{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T11:04:46Z","timestamp":1784372686117,"version":"3.55.0"},"reference-count":46,"publisher":"Oxford University Press (OUP)","issue":"7","license":[{"start":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T00:00:00Z","timestamp":1773187200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472434"],"award-info":[{"award-number":["62472434"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,7,14]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The payload attribution system has been proposed to analyze network traffic and assist investigators in identifying flows containing specific excerpts to locate criminals and potential victims. However, various attacks or data leakage behaviors can obscure and scatter the crucial portion of flow payloads to evade detection. Although existing payload attribution techniques strive to enhance the data reduction ratio and reduce false positive rates, research on similar payload querying is notably lacking. In this study, we introduce bitmap index table fuzzy matching (BIFM), a method for digesting network traffic to query and trace variants of malicious traffic. Unlike deterministic bitmap-index PAS that require deterministic bit co-occurrence\/alignment between the query excerpt and the stored flow bitmap, an assumption violated when payloads are split or jumbled, BIFM overcomes this limitation via progressive relaxation with fuzzy matching and verification. Leveraging the bitmap index table and fuzzy matching, BIFM efficiently identifies flows containing excerpts or their variants (excerpts that change their appearance by splitting or jumbling) by relaxing the matching conditions for candidate malicious flows. To enhance BIFM\u2019s accuracy, we also propose no-shingling and packet caching mechanisms. We extensively evaluate BIFM\u2019s performance using a dataset constructed from real campus network IP-trace data. Our results demonstrate that BIFM outperforms existing state-of-the-art solutions, achieving an accuracy improvement of $\\sim $10% without significantly increasing processing time.<\/jats:p>","DOI":"10.1093\/comjnl\/bxag022","type":"journal-article","created":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T12:26:29Z","timestamp":1771849589000},"page":"1237-1254","source":"Crossref","is-referenced-by-count":0,"title":["BIFM: an effective similar payload attribution approach for cybercriminal detection using bitmap index table and fuzzy matching"],"prefix":"10.1093","volume":"69","author":[{"given":"Yifan","family":"Yang","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology , National University of Defense Technology, No. 109 Deya Road, Kaifu District, Hunan Province, Changsha 410073,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Changsheng","family":"Hou","sequence":"additional","affiliation":[{"name":"Academy of Military Sciences , Beijing 100091,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ling","family":"Hu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology , National University of Defense Technology, No. 109 Deya Road, Kaifu District, Hunan Province, Changsha 410073,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xionglve","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology , National University of Defense Technology, No. 109 Deya Road, Kaifu District, Hunan Province, Changsha 410073,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bingnan","family":"Hou","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology , National University of Defense Technology, No. 109 Deya Road, Kaifu District, Hunan Province, Changsha 410073,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiping","family":"Cai","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology , National University of Defense Technology, No. 109 Deya Road, Kaifu District, Hunan Province, Changsha 410073,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2026,3,11]]},"reference":[{"key":"2026071806511724600_ref1","first-page":"31","article-title":"Payload attribution via hierarchical bloom filters","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS \u201904)","author":"Shanmugasundaram","year":"2004"},{"key":"2026071806511724600_ref2","doi-asserted-by":"crossref","first-page":"109032","DOI":"10.1016\/j.comnet.2022.109032","article-title":"A survey on deep learning for cybersecurity: progress, challenges, and opportunities","volume":"212","author":"Macas","year":"2022","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref3","doi-asserted-by":"crossref","first-page":"108403","DOI":"10.1016\/j.comnet.2021.108403","article-title":"Dmatrix: Toward fast and accurate queries in graph stream","volume":"198","author":"Hou","year":"2021","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref4","doi-asserted-by":"crossref","first-page":"422","DOI":"10.1145\/362686.362692","article-title":"Space\/time trade-offs in hash coding with allowable errors","volume":"13","author":"Bloom","year":"1970","journal-title":"Commun ACM"},{"key":"2026071806511724600_ref5","doi-asserted-by":"crossref","first-page":"4047","DOI":"10.1016\/j.comnet.2013.09.003","article-title":"Bloom filter applications in network security: a state-of-the-art survey","volume":"57","author":"Geravand","year":"2013","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref6","doi-asserted-by":"crossref","first-page":"850","DOI":"10.1109\/TIFS.2017.2769018","article-title":"An effective payload attribution scheme for cybercriminal detection using compressed bitmap index tables and traffic downsampling","volume":"13","author":"Hosseini","year":"2018","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"2026071806511724600_ref7","first-page":"150","article-title":"Highly efficient techniques for network forensics","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS \u201907)","author":"Ponec","year":"2007"},{"key":"2026071806511724600_ref8","doi-asserted-by":"crossref","first-page":"634","DOI":"10.1109\/INFCOM.2007.80","article-title":"Tracing traffic through intermediate hosts that repacketize flows","author":"Pyun","year":"2007","journal-title":"IEEE International Conference on Computer Communications (INFOCOM), Anchorage, AK, USA; 6-12 May 2007"},{"key":"2026071806511724600_ref9","doi-asserted-by":"crossref","first-page":"1646","DOI":"10.1016\/j.comnet.2012.01.017","article-title":"Interval-based flow watermarking for tracing interactive traffic","volume":"56","author":"Pyun","year":"2012","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref10","first-page":"191","article-title":"Rapid and parallel content screening for detecting transformed data exposure","volume-title":"IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Hong Kong, China, 26 Apr\u20131 May 2015","author":"Shu","year":"2015"},{"key":"2026071806511724600_ref11","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxad122","article-title":"A sketch framework for fast, accurate and fine-grained analysis of application traffic","volume":"67","author":"Hou","year":"2024","journal-title":"Comput J"},{"key":"2026071806511724600_ref12","doi-asserted-by":"crossref","DOI":"10.1145\/1364654.1364657","article-title":"Detecting worm variants using machine learning","volume-title":"Proceedings of the ACM CoNEXT Conference (CoNEXT \u201907)","author":"Sharma","year":"2007"},{"key":"2026071806511724600_ref13","first-page":"1","article-title":"A complete study on malware types and detecting ransomware using api calls","volume-title":"International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions) (ICRITO)","author":"Yadav","year":"2021"},{"key":"2026071806511724600_ref14","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/978-3-030-88381-2_5","article-title":"Evaluation of network traffic analysis using approximate matching algorithms","volume-title":"Advances in Digital Forensics XVII","author":"G\u00f6bel","year":"2021"},{"key":"2026071806511724600_ref15","doi-asserted-by":"crossref","first-page":"3312","DOI":"10.1109\/TIFS.2019.2915190","article-title":"Digesting network traffic for forensic investigation using digital signal processing techniques","volume":"14","author":"Mohammad Hosseini","year":"2019","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"2026071806511724600_ref16","doi-asserted-by":"crossref","first-page":"S34","DOI":"10.1016\/j.diin.2011.05.005","article-title":"An evaluation of forensic similarity hashes","volume":"8","author":"Roussev","year":"2011","journal-title":"Digital Invest"},{"key":"2026071806511724600_ref17","doi-asserted-by":"crossref","DOI":"10.1145\/1698750.1698755","article-title":"New payload attribution methods for network forensic investigations","volume":"13","author":"Ponec","year":"2010","journal-title":"ACM Trans Inf Syst Secur"},{"key":"2026071806511724600_ref18","doi-asserted-by":"crossref","first-page":"705","DOI":"10.1109\/TIFS.2013.2252341","article-title":"Payload attribution via character dependent multi-bloom filters","volume":"8","author":"Haghighat","year":"2013","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"2026071806511724600_ref19","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/978-3-319-11119-3_25","article-title":"Winnowing multihashing structure with wildcard query","volume-title":"Web Technologies and Applications","author":"Wei","year":"2014"},{"key":"2026071806511724600_ref20","doi-asserted-by":"publisher","first-page":"454","DOI":"10.1007\/978-3-319-13257-0_28","article-title":"Winnowing double structure for wildcard query in payload attribution","volume-title":"Information Security","author":"Wei","year":"2014"},{"key":"2026071806511724600_ref21","doi-asserted-by":"crossref","first-page":"391","DOI":"10.1109\/DSN.2017.19","article-title":"Exploring the long tail of (malicious) software downloads","volume-title":"2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","author":"Rahbarinia","year":"2017"},{"key":"2026071806511724600_ref22","doi-asserted-by":"crossref","first-page":"659","DOI":"10.1109\/SP.2015.46","article-title":"Sok: Deep packer inspection: A longitudinal study of the complexity of run-time packers","volume-title":"2015 IEEE Symposium on Security and Privacy","author":"Ugarte-Pedrero","year":"2015"},{"key":"2026071806511724600_ref23","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2020.24297","article-title":"Prevalence and impact of low-entropy packing schemes in the malware ecosystem","volume-title":"NDSS 2020, Network and Distributed System Security Symposium, 23-26 February 2020, San Diego, CA, USA","author":"Mantovani","year":"2020"},{"key":"2026071806511724600_ref24","volume-title":"Windows Defender Antivirus Cloud Protection Service: Advanced Real-Time Defense against Never-before-Seen Malware. Microsoft Security Blog. Reports that 96% of Malware Files Detected by Windows Defender Antivirus Were Observed Only Once on a Single Computer","author":"Microsoft Defender Security Research Team (2017)"},{"key":"2026071806511724600_ref25","volume-title":"Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection","author":"Ptacek","year":"1998"},{"key":"2026071806511724600_ref26","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1145\/1159913.1159951","article-title":"Detecting evasion attacks at high speeds without reassembly","volume-title":"Proceedings of the 2006 conference on Applications, technologies, architectures, and protocols for computer communications","author":"Varghese","year":"2006"},{"key":"2026071806511724600_ref27","doi-asserted-by":"crossref","DOI":"10.1109\/ACSAC67867.2025.00062","article-title":"Waffled: exploiting parsing discrepancies to bypass web application firewalls","volume-title":"2025 IEEE Annual Computer Security Applications Conference (ACSAC)","author":"Akhavani","year":"2025"},{"key":"2026071806511724600_ref28","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1016\/j.diin.2006.06.015","article-title":"Identifying almost identical files using context triggered piecewise hashing","volume":"3","author":"Kornblum","year":"2006","journal-title":"Digital Invest"},{"key":"2026071806511724600_ref29","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1016\/j.diin.2007.06.011","article-title":"Multi-resolution similarity hashing","volume":"4","author":"Roussev","year":"2007","journal-title":"Digital Invest"},{"key":"2026071806511724600_ref30","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/978-3-642-39891-9_11","article-title":"Similarity preserving hashing: Eligible properties and a new algorithm mrsh-v2","volume-title":"Digital Forensics and Cyber Crime","author":"Breitinger","year":"2013"},{"key":"2026071806511724600_ref31","first-page":"23","article-title":"File detection on network traffic using approximate matching","volume":"9","author":"Breitinger","year":"2014","journal-title":"J Digit Forensics Secur Law"},{"key":"2026071806511724600_ref32","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-319-25512-5_4","article-title":"How cuckoo filter can improve existing approximate matching techniques","volume-title":"Digital Forensics and Cyber Crime","author":"Gupta","year":"2015"},{"key":"2026071806511724600_ref33","doi-asserted-by":"crossref","first-page":"1224","DOI":"10.1109\/TNSM.2022.3227500","article-title":"Flow-based encrypted network traffic classification with graph neural networks","volume":"20","author":"Huoh","year":"2022","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"2026071806511724600_ref34","doi-asserted-by":"crossref","first-page":"109614","DOI":"10.1016\/j.comnet.2023.109614","article-title":"EC-GCN: a encrypted traffic classification framework based on multi-scale graph convolution networks","volume":"224","author":"Diao","year":"2023","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref35","doi-asserted-by":"crossref","first-page":"110372","DOI":"10.1016\/j.comnet.2024.110372","article-title":"DE-GNN: dual embedding with graph neural network for fine-grained encrypted traffic classification","volume":"245","author":"Han","year":"2024","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref36","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2020.24412","article-title":"Flowprint: Semi-supervised mobile-app fingerprinting on encrypted network traffic","volume-title":"Network and Distributed System Security Symposium (NDSS)","author":"Van Ede","year":"2020"},{"key":"2026071806511724600_ref37","doi-asserted-by":"crossref","first-page":"109309","DOI":"10.1016\/j.comnet.2022.109309","article-title":"Accurate mobile-app fingerprinting using flow-level relationship with graph neural networks","volume":"217","author":"Jiang","year":"2022","journal-title":"Comput Netw"},{"key":"2026071806511724600_ref38","doi-asserted-by":"publisher","first-page":"5326","DOI":"10.1109\/TIFS.2025.3571663","article-title":"FG-SAT: efficient flow graph for encrypted traffic classification under environment shifts","volume":"20","author":"Cui","year":"2025","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"2026071806511724600_ref39","doi-asserted-by":"crossref","first-page":"517","DOI":"10.3233\/JHS-230145","article-title":"HClass: fast hybrid network traffic classification with bit and keyword level signatures","volume":"30","author":"Khandait","year":"2024","journal-title":"J High Speed Networks"},{"key":"2026071806511724600_ref40","first-page":"1","article-title":"Encrypted traffic classification at line rate in programmable switches with machine learning","volume-title":"NOMS 2024-2024 IEEE Network Operations and Management Symposium","author":"Akem","year":"2024"},{"key":"2026071806511724600_ref41","doi-asserted-by":"crossref","first-page":"676","DOI":"10.1016\/j.dcan.2022.09.009","article-title":"Network traffic classification: techniques, datasets, and challenges","volume":"10","author":"Azab","year":"2024","journal-title":"Digit Commun Netw"},{"key":"2026071806511724600_ref42","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1587\/transinf.2024EDP7129","article-title":"Incremental learning for network traffic classification using generative adversarial networks","volume":"108","author":"Ouyang","year":"2025","journal-title":"IEICE Trans Inf"},{"key":"2026071806511724600_ref43","volume-title":"Fingerprinting by Random Polynomials","author":"Rabin","year":"1981"},{"key":"2026071806511724600_ref44","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1007\/978-1-4613-9323-8_11","article-title":"Some applications of rabin\u2019s fingerprinting method","volume-title":"Sequences II","author":"Broder","year":"1993"},{"key":"2026071806511724600_ref45","volume-title":"Spamsum README","author":"Tridgell","year":"2002"},{"key":"2026071806511724600_ref46","doi-asserted-by":"crossref","first-page":"S2","DOI":"10.1016\/j.diin.2009.06.016","article-title":"Bringing science to digital forensics with standardized forensic corpora","volume":"6","author":"Garfinkel","year":"2009","journal-title":"Digital Invest"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/69\/7\/1237\/67302570\/bxag022.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/69\/7\/1237\/67302570\/bxag022.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T10:51:31Z","timestamp":1784371891000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/69\/7\/1237\/8514500"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,11]]},"references-count":46,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2026,3,11]]},"published-print":{"date-parts":[[2026,7,14]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxag022","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2026,7]]},"published":{"date-parts":[[2026,3,11]]}}}