{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T11:48:43Z","timestamp":1775648923264,"version":"3.50.1"},"reference-count":32,"publisher":"Wiley","license":[{"start":{"date-parts":[[2021,6,15]],"date-time":"2021-06-15T00:00:00Z","timestamp":1623715200000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2018YFB0803503"],"award-info":[{"award-number":["2018YFB0803503"]}]},{"name":"National Key Research and Development Program of China","award":["61831007"],"award-info":[{"award-number":["61831007"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["2018YFB0803503"],"award-info":[{"award-number":["2018YFB0803503"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61831007"],"award-info":[{"award-number":["61831007"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2021,6,15]]},"abstract":"<jats:p>Tor is an anonymous communication network used to hide the identities of both parties in communication. Apart from those who want to browse the web anonymously using Tor for a benign purpose, criminals can use Tor for criminal activities. It is recognized that Tor is easily intercepted by the censorship mechanism, so it uses a series of obfuscation mechanisms to avoid censorship, such as Meek, Format-Transforming Encryption (FTE), and Obfs4. In order to detect Tor traffic, we collect three kinds of obfuscated Tor traffic and then use a sliding window to extract 12 features from the stream according to the five-tuple, including the packet length, packet arrival time interval, and the proportion of the number of bytes sent and received. And finally, we use XGBoost, Random Forest, and other machine learning algorithms to identify obfuscated Tor traffic and its types. Our work provides a feasible method for countering obfuscated Tor network, which can identify the three kinds of obfuscated Tor traffic and achieve about 99% precision rate and recall rate.<\/jats:p>","DOI":"10.1155\/2021\/5587837","type":"journal-article","created":{"date-parts":[[2021,6,15]],"date-time":"2021-06-15T21:05:07Z","timestamp":1623791107000},"page":"1-11","source":"Crossref","is-referenced-by-count":9,"title":["Obfuscated Tor Traffic Identification Based on Sliding Window"],"prefix":"10.1155","volume":"2021","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4567-8128","authenticated-orcid":true,"given":"Wenliang","family":"Xu","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5898-7317","authenticated-orcid":true,"given":"Futai","family":"Zou","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","reference":[{"key":"1","doi-asserted-by":"publisher","DOI":"10.1145\/358549.358563"},{"key":"2","doi-asserted-by":"publisher","DOI":"10.1109\/49.668972"},{"key":"3","doi-asserted-by":"crossref","DOI":"10.1007\/3-540-44702-4_4","article-title":"Freenet: a distributed anonymous information storage and retrieval system","volume-title":"Designing Privacy Enhancing Technologies","author":"I. Clarke","year":"2001"},{"key":"4","article-title":"Know your ransomware: CTB-locker","author":"Security Alliance","year":"2017"},{"key":"5","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2015-0009"},{"key":"6","article-title":"Protocol misidentification made easy with format-transforming encryption","author":"K. P. Dyer"},{"key":"7","article-title":"Obfs4","author":"Yawning","year":"2014"},{"key":"8","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.05.048"},{"key":"9","doi-asserted-by":"publisher","DOI":"10.3390\/app9112375"},{"key":"10","article-title":"Characterization of tor traffic using time based features","author":"A. H. Lashkari"},{"key":"11","article-title":"Machine learning approach for detection of nontor traffic","author":"E. Hodo"},{"key":"12","doi-asserted-by":"publisher","DOI":"10.5815\/ijcnis.2015.07.02"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1109\/CSNT.2017.8418516"},{"key":"14","doi-asserted-by":"crossref","article-title":"Tor traffic analysis and detection via machine learning techniques","author":"A. Cuzzocrea","DOI":"10.1109\/BigData.2017.8258487"},{"key":"15","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-017-0566-4"},{"issue":"3","key":"16","first-page":"540","article-title":"Online identification of Tor anonymous communication traffic","volume":"24","author":"G. He","year":"2013","journal-title":"Ruanjian Xuebao\/Journal of Software"},{"key":"17","doi-asserted-by":"crossref","article-title":"Using traffic analysis to identify the second generation onion router","author":"J. Barker","DOI":"10.1109\/EUC.2011.76"},{"key":"18","article-title":"Traffic identification of tor and web-mix","author":"X. Bai"},{"issue":"9","key":"19","doi-asserted-by":"crossref","first-page":"1075","DOI":"10.1002\/sec.669","article-title":"Tor traffic analysis using hidden markov models","volume":"6","author":"S. Zhioua","year":"2013","journal-title":"Security & Communication Networks"},{"key":"20","article-title":"Meek-based tor traffic identification with hidden markov model","author":"Z. Yao"},{"issue":"2","key":"21","first-page":"121","article-title":"A Tor anonymous communication identification method based on cloud traffic obfuscation","volume":"49","author":"Y. He","year":"2017","journal-title":"Journal of Engineering Science and Technology"},{"key":"22","unstructured":"GaoR.Obfs4 Anonymous Network Traffic Identification Research2018Beijing, ChinaBeijing Jiaotong UniversityM.S. thesis"},{"key":"23","unstructured":"ZhaiY.Research on Tor anonymous traffic identification technology based on FTE2018Tianjin, ChinaTianjin UniversityM. S. thesis"},{"issue":"16","key":"24","article-title":"Using dynamic time warping to find patterns in time series","volume":"10","author":"D. J. Berndt","year":"1994","journal-title":"KDD Workshop"},{"key":"25","article-title":"Evaluation: from precision, recall and F-measure to ROC, informedness, markedness and correlation","author":"D. M. W. Powers","year":"2020"},{"key":"26","article-title":"Deep face recognition: a survey","author":"I. Masi"},{"issue":"10","key":"27","doi-asserted-by":"crossref","first-page":"11994","DOI":"10.1016\/j.eswa.2009.05.029","article-title":"Intrusion detection by machine learning: a review","volume":"36","author":"C. F. Tsai","year":"2009","journal-title":"Expert Systems with Applications"},{"key":"28","article-title":"Xgboost: a scalable tree boosting system","author":"T. Chen"},{"issue":"5","key":"29","doi-asserted-by":"crossref","first-page":"1189","DOI":"10.1214\/aos\/1013203451","article-title":"Greedy function approximation: a gradient boosting machine","volume":"29","author":"J. H. Friedman","year":"2001","journal-title":"Annals of Statistics"},{"issue":"1","key":"30","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"L. Breiman","year":"2001","journal-title":"Machine Learning"},{"issue":"2","key":"31","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1002\/asmb.537","article-title":"A tutorial on \u03bd\u2010support vector machines","volume":"21","author":"P. H. Chen","year":"2005","journal-title":"Applied Stochastic Models in Business and Industry"},{"issue":"2","key":"32","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"A. Buczak","year":"2017","journal-title":"IEEE Communications Surveys & Tutorials"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/5587837.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/5587837.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/5587837.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,15]],"date-time":"2021-06-15T21:05:19Z","timestamp":1623791119000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2021\/5587837\/"}},"subtitle":[],"editor":[{"given":"Mamoun","family":"Alazab","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2021,6,15]]},"references-count":32,"alternative-id":["5587837","5587837"],"URL":"https:\/\/doi.org\/10.1155\/2021\/5587837","relation":{},"ISSN":["1939-0122","1939-0114"],"issn-type":[{"value":"1939-0122","type":"electronic"},{"value":"1939-0114","type":"print"}],"subject":[],"published":{"date-parts":[[2021,6,15]]}}}