{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T12:08:33Z","timestamp":1779365313178,"version":"3.53.0"},"reference-count":47,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.comnet.2026.112341","type":"journal-article","created":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T21:59:59Z","timestamp":1777586399000},"page":"112341","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["EN-Fusion: Malware detection through end-net fusion representation"],"prefix":"10.1016","volume":"284","author":[{"given":"Ziqian","family":"Chen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Xia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gang","family":"Xiong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gaopeng","family":"Gou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhen","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haikuo","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112341_b1","doi-asserted-by":"crossref","DOI":"10.1145\/3395233","article-title":"Cosense: The collaborative sensing middleware for the internet-of-things","volume":"1","author":"Schmei\u00dfer","year":"2020","journal-title":"ACM\/IMS Trans. Data Sci."},{"key":"10.1016\/j.comnet.2026.112341_b2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.jpdc.2022.01.029","article-title":"SG-PBFT: A secure and highly efficient distributed blockchain pbft consensus algorithm for intelligent internet of vehicles","volume":"164","author":"Xu","year":"2022","journal-title":"J. Parallel Distrib. Comput."},{"issue":"2","key":"10.1016\/j.comnet.2026.112341_b3","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MC.2017.62","article-title":"Botnets and internet of things security","volume":"50","author":"Bertino","year":"2017","journal-title":"Computer"},{"issue":"1","key":"10.1016\/j.comnet.2026.112341_b4","doi-asserted-by":"crossref","first-page":"402","DOI":"10.1109\/TDSC.2020.2979183","article-title":"Inferring and investigating IoT-generated scanning campaigns targeting a large network telescope","volume":"19","author":"Torabi","year":"2022","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"issue":"7","key":"10.1016\/j.comnet.2026.112341_b5","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MC.2017.201","article-title":"Ddos in the IoT: Mirai and other botnets","volume":"50","author":"Kolias","year":"2017","journal-title":"Computer"},{"key":"10.1016\/j.comnet.2026.112341_b6","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107391","article-title":"Detection of zero-day attacks: An unsupervised port-based approach","volume":"180","author":"Blaise","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112341_b7","doi-asserted-by":"crossref","first-page":"284","DOI":"10.1016\/j.ins.2019.09.024","article-title":"BotMark: Automated botnet detection with hybrid analysis of flow-based and graph-based traffic behaviors","volume":"511","author":"Wang","year":"2020","journal-title":"Inform. Sci."},{"issue":"6","key":"10.1016\/j.comnet.2026.112341_b8","doi-asserted-by":"crossref","first-page":"3692","DOI":"10.1109\/TII.2021.3108464","article-title":"Concept drift analysis by dynamic residual projection for effectively detecting botnet cyber-attacks in IoT scenarios","volume":"18","author":"Qiao","year":"2022","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"10.1016\/j.comnet.2026.112341_b9","doi-asserted-by":"crossref","first-page":"544","DOI":"10.1016\/j.future.2017.07.060","article-title":"Internet of things security and forensics: Challenges and opportunities","volume":"78","author":"Conti","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.comnet.2026.112341_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2022.109365","article-title":"A real-time IoT-based botnet detection method using a novel two-step feature selection technique and the support vector machine classifier","volume":"217","author":"Masoudi-Sobhanzadeh","year":"2022","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112341_b11","doi-asserted-by":"crossref","first-page":"405","DOI":"10.1016\/j.comcom.2022.06.016","article-title":"A discrete time-varying greywolf IoT botnet detection system","volume":"192","author":"Alazab","year":"2022","journal-title":"Comput. Commun."},{"key":"10.1016\/j.comnet.2026.112341_b12","doi-asserted-by":"crossref","first-page":"6871","DOI":"10.1109\/TIFS.2024.3426304","article-title":"Ecnet: Robust malicious network traffic detection with multi-view feature and confidence mechanism","volume":"19","author":"Han","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"10.1016\/j.comnet.2026.112341_b13","doi-asserted-by":"crossref","first-page":"1199","DOI":"10.1109\/TNSM.2022.3200741","article-title":"Effective multitask deep learning for IoT malware detection and identification using behavioral traffic analysis","volume":"20","author":"Ali","year":"2023","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.comnet.2026.112341_b14","doi-asserted-by":"crossref","first-page":"7721","DOI":"10.1007\/s00500-022-06750-4","article-title":"Hybrid deep-learning model to detect botnet attacks over internet of things environments","volume":"26","author":"Alzahrani","year":"2021","journal-title":"Soft Comput."},{"key":"10.1016\/j.comnet.2026.112341_b15","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1016\/j.engappai.2016.12.016","article-title":"MAAR: Robust features to detect malicious activity based on API calls, their arguments and return values","volume":"59","author":"Salehi","year":"2017","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"1","key":"10.1016\/j.comnet.2026.112341_b16","doi-asserted-by":"crossref","first-page":"921","DOI":"10.1109\/TII.2022.3192044","article-title":"Unsupervised learning for feature selection: A proposed solution for botnet detection in 5G networks","volume":"19","author":"Lefoane","year":"2023","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"10.1016\/j.comnet.2026.112341_b17","doi-asserted-by":"crossref","DOI":"10.1002\/int.23074","article-title":"IoT botnet detection with feature reconstruction and interval optimization","volume":"37","author":"Yang","year":"2022","journal-title":"Int. J. Intell. Syst."},{"key":"10.1016\/j.comnet.2026.112341_b18","doi-asserted-by":"crossref","DOI":"10.1016\/j.infsof.2020.106273","article-title":"Detection of malicious software by analyzing the behavioral artifacts using machine learning algorithms","volume":"121","author":"Singh","year":"2020","journal-title":"Inf. Softw. Technol."},{"issue":"1","key":"10.1016\/j.comnet.2026.112341_b19","doi-asserted-by":"crossref","first-page":"518","DOI":"10.1109\/TDSC.2024.3406699","article-title":"SUNDEW: A case-sensitive detection engine to counter malware diversity","volume":"22","author":"Karapoola","year":"2025","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.comnet.2026.112341_b20","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1016\/j.cose.2015.04.001","article-title":"AMAL: High-fidelity, behavior-based automated malware analysis and classification","volume":"52","author":"Mohaisen","year":"2015","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b21","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103734","article-title":"Bitcn-taEfficientNet malware classification approach based on sequence and RGB fusion","volume":"139","author":"Xuan","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b22","doi-asserted-by":"crossref","first-page":"1142","DOI":"10.1109\/TIFS.2023.3328431","article-title":"ResNeXt+: Attention mechanisms based on ResNeXt for malware detection and classification","volume":"19","author":"He","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"05","key":"10.1016\/j.comnet.2026.112341_b23","doi-asserted-by":"crossref","first-page":"4376","DOI":"10.1109\/TDSC.2024.3352604","article-title":"Toward Enhancing Sequence-Optimized Malware Representation With Context-Separated Bi-Directional Long Short-Term Memory and Proximal Policy Optimization","volume":"21","author":"Xie","year":"2024","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.comnet.2026.112341_b24","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103518","article-title":"CTIMD: Cyber threat intelligence enhanced malware detection using api call sequences with parameters","volume":"136","author":"Chen","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b25","doi-asserted-by":"crossref","first-page":"788","DOI":"10.1109\/TIFS.2022.3152360","article-title":"CruParamer: Learning on parameter-augmented API sequences for malware detection","volume":"17","author":"Chen","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112341_b26","doi-asserted-by":"crossref","first-page":"6128","DOI":"10.1109\/TIFS.2024.3407655","article-title":"SIa-cbc: Sensitive intent-assisted and crucial behavior-cognized malware detection based on human brain cognitive theory","volume":"19","author":"Jing","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112341_b27","series-title":"AAAI Conference on Artificial Intelligence","article-title":"Dynamic malware analysis with feature engineering and feature learning","author":"Zhang","year":"2019"},{"key":"10.1016\/j.comnet.2026.112341_b28","doi-asserted-by":"crossref","first-page":"2076","DOI":"10.1109\/TIFS.2023.3262121","article-title":"Real-time malicious traffic detection with online isolation forest over SD-WAN","volume":"18","author":"Zhang","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112341_b29","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102693","article-title":"Machine learning-based early detection of IoT botnets using network-edge traffic","volume":"117","author":"Kumar","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b30","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103064","article-title":"Intelligent IoT-BOTNET attack detection model with optimized hybrid classification model","volume":"126","author":"Bojarajulu","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b31","series-title":"Proceedings of the ACM Web Conference 2024","first-page":"1680","article-title":"Contramtd: An unsupervised malicious network traffic detection method based on contrastive learning","author":"Han","year":"2024"},{"key":"10.1016\/j.comnet.2026.112341_b32","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111147","article-title":"MTCR-AE: A multiscale temporal convolutional recurrent autoencoder for unsupervised malicious network traffic detection","volume":"261","author":"Ahmed","year":"2025","journal-title":"Comput. Netw."},{"issue":"C","key":"10.1016\/j.comnet.2026.112341_b33","article-title":"DawnGNN: Documentation augmented windows malware detection using graph neural network","volume":"140","author":"Feng","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b34","series-title":"Whitening sentence representations for better semantics and faster retrieval","author":"Su","year":"2021"},{"key":"10.1016\/j.comnet.2026.112341_b35","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111636","article-title":"EMTD: Efficient encrypted malware traffic detection based on adaptive meta-path guided graph propagation","volume":"271","author":"Zeng","year":"2025","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112341_b36","doi-asserted-by":"crossref","first-page":"7705","DOI":"10.1109\/TIFS.2024.3443596","article-title":"GraphTunnel: Robust DNS tunnel detection based on DNS recursive resolution graph","volume":"19","author":"Gao","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112341_b37","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1016\/j.comcom.2022.06.039","article-title":"BotStop: Packet-based efficient and explainable IoT botnet detection using machine learning","volume":"193","author":"Alani","year":"2022","journal-title":"Comput. Commun."},{"key":"10.1016\/j.comnet.2026.112341_b38","series-title":"Computer Security \u2013 ESORICS 2021","first-page":"605","article-title":"LiMNet: Early-stage detection of IoT botnets with lightweight memory networks","author":"Giaretta","year":"2021"},{"key":"10.1016\/j.comnet.2026.112341_b39","series-title":"WWW \u201922: The ACM Web Conference 2022, Virtual Event, Lyon, France, April 25 - 29, 2022","first-page":"633","article-title":"ET-BERT: a contextualized datagram representation with pre-training transformers for encrypted traffic classification","author":"Lin","year":"2022"},{"key":"10.1016\/j.comnet.2026.112341_b40","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107247","article-title":"Building an efficient intrusion detection system based on feature selection and ensemble classifier","volume":"174","author":"Zhou","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112341_b41","series-title":"Proceedings of the Canadian Conference on Artificial Intelligence","article-title":"Detecting malicious .net files using CLR header features and machine learning","author":"Hassan","year":"2023"},{"key":"10.1016\/j.comnet.2026.112341_b42","series-title":"Avast-CTU public CAPE dataset","author":"Bosansky","year":"2022"},{"key":"10.1016\/j.comnet.2026.112341_b43","series-title":"MedBIoT: Generation of an IoT botnet dataset in a medium-sized IoT network","author":"Guerra-Manzanares","year":"2020"},{"key":"10.1016\/j.comnet.2026.112341_b44","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103752","article-title":"TS-mal: Malware detection model using temporal and structural features learning","volume":"140","author":"Li","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b45","series-title":"2025 International Joint Conference on Neural Networks","first-page":"1","article-title":"Malse: Malware detection based on multi-dimensional API call sensitivity estimation","author":"Chen","year":"2025"},{"key":"10.1016\/j.comnet.2026.112341_b46","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102684","article-title":"Chameleon: Optimized feature selection using particle swarm optimization and ensemble methods for network anomaly detection","volume":"117","author":"Chohra","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112341_b47","series-title":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing","first-page":"1","article-title":"ANASETC: Automatic neural architecture search for encrypted traffic classification","author":"Zhang","year":"2025"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626003531?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626003531?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T11:33:40Z","timestamp":1779363220000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626003531"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":47,"alternative-id":["S1389128626003531"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112341","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"EN-Fusion: Malware detection through end-net fusion representation","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112341","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112341"}}