{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T16:25:10Z","timestamp":1779294310777,"version":"3.51.4"},"reference-count":35,"publisher":"Tech Science Press","issue":"2","license":[{"start":{"date-parts":[[2025,2,23]],"date-time":"2025-02-23T00:00:00Z","timestamp":1740268800000},"content-version":"vor","delay-in-days":53,"URL":"https:\/\/doi.org\/10.32604\/TSP-CROSSMARKPOLICY"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["CMC"],"published-print":{"date-parts":[[2025]]},"DOI":"10.32604\/cmc.2024.059417","type":"journal-article","created":{"date-parts":[[2024,12,17]],"date-time":"2024-12-17T02:23:26Z","timestamp":1734402206000},"page":"2985-3004","update-policy":"https:\/\/doi.org\/10.32604\/tsp-crossmarkpolicy","source":"Crossref","is-referenced-by-count":3,"title":["TB-Graph: Enhancing Encrypted Malicious Traffic Classification through Relational Graph Attention Networks"],"prefix":"10.32604","volume":"82","author":[{"given":"Ming","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qichao","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenqing","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shengli","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"17807","published-online":{"date-parts":[[2025]]},"reference":[{"key":"ref1","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2023.106531","article-title":"TCGNN: Packet-grained network traffic classification via graph neural networks","volume":"123","author":"Hu","year":"2023, Art. no. 106531","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref2","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110372","article-title":"DE-GNN: Dual embedding with graph neural network for fine-grained encrypted traffic classification","volume":"245","author":"Han","year":"2024, Art. no. 110372","journal-title":"Comput. Netw."},{"key":"ref3","first-page":"40","article-title":"SSL malicious traffic detection based on multi-view features","author":"Dai","year":"2019","journal-title":"Proc. 2019 9th Int. Conf. Commun. Netw. Secur."},{"key":"ref4","series-title":"2023 33rd Int. Telecommun. Netw. Appl. Conf.","first-page":"98","article-title":"Meta-TFEN: A multi-modal deep learning approach for encrypted malicious traffic detection","author":"Gu","year":"2023"},{"key":"ref5","article-title":"Toward identifying malicious encrypted traffic with a causality detection system","volume":"80","author":"Zeng","year":"2024, Art. no. 103644","journal-title":"J. Inf. Secur. Appl."},{"key":"ref6","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103580","article-title":"A malicious network traffic detection model based on bidirectional temporal convolutional network with multi-head self-attention mechanism","volume":"136","author":"Cai","year":"2024, Art. no. 103580","journal-title":"Comput. Secur."},{"key":"ref7","doi-asserted-by":"crossref","first-page":"5011","DOI":"10.1109\/TIFS.2023.3300521","article-title":"CBSeq: A channel-level behavior sequence for encrypted malware traffic detection","volume":"18","author":"Cui","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref8","doi-asserted-by":"crossref","first-page":"11773","DOI":"10.1109\/JIOT.2023.3244544","article-title":"CMTSNN: A deep learning model for multiclassification of abnormal and encrypted traffic of Internet of Things","volume":"10","author":"Zhu","year":"2023","journal-title":"IEEE Internet Things J."},{"key":"ref9","series-title":"2023 IFIP Netw. Conf. (IFIP Netw.)","first-page":"1","article-title":"ER-ERT: A method of ensemble representation learning of encrypted RAT traffic","author":"Zhang","year":"2023"},{"key":"ref10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3613960","article-title":"TLS-MHSA: An efficient detection model for encrypted malicious traffic based on multi-head self-attention mechanism","volume":"26","author":"Chen","year":"2023","journal-title":"ACM Trans. Priv. Secur."},{"key":"ref11","doi-asserted-by":"crossref","first-page":"2367","DOI":"10.1109\/TIFS.2021.3050608","article-title":"Accurate decentralized application identification via encrypted traffic analysis using graph neural networks","volume":"16","author":"Shen","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref12","article-title":"Accurate encrypted malicious traffic identification via traffic interaction pattern using graph convolutional network","volume":"13","author":"Ren","year":"2023, Art. no. 1483","journal-title":"Appl. Sci."},{"key":"ref13","series-title":"Int. Conf. Inf. Syst. Secur. Priv.","first-page":"253","article-title":"Characterization of tor traffic using time based features","volume":"2","author":"Lashkari","year":"2017"},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2023.119229","article-title":"Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features","volume":"644","author":"Hong","year":"2023, Art. no. 119229","journal-title":"Inf. Sci."},{"key":"ref15","series-title":"Proc. 25th Int. Symp. Res. Attacks, Intrusions Defenses","first-page":"495","article-title":"Encrypted malware traffic detection via graph-based network analysis","author":"Fu","year":"2022"},{"key":"ref16","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103466","article-title":"TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks","volume":"135","author":"Wang","year":"2023, Art. no. 103466","journal-title":"Comput. Secur."},{"key":"ref17","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2022.109309","article-title":"Accurate mobile-app fingerprinting using flow-level relationship with graph neural networks","volume":"217","author":"Jiang","year":"2022, Art. no. 109309","journal-title":"Comput. Netw."},{"key":"ref18","series-title":"Advances in Internet, Data & Web Technologies","first-page":"75","article-title":"Graph-based detection of encrypted malicious traffic with spatio-temporal features","author":"Guo","year":"2024"},{"key":"ref19","doi-asserted-by":"crossref","first-page":"1660","DOI":"10.1109\/TNSM.2023.3344580","article-title":"DGNN: Accurate darknet application classification adopting attention graph neural network","volume":"21","author":"Zhu","year":"2023","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref20","doi-asserted-by":"crossref","first-page":"684","DOI":"10.1109\/TNSM.2022.3213807","article-title":"Flow topology-based graph convolutional network for intrusion detection in label-limited IoT networks","volume":"20","author":"Deng","year":"2022","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref21","series-title":"2022 IEEE 24th Int. Conf. High Perform. Comput. Commun.","first-page":"801","article-title":"MateGraph: Toward mobile malware detection through traffic behavior graph","author":"Ge","year":"2022"},{"key":"ref22","series-title":"Proc. 37th Ann. Comput. Secur. Appl. Conf.","first-page":"1025","article-title":"MAppGraph: Mobile-app classification on encrypted network traffic using deep graph convolution neural networks","author":"Pham","year":"2021"},{"key":"ref23","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2024.111423","article-title":"Interaction matters: Encrypted traffic classification via status-based interactive behavior graph","volume":"155","author":"Li","year":"2024, Art. no. 111423","journal-title":"Appl. Soft Comput."},{"key":"ref24","doi-asserted-by":"crossref","first-page":"1.1","DOI":"10.1016\/j.comnet.2024.110403","article-title":"Combine intra- and inter-flow: A multimodal encrypted traffic classification model driven by diverse features","volume":"245","author":"Wang","year":"2024","journal-title":"Comput. Netw."},{"key":"ref25","series-title":"26th USENIX Secur. Symp. (USENIX Secur. 17)","first-page":"1357","article-title":"Beauty and the burst: Remote identification of encrypted video streams","author":"Schuster","year":"2017"},{"key":"ref26","series-title":"2023 Int. Joint Conf. Neural Netw. (IJCNN)","first-page":"1","article-title":"FA-Net: More accurate encrypted network traffic classification based on burst with self-attention","author":"Jiang","year":"2023"},{"key":"ref27","series-title":"MILCOM 2019\u20132019 IEEE Mil. Commun. Conf. (MILCOM)","first-page":"1","article-title":"Detection of encrypted malicious network traffic using machine learning","author":"De Lucia","year":"2019"},{"key":"ref28","unstructured":"B. Duncan, \u201cMalware traffic analysis,\u201d 2024. Accessed: Jun. 10, 2024. [Online]. Available: https:\/\/malware-traffic-analysis.net\/"},{"key":"ref29","series-title":"2016 IEEE Eur. Symp. Secur. Priv. (EuroS&P)","first-page":"439","article-title":"AppScanner: Automatic fingerprinting of smartphone apps from encrypted network traffic","author":"Taylor","year":"2016"},{"key":"ref30","article-title":"Website fingerprinting at internet scale","author":"Panchenko","year":"2016","journal-title":"NDSS '16"},{"key":"ref31","article-title":"FlowPrint: Semi-supervised mobile-app fingerprinting on encrypted network traffic","author":"Van Ede","year":"2020","journal-title":"Netw. Distrib. Syst. Secur. (NDSS) Symp. 2020"},{"key":"ref32","doi-asserted-by":"crossref","first-page":"2166","DOI":"10.1109\/TIFS.2022.3179955","article-title":"Seeing traffic paths: Encrypted traffic classification with path signature features","volume":"17","author":"Xu","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref33","series-title":"IEEE INFOCOM 2019-IEEE Conf. Comput. Commun.","first-page":"1171","article-title":"FS-Net: A flow sequence network for encrypted traffic classification","author":"Liu","year":"2019"},{"key":"ref34","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: A novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Comput."},{"key":"ref35","series-title":"2021 IFIP\/IEEE Int. Symp. Integr. Netw. Manag. (IM)","first-page":"376","article-title":"Encrypted network traffic classification using a geometric learning model","author":"Huoh","year":"2021"}],"container-title":["Computers, Materials &amp; Continua"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/cdn.techscience.cn\/files\/cmc\/2025\/TSP_CMC-82-2\/TSP_CMC_59417\/TSP_CMC_59417.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T06:12:03Z","timestamp":1763100723000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.techscience.com\/cmc\/v82n2\/59498"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":35,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025]]},"published-print":{"date-parts":[[2025]]}},"URL":"https:\/\/doi.org\/10.32604\/cmc.2024.059417","relation":{},"ISSN":["1546-2226"],"issn-type":[{"value":"1546-2226","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"2024-10-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-26","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-17","order":2,"name":"published","label":"Published Online","group":{"name":"publication_history","label":"Publication History"}}]}}