{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T16:14:45Z","timestamp":1774541685882,"version":"3.50.1"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Beijing Natural Science Foundation","award":["L221014"],"award-info":[{"award-number":["L221014"]}]},{"name":"Beijing Natural Science Foundation","award":["M23019"],"award-info":[{"award-number":["M23019"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272029"],"award-info":[{"award-number":["62272029"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Systematic Major Project of China State Railway Group Company Ltd","award":["P2023W002"],"award-info":[{"award-number":["P2023W002"]}]},{"name":"Systematic Major Project of China State Railway Group Company Ltd","award":["P2024S003"],"award-info":[{"award-number":["P2024S003"]}]},{"name":"Systematic Major Project of China State Railway Group Company Ltd","award":["P2024W001-4"],"award-info":[{"award-number":["P2024W001-4"]}]},{"name":"Science and Technology Research and Development Plan of China Railway Information Technology Group Company Ltd","award":["WJZGCKY- 2023014 (2023A08)"],"award-info":[{"award-number":["WJZGCKY- 2023014 (2023A08)"]}]},{"name":"Science and Technology Research and Development Plan of China Railway Information Technology Group Company Ltd","award":["WJZG-CKY-2024040 (2024P01)"],"award-info":[{"award-number":["WJZG-CKY-2024040 (2024P01)"]}]},{"name":"Science and Technology Project of Haihe Laboratory of ITAI","award":["XCHR-20230701"],"award-info":[{"award-number":["XCHR-20230701"]}]},{"name":"Hangzhou Qianjiang Distinguished Experts Programme in 2024"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3561673","type":"journal-article","created":{"date-parts":[[2025,4,18]],"date-time":"2025-04-18T17:36:19Z","timestamp":1744997779000},"page":"4484-4497","source":"Crossref","is-referenced-by-count":1,"title":["SoFi: Spoofing OS Fingerprints Against Network Reconnaissance"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2699-7297","authenticated-orcid":false,"given":"Xu","family":"Han","sequence":"first","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation, Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haocong","family":"Li","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation, Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5974-1589","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Key Laboratory for Intelligent Networks and Network Security, Ministry of Education, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9665-7511","authenticated-orcid":false,"given":"Haining","family":"Wang","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Virginia Tech, Arlington, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0934-5035","authenticated-orcid":false,"given":"Xiaobo","family":"Ma","sequence":"additional","affiliation":[{"name":"Key Laboratory for Intelligent Networks and Network Security, Ministry of Education, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9833-2836","authenticated-orcid":false,"given":"Qiang","family":"Li","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation, Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-019-0038-7"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1057\/s41288-022-00266-6"},{"key":"ref3","volume-title":"Network Security Scanner Tool","year":"1997"},{"key":"ref4","article-title":"FiG: Automatic fingerprint generation","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp. (NDSS)","author":"Caballero"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2021.3088333"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0088"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"Szegedy"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref9","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/694"},{"key":"ref14","first-page":"17","article-title":"Probing TCP implementations","volume-title":"Proc. Usenix Summer","author":"Comer"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-008-0107-z"},{"key":"ref16","volume-title":"SINFP3: A Passive and Active Os Fingerprinting Tool","author":"Proxy","year":"2013"},{"key":"ref17","volume-title":"P0F: A Passive TCP\/IP Stack Fingerprinting Tool","author":"Zalewski","year":"2013"},{"key":"ref18","article-title":"Using neural networks to improve classical operating system fingerprinting techniques","author":"Sarraute","year":"2010","journal-title":"arXiv:1006.1918"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2015.2447492"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109782"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3024293"},{"key":"ref22","first-page":"211","article-title":"An improved clock-skew measurement technique for revealing hidden services","volume-title":"Proc. 17th Conf. Secur. Symp.","author":"Zander"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488793"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488676"},{"key":"ref25","volume-title":"Nessus Vulnerability Scanner","year":"2017"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2017.8228647"},{"key":"ref27","article-title":"Defeating TCP\/IP stack fingerprinting","volume-title":"Proc. 9th USENIX Secur. Symp. (USENIX Secur.)","author":"Smart"},{"key":"ref28","volume-title":"Change Your Windows Os Tcp\/ip Fingerprint To Confuse P0f, Networkminer, Ettercap, Nmap, and Other Os Detection Tools","author":"Crenshaw","year":"2008"},{"key":"ref29","volume-title":"The Emulation of Other OSes at the Network Level","author":"Personality","year":"2013"},{"key":"ref30","volume-title":"Preventing Remote Active\/passive OS Fingerprinting By Tools","year":"2019"},{"key":"ref31","first-page":"4","article-title":"Honeyd-a virtual honeypot daemon","volume-title":"Proc. 10th DFN-CERT Workshop, Hamburg, Germany","volume":"2","author":"Provos"},{"key":"ref32","volume-title":"The Honeynet Project","year":"2015"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.2982955"},{"key":"ref34","first-page":"2705","article-title":"Defeating DNN-based traffic analysis systems in real-time with blind adversarial perturbations","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Nasr"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486875"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3304528"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3698591"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796685"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/WoWMoM.2014.6918979"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2015.7346842"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102456"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179289"},{"key":"ref43","volume-title":"Pattern Recognition and Machine Learning (Information Science and Statistics)","author":"Bishop","year":"2006"},{"key":"ref44","volume-title":"A Free Software Machine Learning Library for the Python Programming Language","year":"2007"},{"key":"ref45","volume-title":"An Open Source Machine Learning Framework that Accelerates the Path From Research Prototyping To Production Deployment","year":"2018"},{"key":"ref46","volume-title":"Canadian Institute for Cybersecurity Intrusion Detection System","year":"2017"},{"key":"ref47","volume-title":"Applying Artificial Intelligence To Os Fingerprinting Nmap","author":"Jove","year":"2015"},{"key":"ref48","article-title":"Honeyd-a OS fingerprinting artifice","volume-title":"Proc. 1st Austral. Comput., Network Inf. Forensics Conf.","author":"Valli","year":"2003"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICOIN53446.2022.9687165"},{"key":"ref50","article-title":"A unified approach to interpreting model predictions","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Lundberg"},{"key":"ref51","first-page":"2009","article-title":"A practical approach for defeating nmap OS-fingerprinting","volume":"12","author":"Berrueta","year":"2003","journal-title":"Retrieved March"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10969800.pdf?arnumber=10969800","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,5]],"date-time":"2025-05-05T17:54:26Z","timestamp":1746467666000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10969800\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3561673","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}