{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T21:04:51Z","timestamp":1768338291394,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,17]],"date-time":"2021-08-17T00:00:00Z","timestamp":1629158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"German Federal Ministry of Transport and Digital Infrastructure","award":["19H19001C"],"award-info":[{"award-number":["19H19001C"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,8,17]]},"DOI":"10.1145\/3465481.3470113","type":"proceedings-article","created":{"date-parts":[[2021,8,16]],"date-time":"2021-08-16T17:57:21Z","timestamp":1629136641000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Detection of Brute-Force Attacks in End-to-End Encrypted Network Traffic"],"prefix":"10.1145","author":[{"given":"Pascal","family":"Wichmann","sequence":"first","affiliation":[{"name":"Universit\u00e4t Hamburg, DE"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Marx","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, DE"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hannes","family":"Federrath","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, DE"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mathias","family":"Fischer","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, DE"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,8,17]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Using Partial Signatures in Intrusion Detection for Multipath TCP. In Nordic Conference on Secure IT Systems. Springer, 71\u201386","author":"Afzal Zeeshan","year":"2019","unstructured":"Zeeshan Afzal, Johan Garcia, Stefan Lindskog, and Anna Brunstrom. 2019. Using Partial Signatures in Intrusion Detection for Multipath TCP. In Nordic Conference on Secure IT Systems. Springer, 71\u201386."},{"key":"e_1_3_2_1_2_1","volume-title":"Lessons learned from the deployment of a high-interaction honeypot","author":"Alata Eric","unstructured":"Eric Alata, Vincent Nicomette, Mohamed Ka\u00e2niche, Marc Dacier, and Matthieu Herrb. 2006. Lessons learned from the deployment of a high-interaction honeypot. In EDCC. IEEE, 39\u201346."},{"key":"e_1_3_2_1_3_1","first-page":"464","article-title":"A comparison of unsupervised learning techniques for encrypted traffic identification","volume":"5","author":"Bacquet Carlos","year":"2010","unstructured":"Carlos Bacquet, Kubra Gumus, Dogukan Tizer, A\u00a0Nur Zincir-Heywood, and Malcolm\u00a0I Heywood. 2010. A comparison of unsupervised learning techniques for encrypted traffic identification. Journal of Information Assurance and Security 5, 1 (2010), 464\u2013472.","journal-title":"Journal of Information Assurance and Security"},{"key":"e_1_3_2_1_4_1","volume-title":"Privacy vulnerabilities in encrypted HTTP streams","author":"Bissias George\u00a0Dean","unstructured":"George\u00a0Dean Bissias, Marc Liberatore, David Jensen, and Brian\u00a0Neil Levine. 2005. Privacy vulnerabilities in encrypted HTTP streams. In PET. Springer, 1\u201311."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2494502"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"S\u00e9bastien Canard A\u00efda Diop Nizar Kheir Marie Paindavoine and Mohamed Sabt. 2017. BlindIDS: Market-Compliant and Privacy-Friendly Intrusion Detection System over Encrypted Traffic. In AsiaCCS. ACM 561\u2013574.","DOI":"10.1145\/3052973.3053013"},{"key":"e_1_3_2_1_7_1","volume-title":"A survey on encrypted traffic classification","author":"Cao Zigang","unstructured":"Zigang Cao, Gang Xiong, Yong Zhao, Zhenzhen Li, and Li Guo. 2014. A survey on encrypted traffic classification. In ATIS. Springer, 73\u201381."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Or\u00e7un \u00c7etin Carlos Gan\u00e1n Lisette Altena Takahiro Kasama Daisuke Inoue Kazuki Tamiya Ying Tie Katsunari Yoshioka and Michel van Eeten. 2019. Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai.. In NDSS.","DOI":"10.14722\/ndss.2019.23438"},{"key":"e_1_3_2_1_9_1","unstructured":"Aldo Cortesi Maximilian Hils Thomas Kriechbaumer and contributors. 2010. mitmproxy: A free and open source interactive HTTPS proxy. https:\/\/mitmproxy.org\/ [Version 5]."},{"key":"e_1_3_2_1_10_1","volume-title":"Communication in Distributed Systems. ITG\/GI Symposium. VDE.","author":"Dressler Falko","year":"2007","unstructured":"Falko Dressler, Wolfgang Jaegers, and Reinhard German. 2007. Flow-based worm detection using correlated honeypot logs. In Communication in Distributed Systems. ITG\/GI Symposium. VDE."},{"key":"e_1_3_2_1_11_1","volume-title":"Security and Privacy","author":"Dyer P.","unstructured":"Kevin\u00a0P. Dyer, Scott\u00a0E. Coull, Thomas Ristenpart, and Thomas Shrimpton. 2012. Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail. In Security and Privacy. IEEE, 332\u2013346."},{"key":"e_1_3_2_1_13_1","volume-title":"International Journal of Cryptology Research","author":"Goh Vik\u00a0Tor","year":"2010","unstructured":"Vik\u00a0Tor Goh, Jacob Zimmermann, and Mark Looi. 2010. Intrusion detection system for encrypted networks using secret-sharing schemes. International Journal of Cryptology Research (2010)."},{"key":"e_1_3_2_1_14_1","unstructured":"Google. 2020. HTTPS encryption on the web. Google. https:\/\/transparencyreport.google.com\/https\/overview"},{"key":"e_1_3_2_1_15_1","volume-title":"SSHCure: a flow-based SSH intrusion detection system","author":"Hellemons Laurens","unstructured":"Laurens Hellemons, Luuk Hendriks, Rick Hofstede, Anna Sperotto, Ramin Sadre, and Aiko Pras. 2012. SSHCure: a flow-based SSH intrusion detection system. In AIMS. Springer, 86\u201397."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Mobin Javed and Vern Paxson. 2013. Detecting stealthy distributed SSH brute-forcing. In CCS. ACM 85\u201396.","DOI":"10.1145\/2508859.2516719"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-019-0038-7"},{"key":"e_1_3_2_1_19_1","volume-title":"Survey: Intrusion Detection Systems in Encrypted Traffic. In NEW2AN\/ruSMART","author":"Kovanen Tiina","year":"2016","unstructured":"Tiina Kovanen, Gil David, and Timo H\u00e4m\u00e4l\u00e4inen. 2016. Survey: Intrusion Detection Systems in Encrypted Traffic. In NEW2AN\/ruSMART. Springer, 281\u2013293."},{"key":"e_1_3_2_1_20_1","volume-title":"maTLS: How to Make TLS middlebox-aware?","author":"Lee Hyunwoo","unstructured":"Hyunwoo Lee, Zach Smith, Junghwan Lim, Gyeongjae Choi, Selin Chun, Taejoong Chung, and Ted\u00a0Taekyoung Kwon. 2019. maTLS: How to Make TLS middlebox-aware?. In NDSS. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss-paper\/matls-how-to-make-tls-middlebox-aware\/"},{"key":"e_1_3_2_1_21_1","volume-title":"Recent Advances in Intrusion Detection(LNCS, Vol.\u00a02516)","author":"Lippmann Richard","unstructured":"Richard Lippmann, Seth\u00a0E. Webster, and Douglas Stetson. 2002. The Effect of Identifying Vulnerabilities and Patching Software on the Utility of Network Intrusion Detection. In Recent Advances in Intrusion Detection(LNCS, Vol.\u00a02516). Springer, 307\u2013326."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Jason Livingood Nirmal Mody and Michael O\u2019Reirdan. 2012. Recommendations for the Remediation of Bots in ISP Networks. RFC 6561.","DOI":"10.17487\/rfc6561"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-019-04030-2"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCWC51732.2021.9375998"},{"key":"e_1_3_2_1_25_1","volume-title":"Real-time Analysis of Flow Data for Network Attack Detection","author":"M\u00fcnz Gerhard","unstructured":"Gerhard M\u00fcnz and Georg Carle. 2007. Real-time Analysis of Flow Data for Network Attack Detection. In IM. IFIP\/IEEE, 100\u2013108."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785956.2787482"},{"key":"e_1_3_2_1_27_1","volume-title":"The role of Internet Service Providers in botnet mitigation","author":"Pijpker Jeroen","unstructured":"Jeroen Pijpker and Harald Vranken. 2016. The role of Internet Service Providers in botnet mitigation. In EISIC. IEEE, 24\u201331."},{"key":"e_1_3_2_1_28_1","unstructured":"The\u00a0Zeek Project. 2020. The Zeek Network Security Monitor. https:\/\/www.zeek.org\/"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.06.005"},{"key":"e_1_3_2_1_30_1","volume-title":"Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization","author":"Sharafaldin Iman","unstructured":"Iman Sharafaldin, Arash\u00a0Habibi Lashkari, and Ali\u00a0A. Ghorbani. 2018. Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. In ICISSP. SciTePress, 108\u2013116."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Justine Sherry Chang Lan Raluca\u00a0Ada Popa and Sylvia Ratnasamy. 2015. BlindBox: Deep Packet Inspection over Encrypted Traffic. In SIGCOMM. ACM 213\u2013226.","DOI":"10.1145\/2829988.2787502"},{"key":"e_1_3_2_1_32_1","volume-title":"Detecting intrusions through attack signature analysis","author":"Snapp R.","unstructured":"Steven\u00a0R. Snapp, Biswanath Mukherjee, and Karl\u00a0N. Levitt. 1991. Detecting intrusions through attack signature analysis. Technical Report. Lawrence Livermore National Lab., CA (United States)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Robin Sommer and Vern Paxson. 2003. Enhancing byte-level network intrusion detection signatures with context. In CCS. ACM 262\u2013271.","DOI":"10.1145\/948109.948145"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2010.032210.00054"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1002\/nem.1901"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICFN.2009.36"},{"key":"e_1_3_2_1_37_1","volume-title":"Security and Privacy","author":"White M.","unstructured":"Andrew\u00a0M. White, Austin\u00a0R. Matthews, Kevin\u00a0Z. Snow, and Fabian Monrose. 2011. Phonotactic reconstruction of encrypted voip conversations: Hookt on fon-iks. In Security and Privacy. IEEE, 3\u201318."},{"key":"e_1_3_2_1_38_1","volume-title":"Security and Privacy","author":"Wright V.","unstructured":"Charles\u00a0V. Wright, Lucas Ballard, Scott\u00a0E. Coull, Fabian Monrose, and Gerald\u00a0M. Masson. 2008. Spot me if you can: Uncovering spoken phrases in encrypted voip conversations. In Security and Privacy. IEEE, 35\u201349."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2005.35"}],"event":{"name":"ARES 2021: The 16th International Conference on Availability, Reliability and Security","location":"Vienna Austria","acronym":"ARES 2021"},"container-title":["Proceedings of the 16th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3465481.3470113","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3465481.3470113","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:17:42Z","timestamp":1750191462000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3465481.3470113"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,17]]},"references-count":37,"alternative-id":["10.1145\/3465481.3470113","10.1145\/3465481"],"URL":"https:\/\/doi.org\/10.1145\/3465481.3470113","relation":{},"subject":[],"published":{"date-parts":[[2021,8,17]]},"assertion":[{"value":"2021-08-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}