{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T19:00:23Z","timestamp":1772046023946,"version":"3.50.1"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T00:00:00Z","timestamp":1572566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T00:00:00Z","timestamp":1572566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T00:00:00Z","timestamp":1572566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["780498"],"award-info":[{"award-number":["780498"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"name":"European Union and Greek national funds through the Operational Program Competitiveness, Entrepreneurship and Innovation, under the call RESEARCH \u2013 CREATE \u2013 INNOVATE MELITY","award":["T1EDK-01958"],"award-info":[{"award-number":["T1EDK-01958"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2019,11]]},"DOI":"10.1109\/tifs.2019.2911156","type":"journal-article","created":{"date-parts":[[2019,5,21]],"date-time":"2019-05-21T22:39:45Z","timestamp":1558478385000},"page":"2916-2926","source":"Crossref","is-referenced-by-count":65,"title":["HEDGE: Efficient Traffic Classification of Encrypted and Compressed Packets"],"prefix":"10.1109","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4296-2876","authenticated-orcid":false,"given":"Fran","family":"Casino","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9208-5336","authenticated-orcid":false,"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4460-9331","authenticated-orcid":false,"given":"Constantinos","family":"Patsakis","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","first-page":"19","article-title":"Statistical identification of encrypted Web browsing traffic","author":"sun","year":"2002","journal-title":"Proc IEEE Symp Secur Privacy"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180437"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/IIH-MSP.2006.264988"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-72367-9_1"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2009.21"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1201\/9780203753064"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CQR.2011.5996087"},{"key":"ref36","first-page":"2745","article-title":"On inferring application protocol behaviors in encrypted network traffic","volume":"7","author":"wright","year":"2006","journal-title":"J Mach Learn Res"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-20305-3_14"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2010.12.002"},{"key":"ref60","year":"2014","journal-title":"NIST 800-22"},{"key":"ref61","first-page":"22","volume":"800","author":"heckert","year":"2001","journal-title":"Andrew Rukhin Juan Soto James Nechvatal Miles Smid Elaine Barker Stefan Leigh Mark Levenson Mark Vangel David Banks"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.48"},{"key":"ref27","first-page":"1","article-title":"Fileprint analysis for malware detection","author":"stolfo","year":"2005","journal-title":"Proceedings of ACM CCS WORM '03"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1949.tb00928.x"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2737970"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2015.2478741"},{"key":"ref20","article-title":"Detecting backdoors","author":"zhang","year":"2000","journal-title":"Proc Usenix Security Symp"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/IPDPS.2007.370614"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_11"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13193-6_32"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/1570256.1570358"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2002.1176314"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1599272.1599278"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1162\/089976603321780272"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2004.833360"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/1268776.1268777"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/0898-1221(93)90001-C"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/0304-4076(89)90083-3"},{"key":"ref56","first-page":"21","article-title":"Power comparisons of shapiro-wilk, kolmogorov-smirnov, lilliefors and anderson-darling tests","volume":"2","author":"razali","year":"2011","journal-title":"Journal of Statistical Modeling and Analytics"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04898-2_326"},{"key":"ref54","author":"ghosh","year":"1991","journal-title":"Handbook of Radioactivity Analysis"},{"key":"ref53","first-page":"687","article-title":"Steal this movie: Automatically bypassing DRM protection in streaming media services","author":"wang","year":"2013","journal-title":"Proc 22nd USENIX Secur Symp"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2010.05.002"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2012.2219591"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/18.61115"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1229291"},{"key":"ref12","first-page":"3","article-title":"Supervised machine learning: A review of classification techniques","volume":"160","author":"kotsiantis","year":"2007","journal-title":"Emerg Artif Intell Appl Comput Eng"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2008.080406"},{"key":"ref14","article-title":"Discriminators for use in flow-based classification","author":"moore","year":"2005"},{"key":"ref15","first-page":"1","article-title":"Clear and present data: Opaque traffic and its security implications for the future","author":"white","year":"2013","journal-title":"Proc NDSS"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2003.1254309"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1925861.1925865"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-01645-5_8"},{"key":"ref19","first-page":"257","article-title":"Dynamic application-layer protocol analysis for network intrusion detection","author":"dreger","year":"2006","journal-title":"Proc 15th Usenix Security Symp"},{"key":"ref4","author":"hahn","year":"2018","journal-title":"Detecting compressed cleartext traffic from consumer Internet of things devices"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00198"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.09.058"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3139937.3139939"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1002\/nem.1901"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1002\/nem.1855"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1815396.1815568"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/NAS.2011.18"},{"key":"ref46","author":"malhotra","year":"2007","journal-title":"Detection of Encrypted Streams for Egress Monitoring"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCNC.2014.6785319"},{"key":"ref48","article-title":"Detecting subverted cryptographic protocols by entropy checking","author":"olivain","year":"2006"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48390-X_9"},{"key":"ref42","first-page":"289","article-title":"Moga: multi-objective genetic algorithms","volume":"1","author":"murata","year":"1999","journal-title":"Proc IEEE Int Conf Evol Comput"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CISDA.2011.5945941"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/j.peva.2007.06.014"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/69.991727"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/8747549\/08691576.pdf?arnumber=8691576","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,13]],"date-time":"2022-07-13T20:59:15Z","timestamp":1657745955000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8691576\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11]]},"references-count":61,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2019.2911156","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,11]]}}}