{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:19:03Z","timestamp":1783437543400,"version":"3.54.6"},"reference-count":39,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2021,6,17]],"date-time":"2021-06-17T00:00:00Z","timestamp":1623888000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"The National Social Science Fund of China under Grant 20&amp;ZD293","award":["20&ZD293"],"award-info":[{"award-number":["20&ZD293"]}]},{"name":"Innovation Environment Construction Special Project of Xinjiang Uygur Autonomous Region","award":["PT1811"],"award-info":[{"award-number":["PT1811"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>The wide application of encryption technology has made traffic classification gradually become a major challenge in the field of network security. Traditional methods such as machine learning, which rely heavily on feature engineering and others, can no longer fully meet the needs of encrypted traffic classification. Therefore, we propose an Inception-LSTM(ICLSTM) traffic classification method in this paper to achieve encrypted traffic service identification. This method converts traffic data into common gray images, and then uses the constructed ICLSTM neural network to extract key features and perform effective traffic classification. To alleviate the problem of category imbalance, different weight parameters are set for each category separately in the training phase to make it more symmetrical for different categories of encrypted traffic, and the identification effect is more balanced and reasonable. The method is validated on the public ISCX 2016 dataset, and the results of five classification experiments show that the accuracy of the method exceeds 98% for both regular encrypted traffic service identification and VPN encrypted traffic service identification. At the same time, this deep learning-based classification method also greatly simplifies the difficulty of traffic feature extraction work.<\/jats:p>","DOI":"10.3390\/sym13061080","type":"journal-article","created":{"date-parts":[[2021,6,17]],"date-time":"2021-06-17T04:15:46Z","timestamp":1623903346000},"page":"1080","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":58,"title":["ICLSTM: Encrypted Traffic Service Identification Based on Inception-LSTM Neural Network"],"prefix":"10.3390","volume":"13","author":[{"given":"Bei","family":"Lu","sequence":"first","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nurbol","family":"Luktarhan","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6008-7863","authenticated-orcid":false,"given":"Chao","family":"Ding","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenhui","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,6,17]]},"reference":[{"key":"ref_1","unstructured":"(2021, February 10). Cisco Encrypted Traffic Analytics 2019. Available online: https:\/\/www.cisco.com\/c\/en\/us\/solutions\/collateral\/enterprise-networks\/enterprise-network-security\/nb-09-encrytd-traf-anlytcs-wp-cte-en.html."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Soleymanpour, S., Sadr, H., and Beheshti, H. (2020, January 22\u201323). An Efficient Deep Learning Method for Encrypted Traffic Classification on the Web. Proceedings of the 2020 6th International Conference on Web Research (ICWR), Tehran, Iran.","DOI":"10.1109\/ICWR49608.2020.9122299"},{"key":"ref_3","unstructured":"Wang, W., Zhu, M., Zeng, X., Ye, X., and Sheng, Y. (2017, January 11\u201313). Malware traffic classification using convolutional neural network for representation learning. Proceedings of the 2017 International Conference on Information Networking (ICOIN), Da Nang, Vietnam."},{"key":"ref_4","first-page":"e2","article-title":"A Deep Learning Approach for Network Intrusion Detection System","volume":"3","author":"Javaid","year":"2016","journal-title":"EAI Endorsed Trans. Security Safety"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Vu, L., Thuy, H.V., Nguyen, Q.U., Ngoc, T.N., Nguyen, D.N., Hoang, D.T., and Dutkiewicz, E. (2018, January 26\u201329). Time Series Analysis for Encrypted Traffic Classification: A Deep Learning Approach. Proceedings of the 2018 18th International Symposium on Communications and Information Technologies (ISCIT), Bangkok, Thailand.","DOI":"10.1109\/ISCIT.2018.8587975"},{"key":"ref_6","unstructured":"Freeman, D.M., Mitrokotsa, A., and Sinha, A. (2016, January 28). Identifying Encrypted Malware Traffic with Contextual Flow Data. Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, AISec@CCS 2016, Vienna, Austria."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Al-Obaidy, F., Momtahen, S., Hossain, M.F., and Mohammadi, F.A. (2019, January 5\u20138). Encrypted Traffic Classification Based ML for Identifying Different Social Media Applications. Proceedings of the 2019 IEEE Canadian Conference of Electrical and Computer Engineering, CCECE 2019, Edmonton, AB, Canada.","DOI":"10.1109\/CCECE.2019.8861934"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1326","DOI":"10.1016\/j.comnet.2010.12.002","article-title":"Can encrypted traffic be identified without port numbers, IP addresses and payload inspection?","volume":"55","author":"Alshammari","year":"2011","journal-title":"Comput. Netw."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Wang, P., Li, S., Ye, F., Wang, Z., and Zhang, M. (2020, January 7\u201311). PacketCGAN: Exploratory Study of Class Imbalance for Encrypted Traffic Classification Using CGAN. Proceedings of the 2020 IEEE International Conference on Communications, ICC 2020, Dublin, Ireland.","DOI":"10.1109\/ICC40277.2020.9148946"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Liu, W., Jia, Y., Sermanet, P., Reed, S.E., Anguelov, D., Erhan, D., Vanhoucke, V., and Rabinovich, A. (2015, January 7\u201312). Going deeper with convolutions. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2015, Boston, MA, USA.","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Pimenta Rodrigues, G.A., De Oliveira Albuquerque, R., Gomes de Deus, F.E., De Sousa, R.T., De Oliveira J\u00fanior, G.A., Garc\u00eda Villalba, L.J., and Kim, T.-H. (2017). Cybersecurity and Network Forensics: Analysis of Malicious Traffic towards a Honeynet with Deep Packet Inspection. Appl. Sci., 7.","DOI":"10.3390\/app7101082"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Ning, J., Poh, G.S., Loh, J., Chia, J., and Chang, E.-C. (2019, January 11\u201315). PrivDPI: Privacy-Preserving Encrypted Traffic Inspection with Reusable Obfuscated Rules. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201919), London, UK.","DOI":"10.1145\/3319535.3354204"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"355","DOI":"10.1002\/nem.1901","article-title":"A survey of methods for encrypted traffic classification and analysis","volume":"25","author":"Velan","year":"2015","journal-title":"Int. J. Netw. Manag."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"102711","DOI":"10.1016\/j.jnca.2020.102711","article-title":"Encrypted traffic classification based on Gaussian mixture models and Hidden Markov Models","volume":"166","author":"Yao","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_15","unstructured":"Madhukar, A., and Williamson, C.L. (2006, January 11\u201314). A Longitudinal Study of P2P Traffic Classification. Proceedings of the 14th International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems (MASCOTS 2006), Monterey, CA, USA."},{"key":"ref_16","unstructured":"Lucia, M.J.D., and Cotton, C. (2019, January 12\u201314). Detection of Encrypted Malicious Network Traffic using Machine Learning. Proceedings of the 2019 IEEE Military Communications Conference, MILCOM 2019, Norfolk, VA, USA."},{"key":"ref_17","unstructured":"Camp, O., Furnell, S., and Mori, P. (2016, January 19\u201321). Characterization of Encrypted and VPN Traffic using Time-related Features. Proceedings of the 2nd International Conference on Information Systems Security and Privacy, ICISSP 2016, Rome, Italy."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Bhatia, M., Sharma, V., Singh, P., and Masud, M. (2020). Multi-Level P2P Traffic Classification Using Heuristic and Statistical-Based Techniques: A Hybrid Approach. Symmetry, 12.","DOI":"10.3390\/sym12122117"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ma, C., Du, X., and Cao, L. (2020). Improved KNN Algorithm for Fine-Grained Classification of Encrypted Network Flow. Electronics, 9.","DOI":"10.3390\/electronics9020324"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"384","DOI":"10.3390\/make1010022","article-title":"Encrypted DNP3 Traffic Classification Using Supervised Machine Learning Algorithms","volume":"1","author":"Torrisi","year":"2019","journal-title":"Mach. Learn. Knowl. Extr."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1007\/s11416-017-0306-6","article-title":"Deciphering malware\u2019s use of TLS (without decryption)","volume":"14","author":"Anderson","year":"2018","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wang, W., Zhu, M., Wang, J., Zeng, X., and Yang, Z. (2017, January 22\u201324). End-to-end encrypted traffic classification with one-dimensional convolution neural networks. Proceedings of the 2017 IEEE International Conference on Intelligence and Security Informatics (ISI), Beijing, China.","DOI":"10.1109\/ISI.2017.8004872"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: A novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Comput."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Zou, Z., Ge, J., Zheng, H., Wu, Y., Han, C., and Yao, Z. (2018, January 28\u201330). Encrypted Traffic Classification with a Convolutional Long Short-Term Memory Neural Network. Proceedings of the 20th IEEE International Conference on High Performance Computing and Communications; 16th IEEE International Conference on Smart City; 4th IEEE International Conference on Data Science and Systems, HPCC\/SmartCity\/DSS 2018, Exeter, UK.","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2018.00074"},{"key":"ref_25","unstructured":"Haddad, H.M., Wainwright, R.L., and Chbeir, R. (2018, January 9\u201313). Applying deep learning on packet flows for botnet detection. Proceedings of the 33rd Annual ACM Symposium on Applied Computing, SAC 2018, Pau, France."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"107258","DOI":"10.1016\/j.comnet.2020.107258","article-title":"CETAnalytics: Comprehensive effective traffic information analytics for encrypted traffic classification","volume":"176","author":"Dong","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Xu, L., Dou, D., and Chao, H.J. (2020, January 14). ETCNet: Encrypted Traffic Classification Using Siamese Convolutional Networks. Proceedings of the Workshop on Network Application Integration\/CoDesign (NAI\u201920), Virtual Event, New York, NY, USA.","DOI":"10.1145\/3405672.3409492"},{"key":"ref_28","unstructured":"(2020, September 20). SplitCap. Available online: https:\/\/www.netresec.com\/index.ashx?page=SplitCap."},{"key":"ref_29","unstructured":"(2020, October 05). Scikitlearn. Available online: https:\/\/www.cntofu.com\/book\/170\/docs\/5.md."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Branson, S., Horn, G.V., Belongie, S.J., and Perona, P. (2014). Bird Species Categorization Using Pose Normalized Deep Convolutional Nets. arXiv.","DOI":"10.5244\/C.28.87"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1231","DOI":"10.1016\/j.neucom.2017.09.061","article-title":"Learning fine-grained features via a CNN Tree for Large-scale Classification","volume":"275","author":"Wang","year":"2018","journal-title":"Neurocomputing"},{"key":"ref_32","unstructured":"Gu, J., Wang, Z., Kuen, J., Ma, L., Shahroudy, A., Shuai, B., Liu, T., Wang, X., and Wang, G. (2015). Recent Advances in Convolutional Neural Networks. arXiv."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"55380","DOI":"10.1109\/ACCESS.2018.2872430","article-title":"Datanet: Deep Learning Based Encrypted Network Traffic Classification in SDN Home Gateway","volume":"6","author":"Wang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Siami-Namini, S., Tavakoli, N., and Namin, A.S. (2019, January 9\u201312). The Performance of LSTM and BiLSTM in Forecasting Time Series. Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9005997"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Huang, Q., Chen, R., Zheng, X., and Dong, Z. (2017, January 15\u201317). Deep Sentiment Representation Based on CNN and LSTM. Proceedings of the 2017 International Conference on Green Informatics (ICGI), Fuzhou, China.","DOI":"10.1109\/ICGI.2017.45"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Luan, Y., and Lin, S. (2019, January 29\u201331). Research on Text Classification Based on CNN and LSTM. Proceedings of the 2019 IEEE International Conference on Artificial Intelligence and Computer Applications (ICAICA), Dalian, China.","DOI":"10.1109\/ICAICA.2019.8873454"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Li, C., Zhan, G., and Li, Z. (2018, January 19\u201321). News Text Classification Based on Improved Bi-LSTM-CNN. Proceedings of the 2018 9th International Conference on Information Technology in Medicine and Education (ITME), Hangzhou, China.","DOI":"10.1109\/ITME.2018.00199"},{"key":"ref_38","unstructured":"Ioffe, S., and Szegedy, C. (2015). Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift. arXiv."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Song, M., Ran, J., and Li, S. (2019, January 19\u201320). Encrypted Traffic Classification Based on Text Convolution Neural Networks. Proceedings of the 2019 IEEE 7th International Conference on Computer Science and Network Technology (ICCSNT), Dalian, China.","DOI":"10.1109\/ICCSNT47585.2019.8962493"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/6\/1080\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:17:15Z","timestamp":1760163435000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/6\/1080"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,17]]},"references-count":39,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2021,6]]}},"alternative-id":["sym13061080"],"URL":"https:\/\/doi.org\/10.3390\/sym13061080","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,17]]}}}