{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T17:59:01Z","timestamp":1785175141023,"version":"3.55.0"},"reference-count":177,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T00:00:00Z","timestamp":1783382400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100007129","name":"Shandong Province Natural Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.comnet.2026.112524","type":"journal-article","created":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T06:48:09Z","timestamp":1783147689000},"page":"112524","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["A comprehensive survey on encrypted network traffic classification"],"prefix":"10.1016","volume":"287","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1976-7856","authenticated-orcid":false,"given":"Shangbin","family":"Han","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Han","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mengmeng","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sifang","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boyuan","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jilong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112524_b1","series-title":"Google transparency report","author":"Google","year":"2025"},{"key":"10.1016\/j.comnet.2026.112524_b2","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1109\/TMLCN.2023.3323915","article-title":"WFF-EGNN: Encrypted traffic classification based on weaved flow fragment via ensemble graph neural networks","volume":"1","author":"Chen","year":"2023","journal-title":"IEEE Trans. Mach. Learn. Commun. Netw."},{"issue":"2","key":"10.1016\/j.comnet.2026.112524_b3","doi-asserted-by":"crossref","DOI":"10.1016\/j.asej.2023.102361","article-title":"Encrypted network traffic classification based on machine learning","volume":"15","author":"Elmaghraby","year":"2024","journal-title":"Ain Shams Eng. J."},{"key":"10.1016\/j.comnet.2026.112524_b4","series-title":"Encrypted threats surge to 87 percent of all cyber threats","author":"Zscaler","year":"2024"},{"issue":"10","key":"10.1016\/j.comnet.2026.112524_b5","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1145\/3559439","article-title":"Traffic classification in an increasingly encrypted web","volume":"65","author":"Akbari","year":"2022","journal-title":"Commun. ACM"},{"key":"10.1016\/j.comnet.2026.112524_b6","series-title":"2021 IEEE International Conference on Cyber Security and Resilience","first-page":"89","article-title":"Using deep packet inspection in cybertraffic analysis","author":"Deri","year":"2021"},{"issue":"5","key":"10.1016\/j.comnet.2026.112524_b7","doi-asserted-by":"crossref","first-page":"355","DOI":"10.1002\/nem.1901","article-title":"A survey of methods for encrypted traffic classification and analysis","volume":"25","author":"Velan","year":"2015","journal-title":"Int. J. Netw. Manage."},{"issue":"6","key":"10.1016\/j.comnet.2026.112524_b8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3457904","article-title":"A survey on encrypted network traffic analysis applications, techniques, and countermeasures","volume":"54","author":"Papadogiannaki","year":"2021","journal-title":"ACM Comput. Surv."},{"issue":"4","key":"10.1016\/j.comnet.2026.112524_b9","doi-asserted-by":"crossref","first-page":"873","DOI":"10.1007\/s10207-022-00581-y","article-title":"A survey on analyzing encrypted network traffic of mobile devices","volume":"21","author":"Agrawal","year":"2022","journal-title":"Int. J. Inf. Secur."},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b10","doi-asserted-by":"crossref","first-page":"791","DOI":"10.1109\/COMST.2022.3208196","article-title":"Machine learning-powered encrypted network traffic analysis: A comprehensive survey","volume":"25","author":"Shen","year":"2022","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"11","key":"10.1016\/j.comnet.2026.112524_b11","doi-asserted-by":"crossref","first-page":"3509","DOI":"10.3390\/s24113509","article-title":"Encrypted network traffic analysis and classification utilizing machine learning","volume":"24","author":"Alwhbi","year":"2024","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112524_b12","series-title":"Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","first-page":"1723","article-title":"Machine learning for encrypted malware traffic classification: accounting for noisy labels and non-stationarity","author":"Anderson","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b13","series-title":"IPSec: Securing VPNs","author":"Davis","year":"2001"},{"key":"10.1016\/j.comnet.2026.112524_b14","series-title":"What is a vpn?","author":"Ferguson","year":"1998"},{"key":"10.1016\/j.comnet.2026.112524_b15","first-page":"303","article-title":"Tor: The second-generation onion router","volume":"vol. 4","author":"Dingledine","year":"2004"},{"key":"10.1016\/j.comnet.2026.112524_b16","series-title":"SSL and TLS: Theory and Practice","author":"Oppliger","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b17","doi-asserted-by":"crossref","unstructured":"E. Rescorla, The transport layer security (TLS) protocol version 1.3, Tech. rep., 2018.","DOI":"10.17487\/RFC8446"},{"key":"10.1016\/j.comnet.2026.112524_b18","series-title":"Proceedings of the Conference of the ACM Special Interest Group on Data Communication","first-page":"183","article-title":"The quic transport protocol: Design and internet-scale deployment","author":"Langley","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b19","series-title":"TCP\/IP illustrated, volume 2: The implementation","author":"Wright","year":"1995"},{"key":"10.1016\/j.comnet.2026.112524_b20","doi-asserted-by":"crossref","unstructured":"J. Postel, User datagram protocol, Tech. rep., 1980.","DOI":"10.17487\/RFC768"},{"key":"10.1016\/j.comnet.2026.112524_b21","doi-asserted-by":"crossref","unstructured":"J. Postel, Internet control message protocol, Tech. rep., 1981.","DOI":"10.17487\/RFC777"},{"key":"10.1016\/j.comnet.2026.112524_b22","series-title":"SNMP, SNMPv2, SNMPv3, and RMON 1 and 2","author":"Stallings","year":"1998"},{"key":"10.1016\/j.comnet.2026.112524_b23","doi-asserted-by":"crossref","unstructured":"B. Claise, Cisco systems netflow services export version 9, Tech. rep., 2004.","DOI":"10.17487\/rfc3954"},{"key":"10.1016\/j.comnet.2026.112524_b24","doi-asserted-by":"crossref","unstructured":"B. Claise, Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information, Tech. rep., 2008.","DOI":"10.17487\/rfc5101"},{"key":"10.1016\/j.comnet.2026.112524_b25","series-title":"Proceedings of the 17th International Conference on Availability, Reliability and Security","first-page":"1","article-title":"Image-based neural network models for malware traffic classification using pcap to picture conversion","author":"Agrafiotis","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b26","first-page":"2008","article-title":"Programming with libpcap-sniffing the network from our own application","volume":"2","author":"Garcia","year":"2008","journal-title":"Hakin9-Computer Secur. Mag."},{"key":"10.1016\/j.comnet.2026.112524_b27","series-title":"2024 2nd International Conference on Self Sustainable Artificial Intelligence Systems","first-page":"1212","article-title":"Automated implementation of a TCPDUMP solution for network traffic analysis, strengthening digital security in cyberspace","author":"Colca-Mendoza","year":"2024"},{"key":"10.1016\/j.comnet.2026.112524_b28","series-title":"Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems","author":"Sanders","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b29","series-title":"2008 11th IEEE Workshop on Design and Diagnostics of Electronic Circuits and Systems","first-page":"1","article-title":"Network probe for flexible flow monitoring","author":"Zadnik","year":"2008"},{"key":"10.1016\/j.comnet.2026.112524_b30","series-title":"Proceedings of the 2nd International Conference on Information Systems Security and Privacy","first-page":"407","article-title":"Characterization of encrypted and vpn traffic using time-related","author":"Draper-Gil","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b31","first-page":"253","article-title":"Characterization of tor traffic using time based features","volume":"vol. 2","author":"Lashkari","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b32","series-title":"2018 IEEE\/ACM 26th International Symposium on Quality of Service (IWQoS)","first-page":"1","article-title":"Mampf: Encrypted traffic classification based on multi-attribute markov probability fingerprints","author":"Liu","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b33","series-title":"Proceedings of the ACM Web Conference 2022","first-page":"633","article-title":"Et-bert: A contextualized datagram representation with pre-training transformers for encrypted traffic classification","author":"Lin","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b34","series-title":"How to achieve high classification accuracy with just a few labels: A semi-supervised approach using sampled packets","author":"Rezaei","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b35","doi-asserted-by":"crossref","DOI":"10.1016\/j.dib.2023.108888","article-title":"CESNET-QUIC22: A large one-month QUIC network traffic dataset from backbone lines","volume":"46","author":"Luxemburk","year":"2023","journal-title":"Data Brief"},{"key":"10.1016\/j.comnet.2026.112524_b36","series-title":"2017 14th IEEE Annual Consumer Communications & Networking Conference","first-page":"1","article-title":"Analyzing HTTPS encrypted traffic to identify user\u2019s operating system, browser and application","author":"Muehlstein","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b37","series-title":"Selenium automates browsers","author":"Selenium","year":"2025"},{"key":"10.1016\/j.comnet.2026.112524_b38","series-title":"Splitcap - pcap file splitter","author":"SplitCap","year":"2025"},{"key":"10.1016\/j.comnet.2026.112524_b39","series-title":"Proceedings of the 37th Annual Computer Security Applications Conference","first-page":"1025","article-title":"Mappgraph: Mobile-app classification on encrypted network traffic using deep graph convolution neural networks","author":"Pham","year":"2021"},{"issue":"22","key":"10.1016\/j.comnet.2026.112524_b40","doi-asserted-by":"crossref","first-page":"11731","DOI":"10.3390\/app122211731","article-title":"A3c system: one-stop automated encrypted traffic labeled sample collection, construction and correlation in multi-systems","volume":"12","author":"Chen","year":"2022","journal-title":"Appl. Sci."},{"key":"10.1016\/j.comnet.2026.112524_b41","series-title":"2015 Military Communications and Information Systems Conference (MilCIS)","first-page":"1","article-title":"UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set)","author":"Moustafa","year":"2015"},{"key":"10.1016\/j.comnet.2026.112524_b42","series-title":"NSL kdd dataset","author":"of Cyber Security","year":"2009"},{"issue":"2018","key":"10.1016\/j.comnet.2026.112524_b43","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization.","volume":"1","author":"Sharafaldin","year":"2018","journal-title":"ICISSp"},{"key":"10.1016\/j.comnet.2026.112524_b44","series-title":"DATACON: open dataset for network security research","author":"Qianxin","year":"2020"},{"issue":"17","key":"10.1016\/j.comnet.2026.112524_b45","doi-asserted-by":"crossref","first-page":"7868","DOI":"10.3390\/app11177868","article-title":"Generating network intrusion detection dataset based on real and encrypted synthetic attack traffic","volume":"11","author":"Ferriyan","year":"2021","journal-title":"Appl. Sci."},{"key":"10.1016\/j.comnet.2026.112524_b46","series-title":"2017 International Conference on Information Networking","first-page":"712","article-title":"Malware traffic classification using convolutional neural network for representation learning","author":"Wang","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b47","series-title":"Stratosphere laboratory datasets","author":"Stratosphere","year":"2015"},{"key":"10.1016\/j.comnet.2026.112524_b48","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1016\/j.comcom.2023.10.011","article-title":"OSF-EIMTC: An open-source framework for standardized encrypted internet traffic classification","volume":"213","author":"Bader","year":"2024","journal-title":"Comput. Commun."},{"key":"10.1016\/j.comnet.2026.112524_b49","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2023.103603","article-title":"IP traffic behavior characterization via semantic mining","volume":"213","author":"Zang","year":"2023","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112524_b50","unstructured":"G. Zhou, Z. Liu, C. Fu, Q. Li, K. Xu, An efficient design of intelligent network data plane, in: 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 6203\u20136220."},{"issue":"3","key":"10.1016\/j.comnet.2026.112524_b51","doi-asserted-by":"crossref","first-page":"1071","DOI":"10.1109\/TNET.2022.3209979","article-title":"A two-phase approach to fast and accurate classification of encrypted traffic","volume":"31","author":"Wang","year":"2022","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b52","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110591","article-title":"Incremental encrypted traffic classification via contrastive prototype networks","volume":"250","author":"Cai","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b53","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104134","article-title":"A graph representation framework for encrypted network traffic classification","volume":"148","author":"Okonkwo","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112524_b54","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2024.111423","article-title":"Interaction matters: Encrypted traffic classification via status-based interactive behavior graph","volume":"155","author":"Li","year":"2024","journal-title":"Appl. Soft Comput."},{"key":"10.1016\/j.comnet.2026.112524_b55","doi-asserted-by":"crossref","DOI":"10.1109\/TNSM.2025.3543903","article-title":"VPN-encrypted network traffic classification using a time-series approach","author":"Kotak","year":"2025","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.comnet.2026.112524_b56","series-title":"Low-quality training data only? A robust framework for detecting encrypted malicious network traffic","author":"Qing","year":"2023"},{"issue":"2","key":"10.1016\/j.comnet.2026.112524_b57","doi-asserted-by":"crossref","first-page":"1218","DOI":"10.1109\/TNSM.2021.3071441","article-title":"FlowPic: A generic representation for encrypted traffic classification and applications identification","volume":"18","author":"Shapira","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"issue":"9","key":"10.1016\/j.comnet.2026.112524_b58","doi-asserted-by":"crossref","first-page":"10741","DOI":"10.1007\/s10489-021-03032-8","article-title":"MTT: an efficient model for encrypted network traffic classification using multi-task transformer","volume":"52","author":"Zheng","year":"2022","journal-title":"Appl. Intell."},{"key":"10.1016\/j.comnet.2026.112524_b59","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110973","article-title":"EAPT: An encrypted traffic classification model via adversarial pre-trained transformers","volume":"257","author":"Zhan","year":"2025","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b60","series-title":"Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security","first-page":"35","article-title":"Identifying encrypted malware traffic with contextual flow data","author":"Anderson","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b61","series-title":"NOMS 2018-2018 IEEE\/IFIP Network Operations and Management Symposium","first-page":"1","article-title":"Fingerprinting encrypted network traffic types using machine learning","author":"Leroux","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b62","series-title":"IEEE INFOCOM 2020-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS)","first-page":"1348","article-title":"Encrypted malware traffic detection using incremental learning","author":"Lee","year":"2020"},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b63","article-title":"GCN-eta: High-efficiency encrypted malicious traffic detection","volume":"2022","author":"Zheng","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b64","series-title":"Integrating explainable ai for effective malware detection in encrypted network traffic","author":"Zeleke","year":"2025"},{"key":"10.1016\/j.comnet.2026.112524_b65","series-title":"International Symposium on Experimental Algorithms","first-page":"373","article-title":"Realtime classification for encrypted traffic","author":"Bar-Yanai","year":"2010"},{"key":"10.1016\/j.comnet.2026.112524_b66","article-title":"Mixture models. Inference and applications to clustering","author":"McLachlan","year":"1988","journal-title":"Stat. Textb. Monogr."},{"key":"10.1016\/j.comnet.2026.112524_b67","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110598","article-title":"Encrypted malicious traffic detection based on natural language processing and deep learning","volume":"250","author":"Zang","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b68","series-title":"2023 IFIP Networking Conference (IFIP Networking)","first-page":"1","article-title":"FSTC: Dynamic category adaptation for encrypted network traffic classification","author":"Malekghaini","year":"2023"},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b69","article-title":"Anomaly detection in encrypted internet traffic using hybrid deep learning","volume":"2021","author":"Bakhshi","year":"2021","journal-title":"Secur. Commun. Netw."},{"issue":"4","key":"10.1016\/j.comnet.2026.112524_b70","doi-asserted-by":"crossref","first-page":"3746","DOI":"10.1109\/TVT.2021.3063738","article-title":"Sequential message characterization for early classification of encrypted internet traffic","volume":"70","author":"Chen","year":"2021","journal-title":"IEEE Trans. Veh. Technol."},{"issue":"13","key":"10.1016\/j.comnet.2026.112524_b71","doi-asserted-by":"crossref","first-page":"5941","DOI":"10.3390\/s23135941","article-title":"CicIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment","volume":"23","author":"Neto","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112524_b72","series-title":"Proceedings of the 8th International Conference on Communication and Information Processing","first-page":"101","article-title":"An encrypted traffic classification method based on contrastive learning","author":"Tian","year":"2022"},{"issue":"6","key":"10.1016\/j.comnet.2026.112524_b73","doi-asserted-by":"crossref","first-page":"1326","DOI":"10.1016\/j.comnet.2010.12.002","article-title":"Can encrypted traffic be identified without port numbers, IP addresses and payload inspection?","volume":"55","author":"Alshammari","year":"2011","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b74","doi-asserted-by":"crossref","unstructured":"R. Fontugne, P. Borgnat, P. Abry, K. Fukuda, MAWILab: Combining Diverse Anomaly Detectors for Automated Anomaly Labeling and Performance Benchmarking, in: ACM CoNEXT \u201910, Philadelphia, PA, 2010, http:\/\/dx.doi.org\/10.1145\/1921168.1921179.","DOI":"10.1145\/1921168.1921179"},{"key":"10.1016\/j.comnet.2026.112524_b75","series-title":"Skype traces","author":"Tstat","year":"2006"},{"issue":"4","key":"10.1016\/j.comnet.2026.112524_b76","doi-asserted-by":"crossref","first-page":"3843","DOI":"10.1109\/TVT.2019.2894290","article-title":"A heuristic statistical testing based approach for encrypted network traffic identification","volume":"68","author":"Niu","year":"2019","journal-title":"IEEE Trans. Veh. Technol."},{"key":"10.1016\/j.comnet.2026.112524_b77","series-title":"Proceedings of the 7th Symposium on Information and Communication Technology","first-page":"147","article-title":"Learning from imbalanced data for encrypted traffic identification problem","author":"Vu","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b78","article-title":"C4. 5, class imbalance, and cost sensitivity: why under-sampling beats over-sampling","volume":"vol. 11","author":"Drummond","year":"2003"},{"issue":"3","key":"10.1016\/j.comnet.2026.112524_b79","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1109\/TIT.1968.1054155","article-title":"The condensed nearest neighbor rule (corresp.)","volume":"14","author":"Hart","year":"1968","journal-title":"IEEE Trans. Inform. Theory"},{"key":"10.1016\/j.comnet.2026.112524_b80","first-page":"10","article-title":"Learning from imbalanced data sets: a comparison of various strategies","volume":"vol. 68","author":"Japkowicz","year":"2000"},{"key":"10.1016\/j.comnet.2026.112524_b81","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: synthetic minority over-sampling technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artificial Intelligence Res."},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b82","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1504\/IJKESDP.2011.039875","article-title":"Borderline over-sampling for imbalanced data classification","volume":"3","author":"Nguyen","year":"2011","journal-title":"Int. J. Knowl. Eng. Soft Data Parad."},{"key":"10.1016\/j.comnet.2026.112524_b83","series-title":"2018 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA)","first-page":"1","article-title":"Multilayer perceptron neural network for detection of encrypted vpn network traffic","author":"Miller","year":"2018"},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b84","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1109\/TBDATA.2019.2940675","article-title":"Identification of encrypted traffic through attention mechanism based long short term memory","volume":"8","author":"Yao","year":"2019","journal-title":"IEEE Trans. Big Data"},{"key":"10.1016\/j.comnet.2026.112524_b85","doi-asserted-by":"crossref","unstructured":"Z. Yang, D. Yang, C. Dyer, X. He, A. Smola, E. Hovy, Hierarchical attention networks for document classification, in: Proceedings of the 2016 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, 2016, pp. 1480\u20131489.","DOI":"10.18653\/v1\/N16-1174"},{"key":"10.1016\/j.comnet.2026.112524_b86","series-title":"2021 22nd Asia-Pacific Network Operations and Management Symposium","first-page":"238","article-title":"Encrypted network traffic identification based on 2d-cnn model","author":"Zhou","year":"2021"},{"key":"10.1016\/j.comnet.2026.112524_b87","series-title":"Proceedings of the 2023 on Systems and Network Telemetry and Analytics","first-page":"9","article-title":"Insights into doh: Traffic classification for dns over https in an encrypted network","author":"Bannat Wala","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b88","series-title":"2017 Fifth International Conference on Advanced Cloud and Big Data","first-page":"279","article-title":"Identifying mobile applications for encrypted network traffic","author":"He","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b89","series-title":"International Symposium on Research in Attacks, Intrusions, and Defenses","first-page":"315","article-title":"Otter: A scalable high-resolution encrypted traffic identification engine","author":"Papadogiannaki","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b90","series-title":"Network and Distributed System Security Symposium","article-title":"Flowprint: Semi-supervised mobile-app fingerprinting on encrypted network traffic","volume":"27","author":"Van Ede","year":"2020"},{"key":"10.1016\/j.comnet.2026.112524_b91","series-title":"IEEE INFOCOM 2014-IEEE Conference on Computer Communications","first-page":"781","article-title":"Markov chain fingerprinting to classify encrypted traffic","author":"Korczy\u0144ski","year":"2014"},{"issue":"11","key":"10.1016\/j.comnet.2026.112524_b92","doi-asserted-by":"crossref","first-page":"2916","DOI":"10.1109\/TIFS.2019.2911156","article-title":"HEDGE: efficient traffic classification of encrypted and compressed packets","volume":"14","author":"Casino","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112524_b93","series-title":"Proceedings of the 32nd Annual Conference on Computer Security Applications","first-page":"177","article-title":"Adaptive encrypted traffic fingerprinting with bi-directional dependence","author":"Al-Naami","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b94","series-title":"2018 IEEE Symposium on Computers and Communications","first-page":"1","article-title":"Lafft: Length-aware fft based fingerprinting for encrypted network traffic classification","author":"Liu","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b95","series-title":"2016 IEEE European Symposium on Security and Privacy (EuroS&P)","first-page":"439","article-title":"Appscanner: Automatic fingerprinting of smartphone apps from encrypted network traffic","author":"Taylor","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b96","series-title":"IEEE INFOCOM 2019-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS)","first-page":"84","article-title":"Early online classification of encrypted traffic streams using multi-fractal features","author":"Arestr\u00f6m","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b97","doi-asserted-by":"crossref","first-page":"2166","DOI":"10.1109\/TIFS.2022.3179955","article-title":"Seeing traffic paths: Encrypted traffic classification with path signature features","volume":"17","author":"Xu","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112524_b98","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104283","article-title":"Unveiling traffic paths: Explainable path signature feature-based encrypted traffic classification","volume":"150","author":"Xu","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112524_b99","series-title":"Proceedings of the 13th ACM Conference on Computer and Communications Security","first-page":"255","article-title":"Inferring the source of encrypted HTTP connections","author":"Liberatore","year":"2006"},{"key":"10.1016\/j.comnet.2026.112524_b100","unstructured":"T. Wang, X. Cai, R. Nithyanand, R. Johnson, I. Goldberg, Effective attacks and provable defenses for website fingerprinting, in: 23rd USENIX Security Symposium (USENIX Security 14), 2014, pp. 143\u2013157."},{"key":"10.1016\/j.comnet.2026.112524_b101","series-title":"HTTPS websites dataset","author":"Wazen","year":"2016"},{"issue":"3","key":"10.1016\/j.comnet.2026.112524_b102","doi-asserted-by":"crossref","first-page":"842","DOI":"10.1109\/TNSM.2019.2933155","article-title":"Transparent and service-agnostic monitoring of encrypted web traffic","volume":"16","author":"Brissaud","year":"2019","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.comnet.2026.112524_b103","article-title":"A unified approach to interpreting model predictions","volume":"30","author":"Lundberg","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112524_b104","series-title":"2018 18th International Symposium on Communications and Information Technologies","first-page":"121","article-title":"Time series analysis for encrypted traffic classification: A deep learning approach","author":"Vu","year":"2018"},{"issue":"3","key":"10.1016\/j.comnet.2026.112524_b105","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: A novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Comput."},{"key":"10.1016\/j.comnet.2026.112524_b106","series-title":"Proceedings of the 2022 Australasian Computer Science Week","first-page":"74","article-title":"A CNN based encrypted network traffic classifier","author":"Okonkwo","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b107","series-title":"2022 8th International Conference on Web Research","first-page":"1","article-title":"Encrypted network traffic classification using deep learning method","author":"Banihashemi","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b108","series-title":"Joy","author":"Cisco","year":"2025"},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b109","doi-asserted-by":"crossref","first-page":"420","DOI":"10.1109\/TAI.2023.3244168","article-title":"Extensible machine learning for encrypted network traffic application labeling via uncertainty quantification","volume":"5","author":"Jorgensen","year":"2023","journal-title":"IEEE Trans. Artif. Intell."},{"issue":"6","key":"10.1016\/j.comnet.2026.112524_b110","doi-asserted-by":"crossref","first-page":"1936","DOI":"10.1007\/s10618-020-00710-y","article-title":"Inceptiontime: Finding alexnet for time series classification","volume":"34","author":"Ismail Fawaz","year":"2020","journal-title":"Data Min. Knowl. Discov."},{"key":"10.1016\/j.comnet.2026.112524_b111","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2021.108472","article-title":"MATEC: A lightweight neural network for online encrypted traffic classification","volume":"199","author":"Cheng","year":"2021","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b112","series-title":"2020 IEEE 39th International Performance Computing and Communications Conference","first-page":"1","article-title":"An encrypted traffic classification method combining graph convolutional network and autoencoder","author":"Sun","year":"2020"},{"key":"10.1016\/j.comnet.2026.112524_b113","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2021.108535","article-title":"Bytesgan: A semi-supervised generative adversarial network for encrypted traffic classification in SDN edge gateway","volume":"200","author":"Wang","year":"2021","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b114","series-title":"2022 IEEE 8th International Conference on Network Softwarization (NetSoft)","first-page":"366","article-title":"Encrypted network traffic classification using self-supervised learning","author":"Towhid","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b115","series-title":"IEEE INFOCOM 2019-IEEE Conference on Computer Communications","first-page":"1171","article-title":"Fs-net: A flow sequence network for encrypted traffic classification","author":"Liu","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b116","series-title":"IEEE INFOCOM 2020-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS)","first-page":"424","article-title":"App-net: A hybrid neural network for encrypted mobile traffic classification","author":"Wang","year":"2020"},{"key":"10.1016\/j.comnet.2026.112524_b117","series-title":"On learning hierarchical embeddings from encrypted network traffic","author":"Wehner","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b118","doi-asserted-by":"crossref","first-page":"2367","DOI":"10.1109\/TIFS.2021.3050608","article-title":"Accurate decentralized application identification via encrypted traffic analysis using graph neural networks","volume":"16","author":"Shen","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"10.1016\/j.comnet.2026.112524_b119","doi-asserted-by":"crossref","first-page":"1224","DOI":"10.1109\/TNSM.2022.3227500","article-title":"Flow-based encrypted network traffic classification with graph neural networks","volume":"20","author":"Huoh","year":"2022","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.comnet.2026.112524_b120","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109614","article-title":"EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks","volume":"224","author":"Diao","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b121","series-title":"2017 IEEE International Conference on Intelligence and Security Informatics","first-page":"43","article-title":"End-to-end encrypted traffic classification with one-dimensional convolution neural networks","author":"Wang","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b122","series-title":"2018 IEEE 20th International Conference on High Performance Computing and Communications; IEEE 16th International Conference on Smart City; IEEE 4th International Conference on Data Science and Systems (HPCC\/SmartCity\/DSS)","first-page":"329","article-title":"Encrypted traffic classification with a convolutional long short-term memory neural network","author":"Zou","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b123","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104023","article-title":"A balanced supervised contrastive learning-based method for encrypted network traffic classification","volume":"145","author":"Ma","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112524_b124","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109728","article-title":"Zero-relabelling mobile-app identification over drifted encrypted network traffic","volume":"228","author":"Jiang","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112524_b125","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1016\/j.ins.2020.05.035","article-title":"Attention-based bidirectional GRU networks for efficient HTTPS traffic classification","volume":"541","author":"Liu","year":"2020","journal-title":"Inform. Sci."},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b126","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3447382","article-title":"A look behind the curtain: Traffic classification in an increasingly encrypted web","volume":"5","author":"Akbari","year":"2021","journal-title":"Proc. the ACM Meas. Anal. Comput. Syst."},{"key":"10.1016\/j.comnet.2026.112524_b127","article-title":"A longitudinal study of pii leaks across android app versions","volume":"vol. 10","author":"Ren","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b128","series-title":"An international view of privacy risks for mobile apps","author":"Ren","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b129","series-title":"2014 Third International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security","first-page":"3","article-title":"Andrubis\u20131,000,000 apps later: A view on current android malware behaviors","author":"Lindorfer","year":"2014"},{"key":"10.1016\/j.comnet.2026.112524_b130","series-title":"2021 IEEE 6th International Conference on Computer and Communication Systems","first-page":"1128","article-title":"Online encrypted mobile application traffic classification at the early stage: Challenges, evaluation criteria, comparison methods","author":"Shi","year":"2021"},{"key":"10.1016\/j.comnet.2026.112524_b131","series-title":"2013 Proceedings IEEE INFOCOM","first-page":"1358","article-title":"Detecting encrypted botnet traffic","author":"Zhang","year":"2013"},{"key":"10.1016\/j.comnet.2026.112524_b132","first-page":"1","article-title":"Bothunter: Detecting malware infection through ids-driven dialog correlation.","volume":"vol. 7","author":"Gu","year":"2007"},{"key":"10.1016\/j.comnet.2026.112524_b133","series-title":"2013 IEEE International Workshop on Measurements & Networking (M&N)","first-page":"149","article-title":"A real time unsupervised NIDS for detecting unknown and encrypted network attacks in high speed network","author":"Amoli","year":"2013"},{"key":"10.1016\/j.comnet.2026.112524_b134","series-title":"Proceedings of the 16th International Conference on Availability, Reliability and Security","first-page":"1","article-title":"Detection of brute-force attacks in end-to-end encrypted network traffic","author":"Wichmann","year":"2021"},{"key":"10.1016\/j.comnet.2026.112524_b135","series-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","first-page":"875","article-title":"Exposing the rat in the tunnel: Using traffic analysis for tor-based malware detection","author":"Dodia","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b136","unstructured":"J. Hayes, G. Danezis, k-fingerprinting: A robust scalable website fingerprinting technique, in: 25th USENIX Security Symposium (USENIX Security 16), 2016, pp. 1187\u20131203."},{"key":"10.1016\/j.comnet.2026.112524_b137","series-title":"Autogluon-tabular: Robust and accurate automl for structured data","author":"Erickson","year":"2020"},{"issue":"5","key":"10.1016\/j.comnet.2026.112524_b138","doi-asserted-by":"crossref","first-page":"1213","DOI":"10.1093\/comjnl\/bxac008","article-title":"DEV-eta: An interpretable detection framework for encrypted malicious traffic","volume":"66","author":"Yang","year":"2023","journal-title":"Comput. J."},{"key":"10.1016\/j.comnet.2026.112524_b139","series-title":"Proceedings of the 22nd Acm Sigkdd International Conference on Knowledge Discovery and Data Mining","first-page":"785","article-title":"Xgboost: A scalable tree boosting system","author":"Chen","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b140","series-title":"Consistent individualized feature attribution for tree ensembles","author":"Lundberg","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b141","series-title":"Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","first-page":"1135","article-title":"\u201d Why should i trust you?\u201d explaining the predictions of any classifier","author":"Ribeiro","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b142","series-title":"The 22nd International Conference on Artificial Intelligence and Statistics","first-page":"567","article-title":"What made you do this? understanding black-box decisions with sufficient input subsets","author":"Carter","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b143","series-title":"Semi-supervised classification with graph convolutional networks","author":"Kipf","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b144","series-title":"Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses","first-page":"495","article-title":"Encrypted malware traffic detection via graph-based network analysis","author":"Fu","year":"2022"},{"key":"10.1016\/j.comnet.2026.112524_b145","series-title":"Detecting unknown encrypted malicious traffic in real time via flow interaction graph analysis","author":"Fu","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b146","series-title":"2020 IEEE 7th International Conference on Data Science and Advanced Analytics","first-page":"469","article-title":"Cross-layer profiling of encrypted network data for anomaly detection","author":"Meghdouri","year":"2020"},{"issue":"5","key":"10.1016\/j.comnet.2026.112524_b147","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1145\/1163593.1163596","article-title":"A preliminary performance comparison of five machine learning algorithms for practical IP traffic flow classification","volume":"36","author":"Williams","year":"2006","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"10.1016\/j.comnet.2026.112524_b148","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.comnet.2016.03.012","article-title":"Time-activity footprints in IP traffic","volume":"107","author":"Iglesias","year":"2016","journal-title":"Comput. Netw."},{"issue":"4","key":"10.1016\/j.comnet.2026.112524_b149","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1109\/TBDATA.2017.2723893","article-title":"Pattern discovery in internet background radiation","volume":"5","author":"Iglesias","year":"2017","journal-title":"IEEE Trans. Big Data"},{"key":"10.1016\/j.comnet.2026.112524_b150","series-title":"Proceedings of the Reproducibility Workshop","first-page":"17","article-title":"A meta-analysis approach for feature selection in network traffic research","author":"Ferreira","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b151","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2020.102871","article-title":"Distributed real-time SlowDoS attacks detection over encrypted traffic using artificial intelligence","volume":"173","author":"Garcia","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112524_b152","series-title":"2012 IEEE Fifth International Conference on Software Testing, Verification and Validation","first-page":"860","article-title":"Events-based security monitoring using MMT tool","author":"Wehbi","year":"2012"},{"key":"10.1016\/j.comnet.2026.112524_b153","series-title":"2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC\/PiCom\/CBDCom\/CyberSciTech)","first-page":"63","article-title":"Detection of doh tunnels using time-series classification of encrypted traffic","author":"MontazeriShatoori","year":"2020"},{"key":"10.1016\/j.comnet.2026.112524_b154","series-title":"2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks\u2013Supplemental Volume (DSN-S)","first-page":"19","article-title":"Bayesian neural network based encrypted traffic classification using initial handshake packets","author":"Yang","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b155","series-title":"Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP 2016)","first-page":"407","article-title":"Characterization of encrypted and VPN traffic using time-related features","author":"Gil","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b156","series-title":"Malware-traffic-analysis.net","author":"Duncan","year":"2025"},{"key":"10.1016\/j.comnet.2026.112524_b157","series-title":"2019 International Carnahan Conference on Security Technology","first-page":"1","article-title":"Extensible android malware detection and family classification using network-flows and API-calls","author":"Taheri","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b158","series-title":"CTU-13","author":"Index of \/publicDatasetsr","year":"2016"},{"key":"10.1016\/j.comnet.2026.112524_b159","series-title":"2014 IEEE Conference on Communications and Network Security","first-page":"247","article-title":"Towards effective feature selection in machine learning-based botnet detection approaches","author":"Beigi","year":"2014"},{"key":"10.1016\/j.comnet.2026.112524_b160","series-title":"CIRA-CIC-DoHBrw-2020","author":"UNB","year":"2020"},{"key":"10.1016\/j.comnet.2026.112524_b161","series-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","first-page":"73","article-title":"Malware detection by analysing encrypted network traffic with neural networks","author":"Prasse","year":"2017"},{"key":"10.1016\/j.comnet.2026.112524_b162","series-title":"2020 10th Annual Computing and Communication Workshop and Conference","first-page":"0200","article-title":"Detecting malign encrypted network traffic using perlin noise and convolutional neural network","author":"Bazuhair","year":"2020"},{"key":"10.1016\/j.comnet.2026.112524_b163","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2023.119229","article-title":"Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features","volume":"644","author":"Hong","year":"2023","journal-title":"Inform. Sci."},{"issue":"1","key":"10.1016\/j.comnet.2026.112524_b164","article-title":"Tlsmell: Direct identification on malicious HTTPs encryption traffic with simple connection-specific indicators.","volume":"37","author":"Weng","year":"2021","journal-title":"Comput. Syst. Sci. Eng."},{"key":"10.1016\/j.comnet.2026.112524_b165","series-title":"International Conference on Information and Communications Security","first-page":"3","article-title":"Prototype-based malware traffic classification with novelty detection","author":"Zhao","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b166","series-title":"Australasian Conference on Information Security and Privacy","first-page":"630","article-title":"Encrypted network traffic classification with higher order graph neural network","author":"Okonkwo","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b167","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104195","article-title":"Hierarchical perception for encrypted traffic classification via class incremental learning","volume":"149","author":"Li","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112524_b168","series-title":"2023 26th International Conference on Computer Supported Cooperative Work in Design","first-page":"47","article-title":"ACG: Attack classification on encrypted network traffic using graph convolution attention networks","author":"Wang","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b169","article-title":"ATVITSC: A novel encrypted traffic classification method based on deep learning","author":"Liu","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112524_b170","series-title":"2023 International Conference on Ambient Intelligence, Knowledge Informatics and Industrial Electronics","first-page":"1","article-title":"Detection of encrypted and malicious network traffic using deep learning","author":"Reddy","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b171","series-title":"2023 International Conference on Computer, Electronics & Electrical Engineering & their Applications (IC2E3)","first-page":"1","article-title":"Traffic congestion detection from surveillance videos using deep learning","author":"Madhavi","year":"2023"},{"key":"10.1016\/j.comnet.2026.112524_b172","series-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","first-page":"3659","article-title":"Detecting tunneled flooding traffic via deep semantic analysis of packet length patterns","author":"Fu","year":"2024"},{"key":"10.1016\/j.comnet.2026.112524_b173","series-title":"Kitsune: an ensemble of autoencoders for online network intrusion detection","author":"Mirsky","year":"2018"},{"key":"10.1016\/j.comnet.2026.112524_b174","series-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","first-page":"85","article-title":"Learning detector of malicious network traffic from weak labels","author":"Franc","year":"2015"},{"key":"10.1016\/j.comnet.2026.112524_b175","series-title":"Zeek-an open source network security monitoring tool","author":"Paxson","year":"1994"},{"key":"10.1016\/j.comnet.2026.112524_b176","first-page":"4602","article-title":"Weisfeiler and leman go neural: Higher-order graph neural networks","volume":"vol. 33","author":"Morris","year":"2019"},{"key":"10.1016\/j.comnet.2026.112524_b177","series-title":"2016 IEEE European Symposium on Security and Privacy (EuroS&P)","first-page":"81","article-title":"The OPTLS protocol and TLS 1.3","author":"Krawczyk","year":"2016"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626005360?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626005360?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T16:59:21Z","timestamp":1785171561000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626005360"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":177,"alternative-id":["S1389128626005360"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112524","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A comprehensive survey on encrypted network traffic classification","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112524","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier B.V.","name":"copyright","label":"Copyright"}],"article-number":"112524"}}