{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T12:47:53Z","timestamp":1783946873274,"version":"3.55.0"},"reference-count":44,"publisher":"PeerJ","license":[{"start":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T00:00:00Z","timestamp":1763078400000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62372106"],"award-info":[{"award-number":["62372106"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Nsfocus Information Technology Co., Ltd","award":["CCF-NSFOCUS202206"],"award-info":[{"award-number":["CCF-NSFOCUS202206"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"abstract":"<jats:p>\n                    As encrypted network traffic becomes more prevalent, cybercriminals increasingly conceal their malicious activities within encrypted session contents. Traditional methods for detecting malicious encrypted traffic focus on inspecting the plaintext payload during the Transport Layer Security (TLS) handshake phase and analyzing directed Internet Protocol (IP) packet length sequences during the subsequent encrypted transmission phase. However, these methods often have high miss-detection rates in real-world scenarios. For example, attackers employ active traffic obfuscation techniques, such as forging TLS Service Name Indicators (SNI) and certificates to evade detection, while network environments introduce passive obfuscation through packet sequence perturbations. To address these challenges and improve detection robustness, we propose transGraphNet, a novel framework that integrates multi-granularity features from both the packet-length sequences within individual network connections and the flow-relation graphs representing interactions among multiple connections. For each session between a pair of client-server IP hosts, we partition its involved flows into session windows using an adaptive session window algorithm, and then capture concurrency and trigger relationships between their transmitted flows by constructing an Adaptive Sliding-Window Flow-level burst Graph (AFG). Unlike prior methods such as FG-Net, which constructs a flow-relation graph for each client host, our TransGraphNet groups the flows within the same client-server session and with proximate start times into a session window, which is used as a more fine-grained target for traffic classification. Additionally, for each five-tuple flow, we apply the packet length standardization using an enhanced Power Law Division (PLD) algorithm to mitigate time-series noise caused by passive obfuscation. We also integrate packet length sequence modeling and capture its long-range dependencies through a transformer-GNN model, thereby enhancing its representational power. Specifically, for each flow, temporal statistical features are extracted using Convolutional Neural Network (CNN), while long-range dependencies within the packet length sequence are captured\n                    <jats:italic>via<\/jats:italic>\n                    Bidirectional Encoder Representations from Transformers (BERT). These flow representations serve as node features in the AFG, where a graph attention network is employed to propagate and aggregate information across the graph\u2019s topology. The resulting AFG representation is then used for malicious encrypted traffic detection. Extensive experiments on the traffic dataset with obfuscation show that TransGraphNet outperforms state-of-the-art methods such as FG-Net, ET-BERT, and GraphDApp, improving accuracy by 11%, 5.4% and 6.8%, respectively.\n                  <\/jats:p>","DOI":"10.7717\/peerj-cs.3353","type":"journal-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T08:38:35Z","timestamp":1763109515000},"page":"e3353","source":"Crossref","is-referenced-by-count":1,"title":["TransGraphNet: robust detection of malicious encrypted network traffic\n                    <i>via<\/i>\n                    transformer and graph neural models"],"prefix":"10.7717","volume":"11","author":[{"given":"Qiang","family":"Shi","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dacheng","family":"Shi","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liukun","family":"He","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingjun","family":"Xiao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"},{"name":"Purple Mountain Laboratories, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liang","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0001-1626-3951","authenticated-orcid":true,"given":"Jingdong","family":"He","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qifan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"4443","published-online":{"date-parts":[[2025,11,14]]},"reference":[{"key":"10.7717\/peerj-cs.3353\/ref-1","doi-asserted-by":"crossref","DOI":"10.1145\/2991079.2991123","article-title":"Adaptive encrypted traffic fingerprinting with bi-directional dependence","author":"Al-Naami","year":"2016"},{"issue":"6","key":"10.7717\/peerj-cs.3353\/ref-2","doi-asserted-by":"publisher","first-page":"1326","DOI":"10.1016\/j.comnet.2010.12.002","article-title":"Can encrypted traffic be identified without port numbers, IP addresses and payload inspection?","volume":"55","author":"Alshammari","year":"2011","journal-title":"Computer Networks"},{"key":"10.7717\/peerj-cs.3353\/ref-3","doi-asserted-by":"crossref","DOI":"10.1109\/ISCC47284.2019.8969728","article-title":"Identifying and characterizing bashlite and mirai C&C servers","author":"Bastos","year":"2019"},{"key":"10.7717\/peerj-cs.3353\/ref-4","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2106.12693","article-title":"Deep learning for network traffic classification","author":"Bayat","year":"2021"},{"key":"10.7717\/peerj-cs.3353\/ref-5","article-title":"Valid SSL certificates with SSL beacon","author":"CobaltStrike","year":"2024"},{"key":"10.7717\/peerj-cs.3353\/ref-6","first-page":"40","article-title":"SSL malicious traffic detection based on multi-view features","author":"Dai","year":"2019"},{"key":"10.7717\/peerj-cs.3353\/ref-7","doi-asserted-by":"publisher","first-page":"109614","DOI":"10.1016\/j.comnet.2023.109614","article-title":"EC-GCN: a encrypted traffic classification framework based on multi-scale graph convolution networks","volume":"224","author":"Diao","year":"2023","journal-title":"Computer Networks"},{"key":"10.7717\/peerj-cs.3353\/ref-8","article-title":"MTA dataset: malware traffic analysis","author":"Duncan","year":"2024"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-9","doi-asserted-by":"publisher","first-page":"20511","DOI":"10.1038\/s41598-025-07956-w","article-title":"Advanced cloud intrusion detection framework using graph based features transformers and contrastive learning","volume":"15","author":"Govindarajan","year":"2025","journal-title":"Scientific Reports"},{"issue":"9","key":"10.7717\/peerj-cs.3353\/ref-10","doi-asserted-by":"publisher","first-page":"100077","DOI":"10.1016\/j.teler.2023.100077","article-title":"Dependable intrusion detection system using deep convolutional neural network: a novel framework and performance evaluation approach","volume":"11","author":"Hnamte","year":"2023","journal-title":"Telematics and Informatics Reports"},{"key":"10.7717\/peerj-cs.3353\/ref-11","first-page":"383","article-title":"An encrypted traffic classification framework based on higher-interaction-graph neural network","author":"Hu","year":"2024"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-12","doi-asserted-by":"publisher","first-page":"109309","DOI":"10.1016\/j.comnet.2022.109309","article-title":"Accurate mobile-app fingerprinting using flow-level relationship with graph neural networks","volume":"217","author":"Jiang","year":"2022","journal-title":"Computer Networks"},{"key":"10.7717\/peerj-cs.3353\/ref-13","doi-asserted-by":"crossref","DOI":"10.1007\/978-981-16-8059-5_13","article-title":"A review on TLS encryption malware detection: Tls features, machine learning usage, and future directions","author":"Keshkeh","year":"2021"},{"key":"10.7717\/peerj-cs.3353\/ref-14","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2103.11943","article-title":"Bert: a review of applications in natural language processing and understanding","author":"Koroteev","year":"2021"},{"key":"10.7717\/peerj-cs.3353\/ref-15","article-title":"A graph neural network and transformer encoder technique for anomaly and cyber threat detection in smart grids","author":"Lakshmanan","year":"2024"},{"key":"10.7717\/peerj-cs.3353\/ref-16","doi-asserted-by":"crossref","DOI":"10.1109\/CCST.2018.8585560","article-title":"Toward developing a systematic approach to generate benchmark android malware datasets and classification","author":"Lashkari","year":"2018"},{"key":"10.7717\/peerj-cs.3353\/ref-17","first-page":"85","article-title":"Encrypted malware traffic detection using TLS features and random forest","author":"Lee","year":"2021"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-18","doi-asserted-by":"publisher","first-page":"102368","DOI":"10.1016\/j.rcim.2022.102368","article-title":"Intelligent tool wear prediction based on informer encoder and stacked bidirectional gated recurrent unit","volume":"77","author":"Li","year":"2022","journal-title":"Robotics and Computer-Integrated Manufacturing"},{"key":"10.7717\/peerj-cs.3353\/ref-19","doi-asserted-by":"publisher","first-page":"2524","DOI":"10.1109\/tifs.2023.3267885","article-title":"Prism: real-time privacy protection against temporal network traffic analyzers","volume":"18","author":"Li","year":"2023","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.7717\/peerj-cs.3353\/ref-20","first-page":"633","article-title":"ET-BERT: a contextualized datagram representation with pre-training transformers for encrypted traffic classification","author":"Lin","year":"2022"},{"key":"10.7717\/peerj-cs.3353\/ref-21","doi-asserted-by":"crossref","DOI":"10.1109\/IWQoS.2018.8624124","article-title":"MAMPF: encrypted traffic classification based on multi-attribute Markov probability fingerprints","author":"Liu","year":"2018"},{"key":"10.7717\/peerj-cs.3353\/ref-22","first-page":"1171","article-title":"FS-Net: a flow sequence network for encrypted traffic classification","author":"Liu","year":"2019"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-23","doi-asserted-by":"publisher","first-page":"7117863","DOI":"10.1155\/2023\/7117863","article-title":"Spatial-temporal feature with dual-attention mechanism for encrypted malicious traffic detection","volume":"2023","author":"Liu","year":"2023","journal-title":"Security and Communication Networks"},{"key":"10.7717\/peerj-cs.3353\/ref-24","first-page":"131","article-title":"k-NN classification of malware in HTTPS traffic using the metric space approach","author":"Loko\u010d","year":"2016"},{"issue":"3","key":"10.7717\/peerj-cs.3353\/ref-25","doi-asserted-by":"publisher","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: a novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Computing"},{"issue":"18","key":"10.7717\/peerj-cs.3353\/ref-26","doi-asserted-by":"publisher","first-page":"e2152","DOI":"10.7717\/peerj-cs.2152","article-title":"An intrusion detection system based on convolution neural network","volume":"10","author":"Mo","year":"2024","journal-title":"PeerJ Computer Science"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-27","doi-asserted-by":"publisher","first-page":"5758437","DOI":"10.1155\/2019\/5758437","article-title":"Using burstiness for network applications classification","volume":"2019","author":"Oudah","year":"2019","journal-title":"Journal of Computer Networks and Communications"},{"key":"10.7717\/peerj-cs.3353\/ref-28","doi-asserted-by":"crossref","DOI":"10.1109\/MALWARE.2018.8659361","article-title":"An in-depth study of open-source command and control frameworks","author":"Piet","year":"2018"},{"key":"10.7717\/peerj-cs.3353\/ref-29","doi-asserted-by":"publisher","first-page":"2367","DOI":"10.1109\/tifs.2021.3050608","article-title":"Accurate decentralized application identification via encrypted traffic analysis using graph neural networks","volume":"16","author":"Shen","year":"2021","journal-title":"IEEE TIFS"},{"key":"10.7717\/peerj-cs.3353\/ref-30","doi-asserted-by":"crossref","DOI":"10.1145\/3326285.3329053","article-title":"Encrypted traffic classification of decentralized applications on ethereum using feature fusion","author":"Shen","year":"2019"},{"key":"10.7717\/peerj-cs.3353\/ref-31","first-page":"1928","article-title":"Deep fingerprinting: undermining website fingerprinting defenses with deep learning","author":"Sirinam","year":"2018"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-32","doi-asserted-by":"publisher","first-page":"115","DOI":"10.3390\/electronics12010115","article-title":"A deep learning-based encrypted VPN traffic classification method using packet block image","volume":"12","author":"Sun","year":"2022","journal-title":"Electronics"},{"key":"10.7717\/peerj-cs.3353\/ref-33","first-page":"439","article-title":"Appscanner: automatic fingerprinting of smartphone apps from encrypted network traffic","author":"Taylor","year":"2016"},{"key":"10.7717\/peerj-cs.3353\/ref-34","article-title":"Cobalt strike, a defender\u2019s guide","author":"The DFIR Report","year":"2021"},{"key":"10.7717\/peerj-cs.3353\/ref-35","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1710.10903","article-title":"Graph attention networks","author":"Veli\u010dkovi\u0107","year":"2017"},{"key":"10.7717\/peerj-cs.3353\/ref-36","doi-asserted-by":"publisher","first-page":"109992","DOI":"10.1016\/j.comnet.2023.109992","article-title":"CI_GRU: an efficient DGA botnet classification model based on an attention recurrence plot","volume":"235","author":"Wang","year":"2023","journal-title":"Computer Networks"},{"issue":"1","key":"10.7717\/peerj-cs.3353\/ref-37","doi-asserted-by":"publisher","first-page":"105","DOI":"10.32604\/csse.2021.015074","article-title":"TLSmell: direct identification on malicious https encryption traffic with simple connection-specific indicators","volume":"37","author":"Weng","year":"2021","journal-title":"Computer Systems Science and Engineering"},{"issue":"3","key":"10.7717\/peerj-cs.3353\/ref-38","doi-asserted-by":"publisher","first-page":"3583","DOI":"10.1109\/tnsm.2024.3383851","article-title":"Mtsecurity: privacy-preserving malicious traffic classification using graph neural network and transformer","volume":"21","author":"Yang","year":"2024a","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"10.7717\/peerj-cs.3353\/ref-39","doi-asserted-by":"publisher","first-page":"128801","DOI":"10.1016\/j.physa.2023.128801","article-title":"Stability enhancement for traffic flow via self\u2013stabilizing control strategy in the presence of packet loss","volume":"622","author":"Yang","year":"2023","journal-title":"Physica A: Statistical Mechanics and its Applications"},{"key":"10.7717\/peerj-cs.3353\/ref-40","doi-asserted-by":"publisher","first-page":"110120","DOI":"10.1016\/j.comnet.2023.110120","article-title":"PETNet: plaintext-aware encrypted traffic detection network for identifying cobalt strike https traffics","volume":"238","author":"Yang","year":"2024b","journal-title":"Computer Networks"},{"issue":"9","key":"10.7717\/peerj-cs.3353\/ref-41","doi-asserted-by":"publisher","first-page":"1888","DOI":"10.11897\/SP.J.1016.2023.01888","article-title":"Encrypted malware traffic detection based on multi-granularity representation learning","volume":"46","author":"Yonghao","year":"2023","journal-title":"Chinese Journal of Computers"},{"key":"10.7717\/peerj-cs.3353\/ref-42","doi-asserted-by":"publisher","first-page":"110994","DOI":"10.1016\/j.patcog.2024.110994","article-title":"TFformer: a time\u2013frequency domain bidirectional sequence-level attention based transformer for interpretable long-term sequence forecasting","volume":"158","author":"Zhao","year":"2025","journal-title":"Pattern Recognition"},{"issue":"2","key":"10.7717\/peerj-cs.3353\/ref-43","doi-asserted-by":"publisher","first-page":"1660","DOI":"10.1109\/tnsm.2023.3344580","article-title":"DGNN: accurate darknet application classification adopting attention graph neural network","volume":"21","author":"Zhu","year":"2023","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"10.7717\/peerj-cs.3353\/ref-44","article-title":"2023 state of encrypted attacks report","author":"Zscaler","year":"2023"}],"container-title":["PeerJ Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/peerj.com\/articles\/cs-3353.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/peerj.com\/articles\/cs-3353.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/peerj.com\/articles\/cs-3353.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/peerj.com\/articles\/cs-3353.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T08:38:41Z","timestamp":1763109521000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/peerj.com\/articles\/cs-3353"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,14]]},"references-count":44,"alternative-id":["10.7717\/peerj-cs.3353"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.7717\/peerj-cs.3353","archive":["CLOCKSS","LOCKSS","Portico"],"relation":{},"ISSN":["2376-5992"],"issn-type":[{"value":"2376-5992","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,14]]},"article-number":"e3353"}}