{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T11:59:16Z","timestamp":1781265556802,"version":"3.54.1"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Key Laboratory Project of Enterprise Informatization and IoT Measurement and Control Technology for Universities in Sichuan Province","award":["NO: 2024WYJ06"],"award-info":[{"award-number":["NO: 2024WYJ06"]}]},{"name":"Central Guidance for Local Science and Technology Development Fund Projects","award":["NO: 2024ZYD0266"],"award-info":[{"award-number":["NO: 2024ZYD0266"]}]},{"name":"Tibet Science and Technology Program","award":["NO: XZ202401YD0023"],"award-info":[{"award-number":["NO: XZ202401YD0023"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1007\/s10586-026-06078-w","type":"journal-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T11:31:58Z","timestamp":1781263918000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["STFNT: An encrypted traffic classification method integrating TLS handshake features and spatiotemporal characteristics"],"prefix":"10.1007","volume":"29","author":[{"given":"Hong","family":"Huang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaolin","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ye","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zesong","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingping","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,12]]},"reference":[{"issue":"6","key":"6078_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3457904","volume":"54","author":"E Papadogiannaki","year":"2021","unstructured":"Papadogiannaki, E., Ioannidis, S.: A survey on encrypted network traffic analysis applications, techniques, and countermeasures. ACM Comput. Surv. (CSUR). 54(6), 1\u201335 (2021)","journal-title":"ACM Comput. Surv. (CSUR)"},{"issue":"9","key":"6078_CR2","doi-asserted-by":"publisher","first-page":"12569","DOI":"10.1007\/s10586-024-04544-x","volume":"27","author":"L Yuan","year":"2024","unstructured":"Yuan, L., et al.: Enhancing network security with information-guided-enhanced Runge Kutta feature selection for intrusion detection. Cluster Comput. 27(9), 12569\u201312602 (2024)","journal-title":"Cluster Comput."},{"issue":"3","key":"6078_CR3","doi-asserted-by":"publisher","first-page":"676","DOI":"10.1016\/j.dcan.2022.09.009","volume":"10","author":"A Azab","year":"2024","unstructured":"Azab, A., Khasawneh, M., Alrabaee, S., Choo, K.-K.R., Sarsour, M.: Network traffic classification: Techniques, datasets, and challenges. Digit. Commun. Networks. 10(3), 676\u2013692 (2024)","journal-title":"Digit. Commun. Networks"},{"issue":"5","key":"6078_CR4","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MCOM.2019.1800819","volume":"57","author":"S Rezaei","year":"2019","unstructured":"Rezaei, S., Liu, X.: Deep learning for encrypted traffic classification: An overview. IEEE Commun. Mag. 57(5), 76\u201381 (2019)","journal-title":"IEEE Commun. Mag."},{"key":"6078_CR5","doi-asserted-by":"crossref","unstructured":"Yang, L., et al.: MM4flow: A Pre-trained Multi-modal Model for Versatile Network Traffic Analysis. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, pp. 1664\u20131678. (2025)","DOI":"10.1145\/3719027.3744804"},{"key":"6078_CR6","doi-asserted-by":"publisher","first-page":"109614","DOI":"10.1016\/j.comnet.2023.109614","volume":"224","author":"Z Diao","year":"2023","unstructured":"Diao, Z., et al.: EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks. Comput. Netw. 224, 109614 (2023)","journal-title":"Comput. Netw."},{"issue":"1","key":"6078_CR7","first-page":"7068349","volume":"2018","author":"A Voulodimos","year":"2018","unstructured":"Voulodimos, A., Doulamis, N., Doulamis, A., Protopapadakis, E.: Deep learning for computer vision: A brief review. Comput. Intell. Neurosci. 2018(1), 7068349 (2018)","journal-title":"Comput. Intell. Neurosci."},{"key":"6078_CR8","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/s00145-009-9052-3","volume":"23","author":"P Morrissey","year":"2010","unstructured":"Morrissey, P., Smart, N.P., Warinschi, B.: The TLS handshake protocol: A modular analysis. J. Cryptol. 23, 187\u2013223 (2010)","journal-title":"J. Cryptol."},{"issue":"4","key":"6078_CR9","doi-asserted-by":"publisher","first-page":"3746","DOI":"10.1109\/TVT.2021.3063738","volume":"70","author":"W Chen","year":"2021","unstructured":"Chen, W., Lyu, F., Wu, F., Yang, P., Xue, G., Li, M.: Sequential message characterization for early classification of encrypted internet traffic. IEEE Trans. Veh. Technol. 70(4), 3746\u20133760 (2021)","journal-title":"IEEE Trans. Veh. Technol."},{"issue":"2","key":"6078_CR10","doi-asserted-by":"publisher","first-page":"102361","DOI":"10.1016\/j.asej.2023.102361","volume":"15","author":"RT Elmaghraby","year":"2024","unstructured":"Elmaghraby, R.T., Aziem, N.M.A., Sobh, M.A., Bahaa-Eldin, A.M.: Encrypted network traffic classification based on machine learning. Ain Shams Eng. J. 15(2), 102361 (2024)","journal-title":"Ain Shams Eng. J."},{"key":"6078_CR11","doi-asserted-by":"crossref","unstructured":"Wang, W., Zhu, M., Wang, J., Zeng, X., Yang, Z.: End-to-end encrypted traffic classification with one-dimensional convolution neural networks. In IEEE international conference on intelligence and security informatics (ISI), 2017: pp. 43\u201348. (IEEE, 2017)","DOI":"10.1109\/ISI.2017.8004872"},{"key":"6078_CR12","doi-asserted-by":"publisher","first-page":"18042","DOI":"10.1109\/ACCESS.2017.2747560","volume":"5","author":"M Lopez-Martin","year":"2017","unstructured":"Lopez-Martin, M., Carro, B., Sanchez-Esguevillas, A., Lloret, J.: Network traffic classifier with convolutional and recurrent neural networks for Internet of Things. IEEE access. 5, 18042\u201318050 (2017)","journal-title":"IEEE access."},{"key":"6078_CR13","doi-asserted-by":"publisher","first-page":"132950","DOI":"10.1109\/ACCESS.2020.3010637","volume":"8","author":"Z Bu","year":"2020","unstructured":"Bu, Z., Zhou, B., Cheng, P., Zhang, K., Ling, Z.-H.: Encrypted network traffic classification using deep and parallel network-in-network models. Ieee Access. 8, 132950\u2013132959 (2020)","journal-title":"Ieee Access."},{"issue":"2","key":"6078_CR14","doi-asserted-by":"publisher","first-page":"1218","DOI":"10.1109\/TNSM.2021.3071441","volume":"18","author":"T Shapira","year":"2021","unstructured":"Shapira, T., Shavitt, Y.: FlowPic: A generic representation for encrypted traffic classification and applications identification. IEEE Trans. Netw. Serv. Manage. 18(2), 1218\u20131232 (2021)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"6078_CR15","doi-asserted-by":"crossref","unstructured":"Zhang, H., et al.: Tfe-gnn: A temporal fusion encoder using graph neural networks for fine-grained encrypted traffic classification, in Proceedings of the ACM Web Conference 2023, pp. 2066\u20132075. (2023)","DOI":"10.1145\/3543507.3583227"},{"key":"6078_CR16","doi-asserted-by":"crossref","unstructured":"Lin, X., Xiong, G., Gou, G., Li, Z., Shi, J., Yu, J.: Et-bert: A contextualized datagram representation with pre-training transformers for encrypted traffic classification, in Proceedings of the ACM Web Conference 2022, pp. 633\u2013642. (2022)","DOI":"10.1145\/3485447.3512217"},{"key":"6078_CR17","doi-asserted-by":"crossref","unstructured":"Liu, Y., Wang, X., Qu, B., Zhao, F.: ATVITSC: A novel encrypted traffic classification method based on deep learning. IEEE Trans. Inf. Forensics Secur. 19, 9374\u20139389 (2024)","DOI":"10.1109\/TIFS.2024.3433446"},{"key":"6078_CR18","doi-asserted-by":"crossref","unstructured":"Wang, T., Xie, X., Wang, W., Wang, C., Zhao, Y., Cui, Y.: Netmamba: Efficient network traffic classification via pre-training unidirectional mamba, in IEEE 32nd International Conference on Network Protocols (ICNP), 2024: pp. 1\u201311. (IEEE, 2024)","DOI":"10.1109\/ICNP61940.2024.10858569"},{"issue":"3","key":"6078_CR19","doi-asserted-by":"publisher","first-page":"1785","DOI":"10.1007\/s10586-022-03709-w","volume":"26","author":"C Jiang","year":"2023","unstructured":"Jiang, C., Xu, S., Geng, G., Weng, J., Zhang, X.: Seq2Path: a sequence-to-path-based flow feature fusion approach for encrypted traffic classification. Cluster Comput. 26(3), 1785\u20131800 (2023)","journal-title":"Cluster Comput."},{"key":"6078_CR20","doi-asserted-by":"crossref","unstructured":"Draper-Gil, G., Lashkari, A.H., Mamun, M.S.I., Ghorbani, A.A.: Characterization of encrypted and vpn traffic using time-related, in Proceedings of the 2nd international conference on information systems security and privacy (ICISSP), pp. 407\u2013414. (2016)","DOI":"10.5220\/0005740704070414"},{"key":"6078_CR21","doi-asserted-by":"crossref","unstructured":"Wang, W., Zhu, M., Zeng, X., Ye, X., Sheng, Y.: Malware traffic classification using convolutional neural network for representation learning, in International conference on information networking (ICOIN), 2017: IEEE, pp. 712\u2013717. (2017)","DOI":"10.1109\/ICOIN.2017.7899588"},{"issue":"3","key":"6078_CR22","doi-asserted-by":"publisher","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","volume":"24","author":"M Lotfollahi","year":"2020","unstructured":"Lotfollahi, M., Jafari Siavoshani, M., Shirali Hossein, R., Zade, Saberian, M.: Deep packet: A novel approach for encrypted traffic classification using deep learning. Soft. Comput. 24(3), 1999\u20132012 (2020)","journal-title":"Soft. Comput."},{"issue":"6","key":"6078_CR23","doi-asserted-by":"publisher","first-page":"7493","DOI":"10.1007\/s10586-024-04365-y","volume":"27","author":"R Ahmad","year":"2024","unstructured":"Ahmad, R., Alsmadi, I.: Data fusion and network intrusion detection systems. Cluster Comput. 27(6), 7493\u20137519 (2024)","journal-title":"Cluster Comput."},{"key":"6078_CR24","first-page":"3","volume":"78","author":"H Huang","year":"2024","unstructured":"Huang, H., Zhang, X., Lu, Y., Li, Z., Zhou, S.: BSTFNet: An Encrypted Malicious Traffic Classification Method Integrating Global Semantic and Spatiotemporal Features. Computers Mater. Continua. 78, 3 (2024)","journal-title":"Computers Mater. Continua"},{"issue":"10","key":"6078_CR25","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1145\/3559439","volume":"65","author":"I Akbari","year":"2022","unstructured":"Akbari, I., et al.: Traffic classification in an increasingly encrypted web. Commun. ACM. 65(10), 75\u201383 (2022)","journal-title":"Commun. ACM"},{"issue":"1","key":"6078_CR26","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1109\/TBDATA.2019.2940675","volume":"8","author":"H Yao","year":"2019","unstructured":"Yao, H., Liu, C., Zhang, P., Wu, S., Jiang, C., Yu, S.: Identification of encrypted traffic through attention mechanism based long short term memory. IEEE Trans. big data. 8(1), 241\u2013252 (2019)","journal-title":"IEEE Trans. big data"},{"key":"6078_CR27","doi-asserted-by":"publisher","first-page":"1792","DOI":"10.1109\/ACCESS.2017.2780250","volume":"6","author":"W Wang","year":"2017","unstructured":"Wang, W., et al.: HAST-IDS: Learning hierarchical spatial-temporal features using deep neural networks to improve intrusion detection. IEEE access. 6, 1792\u20131806 (2017)","journal-title":"IEEE access."},{"key":"6078_CR28","doi-asserted-by":"crossref","unstructured":"Zou, Z., Ge, J., Zheng, H., Wu, Y., Han, C., Yao, Z.: Encrypted traffic classification with a convolutional long short-term memory neural network, in IEEE 20th International Conference on High Performance Computing and Communications; IEEE 16th International Conference on Smart City; IEEE 4th International Conference on Data Science and Systems (HPCC\/SmartCity\/DSS), 2018: pp. 329\u2013334. (IEEE, 2018)","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2018.00074"},{"key":"6078_CR29","first-page":"100475","volume":"26","author":"H Huang","year":"2024","unstructured":"Huang, H., Lu, Y., Zhou, S., Zhang, X., Li, Z.: CoTNeT: Contextual transformer network for encrypted traffic classification. Egypt. Inf. J. 26, 100475 (2024)","journal-title":"Egypt. Inf. J."},{"key":"6078_CR30","doi-asserted-by":"publisher","first-page":"103624","DOI":"10.1016\/j.cose.2023.103624","volume":"137","author":"X Li","year":"2024","unstructured":"Li, X., et al.: Let model keep evolving: Incremental learning for encrypted traffic classification. Computers Secur. 137, 103624 (2024)","journal-title":"Computers Secur."},{"issue":"1","key":"6078_CR31","doi-asserted-by":"publisher","first-page":"8995","DOI":"10.1038\/s41598-025-94240-6","volume":"15","author":"S Xu","year":"2025","unstructured":"Xu, S., Han, J., Liu, Y., Liu, H., Bai, Y.: Few-shot traffic classification based on autoencoder and deep graph convolutional networks. Sci. Rep. 15(1), 8995 (2025)","journal-title":"Sci. Rep."}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-026-06078-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10586-026-06078-w","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-026-06078-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T11:32:09Z","timestamp":1781263929000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10586-026-06078-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":31,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["6078"],"URL":"https:\/\/doi.org\/10.1007\/s10586-026-06078-w","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"value":"1386-7857","type":"print"},{"value":"1573-7543","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"24 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 January 2026","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 March 2026","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 June 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics statement"}}],"article-number":"330"}}