{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T02:19:33Z","timestamp":1760235573373,"version":"build-2065373602"},"reference-count":53,"publisher":"MDPI AG","issue":"17","license":[{"start":{"date-parts":[[2021,9,3]],"date-time":"2021-09-03T00:00:00Z","timestamp":1630627200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62071056"],"award-info":[{"award-number":["62071056"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"the action plan project of Beijing University of Posts and Telecommunication","award":["No.2020XD-A03-1"],"award-info":[{"award-number":["No.2020XD-A03-1"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Information and communication technologies have essential impacts on people\u2019s life. The real time convenience of the internet greatly facilitates the information transmission and knowledge exchange of users. However, network intruders utilize some communication holes to complete malicious attacks. Some traditional machine learning (ML) methods based on business features and deep learning (DL) methods extracting features automatically are used to identify these malicious behaviors. However, these approaches tend to use only one type of data source, which can result in the loss of some features that can not be mined in the data. In order to address this problem and to improve the precision of malicious behavior detection, this paper proposed a one-dimensional (1D) convolution-based fusion model of packet capture files and business feature data for malicious network behavior detection. Fusion models improve the malicious behavior detection results compared with single ones in some available network traffic and Internet of things (IOT) datasets. The experiments also indicate that early data fusion, feature fusion and decision fusion are all effective in the model. Moreover, this paper also discusses the adaptability of one-dimensional convolution and two-dimensional (2D) convolution to network traffic data.<\/jats:p>","DOI":"10.3390\/s21175942","type":"journal-article","created":{"date-parts":[[2021,9,6]],"date-time":"2021-09-06T13:18:26Z","timestamp":1630934306000},"page":"5942","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Malicious Network Behavior Detection Using Fusion of Packet Captures Files and Business Feature Data"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2896-4595","authenticated-orcid":false,"given":"Mingshu","family":"He","sequence":"first","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojuan","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4855-2464","authenticated-orcid":false,"given":"Lei","family":"Jin","sequence":"additional","affiliation":[{"name":"School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bingying","family":"Dai","sequence":"additional","affiliation":[{"name":"Department of Statistics, Colorado State University, Fort Collins, CO 80523, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaiwenlv","family":"Kacuila","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0432-702X","authenticated-orcid":false,"given":"Xiaosu","family":"Xue","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,9,3]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Wei, X., Feng, W., Wan, S., Xu, J., Liu, J., Lei, Q., and Wang, W. (2020, January 11\u201314). Deep Learning and Distributed Data Storage System in Identity Recognition and Account Security. Proceedings of the 2020 IEEE 6th International Conference on Computer and Communications (ICCC), Chengdu, China.","DOI":"10.1109\/ICCC51575.2020.9345299"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"106273","DOI":"10.1016\/j.infsof.2020.106273","article-title":"Detection of malicious software by analyzing the behavioral artifacts using machine learning algorithms","volume":"121","author":"Singh","year":"2020","journal-title":"Inf. Softw. Technol."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Alrubaiq, A., and Alharbi, T. (2021). Developing a Cybersecurity Framework for e-Government Project in the Kingdom of Saudi Arabia. J. Cybersecur. Priv., 1.","DOI":"10.3390\/jcp1020017"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Antunes, M., Maximiano, M., Gomes, R., and Pinto, D. (2021). Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal. J. Cybersecur. Priv., 1.","DOI":"10.3390\/jcp1020012"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Preuveneers, D., and Joosen, W. (2021). Sharing Machine Learning Models as Indicators of Compromise for Cyber Threat Intelligence. J. Cybersecur. Priv., 1.","DOI":"10.3390\/jcp1010008"},{"key":"ref_6","unstructured":"Beaugnon, A., and Chifflier, P. (2018, January 19\u201321). Machine Learning for Computer Security Detection Systems: Practical Feedback and Solutions. Proceedings of the 2018 Intelligence Artificielle et Cybers\u00e9curit\u00e9\/Artificial Intelligence and Cybersecurity(C&ESAR), Rennes, France."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"339","DOI":"10.1145\/1151659.1159952","article-title":"Algorithms to accelerate multiple regular expressions matching for deep packet inspection","volume":"36","author":"Kumar","year":"2006","journal-title":"ACM Sigcomm Comput. Commun. Rev."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1135","DOI":"10.1109\/SURV.2013.100613.00161","article-title":"A Survey of Payload-Based Traffic Classification Approaches","volume":"16","author":"Finsterbusch","year":"2014","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Song, W., Beshley, M., Przystupa, K., Beshley, H., Kochan, O., Pryslupskyi, A., Pieniak, D., and Su, J. (2020). A software deep packet inspection system for network traffic analysis and anomaly detection. Sensors, 20.","DOI":"10.3390\/s20061637"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Wei, H., Jafari, R., and Kehtarnavaz, N. (2019). Fusion of video and inertial sensing for deep learning\u2013based human action recognition. Sensors, 19.","DOI":"10.3390\/s19173680"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"6055","DOI":"10.1109\/JSEN.2020.2973361","article-title":"Simultaneous utilization of inertial and video sensing for action detection and recognition in continuous action streams","volume":"20","author":"Wei","year":"2020","journal-title":"IEEE Sens. J."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Wei, H., Chopada, P., and Kehtarnavaz, N. (2020). C-MHAD: Continuous multimodal human action dataset of simultaneous video and inertial sensing. Sensors, 20.","DOI":"10.3390\/s20102905"},{"key":"ref_13","first-page":"1","article-title":"A survey of neural networks usage for intrusion detection systems","volume":"12","year":"2020","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Waskle, S., Parashar, L., and Singh, U. (2020, January 2\u20134). Intrusion Detection System Using PCA with Random Forest Approach. Proceedings of the 2020 International Conference on Electronics and Sustainable Communication Systems (ICESC), Coimbatore, India.","DOI":"10.1109\/ICESC48915.2020.9155656"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Lu, T., Huang, Y., Zhao, W., and Zhang, J. (2019, January 19\u201320). The metering automation system based intrusion detection using random forest classifier with smote+ enn. Proceedings of the 2019 IEEE 7th International Conference on Computer Science and Network Technology (ICCSNT), Dalian, China.","DOI":"10.1109\/ICCSNT47585.2019.8962430"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"82512","DOI":"10.1109\/ACCESS.2019.2923640","article-title":"An adaptive ensemble machine learning model for intrusion detection","volume":"7","author":"Gao","year":"2019","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2157","DOI":"10.1109\/TIFS.2021.3050605","article-title":"Random Partitioning Forest for Point-Wise and Collective Anomaly Detection\u2014Application to Network Intrusion Detection","volume":"16","author":"Marteau","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Miah, M.O., Khan, S.S., Shatabda, S., and Farid, D.M. (2019, January 3\u20135). Improving Detection Accuracy for Imbalanced Network Intrusion Classification using Cluster-based Under-sampling with Random Forests. Proceedings of the 2019 1st International Conference on Advances in Science, Engineering and Robotics Technology (ICASERT), Dhaka, Bangladesh.","DOI":"10.1109\/ICASERT.2019.8934495"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1016\/j.cose.2017.06.005","article-title":"A GA-LR wrapper approach for feature selection in network intrusion detection","volume":"70","author":"Khammassi","year":"2017","journal-title":"Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Halimaa, A., and Sundarakantham, K. (2019, January 23\u201325). Machine learning based intrusion detection system. Proceedings of the 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI.2019.8862784"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Moreira, R., Rodrigues, L., Rosa, P., and Silva, F. (2020, January 9\u201311). Improving the network traffic classification using the Packet Vision approach. Proceedings of the 2019 15th Workshop de Visao Computational (WVC), Sao Paulo, Brazil.","DOI":"10.5753\/wvc.2020.13496"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"214781","DOI":"10.1109\/ACCESS.2020.3040510","article-title":"NADS-RA: Network Anomaly Detection Scheme Based on Feature Representation and Data Augmentation","volume":"8","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"key":"ref_23","unstructured":"Lin, Y., and Chang, X. (2021). Towards Interpretable Ensemble Learning for Image-based Malware Detection. arXiv."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"4943509","DOI":"10.1155\/2018\/4943509","article-title":"TR-IDS: Anomaly-based intrusion detection through text-convolutional neural network and random forest","volume":"2018","author":"Min","year":"2018","journal-title":"Secur. Commun. Netw."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Nguyen, Q.P., Lim, K.W., Divakaran, D.M., Low, K.H., and Chan, M.C. (2019, January 10\u201312). Gee: A gradient-based explainable variational autoencoder for network anomaly detection. Proceedings of the 2019 IEEE 7th Conference on Communications and Network Security (CNS), Washington, DC, USA.","DOI":"10.1109\/CNS.2019.8802833"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Zheng, W., Gou, C., Yan, L., and Mo, S. (2020, January 20\u201324). Learning to Classify: A Flow-Based Relation Network for Encrypted Traffic Classification. Proceedings of the Web Conference 2020, Taipei, Taiwan.","DOI":"10.1145\/3366423.3380090"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"6659022","DOI":"10.1155\/2021\/6659022","article-title":"Deep-Feature-Based Autoencoder Network for Few-Shot Malicious Traffic Detection","volume":"2021","author":"He","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"ref_28","unstructured":"Haber, P., Lampoltshammer, T., Mayr, M., and Plankensteiner, K. Deepmal-Deep Learning Models for Malware Traffic Detection and Classification, Science\u2014Analytics and Applications."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"4738","DOI":"10.1109\/ACCESS.2020.3048348","article-title":"Explaining Deep Learning-based Traffic Classification using a Genetic Algorithm","volume":"9","author":"Ahn","year":"2020","journal-title":"IEEE Access"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Yang, Y., Zheng, K., Wu, C., and Yang, Y. (2019). Improving the classification effectiveness of intrusion detection by using improved conditional variational autoencoder and deep neural network. Sensors, 19.","DOI":"10.3390\/s19112528"},{"key":"ref_31","first-page":"2103","article-title":"A novel transfer learning based on albert for malicious network traffic classification","volume":"16","author":"Han","year":"2020","journal-title":"Int. J. Innov. Comput. Inf. Control"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"He, H.Y., Yang, Z.G., and Chen, X.N. (2020, January 7\u201311). PERT: Payload Encoding Representation from Transformer for Encrypted Traffic Classification. Proceedings of the 2020 ITU Kaleidoscope: Industry-Driven Digital Transformation (ITU K), Ha Noi, Vietnam.","DOI":"10.23919\/ITUK50268.2020.9303204"},{"key":"ref_33","first-page":"34","article-title":"Web log classification framework with data augmentation based on GANs","volume":"27","author":"He","year":"2020","journal-title":"J. China Univ. Posts Telecommun."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Mihailescu, M.E., Mihai, D., Carabas, M., Komisarek, M., Pawlicki, M., Ho\u0142ubowicz, W., and Kozik, R. (2021). The Proposition and Evaluation of the RoEduNet-SIMARGL2021 Network Intrusion Detection Dataset. Sensors, 21.","DOI":"10.3390\/s21134319"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Ahmad, R., Wazirali, R., Bsoul, Q., Abu-Ain, T., and Abu-Ain, W. (2021). Feature-Selection and Mutual-Clustering Approaches to Improve DoS Detection and Maintain WSNs\u2019 Lifetime. Sensors, 21.","DOI":"10.3390\/s21144821"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"4405","DOI":"10.1007\/s11042-015-3177-1","article-title":"A survey of depth and inertial sensor fusion for human action recognition","volume":"76","author":"Chen","year":"2017","journal-title":"Multimed. Tools Appl."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"9660","DOI":"10.1109\/JSEN.2018.2872862","article-title":"Action detection and recognition in continuous action streams by deep learning-based sensing fusion","volume":"18","author":"Dawar","year":"2018","journal-title":"IEEE Sens. J."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/LSENS.2018.2878572","article-title":"Data augmentation in deep learning-based fusion of depth and inertial sensing for action recognition","volume":"3","author":"Dawar","year":"2018","journal-title":"IEEE Sens. Lett."},{"key":"ref_39","unstructured":"(2021, July 10). UNSW-NB15. Available online: https:\/\/cloudstor.aarnet.edu.au\/plus\/index.php\/s\/2DhnLGDdEECo4ys."},{"key":"ref_40","unstructured":"(2021, July 10). Intrusion Detection Evaluation Dataset (ISCXIDS2012). Available online: https:\/\/www.unb.ca\/cic\/datasets\/ids.html."},{"key":"ref_41","unstructured":"(2021, July 10). Intrusion Detection Evaluation Dataset (CIC-IDS2017). Available online: https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html."},{"key":"ref_42","unstructured":"(2021, July 10). VPN-nonVPN Dataset (ISCXVPN2016). Available online: https:\/\/www.unb.ca\/cic\/datasets\/vpn.html."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Yang, S., Wu, P., and Guo, H. (2020). DualNet: Locate Then Detect Effective Payload with Deep Attention Network. arXiv.","DOI":"10.1109\/DSC49826.2021.9346261"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"30373","DOI":"10.1109\/ACCESS.2019.2899721","article-title":"A novel two-stage deep learning model for efficient network intrusion detection","volume":"7","author":"Khan","year":"2019","journal-title":"IEEE Access"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","article-title":"Deep learning approach for intelligent intrusion detection system","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Janarthanan, T., and Zargari, S. (2017, January 19\u201321). Feature selection in UNSW-NB15 and KDDCUP\u201999 datasets. Proceedings of the 2017 IEEE 26th International Symposium on Industrial Electronics (ISIE), Edinburgh, UK.","DOI":"10.1109\/ISIE.2017.8001537"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1007\/s11554-019-00930-6","article-title":"Deep learning-based real-time VPN encrypted traffic identification methods","volume":"17","author":"Guo","year":"2020","journal-title":"J. Real-Time Image Process."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Song, M., Ran, J., and Li, S. (2019, January 19\u201320). Encrypted Traffic Classification Based on Text Convolution Neural Networks. Proceedings of the 2019 IEEE 7th International Conference on Computer Science and Network Technology (ICCSNT), Dalian, China.","DOI":"10.1109\/ICCSNT47585.2019.8962493"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Kim, I., and Chung, T.M. (2020, January 25\u201327). Malicious-Traffic Classification Using Deep Learning with Packet Bytes and Arrival Time. Proceedings of the International Conference on Future Data and Security Engineering, Quy Nhon, Vietnam.","DOI":"10.1007\/978-3-030-63924-2_20"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Le, T.T.H., Kim, Y., and Kim, H. (2019). Network intrusion detection based on novel feature selection model and various recurrent neural networks. Appl. Sci., 9.","DOI":"10.3390\/app9071392"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"8890306","DOI":"10.1155\/2020\/8890306","article-title":"DL-IDS: Extracting features using CNN-LSTM hybrid network for intrusion detection system","volume":"2020","author":"Sun","year":"2020","journal-title":"Secur. Commun. Netw."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"1285","DOI":"10.1109\/TEM.2019.2922936","article-title":"DeepCoin: A novel deep learning and blockchain-based energy exchange framework for smart grids","volume":"67","author":"Ferrag","year":"2019","journal-title":"IEEE Trans. Eng. Manag."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Cheng, G., Jiang, S., and Dai, M. (2019). An efficient intrusion detection system based on feature selection and ensemble classifier. arXiv.","DOI":"10.1016\/j.comnet.2020.107247"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/17\/5942\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:56:13Z","timestamp":1760165773000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/17\/5942"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,3]]},"references-count":53,"journal-issue":{"issue":"17","published-online":{"date-parts":[[2021,9]]}},"alternative-id":["s21175942"],"URL":"https:\/\/doi.org\/10.3390\/s21175942","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2021,9,3]]}}}