{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:59:00Z","timestamp":1784300340281,"version":"3.55.0"},"reference-count":65,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2025,5,27]],"date-time":"2025-05-27T00:00:00Z","timestamp":1748304000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Australian Government's Cooperative Research Centres Projects","award":["CRCPXIV000099"],"award-info":[{"award-number":["CRCPXIV000099"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Meas. Anal. Comput. Syst."],"published-print":{"date-parts":[[2025,5,27]]},"abstract":"<jats:p>Network traffic classification is of great importance for network operators in their daily routines, such as analyzing the usage patterns of multimedia applications and optimizing network configurations. Internet service providers (ISPs) that operate high-speed links expect network flow classifiers to accurately classify flows early, using the minimal number of necessary initial packets per flow. These classifiers must also be robust to packet sequence disorders (drops and retransmissions) in candidate flows and capable of detecting unseen flow types that are not within the existing classification scope, which are not well achieved by existing methods. In this paper, we develop FastFlow, a time-series flow classification method that accurately classifies network flows as one of the known types or the unknown type, which dynamically selects the minimal number of packets to balance accuracy and efficiency. Toward the objectives, we first develop a flow representation process that converts packet streams at both per-packet and per-slot granularity for precise packet statistics with robustness to packet sequence disorders. Second, we develop a sequential decision-based classification model that leverages LSTM architecture trained with reinforcement learning. Our model makes dynamic decisions on the minimal number of time-series data points per flow for the confident classification as one of the known flow types or an unknown one. We evaluated our method on public datasets and demonstrated its superior performance in early and accurate flow classification. Deployment insights on the classification of over 22.9 million flows across seven application types and 33 content providers in a campus network over one week are discussed, showing that FastFlow requires an average of only 8.37 packets and 0.5 seconds to classify the application type of a flow with over 91% accuracy and over 96% accuracy for the content providers.<\/jats:p>","DOI":"10.1145\/3727115","type":"journal-article","created":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T09:43:35Z","timestamp":1749030215000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["FastFlow: Early Yet Robust Network Flow Classification using the Minimal Number of Time-Series Packets"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2164-3277","authenticated-orcid":false,"given":"Rushi Jayeshkumar","family":"Babaria","sequence":"first","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8677-248X","authenticated-orcid":false,"given":"Minzhao","family":"Lyu","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3482-8442","authenticated-orcid":false,"given":"Gustavo","family":"Batista","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7985-6765","authenticated-orcid":false,"given":"Vijay","family":"Sivaraman","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,3]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Neurocomputing","volume":"409","author":"Aceto Giuseppe","year":"2020","unstructured":"Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, and Antonio Pescap\u00e9. 2020. Toward effective mobile encrypted traffic classification through deep learning. Neurocomputing, Vol. 409 (Apr 2020), 306--315."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3410220.3453921"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2992556"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIT52682.2021.9491770"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dcan.2022.09.009"},{"key":"e_1_2_1_6_1","volume-title":"Learning and Sequential Decision Making","author":"Barto Andrew Gehret","unstructured":"Andrew Gehret Barto, Richard S Sutton, and CJCH Watkins. 1989. Learning and Sequential Decision Making. Vol. 89. University of Massachusetts Amherst, MA."},{"key":"e_1_2_1_7_1","volume-title":"Proc. Automated Software Engineering","author":"Berend David","year":"2021","unstructured":"David Berend, Xiaofei Xie, Lei Ma, Lingjun Zhou, Yang Liu, Chi Xu, and Jianjun Zhao. 2021. Cats are not fish: deep learning testing calls for out-of-distribution awareness. In Proc. Automated Software Engineering. Virtual Event, Australia, 1041--1052."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1129582.1129589"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2023.103465"},{"key":"e_1_2_1_10_1","volume-title":"Computer Networks","volume":"180","author":"Blaise Agathe","year":"2020","unstructured":"Agathe Blaise, Mathieu Bouet, Vania Conan, and Stefano Secci. 2020. Detection of zero-day attacks: An unsupervised port-based approach. Computer Networks, Vol. 180 (Oct 2020), 107391."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.3390\/app12031759"},{"key":"e_1_2_1_12_1","volume-title":"Proc. ACM IMC. Virtual Event.","author":"Chang Hyunseok","year":"2021","unstructured":"Hyunseok Chang, Matteo Varvello, Fang Hao, and Sarit Mukherjee. 2021. Can You See Me Now? A Measurement Study of Zoom, Webex, and Meet. In Proc. ACM IMC. Virtual Event."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-98785-5_25"},{"key":"e_1_2_1_14_1","volume-title":"RFSE-GRU: Data Balanced Classification Model for Mobile Encrypted Traffic in Big Data Environment","author":"Dener Murat","year":"2023","unstructured":"Murat Dener, Samed Al, and Gokce Ok. 2023. RFSE-GRU: Data Balanced Classification Model for Mobile Encrypted Traffic in Big Data Environment. IEEE Access (Jan 2023)."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5220\/0005740704070414"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2011.5982804"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3229543.3229548"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24797-2"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/LNET.2021.3098455"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484758"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2012.12.039"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2962106"},{"key":"e_1_2_1_23_1","volume-title":"Advances in Neural Information Processing Systems","volume":"31","author":"Jin Chi","year":"2018","unstructured":"Chi Jin, Zeyuan Allen-Zhu, Sebastien Bubeck, and Michael I Jordan. 2018. Is Q-learning provably efficient? Advances in Neural Information Processing Systems, Vol. 31 (Dec 2018)."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2023.3244168"},{"key":"e_1_2_1_25_1","volume-title":"Proc. ICLR","author":"Lillicrap Timothy P","year":"2016","unstructured":"Timothy P Lillicrap, Jonathan J Hunt, Alexander Pritzel, Nicolas Heess, Tom Erez, Yuval Tassa, David Silver, and Daan Wierstra. 2016. Continuous Control with Deep Reinforcement Learning. In Proc. ICLR. San Juan, Puerto Rico."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CIAPP.2017.8167261"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2747560"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-56249-5_3"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626786"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487842"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-98785-5_17"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24668-8_21"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3517745.3561414"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/IIPHDW.2018.8388338"},{"key":"e_1_2_1_35_1","volume-title":"Proc. ICML","author":"Mnih Volodymyr","year":"2016","unstructured":"Volodymyr Mnih, Adria Puigdomenech Badia, Mehdi Mirza, Alex Graves, Timothy Lillicrap, Tim Harley, David Silver, and Koray Kavukcuoglu. 2016. Asynchronous Methods for Deep Reinforcement Learning. In Proc. ICML. New York City, USA, 1928--1937."},{"key":"e_1_2_1_36_1","unstructured":"Obkio. 2024. What is Acceptable Packet Loss? 10% Packet Loss = 100x Slower. https:\/\/obkio.com\/acceptable-packet-loss\/ Accessed: 2024--11-08."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2883147"},{"key":"e_1_2_1_38_1","volume-title":"Neurocomputing","volume":"156","author":"Peng Lizhi","year":"2015","unstructured":"Lizhi Peng, Bo Yang, and Yuehui Chen. 2015. Effective Packet Number for Early Stage Internet Traffic Identification. Neurocomputing, Vol. 156 (May 2015), 252--267."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3603269.3604840"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/NAS.2012.45"},{"key":"e_1_2_1_41_1","volume-title":"Computer Communications","volume":"186","author":"Roy Sangita","year":"2022","unstructured":"Sangita Roy, Tal Shapira, and Yuval Shavitt. 2022. Fast and lean encrypted Internet traffic classification. Computer Communications , Vol. 186 (May 2022), 166--173."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12243-020-00770-7"},{"key":"e_1_2_1_43_1","volume-title":"Proc. ICLR","author":"Schaul Tom","year":"2016","unstructured":"Tom Schaul, John Quan, Ioannis Antonoglou, and David Silver. 2016. Prioritized Experience Replay. In Proc. ICLR. San Juan, Puerto Rico."},{"key":"e_1_2_1_44_1","volume-title":"Proximal Policy Optimization Algorithms. arXiv preprint arXiv:1707.06347 (Jul","author":"Schulman John","year":"2017","unstructured":"John Schulman, Filip Wolski, Prafulla Dhariwal, Alec Radford, and Oleg Klimov. 2017. Proximal Policy Optimization Algorithms. arXiv preprint arXiv:1707.06347 (Jul 2017)."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3071441"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10295"},{"key":"e_1_2_1_48_1","volume-title":"Proc. USENIX NSDI","author":"Wan Garry","year":"2025","unstructured":"Garry Wan, Shinan Liu, Francesco Bronzino, Nick Feamster, and Zakir Durumeric. 2025. CATO: End-to-end Optimization of ML Traffic Analysis Pipelines. In Proc. USENIX NSDI. Philadelphia, PA, USA."},{"key":"e_1_2_1_49_1","volume-title":"HAST-IDS: Learning Hierarchical Spatial-Temporal Features using Deep Neural Networks to Improve Intrusion Detection","author":"Wang Wei","year":"2017","unstructured":"Wei Wang, Y. Sheng, Jinlin Wang, Xuewen Zeng, Xiaozhou Ye, Yongzhong Huang, and Ming Zhu. 2017a. HAST-IDS: Learning Hierarchical Spatial-Temporal Features using Deep Neural Networks to Improve Intrusion Detection. IEEE Access (Dec 2017)."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2017.8004872"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2015.7366364"},{"key":"e_1_2_1_52_1","first-page":"3","article-title":"A Two-Phase Approach to Fast and Accurate Classification of Encrypted Traffic","volume":"31","author":"Wang Yipeng","year":"2022","unstructured":"Yipeng Wang, Huijie He, Yingxu Lai, and Alex X. Liu. 2022. A Two-Phase Approach to Fast and Accurate Classification of Encrypted Traffic. IEEE\/ACM Trans. Netw., Vol. 31, 3 (Jun 2022), 1071--1086.","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3646547.3688435"},{"key":"e_1_2_1_54_1","volume-title":"Proc. ICML","author":"Wang Ziyu","year":"2016","unstructured":"Ziyu Wang, Tom Schaul, Matteo Hessel, Hado Hasselt, Marc Lanctot, and Nando Freitas. 2016. Dueling Network Architectures for Deep Reinforcement Learning. In Proc. ICML. New York City, USA, 1995--2003."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF00992698"},{"key":"e_1_2_1_56_1","volume-title":"Packet Loss: Understanding, Diagnosing & Fixing in Networks. https:\/\/www.websentra.com\/packet-loss-understanding-diagnosing-fixing-in-networks\/ Accessed: 2024--11-08.","year":"2024","unstructured":"WebSentra. 2024. Packet Loss: Understanding, Diagnosing & Fixing in Networks. https:\/\/www.websentra.com\/packet-loss-understanding-diagnosing-fixing-in-networks\/ Accessed: 2024--11-08."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/DICTA.2016.7797091"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179576.1179584"},{"key":"e_1_2_1_59_1","volume-title":"Proc. International Conference on Computer Networks and Communications","author":"Yamansavascilar Baris","unstructured":"Baris Yamansavascilar, M. Amac Guvensan, A. Gokhan Yavuz, and M. E. Karsligil. 2017. Application Identification via Network Traffic Classification. In Proc. International Conference on Computer Networks and Communications. Silicon Valley, USA, 843--848."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3122940"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-008-9131-2"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2005.35"},{"key":"e_1_2_1_63_1","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1109\/TNSM.2013.022713.120250","article-title":"An Effective Network Traffic Classification Method with Unknown Flow Detection","volume":"10","author":"Zhang Jun","year":"2013","unstructured":"Jun Zhang, Chao Chen, Yang Xiang, Wanlei Zhou, and Athanasios V. Vasilakos. 2013. An Effective Network Traffic Classification Method with Unknown Flow Detection. IEEE Trans. Netw. Serv. Manag. , Vol. 10, 2 (Jun 2013), 133--147.","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2014.2320577"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2018.00074"}],"container-title":["Proceedings of the ACM on Measurement and Analysis of Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3727115","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3727115","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T21:31:42Z","timestamp":1755898302000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3727115"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,27]]},"references-count":65,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,5,27]]}},"alternative-id":["10.1145\/3727115"],"URL":"https:\/\/doi.org\/10.1145\/3727115","relation":{},"ISSN":["2476-1249"],"issn-type":[{"value":"2476-1249","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,27]]},"assertion":[{"value":"2025-06-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}