{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T12:23:06Z","timestamp":1783513386621,"version":"3.55.0"},"reference-count":43,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.comnet.2026.112477","type":"journal-article","created":{"date-parts":[[2026,6,14]],"date-time":"2026-06-14T17:03:36Z","timestamp":1781456616000},"page":"112477","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["When BERT meets BLOCK: A pre-training and fine-tuning malicious encrypted traffic detection method based on protocol semantic units"],"prefix":"10.1016","volume":"286","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-5574-4257","authenticated-orcid":false,"given":"Yaohui","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6408-2032","authenticated-orcid":false,"given":"DeGang","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7179-140X","authenticated-orcid":false,"given":"Wei","family":"Wan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-5933-1301","authenticated-orcid":false,"given":"Jing","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-7988-8892","authenticated-orcid":false,"given":"Guanyao","family":"Du","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-3463-3635","authenticated-orcid":false,"given":"Chun","family":"Long","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112477_b1","series-title":"An update on android TLS adoption","author":"Bonn\u00e9","year":"2019"},{"key":"10.1016\/j.comnet.2026.112477_b2","series-title":"The Transport Layer Security (TLS) Protocol Version 1.3","author":"Rescorla","year":"2018"},{"issue":"12","key":"10.1016\/j.comnet.2026.112477_b3","first-page":"1","article-title":"Mobile app identification for encrypted network flows by traffic correlation","volume":"14","author":"He","year":"2018","journal-title":"Int. J. Distrib. Sens. Networks"},{"key":"10.1016\/j.comnet.2026.112477_b4","series-title":"Malware is moving heavily to HTTPS","author":"Arna","year":"2019"},{"issue":"16","key":"10.1016\/j.comnet.2026.112477_b5","doi-asserted-by":"crossref","first-page":"3414","DOI":"10.3390\/app9163414","article-title":"An LSTM-based deep learning approach for classifying malicious traffic at the packet level","volume":"9","author":"Hwang","year":"2019","journal-title":"Appl. Sci."},{"key":"10.1016\/j.comnet.2026.112477_b6","series-title":"2017 International Conference on Information Networking","first-page":"712","article-title":"Malware traffic classification using convolutional neural network for representation learning","author":"Wang","year":"2017"},{"key":"10.1016\/j.comnet.2026.112477_b7","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1007\/s11416-017-0306-6","article-title":"Deciphering malware\u2019s use of TLS (without decryption)","volume":"14","author":"Anderson","year":"2018","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"10.1016\/j.comnet.2026.112477_b8","series-title":"IEEE INFOCOM 2019-IEEE Conference on Computer Communications","first-page":"1171","article-title":"FS-Net: A flow sequence network for encrypted traffic classification","author":"Liu","year":"2019"},{"key":"10.1016\/j.comnet.2026.112477_b9","series-title":"IEEE INFOCOM 2019-IEEE Conference on Computer Communications Workshops","first-page":"680","article-title":"FlowPic: Encrypted internet traffic classification is as easy as image recognition","author":"Shapira","year":"2019"},{"key":"10.1016\/j.comnet.2026.112477_b10","article-title":"FlowPrint: Semi-supervised mobile-app fingerprinting on encrypted network traffic","volume":"vol. 27","author":"Ede","year":"2020"},{"key":"10.1016\/j.comnet.2026.112477_b11","first-page":"23477","article-title":"Website fingerprinting at internet scale","volume":"Vol. 1","author":"Panchenko","year":"2016"},{"issue":"1","key":"10.1016\/j.comnet.2026.112477_b12","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1109\/TIFS.2017.2737970","article-title":"Robust smartphone app identification via encrypted network traffic analysis","volume":"13","author":"Taylor","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112477_b13","doi-asserted-by":"crossref","unstructured":"X. Lin, G. Xiong, G. Gou, Z. Li, J. Shi, J. Yu, ET-BERT: A Contextualized Datagram Representation with Pre-Training Transformers for Encrypted Traffic Classification, in: Proceedings of the ACM Web Conference 2022, 2022, pp. 633\u2013642.","DOI":"10.1145\/3485447.3512217"},{"key":"10.1016\/j.comnet.2026.112477_b14","doi-asserted-by":"crossref","unstructured":"J. Devlin, M.-W. Chang, K. Lee, K. Toutanova, BERT: Pre-Training of Deep Bidirectional Transformers for Language Understanding, in: Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers), 2019, pp. 4171\u20134186.","DOI":"10.18653\/v1\/N19-1423"},{"key":"10.1016\/j.comnet.2026.112477_b15","series-title":"2025 IEEE Symposium on Security and Privacy","first-page":"102","article-title":"TrafficFormer: An efficient pre-trained model for traffic data","author":"Zhou","year":"2025"},{"issue":"5","key":"10.1016\/j.comnet.2026.112477_b16","doi-asserted-by":"crossref","first-page":"679","DOI":"10.3390\/electronics11050679","article-title":"Encrypted malicious traffic detection based on Word2Vec","volume":"11","author":"Ferriyan","year":"2022","journal-title":"Electronics"},{"key":"10.1016\/j.comnet.2026.112477_b17","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2022\/6480172","article-title":"GCN-ETA: High-efficiency encrypted malicious traffic detection","author":"Zheng","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"10.1016\/j.comnet.2026.112477_b18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2021\/5363750","article-title":"Anomaly detection in encrypted internet traffic using hybrid deep learning","author":"Bakhshi","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"10.1016\/j.comnet.2026.112477_b19","series-title":"DataCon open dataset: Encrypted malicious traffic dataset (DataCon 2020)","author":"DataCon Community","year":"2021"},{"key":"10.1016\/j.comnet.2026.112477_b20","doi-asserted-by":"crossref","DOI":"10.1109\/TIFS.2025.3560560","article-title":"Robust detection of malicious encrypted traffic via contrastive learning","author":"Shen","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112477_b21","series-title":"Detecting unknown encrypted malicious traffic in real time via flow interaction graph analysis","author":"Fu","year":"2023"},{"issue":"1","key":"10.1016\/j.comnet.2026.112477_b22","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1186\/s42400-024-00301-0","article-title":"EnMob: Unveil the behavior with multi-flow analysis of encrypted app traffic","volume":"8","author":"Mengmeng","year":"2025","journal-title":"Cybersecurity"},{"issue":"1\u20133","key":"10.1016\/j.comnet.2026.112477_b23","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1007\/s10994-014-5473-9","article-title":"Analysis of network traffic features for anomaly detection","volume":"101","author":"Iglesias","year":"2015","journal-title":"Mach. Learn."},{"key":"10.1016\/j.comnet.2026.112477_b24","doi-asserted-by":"crossref","first-page":"385","DOI":"10.1016\/j.neucom.2015.04.101","article-title":"Detection of known and unknown DDoS attacks using artificial neural networks","volume":"172","author":"Saied","year":"2016","journal-title":"Neurocomputing"},{"key":"10.1016\/j.comnet.2026.112477_b25","doi-asserted-by":"crossref","unstructured":"A.G.P. Lobato, M.A. Lopez, I.J. Sanz, A.A. Cardenas, O.C.M.B. Duarte, G. Pujolle, An Adaptive Real-Time Architecture for Zero-Day Threat Detection, in: Proceedings of the IEEE International Conference on Communications, ICC, Waikiki, Hawaii, USA, 2018, pp. 1\u20136.","DOI":"10.1109\/ICC.2018.8422622"},{"key":"10.1016\/j.comnet.2026.112477_b26","series-title":"Proceedings of the International Conference on Neural Information Processing","first-page":"565","article-title":"A grassmannian approach to zero-shot learning for network intrusion detection","author":"Rivero","year":"2017"},{"key":"10.1016\/j.comnet.2026.112477_b27","series-title":"2018 IEEE 38th International Conference on Distributed Computing Systems","first-page":"1595","article-title":"An empirical study on network anomaly detection using convolutional neural networks","author":"Kwon","year":"2018"},{"key":"10.1016\/j.comnet.2026.112477_b28","series-title":"Network traffic anomaly detection using recurrent neural networks","author":"Radford","year":"2018"},{"key":"10.1016\/j.comnet.2026.112477_b29","doi-asserted-by":"crossref","unstructured":"G. Nychis, V. Sekar, D.G. Andersen, H.S. Kim, H. Zhang, An Empirical Evaluation of Entropy-Based Traffic Anomaly Detection, in: ACM\/SIGCOMM Internet Measurement Conference, 2008.","DOI":"10.1145\/1452520.1452539"},{"key":"10.1016\/j.comnet.2026.112477_b30","series-title":"Common Pattern Generation for the Detection of LOLBIN Attacks","author":"AbuShqeir","year":"2023"},{"key":"10.1016\/j.comnet.2026.112477_b31","doi-asserted-by":"crossref","DOI":"10.1155\/2022\/1556768","article-title":"AS-DMF: A lightweight malware encrypted traffic detection method based on active learning and feature selection","author":"Huo","year":"2022","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"10.1016\/j.comnet.2026.112477_b32","series-title":"Improving language understanding by generative pre-training","author":"Radford","year":"2018"},{"key":"10.1016\/j.comnet.2026.112477_b33","doi-asserted-by":"crossref","unstructured":"K. He, H. Fan, Y. Wu, S. Xie, R. Girshick, Momentum Contrast for Unsupervised Visual Representation Learning, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2020, pp. 9729\u20139738.","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"10.1016\/j.comnet.2026.112477_b34","series-title":"International Conference on Machine Learning","first-page":"1597","article-title":"A simple framework for contrastive learning of visual representations","author":"Chen","year":"2020"},{"key":"10.1016\/j.comnet.2026.112477_b35","article-title":"Attention is all you need","volume":"30","author":"Vaswani","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112477_b36","series-title":"BART: Denoising sequence-to-sequence pre-training for natural language generation, translation, and comprehension","author":"Lewis","year":"2019"},{"key":"10.1016\/j.comnet.2026.112477_b37","first-page":"5420","article-title":"Yet another traffic classifier: A masked autoencoder based traffic transformer with multi-level flow representation","volume":"vol. 37","author":"Zhao","year":"2023"},{"key":"10.1016\/j.comnet.2026.112477_b38","doi-asserted-by":"crossref","unstructured":"P. Sirinam, M. Imani, M. Juarez, M. Wright, Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep Learning, in: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018, pp. 1928\u20131943.","DOI":"10.1145\/3243734.3243768"},{"key":"10.1016\/j.comnet.2026.112477_b39","series-title":"Bidirectional LSTM-CRF models for sequence tagging","author":"Huang","year":"2015"},{"key":"10.1016\/j.comnet.2026.112477_b40","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2022.109467","article-title":"Fine-grained TLS services classification with reject option","volume":"220","author":"Luxemburk","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112477_b41","series-title":"Decoupled weight decay regularization","author":"Loshchilov","year":"2017"},{"key":"10.1016\/j.comnet.2026.112477_b42","doi-asserted-by":"crossref","unstructured":"T. Chen, C. Guestrin, XGBoost: A Scalable Tree Boosting System, in: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016, pp. 785\u2013794.","DOI":"10.1145\/2939672.2939785"},{"key":"10.1016\/j.comnet.2026.112477_b43","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","article-title":"An empirical comparison of botnet detection methods","volume":"45","author":"Garcia","year":"2014","journal-title":"Comput. Secur."}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004895?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004895?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:57:25Z","timestamp":1783511845000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626004895"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":43,"alternative-id":["S1389128626004895"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112477","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"When BERT meets BLOCK: A pre-training and fine-tuning malicious encrypted traffic detection method based on protocol semantic units","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112477","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112477"}}