{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:35Z","timestamp":1777806275918,"version":"3.51.4"},"reference-count":46,"publisher":"SAGE Publications","issue":"3","license":[{"start":{"date-parts":[[2025,4,13]],"date-time":"2025-04-13T00:00:00Z","timestamp":1744502400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172194, 62202206 and U183611"],"award-info":[{"award-number":["62172194, 62202206 and U183611"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100016073","name":"Key Technologies Research and Development Program of Anhui Province","doi-asserted-by":"publisher","award":["2020YFB1005500"],"award-info":[{"award-number":["2020YFB1005500"]}],"id":[{"id":"10.13039\/100016073","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Natural Science Foundation of Jiangsu Province","doi-asserted-by":"publisher","award":["BK20220515"],"award-info":[{"award-number":["BK20220515"]}],"id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2021M691310"],"award-info":[{"award-number":["2021M691310"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013088","name":"Qinglan Project of Jiangsu Province of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100013088","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2025,5]]},"abstract":"<jats:p>The growing prevalence of encrypted malicious network traffic poses significant challenges for cybersecurity, as it conceals the content from traditional detection methods. Temporal convolutional networks (TCNs) present promising capabilities for extracting complex temporal features and patterns from the dynamic traffic flow data. However, the unidirectional nature of traditional TCNs limits their effectiveness in capturing the full context of network traffic, which often exhibits bidirectional temporal dependencies. Consequently, a few studies have proposed bidirectional TCN (BiTCN) architectures to address the limitations. However, these methods present complex architectures that require a significant amount of parameters to be learned, which imposes high memory requirements on the computational resources for training such models. In this study, we introduce the efficient bidirectional TCN (eBiTCN) model, an efficient BiTCN that requires fewer parameters yet not at the expense of computational cost and effective detection. The eBiTCN framework combines a bidirectional processor, a lightweight gating mechanism, temporal attention, dropout, a novel loss function, and dense layers. Extensive experiments show that eBiTCN outperforms eight state-of-the-art competing models in terms of detection efficacy, speed, and scalability. The eBiTCN model showcased robust performance in detecting evolving attacks and excelled across various real-world datasets. Its efficiency in training speed and reduced memory usage translates to lower infrastructure costs, making it an accessible and effective choice for deployment. These findings highlight eBiTCN\u2019s practicality and dependability in addressing contemporary network security needs.<\/jats:p>","DOI":"10.1177\/0926227x251326282","type":"journal-article","created":{"date-parts":[[2025,4,14]],"date-time":"2025-04-14T02:12:46Z","timestamp":1744596766000},"page":"180-211","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":4,"title":["eBiTCN: Efficient bidirectional temporal convolution network for encrypted malicious network traffic detection"],"prefix":"10.1177","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2540-3861","authenticated-orcid":false,"given":"Ernest","family":"Akpaku","sequence":"first","affiliation":[{"name":"School of Computer Science and Communication Engineering, Jiangsu University, Zhenjiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3124-5452","authenticated-orcid":false,"given":"Jinfu","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Communication Engineering, Jiangsu University, Zhenjiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0167-5593","authenticated-orcid":false,"given":"Mukhtar","family":"Ahmed","sequence":"additional","affiliation":[{"name":"School of Computer Science and Communication Engineering, Jiangsu University, Zhenjiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5527-5114","authenticated-orcid":false,"given":"Rexford Nii","family":"Ayitey Sosu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Communication Engineering, Jiangsu University, Zhenjiang, China"},{"name":"Department of Information Systems, Ghana Communication Technology University, Accra, Ghana"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0569-2985","authenticated-orcid":false,"given":"Francis Kwadzo","family":"Agbenyegah","sequence":"additional","affiliation":[{"name":"School of Computer Science and Communication Engineering, Jiangsu University, Zhenjiang, China"},{"name":"Department of Information Systems, Ghana Communication Technology University, Accra, Ghana"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6650-8550","authenticated-orcid":false,"given":"Dominic","family":"Kofi Louis","sequence":"additional","affiliation":[{"name":"Department of Information Systems, Ghana Communication Technology University, Accra, Ghana"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2025,4,13]]},"reference":[{"key":"e_1_3_4_2_2","doi-asserted-by":"crossref","unstructured":"El-Maghraby RT Abd Elazim NM Bahaa-Eldin AM. A survey on deep packet inspection. In: 2017 12th International conference on computer engineering and systems (ICCES) 2017 pp.188\u2013197. DOI:10.1109\/ICCES.2017.8275301.","DOI":"10.1109\/ICCES.2017.8275301"},{"key":"e_1_3_4_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3613960"},{"key":"e_1_3_4_4_2","unstructured":"Roques O. Detecting malware in tls traffic 2019 https:\/\/api.semanticscholar.org\/CorpusID:208194045."},{"key":"e_1_3_4_5_2","doi-asserted-by":"crossref","unstructured":"Xie R Wang Y Cao J et al. Rosetta: enabling robust tls encrypted traffic classification in diverse network environments with tcp-aware traffic augmentation. In: Proceedings of the ACM turing award celebration conference - China 2023 2023 ACM TURC \u201923 pp.131\u2013132 New York NY USA. Association for Computing Machinery.","DOI":"10.1145\/3603165.3607437"},{"key":"e_1_3_4_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.asej.2023.102361"},{"key":"e_1_3_4_7_2","first-page":"33","article-title":"A survey on encrypted network traffic analysis applications, techniques, and countermeasures","volume":"54","author":"Papadogiannaki E","year":"2021","unstructured":"Papadogiannaki E, Ioannidis S. A survey on encrypted network traffic analysis applications, techniques, and countermeasures. ACM Comput Surv 2021; 54: 33.","journal-title":"ACM Comput Surv"},{"key":"e_1_3_4_8_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12132849"},{"key":"e_1_3_4_9_2","doi-asserted-by":"crossref","unstructured":"Cao J Xie R Sun K et al. When match fields do not need to match: buffered packets hijacking in SDN. Proc. of the Network and Distributed System Security Symposium (NDSS\u201920) 2020 DOI: 10.14722\/ndss.2020.23040. https:\/\/par.nsf.gov\/biblio\/10172419.","DOI":"10.14722\/ndss.2020.23040"},{"key":"e_1_3_4_10_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103580"},{"key":"e_1_3_4_11_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2023.107166"},{"key":"e_1_3_4_12_2","doi-asserted-by":"publisher","DOI":"10.1080\/09540091.2022.2067124"},{"key":"e_1_3_4_13_2","doi-asserted-by":"crossref","unstructured":"He X Cao J Wang S et al. AUTER: automatically tuning multi-layer network buffers in long-distance shadowsocks networks. In: IEEE INFOCOM 2022 - IEEE conference on computer communications 2022 pp.1689\u20131698. DOI: 10.1109\/INFOCOM48880.2022.9796882.","DOI":"10.1109\/INFOCOM48880.2022.9796882"},{"key":"e_1_3_4_14_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijforecast.2021.11.011"},{"key":"e_1_3_4_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3154244"},{"key":"e_1_3_4_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102542"},{"key":"e_1_3_4_17_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2020.03.011"},{"key":"e_1_3_4_18_2","doi-asserted-by":"crossref","unstructured":"Zhu M Ye K Wang Y et al. A deep learning approach for network anomaly detection based on AMF-LSTM. In: Network and parallel computing: 15th IFIP WG 10.3 international conference NPC 2018 Muroran Japan November 29\u2013December 1 2018 Proceedings 15 2018 pp.137\u2013141. Springer.","DOI":"10.1007\/978-3-030-05677-3_13"},{"key":"e_1_3_4_19_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103465"},{"key":"e_1_3_4_20_2","doi-asserted-by":"crossref","unstructured":"Mehta A Yang W. NAC-TCN: temporal convolutional networks with causal dilated neighborhood attention for emotion understanding. In: Proceedings of the 2023 7th international conference on video and image processing 2024 ICVIP \u201923 pp.9\u201316 New York NY USA. Association for Computing Machinery.","DOI":"10.1145\/3639390.3639392"},{"key":"e_1_3_4_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2022.3215507"},{"key":"e_1_3_4_22_2","doi-asserted-by":"crossref","unstructured":"Huang C Wang R Zhao J et al. Malicious network traffic detection method based on traffic behavior characteristics and machine learning. In: 2023 IEEE 6th International conference on automation electronics and electrical engineering (AUTEEE) 2023 pp.167\u2013172. DOI: 10.1109\/AUTEEE60196.2023.10407590.","DOI":"10.1109\/AUTEEE60196.2023.10407590"},{"key":"e_1_3_4_23_2","doi-asserted-by":"crossref","unstructured":"Tang BH Deng SY Wu CP et al. Research on malicious traffic detection methods based on deep learning. In: 2021 4th International conference on pattern recognition and artificial intelligence (PRAI) 2021 pp.469\u2013475.","DOI":"10.1109\/PRAI53619.2021.9551056"},{"key":"e_1_3_4_24_2","doi-asserted-by":"crossref","unstructured":"Chen J Yin S Cai S et al. An efficient network intrusion detection model based on temporal convolutional networks. In: 2021 IEEE 21st International conference on software quality reliability and security (QRS) 2021 pp.768\u2013775. DOI: 10.1109\/QRS54544.2021.00086.","DOI":"10.1109\/QRS54544.2021.00086"},{"key":"e_1_3_4_25_2","doi-asserted-by":"publisher","DOI":"10.3390\/s24072353"},{"key":"e_1_3_4_26_2","doi-asserted-by":"publisher","DOI":"10.1080\/09540091.2022.2067124"},{"key":"e_1_3_4_27_2","first-page":"93","article-title":"Network abnormal traffic detection model based on CNN-bibasru-at","volume":"41","author":"Yiling L","year":"2024","unstructured":"Yiling L, Xiyong Z. Network abnormal traffic detection model based on CNN-bibasru-at. Microelect Comput 2024; 41: 93\u201399.","journal-title":"Microelect Comput"},{"key":"e_1_3_4_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111772"},{"key":"e_1_3_4_29_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ces.2020.115956"},{"key":"e_1_3_4_30_2","doi-asserted-by":"crossref","unstructured":"Gao R. Rethinking dilated convolution for real-time semantic segmentation. In: 2023 IEEE\/CVF conference on computer vision and pattern recognition workshops (CVPRW) 2023 pp.4675\u20134684. DOI: 10.1109\/CVPRW59228.2023.00493.","DOI":"10.1109\/CVPRW59228.2023.00493"},{"key":"e_1_3_4_31_2","unstructured":"Hendrycks D Gimpel K. Gaussian error linear units (GELUs) 2023."},{"key":"e_1_3_4_32_2","unstructured":"Bai S Kolter JZ Koltun V. An empirical evaluation of generic convolutional and recurrent networks for sequence modeling. CoRR 2018 abs\/1803.01271 http:\/\/arxiv.org\/abs\/1803.01271."},{"key":"e_1_3_4_33_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103385"},{"key":"e_1_3_4_34_2","unstructured":"van den Oord A Dieleman S Zen H et al. Wavenet: a generative model for raw audio. ArXiv 2016 abs\/1609.03499 https:\/\/api.semanticscholar.org\/CorpusID:6254678."},{"key":"e_1_3_4_35_2","doi-asserted-by":"crossref","unstructured":"Xu S Cheng Y Gu K et al. Jointly attentive spatial-temporal pooling networks for video-based person re-identification. In: 2017 IEEE International conference on computer vision (ICCV) 2017 pp.4743\u20134752 Los Alamitos CA USA. IEEE Computer Society.","DOI":"10.1109\/ICCV.2017.507"},{"key":"e_1_3_4_36_2","doi-asserted-by":"crossref","unstructured":"Sharafaldin I Lashkari AH Ghorbani AA. Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: International conference on information systems security and privacy 2018 https:\/\/api.semanticscholar.org\/CorpusID:4707749.","DOI":"10.5220\/0006639801080116"},{"key":"e_1_3_4_37_2","unstructured":"Stratosphere. Stratosphere laboratory datasets. Available from https:\/\/www.stratosphereips.org\/datasets-overview (2022 accessed 13 March 2020)."},{"key":"e_1_3_4_38_2","doi-asserted-by":"crossref","unstructured":"Wang W Zhu M Zeng X et al. Malware traffic classification using convolutional neural network for representation learning. In: 2017 International conference on information networking (ICOIN) 2017 pp.712\u2013717. DOI: 10.1109\/ICOIN.2017.7899588.","DOI":"10.1109\/ICOIN.2017.7899588"},{"key":"e_1_3_4_39_2","doi-asserted-by":"crossref","unstructured":"Liu X. An abnormal network traffic detection method on mawilab dataset based on convolutional neural network. In: 2022 IEEE 2nd International conference on electronic technology communication and information (ICETCI) 2022 pp.1233\u20131235.","DOI":"10.1109\/ICETCI55101.2022.9832256"},{"key":"e_1_3_4_40_2","doi-asserted-by":"crossref","unstructured":"Draper-Gil G Lashkari AH Mamun MSI et al. Characterization of encrypted and vpn traffic using time-related features. In: International conference on information systems security and privacy 2016 https:\/\/api.semanticscholar.org\/CorpusID:21535780.","DOI":"10.5220\/0005740704070414"},{"key":"e_1_3_4_41_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104083"},{"key":"e_1_3_4_42_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-023-08818-0"},{"key":"e_1_3_4_43_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.106798"},{"key":"e_1_3_4_44_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2019.07.007"},{"key":"e_1_3_4_45_2","unstructured":"NVIDIA. Geforce gtx 1080 ti specifications. Online. Available: https:\/\/www.nvidia.com\/en-gb\/geforce\/graphics-cards\/geforce-gtx-1080-ti% \/specifications\/ ( (2024 accessed 3 May 2024)."},{"key":"e_1_3_4_46_2","volume-title":"Enhancing the locality and breaking the memory bottleneck of transformer on time series forecasting","author":"Li S","year":"2019","unstructured":"Li S, Jin X, Xuan Y, et al. Enhancing the locality and breaking the memory bottleneck of transformer on time series forecasting. NY, USA: Curran Associates Inc., Red Hook, 2019."},{"key":"e_1_3_4_47_2","unstructured":"Amazon. Nvidia geforce rtx 2080 ti founders edition. Online. Available: https:\/\/www.amazon.com\/NVIDIA-GEFORCE-RTX-2080-Founders\/dp\/B07HWMDDMK (2024 accessed 3 May 2024)."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251326282","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0926227X251326282","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251326282","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:53Z","timestamp":1777495553000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0926227X251326282"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,13]]},"references-count":46,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,5]]}},"alternative-id":["10.1177\/0926227X251326282"],"URL":"https:\/\/doi.org\/10.1177\/0926227x251326282","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,13]]}}}