":"5_CR15","doi-asserted-by":"publisher","unstructured":"Cicala, F., Bertino, E.: Analysis of encryption key generation in modern crypto ransomware. IEEE Trans. Dependable Secure Comput. (Early Access), 1\u201315 (2020). https:\/\/doi.org\/10.1109\/TDSC.2020.3005976","DOI":"10.1109\/TDSC.2020.3005976"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Craciun, V.C., Mogage, A., Simion, E.: Trends in design of ransomware viruses. In: Proceedings of the International Conference on Security for Information Technology and Communications (SECITC), pp. 259\u2013272 (2019)","DOI":"10.1007\/978-3-030-12942-2_20"},{"key":"5_CR17","doi-asserted-by":"publisher","first-page":"5011","DOI":"10.1109\/TIFS.2023.3300521","volume":"18","author":"S Cui","year":"2023","unstructured":"Cui, S.: CBSeq: a channel-level behavior sequence for encrypted malware traffic detection. IEEE Trans. Inf. Forensics Secur. 18, 5011\u20135025 (2023). https:\/\/doi.org\/10.1109\/TIFS.2023.3300521","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"Cui, S., et al.: A session-packets-based encrypted traffic classification using capsule neural networks. In: 2019 IEEE 21st International Conference on High Performance Computing and Communications; IEEE 17th International Conference on Smart City; IEEE 5th International Conference on Data Science and Systems (HPCC\/SmartCity\/DSS), pp. 429\u2013436. IEEE (2019)","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00071"},{"key":"5_CR19","doi-asserted-by":"publisher","unstructured":"d\u2019Estalenx, A., Ga\u00f1\u00e1n, C.: Nurse: end-user IoT malware detection tool for smart homes. In: Proceedings of the 11th International Conference on the Internet of Things, pp. 134\u2013142. IoT \u201921, Association for Computing Machinery, New York (2022). https:\/\/doi.org\/10.1145\/3494322.3494340","DOI":"10.1145\/3494322.3494340"},{"key":"5_CR20","doi-asserted-by":"publisher","unstructured":"Dhanasekar, D., Troia, F.D., Potika, K., Stamp, M.: Detecting encrypted and polymorphic malware using hidden Markov models. Guide to Vulnerability Anal. Comput. Netw. Syst. Computer Communications and Networks, 281\u2013299 (2018). https:\/\/doi.org\/10.1007\/978-3-319-92624-7_12","DOI":"10.1007\/978-3-319-92624-7_12"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Fan, Y., Hou, S., Zhang, Y., Ye, Y., Abdulhayoglu, M.: Gotcha-Sly malware! scorpion a metagraph2vec based malware detection system. In: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 253\u2013262 (2018)","DOI":"10.1145\/3219819.3219862"},{"issue":"2016","key":"5_CR22","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1016\/j.comnet.2016.05.019","volume":"109","author":"T Ha","year":"2016","unstructured":"Ha, T., et al.: Suspicious traffic sampling for intrusion detection in software-defined networks. Comput. Netw. 109(2016), 172\u2013182 (2016). https:\/\/doi.org\/10.1016\/j.comnet.2016.05.019","journal-title":"Comput. Netw."},{"key":"5_CR23","doi-asserted-by":"publisher","unstructured":"Hang, Z., Lu, Y., Wang, Y., Xie, Y.: Flow-MAE: leveraging masked autoencoder for accurate, efficient and robust malicious traffic classification. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, pp. 297\u2013314. RAID \u201923, Association for Computing Machinery, New York, (2023). https:\/\/doi.org\/10.1145\/3607199.3607206","DOI":"10.1145\/3607199.3607206"},{"key":"5_CR24","doi-asserted-by":"publisher","unstructured":"Hus\u00e1k, M., \u010cerm\u00e1k, M., Jirs\u00edk, T., \u010celeda, P.: HTTPS traffic analysis and client identification using passive SSL\/TLS fingerprinting. EURASIP J. Inf. Secur. 2016(1) (2016). https:\/\/doi.org\/10.1186\/s13635-016-0030-7","DOI":"10.1186\/s13635-016-0030-7"},{"key":"5_CR25","doi-asserted-by":"publisher","unstructured":"Li, H., et al.: DART: detecting unseen malware variants using adaptation regularization transfer learning. In: Proceedings of the 2019 IEEE International Conference on Communications (ICC), pp.\u00a01\u20136 (2019). https:\/\/doi.org\/10.1109\/ICC.2019.8761598","DOI":"10.1109\/ICC.2019.8761598"},{"key":"5_CR26","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103000","volume":"124","author":"A Lichy","year":"2023","unstructured":"Lichy, A., Bader, O., Dubin, R., Dvir, A., Hajaj, C.: When a RF beats a CNN and GRU, together\u2014a comparison of deep learning and classical machine learning approaches for encrypted malware traffic classification. Comput. Secur. 124, 103000 (2023)","journal-title":"Comput. Secur."},{"key":"5_CR27","doi-asserted-by":"publisher","unstructured":"Liu, J., Tian, Z., Zheng, R., Liu, L.: A distance-based method for building an encrypted malware traffic identification framework. IEEE Access 7, 100014\u2013100028 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2930717","DOI":"10.1109\/ACCESS.2019.2930717"},{"issue":"2","key":"5_CR28","doi-asserted-by":"publisher","first-page":"721","DOI":"10.32604\/cmc.2019.05610","volume":"60","author":"J Liu","year":"2019","unstructured":"Liu, J., Zeng, Y., Shi, J., Yang, Y., Wang, R., He, L.: Maldetect: a structure of encrypted malware traffic detection. CMC-COMPUTERS MATERIALS & CONTINUA 60(2), 721\u2013739 (2019)","journal-title":"CMC-COMPUTERS MATERIALS & CONTINUA"},{"key":"5_CR29","doi-asserted-by":"crossref","unstructured":"Luo, J.S., Lo, D.C.T.: Binary malware image classification using machine learning with local binary pattern. In: 2017 IEEE International Conference on Big Data (Big Data), pp. 4664\u20134667. IEEE (2017)","DOI":"10.1109\/BigData.2017.8258512"},{"key":"5_CR30","doi-asserted-by":"publisher","unstructured":"Marin, G., Casas, P., Capdehourat, G.: Deep in the dark - deep learning-based malware traffic detection without expert knowledge. In: Proceedings of the 2019 IEEE Security and Privacy Workshops (SPW), pp. 36\u201342 (2019). https:\/\/doi.org\/10.1109\/SPW.2019.00019","DOI":"10.1109\/SPW.2019.00019"},{"key":"5_CR31","doi-asserted-by":"publisher","unstructured":"McGrew, D., Anderson, B.: Enhanced telemetry for encrypted threat analytics. In: 2016 IEEE 24th International Conference on Network Protocols (ICNP), pp.\u00a01\u20136 (2016). https:\/\/doi.org\/10.1109\/ICNP.2016.7785325","DOI":"10.1109\/ICNP.2016.7785325"},{"key":"5_CR32","unstructured":"Milletary, J.: Citadel trojan malware analysis. Tech. rep., Dell SecureWorks Counter Threat Unit\u2122Intelligence Services (2012). https:\/\/botnetlegalnotice.com\/citadel\/files\/Patel_Decl_Ex20.pdf"},{"key":"5_CR33","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1016\/j.ins.2022.04.018","volume":"601","author":"Z Niu","year":"2022","unstructured":"Niu, Z., Xue, J., Qu, D., Wang, Y., Zheng, J., Zhu, H.: A novel approach based on adaptive online analysis of encrypted traffic for identifying malware in IIoT. Inf. Sci. 601, 162\u2013174 (2022)","journal-title":"Inf. Sci."},{"key":"5_CR34","doi-asserted-by":"crossref","unstructured":"Papadogiannaki, E., Tsirantonakis, G., Ioannidis, S.: Network intrusion detection in encrypted traffic. In: 2022 IEEE Conference on Dependable and Secure Computing (DSC), pp.\u00a01\u20138. IEEE (2022)","DOI":"10.1109\/DSC54232.2022.9888942"},{"key":"5_CR35","doi-asserted-by":"crossref","unstructured":"Park, C., Park, H., Kim, K.: Realtime C &C zeus packet detection based on rc4 decryption of packet length field. Adv. Sci. Technol. Lett. 64, 55\u201359 (2014). https:\/\/pdfs.semanticscholar.org\/4cb5\/9efe53c9e1272fdf27cba46cd02d934ee40f.pdf","DOI":"10.14257\/astl.2014.64.14"},{"issue":"3","key":"5_CR36","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1145\/3308897.3308961","volume":"46","author":"M Piskozub","year":"2019","unstructured":"Piskozub, M., Spolaor, R., Martinovic, I.: MalAlert: Detecting malware in large-scale network traffic using statistical features. SIGMETRICS Perform. Eval. Rev. 46(3), 151\u2013154 (2019). https:\/\/doi.org\/10.1145\/3308897.3308961","journal-title":"SIGMETRICS Perform. Eval. Rev."},{"key":"5_CR37","doi-asserted-by":"publisher","unstructured":"Radivilova, T., Kirichenko, L., Ageyev, D., Tawalbeh, M., Bulakh, V.: Decrypting SSL\/TLS traffic for hidden threats detection. In: Proceedings of the IEEE 9th International Conference on Dependable Systems, Services and Technologies (DESSERT), pp. 143\u2013146 (2018).https:\/\/doi.org\/10.1109\/DESSERT.2018.8409116","DOI":"10.1109\/DESSERT.2018.8409116"},{"key":"5_CR38","doi-asserted-by":"publisher","unstructured":"Rahimian, A., Ziarati, R., Preda, S., Debbabi, M.: On the reverse engineering of the citadel botnet. In: Revised Selected Papers of the 6th International Symposium on Foundations and Practice of Security (FPS) - vol. 8352, pp. 408\u2013425 (2013). https:\/\/doi.org\/10.1007\/978-3-319-05302-8_25","DOI":"10.1007\/978-3-319-05302-8_25"},{"key":"5_CR39","doi-asserted-by":"crossref","unstructured":"Ran, J., Chen, Y., Li, S.: Three-dimensional convolutional neural network based traffic classification for wireless communications. In: 2018 IEEE Global Conference on Signal and Information Processing (GlobalSIP), pp. 624\u2013627. IEEE (2018)","DOI":"10.1109\/GlobalSIP.2018.8646659"},{"key":"5_CR40","doi-asserted-by":"publisher","first-page":"2385","DOI":"10.1007\/s12083-020-00975-6","volume":"14","author":"D Rani","year":"2021","unstructured":"Rani, D., Geethakumari, G.: A framework for the identification of suspicious packets to detect anti-forensic attacks in the cloud environment. Peer-to-Peer Netw. Appl. 14, 2385\u20132398 (2021)","journal-title":"Peer-to-Peer Netw. Appl."},{"key":"5_CR41","doi-asserted-by":"crossref","unstructured":"Santos, I., Brezo, F., Nieves, J., Penya, Y.K., Sanz, B., Laorden, C., Bringas, P.G.: Idea: opcode-sequence-based malware detection. In: International Symposium on Engineering Secure Software and Systems, pp. 35\u201343. Springer (2010)","DOI":"10.1007\/978-3-642-11747-3_3"},{"key":"5_CR42","doi-asserted-by":"publisher","unstructured":"Sharafaldin, I., Lashkari, A.H., Ghorbani, A.A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), pp. 108\u2013116 (2018).https:\/\/doi.org\/10.5220\/0006639801080116","DOI":"10.5220\/0006639801080116"},{"issue":"4","key":"5_CR43","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1145\/2829988.2787502","volume":"45","author":"J Sherry","year":"2015","unstructured":"Sherry, J., Lan, C., Popa, R.A., Ratnasamy, S.: Blindbox: deep packet inspection over encrypted traffic. SIGCOMM Comput. Commun. Rev. 45(4), 213\u2013226 (2015). https:\/\/doi.org\/10.1145\/2829988.2787502","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"5_CR44","doi-asserted-by":"publisher","unstructured":"Son, J., Ko, E., Boyanapalli, U.B., Kim, D., Kim, Y., Kang, M.: Fast and accurate machine learning-based malware detection via rc4 ciphertext analysis. In: Proceedings of the 2019 International Conference on Computing, Networking and Communications (ICNC), pp. 159\u2013163 (2019). https:\/\/doi.org\/10.1109\/ICCNC.2019.8685644","DOI":"10.1109\/ICCNC.2019.8685644"},{"issue":"3","key":"5_CR45","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13673-018-0125-x","volume":"8","author":"A Souri","year":"2018","unstructured":"Souri, A., Hosseini, R.: A state-of-the-art survey of malware detection approaches using data mining techniques. HCIS 8(3), 1\u201322 (2018). https:\/\/doi.org\/10.1186\/s13673-018-0125-x","journal-title":"HCIS"},{"key":"5_CR46","doi-asserted-by":"publisher","unstructured":"Stone, W., Kim, D., Kemmoe, V.Y., Kang, M., Son, J.: Rethinking the weakness of stream ciphers and its application to encrypted malware detection. IEEE Access 8, 191602\u2013191616 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.3030559","DOI":"10.1109\/ACCESS.2020.3030559"},{"key":"5_CR47","doi-asserted-by":"publisher","unstructured":"Su, L., et al.: Hierarchical clustering based network traffic data reduction for improving suspicious flow detection. In: 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE), pp. 744\u2013753 (2018). https:\/\/doi.org\/10.1109\/TrustCom\/BigDataSE.2018.00108","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00108"},{"key":"5_CR48","doi-asserted-by":"crossref","unstructured":"Tabish, S.M., Shafiq, M.Z., Farooq, M.: Malware detection using statistical analysis of byte-level file content. In: Proceedings of the ACM SIGKDD Workshop on CyberSecurity and Intelligence Informatics, pp. 23\u201331 (2009)","DOI":"10.1145\/1599272.1599278"},{"key":"5_CR49","unstructured":"Toro, A.: A tale of two crypters. Tech. rep., Forcepoint Security Labs (2017). https:\/\/www.forcepoint.com\/blog\/x-labs\/tale-two-crypters"},{"key":"5_CR50","unstructured":"Vallejo, J.: Cryptoapi in malware (2018). https:\/\/outpost24.com\/blog\/cryptoapi-in-malware\/"},{"issue":"11","key":"5_CR51","doi-asserted-by":"publisher","DOI":"10.1002\/ett.3789","volume":"31","author":"DL Vu","year":"2020","unstructured":"Vu, D.L., Nguyen, T.K., Nguyen, T.V., Nguyen, T.N., Massacci, F., Phung, P.H.: Hit4mal: hybrid image transformation for malware classification. Trans. Emerg. Telecommun. Technol. 31(11), e3789 (2020)","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"5_CR52","doi-asserted-by":"crossref","unstructured":"Wang, W., Zhu, M., Wang, J., Zeng, X., Yang, Z.: End-to-end encrypted traffic classification with one-dimensional convolution neural networks. In: 2017 IEEE international conference on intelligence and security informatics (ISI), pp. 43\u201348. IEEE (2017)","DOI":"10.1109\/ISI.2017.8004872"},{"key":"5_CR53","doi-asserted-by":"crossref","unstructured":"Wang, Y., An, J., Huang, W.: Using CNN-based representation learning method for malicious traffic identification. In: 2018 IEEE\/ACIS 17th International Conference on Computer and Information Science (ICIS), pp. 400\u2013404. IEEE (2018)","DOI":"10.1109\/ICIS.2018.8466404"},{"key":"5_CR54","doi-asserted-by":"publisher","unstructured":"Xu, K., et al.: Self-supervised learning malware traffic classification based on masked auto-encoder. IEEE Internet Things J., 1\u20131 (2024). https:\/\/doi.org\/10.1109\/JIOT.2024.3357072","DOI":"10.1109\/JIOT.2024.3357072"},{"key":"5_CR55","doi-asserted-by":"crossref","unstructured":"Yewale, A., Singh, M.: Malware detection based on opcode frequency. In: 2016 International Conference on Advanced Communication Control and Computing Technologies (ICACCCT,. pp. 646\u2013649. IEEE (2016)","DOI":"10.1109\/ICACCCT.2016.7831719"},{"issue":"5","key":"5_CR56","doi-asserted-by":"publisher","first-page":"8448","DOI":"10.1109\/JIOT.2023.3318290","volume":"11","author":"X Zhang","year":"2024","unstructured":"Zhang, X., Hao, L., Gui, G., Wang, Y., Adebisi, B., Sari, H.: An automatic and efficient malware traffic classification method for secure internet of things. IEEE Internet Things J. 11(5), 8448\u20138458 (2024). https:\/\/doi.org\/10.1109\/JIOT.2023.3318290","journal-title":"IEEE Internet Things J."},{"key":"5_CR57","unstructured":"Zhao, Z., et al.: ERNN: Error-resilient RNN for encrypted traffic detection towards network-induced phenomena. IEEE Trans. Dependable Secure Comput. (2023)"},{"issue":"5","key":"5_CR58","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0232696","volume":"15","author":"R Zheng","year":"2020","unstructured":"Zheng, R.: Two-layer detection framework with a high accuracy and efficiency for a malware family over the TLS protocol. PLoS ONE 15(5), e0232696 (2020)","journal-title":"PLoS ONE"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-94448-2_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T00:22:08Z","timestamp":1757463728000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-94448-2_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,1]]},"ISBN":["9783031944475","9783031944482"],"references-count":58,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-94448-2_5","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2025,9,1]]},"assertion":[{"value":"1 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dubai","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Arab Emirates","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 October 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}