1.东南大学网络空间安全学院,江苏南京 211189
2.网络通信与安全紫金山实验室,江苏南京 211189
3.区块链应用监管教育部工程研究中心(东南大学),江苏南京 211189
4.浙江大学计算机科学与技术学院,浙江杭州 310027
吕梦达 男,1998年12月出生于山东省菏泽市。现为东南大学网络空间安全学院博士研究生。主要研究方向为加密流量分析。中国电子学会会员编号:E190202388A。E-mail: mdlyu@seu.edu.cn
胡晓艳 女,1985年7月出生于江西省抚州市。2012年博士毕业于东南大学,现为东南大学网络空间安全学院副教授。主要研究方向为加密流量分析、网络空间安全、未来网络体系结构。 E-mail: xyhu@seu.edu.cn
卢俊羲 男,1998年3月出生于山东省淄博市。现为东南大学网络空间安全学院博士研究生。主要研究方向为钓鱼网站检测与域名安全。E-mail: jxlu@seu.edu.cn
李清昀 男,2000年2月出生于陕西省宝鸡市。现为东南大学网络空间安全学院硕士研究生。主要研究方向为加密流量分析。 E-mail: 220235248@seu.edu.cn
吴桦 女,1973年4月出生于江苏省南京市。2010年博士毕业于东南大学,现为东南大学网络空间安全学院副教授。主要研究方向为加密流量分析、网络空间安全、网络态势感知。E-mail: hwu@seu.edu.cn
袁亚丽 女,1986年2月出生于河南省周口市。2018年毕业于德国哥廷根大学,现为东南大学网络空间安全学院副教授。主要研究方向为网络流量安全分析、协议逆向、漏洞挖掘、网络攻防、暗网、人工智能安全。中国电子学会会员编号:E190202061M。 E-mail: yaliyuan@seu.edu.cn
张帆 男,1978年10月出生于浙江省杭州市。2011年博士毕业于美国康涅狄格大学,现为浙江大学计算机科学与技术学院教授。主要研究方向为硬件安全、物联网安全、网络安全、系统安全、密码学等。 E-mail: fanzhang@zju.edu.cn
收稿:2026-01-12,
录用:2026-02-03,
网络首发:2026-05-28,
纸质出版:2026-04-25
移动端阅览
吕梦达, 胡晓艳, 卢俊羲, 等. 加密隧道审查规避技术及流量分析研究综述[J]. 电子学报, 2026, 54(04): 1393-1424.
LÜ Mengda, HU Xiaoyan, LU Junxi, et al. A Review of Techniques for Bypassing Censorship in Encrypted Tunnels and Traffic Analysis[J]. Acta Electronica Sinica, 2026, 54(04): 1393-1424.
吕梦达, 胡晓艳, 卢俊羲, 等. 加密隧道审查规避技术及流量分析研究综述[J]. 电子学报, 2026, 54(04): 1393-1424. DOI:10.12263/DZXB.20251052
LÜ Mengda, HU Xiaoyan, LU Junxi, et al. A Review of Techniques for Bypassing Censorship in Encrypted Tunnels and Traffic Analysis[J]. Acta Electronica Sinica, 2026, 54(04): 1393-1424. DOI:10.12263/DZXB.20251052
网络通信的加密化已成为不可逆转的趋势,在提升用户隐私安全基线的同时,也为恶意活动与审查规避提供了可乘之机。加密隧道技术因其独特的双重用途特性,成为网络攻防博弈的焦点。本文将虚拟专用网络(Virtual Private Network, VPN)和加密代理技术作为加密隧道的代表性技术,系统阐释其核心通信机理、典型协议形态与主流规避策略,并构建了涵盖被动流量监听与主动探针探测能力的现实威胁模型,明确了审查方在连接级识别、行为级分类及端到端关联等维度的能力边界。在此基础上,本文从数据集构建、特征提取方法、分析算法和研究动态四个维度,分别对VPN和加密代理的流量分析研究现状进行了深入梳理与对比。首先,本文分析了数据集构建现状,将其分为公开数据集与自采数据集,指出公开数据集存在时效性滞后与协议覆盖不足的问题,而自采数据集虽具有针对性,但其面临采集环境单一与复现困难的挑战。其次,本文从包级别、流级别、主机级别以及深度学习维度展开介绍了特征提取方法,系统归纳了从微观序列指纹到宏观行为图谱的多层次特征工程技术。然后,本文梳理了分析算法的演进路径,展示了从依赖专家知识的规则匹配,到基于统计规律的机器学习,再到具备强大端到端表征能力的深度学习算法的发展脉络,并总结了流量检测、业务分类、指纹识别及生态审计等主要研究动态。最后,本文提炼了当前研究在面对协议伪装等高级规避技术时所面临的核心挑战,包括规避协议快速迭代引发的概念漂移、多路复用与快速UDP互联网连接(Quick UDP Internet Connections,QUIC)协议连接迁移导致的流定义失效、实验室环境与现网威胁模型的差异、深度学习模型的可解释性缺失以及大规模背景流量下的基本比率谬误,并据此展望了协议无关检测、在线部署模型设计、自动化基准数据集构建及生成式隐写技术探索等未来研究方向。
The encryption of network traffic has become an irreversible trend. While enhancing the baseline for user privacy and security
it also creates opportunities for malicious activities and censorship evasion. Encrypted tunneling technology
owing to its unique dual-use nature
has emerged as a focal point in the adversarial network landscape. This paper regards virtual private networks (VPNs) and encrypted proxies as representative encrypted tunneling technologies. It systematically elucidates their core communication mechanisms
typical protocol morphologies
and mainstream evasion strategies. Furthermore
a realistic threat model encompassing passive traffic monitoring and active probing capabilities is constructed to delineate the censor’s capability boundaries in connection-level identification
behavioral classification
and end-to-end correlation. Building upon this foundation
this paper presents an in-depth review and comparative analysis of the current research landscape regarding traffic analysis for VPNs and encrypted proxies. This analysis is structured across four dimensions: dataset construction
feature extraction methodologies
analytical algorithms
and research dynamics. First
the status of dataset construction is analyzed by categorizing datasets into public and self-collected types. The paper points out that public datasets suffer from issues such as timeliness lag and insufficient protocol coverage
whereas self-collected datasets
despite their targeted nature
face challenges related to singular collection environments and difficulties in reproducibility. Second
feature extraction methodologies are detailed across packet-level
flow-level
and host-level dimensions
and
in the deep learning domain
systematically summarized
ranging from microscopic sequence fingerprints to macroscopic behavioral graphs. Third
the evolutionary path of analytical algorithms is outlined
demonstrating the development trajectory from rule-based matching reliant on expert knowledge
to machine learning based on statistical laws
and finally to deep learning algorithms possessing powerful end-to-end representation capabilities. Additionally
major research dynamics
including traffic detection
service classification
fingerprint identification
and ecosystem auditing
are summarized. Finally
this paper distills the core challenges currently faced in confronting advanced evasion techniques such as protocol imitation. These challenges include concept drift triggered by rapid iteration of evasion protocols
flow-definition failures caused by multiplexing and quick UDP Internet connections (QUIC) connection migration
discrepancies between laboratory environments and real-world threat models
the lack of interpretability in deep learning models
and the base-rate fallacy under large-scale background traffic. Based on these challenges
future research directions include protocol-agnostic detection
the design of online deployment models
automated construction of benchmark datasets
and the exploration of generative steganography techniques.
Google . HTTPS encryption on the web [R/OL ] . ( 2025-06-01 )[ 2025-11-14 ] . https://transparencyreport.google.com/https/overview https://transparencyreport.google.com/https/overview .
Shen Meng , Ye Ke , Liu Xingtong , et al . Machine learning-powered encrypted network traffic analysis: A comprehensive survey [J ] . IEEE Communications Surveys & Tutorials , 2023 , 25 ( 1 ): 791 - 824 . DOI: 10.1109/comst.2022.3208196 http://dx.doi.org/10.1109/comst.2022.3208196
Shadowsocks . Shadowsocks | A fast tunnel proxy that helps you bypass firewalls [EB/OL ] . ( 2025-03-07 )[ 2025-11-14 ] . https://shadowsocks.org/ https://shadowsocks.org/ .
Dingledine R , Mathewson N , Syverson P . Tor: The second-generation onion router [C ] // Proceedings of the 13th USENIX Security Symposium (USENIX Security 04) . San Diego : USENIX Association , 2004 : 21 . DOI: 10.21236/ada465464 http://dx.doi.org/10.21236/ada465464
Ensafi R , Fifield D , Winter P , et al . Examining how the great firewall discovers hidden circumvention servers [C ] // Proceedings of the 2015 Internet Measurement Conference . New York : ACM , 2015 : 445 - 458 . DOI: 10.1145/2815675.2815690 http://dx.doi.org/10.1145/2815675.2815690
V 2 Fly . VMess protocol | V 2Fly.org[EB/OL ] . ( 2022-01-01 )[ 2025-11-14 ] . https://www.v2fly.org/en_US/developer/protocols/vmess.html https://www.v2fly.org/en_US/developer/protocols/vmess.html .
Alice , Bob , Carol , et al . How China detects and blocks shadowsocks [C ] // Proceedings of the ACM Internet Measurement Conference . New York : ACM , 2020 : 111 - 124 . DOI: 10.1145/3419394.3423644 http://dx.doi.org/10.1145/3419394.3423644
Yawning . Obfs4 - the obfourscator [EB/OL ] . ( 2022-09-04 )[ 2025-11-14 ] . https://github.com/yawning/obfs4 https://github.com/yawning/obfs4 .
shadowsocksrr . ShadowsocksR: Python port of ShadowsocksR [EB/OL ] . ( 2023-01-03 )[ 2025-11-14 ] . https://github.com/shadowsocksrr/shadowsocksr https://github.com/shadowsocksrr/shadowsocksr .
Frolov S , Wampler J , Wustrow E . Detecting probe-resistant proxies [C ] // Proceedings of 2020 Network and Distributed System Security Symposium . San Diego : NDSS Symposium , 2020 . DOI: 10.14722/ndss.2020.23087 http://dx.doi.org/10.14722/ndss.2020.23087
Wu Mingshi , Sippe J , Sivakumar D , et al . How the great firewall of China detects and blocks fully encrypted traffic [C ] // Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim : USENIX Association , 2023 : 149 .
Trojan-GFW . Trojan documentation [EB/OL ] . ( 2024-08-21 )[ 2025-11-14 ] . https://trojan-gfw.github.io/trojan/ https://trojan-gfw.github.io/trojan/ . DOI: 10.1093/gmo/9781561592630.article.50996 http://dx.doi.org/10.1093/gmo/9781561592630.article.50996
Xue Diwen , Kallitsis M , Houmansadr A , et al . Fingerprinting obfuscated proxy traffic with encapsulated TLS handshakes [C ] // Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24) . Philadelphia : USENIX Association , 2024 : 2689 - 2706 .
XTLS . XTLS vision, fixes TLS in TLS, to the star and beyond XTLS/Xray-core discussion #1295 [EB/OL ] . ( 2022-10-31 )[ 2025-11-14 ] . https://github.com/XTLS/Xray-core/discussions/1295 https://github.com/XTLS/Xray-core/discussions/1295 .
Xue Diwen , Stanley R , Kumar P , et al . The discriminative power of cross-layer RTTs in fingerprinting proxy traffic [C ] // Proceedings of the 32nd Network and Distributed System Security Symposium . San Diego : NDSS Symposium , 2025 . DOI: 10.14722/ndss.2025.240966 http://dx.doi.org/10.14722/ndss.2025.240966
梅汉涛 , 程光 , 朱怡霖 , 等 . Tor被动流量分析综述 [J ] . 软件学报 , 2025 , 36 ( 1 ): 253 - 288 .
Mei Hantao , Cheng Guang , Zhu Yilin , et al . Survey on Tor passive traffic analysis [J ] . Journal of Software , 2025 , 36 ( 1 ): 253 - 288 . (in Chinese)
邹鸿程 , 苏金树 , 魏子令 , 等 . 网站指纹识别与防御研究综述 [J ] . 计算机学报 , 2022 , 45 ( 10 ): 2243 - 2278 . DOI: 10.11897/SP.J.1016.2022.02243 http://dx.doi.org/10.11897/SP.J.1016.2022.02243
Zou Hongcheng , Su Jinshu , Wei Ziling , et al . A review of the research of website fingerprinting identification and defense [J ] . Chinese Journal of Computers , 2022 , 45 ( 10 ): 2243 - 2278 . (in Chinese) . DOI: 10.11897/SP.J.1016.2022.02243 http://dx.doi.org/10.11897/SP.J.1016.2022.02243
姚忠将 , 葛敬国 , 张潇丹 , 等 . 流量混淆技术及相应识别、追踪技术研究综述 [J ] . 软件学报 , 2018 , 29 ( 10 ): 3205 - 3222 . DOI: 10.13328/j.cnki.jos.005620 http://dx.doi.org/10.13328/j.cnki.jos.005620
Yao Zhongjiang , Ge Jingguo , Zhang Xiaodan , et al . Research review on traffic obfuscation and its corresponding identification and tracking technologies [J ] . Journal of Software , 2018 , 29 ( 10 ): 3205 - 3222 . (in Chinese) . DOI: 10.13328/j.cnki.jos.005620 http://dx.doi.org/10.13328/j.cnki.jos.005620
史鑫 , 郭云飞 , 王亚文 , 等 . 面向匿名网络的审查规避技术研究综述 [J ] . 信息工程大学学报 , 2024 , 25 ( 5 ): 552 - 558 .
Shi Xin , Guo Yunfei , Wang Yawen , et al . A survey on censorship circumvention technologies for anonymous networks [J ] . Journal of Information Engineering University , 2024 , 25 ( 5 ): 552 - 558 . (in Chinese)
Ikram M , Vallina-Rodriguez N , Seneviratne S , et al . An analysis of the privacy and security risks of Android VPN permission-enabled apps [C ] // Proceedings of the 2016 Internet Measurement Conference . New York : ACM , 2016 : 349 - 364 . DOI: 10.1145/2987443.2987471 http://dx.doi.org/10.1145/2987443.2987471
Draper-Gil G , Lashkari A H , Mamun M S I , et al . Characterization of encrypted and VPN traffic using time-related features [C ] // Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP) . Rome : SciTePress , 2016 : 407 - 414 . DOI: 10.5220/0005740704070414 http://dx.doi.org/10.5220/0005740704070414
Feghhi S , Leith D J . A web traffic analysis attack using only timing information [J ] . IEEE Transactions on Information Forensics and Security , 2016 , 11 ( 8 ): 1747 - 1759 . DOI: 10.1109/tifs.2016.2551203 http://dx.doi.org/10.1109/tifs.2016.2551203
Khan M T , Deblasio J , Voelker G M , et al . An empirical analysis of the commercial VPN ecosystem [C ] // Proceedings of the Internet Measurement Conference 2018 . New York : ACM , 2018 : 443 - 456 . DOI: 10.1145/3278532.3278570 http://dx.doi.org/10.1145/3278532.3278570
Zain Ul Abideen M , Saleem S , Ejaz M . VPN traffic detection in SSL-protected channel [J ] . Security and Communication Networks , 2019 , 2019 : 7924690 . DOI: 10.1155/2019/7924690 http://dx.doi.org/10.1155/2019/7924690
Shapira T , Shavitt Y . FlowPic: Encrypted Internet traffic classification is as easy as image recognition [C ] // Proceedings of the IEEE INFOCOM 2019 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS) . Piscataway : IEEE , 2019 : 680 - 687 . DOI: 10.1109/infcomw.2019.8845315 http://dx.doi.org/10.1109/infcomw.2019.8845315
Zhao Ying , Chen Junjun , Wu Di , et al . Multi-task network anomaly detection using federated learning [C ] // Proceedings of the 10th International Symposium on Information and Communication Technology . New York : ACM , 2019 : 273 - 279 . DOI: 10.1145/3368926.3369705 http://dx.doi.org/10.1145/3368926.3369705
Gao Ping , Li Guangsong , Shi Yanan , et al . VPN traffic classification based on payload length sequence [C ] // Proceedings of 2020 International Conference on Networking and Network Applications (NaNA) . Piscataway : IEEE , 2020 : 241 - 247 . DOI: 10.1109/NaNA51271.2020.00048 http://dx.doi.org/10.1109/NaNA51271.2020.00048
Guo Lulu , Wu Qianqiong , Liu Shengli , et al . Deep learning-based real-time VPN encrypted traffic identification methods [J ] . Journal of Real-Time Image Processing , 2020 , 17 ( 1 ): 103 - 114 . DOI: 10.1007/s11554-019-00930-6 http://dx.doi.org/10.1007/s11554-019-00930-6
Wu Hua , Liu Yujie , Cheng Guang , et al . RT-CBCH: Real-time VPN traffic service identification based on sampled data in high-speed networks [J ] . IEEE Transactions on Network and Service Management , 2024 , 21 ( 1 ): 88 - 107 . DOI: 10.1109/tnsm.2023.3286446 http://dx.doi.org/10.1109/tnsm.2023.3286446
Oh S , Lee M , Lee H , et al . AppSniffer: Towards robust mobile app fingerprinting against VPN [C ] // Proceedings of the ACM Web Conference 2023 . New York : ACM , 2023 : 2318 - 2328 . DOI: 10.1145/3543507.3583473 http://dx.doi.org/10.1145/3543507.3583473
Tian Yuan , Cao Zechun , Huang S H S . Detecting VPN traffic in real-time with active probing [C ] // Proceedings of 2024 22nd International Symposium on Network Computing and Applications (NCA) . Piscataway : IEEE , 2024 : 132 - 139 . DOI: 10.1109/nca61908.2024.00030 http://dx.doi.org/10.1109/nca61908.2024.00030
Xue Diwen , Ramesh R , Jain A , et al . OpenVPN is open to VPN fingerprinting [J ] . Communications of the ACM , 2025 , 68 ( 1 ): 79 - 87 . DOI: 10.1145/3618117 http://dx.doi.org/10.1145/3618117
Wang Chenxu , Yin Jiangyi , Li Zhao , et al . Identifying VPN servers through graph-represented behaviors [C ] // Proceedings of the ACM Web Conference 2024 . New York : ACM , 2024 : 1790 - 1799 . DOI: 10.1145/3589334.3645552 http://dx.doi.org/10.1145/3589334.3645552
Guo Xiaoguang , Yu Keyang , Li Qi , et al . Fingerprinting voice commands of VPN-protected smart speakers [J ] . ACM Transactions on Sensor Networks , 2026 , 22 ( 4 ): 1 - 31 . DOI: 10.1145/3734870 http://dx.doi.org/10.1145/3734870
Wang W , Ortwein A , Sobrados E , et al . MVPNalyzer: An investigative framework for auditing the security & privacy of mobile VPNs [C ] // Proceedings of the 2026 Network and Distributed System Security (NDSS) Symposium . San Diego : The Internet Society , 2026 . DOI: 10.14722/ndss.2026.231573 http://dx.doi.org/10.14722/ndss.2026.231573 .
Kotak J , Yankelev I , Bibi I , et al . VPN-encrypted network traffic classification using a time-series approach [J ] . IEEE Transactions on Network and Service Management , 2025 , 22 ( 2 ): 2225 - 2242 . DOI: 10.1109/tnsm.2025.3543903 http://dx.doi.org/10.1109/tnsm.2025.3543903
Naas M , Fesl J . A novel dataset for encrypted virtual private network traffic analysis [J ] . Data in Brief , 2023 , 47 : 108945 . DOI: 10.1016/j.dib.2023.108945 http://dx.doi.org/10.1016/j.dib.2023.108945
Xu Zhenyu , Ren Xurui , Zhang Yi , et al . Peering through the veil: A segment-based approach for VPN encapsulated video title identification [C ] // Proceedings of the IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) . Piscataway : IEEE , 2024 : 1500 - 1505 . DOI: 10.1109/trustcom63139.2024.00207 http://dx.doi.org/10.1109/trustcom63139.2024.00207
Li Qi , Yu Keyang , Chen Dong , et al . TrafficSpy: Disaggregating VPN-encrypted IoT network traffic for user privacy inference [C ] // Proceedings of 2022 IEEE Conference on Communications and Network Security . Piscataway : IEEE , 2022 : 145 - 153 . DOI: 10.1109/cns56114.2022.9947251 http://dx.doi.org/10.1109/cns56114.2022.9947251
Mixon-Baca B , Knockel J , Crandall J R . Hidden links: Analyzing secret families of VPN apps [C ] // Proceedings of the 15th Workshop on Free and Open Communications on the Internet (FOCI) . Washington : The PETS Symposium , 2025 : 18 - 27 .
Liu Haotian , Alshammari R , Zincir-Heywood N . Edge-cloud VPN traffic analysis over cross platforms [C ] // Proceedings of 2024 IEEE 10th World Forum on Internet of Things (WF-IoT) . Piscataway : IEEE , 2024 : 10811218 . DOI: 10.1109/wf-iot62078.2024.10811218 http://dx.doi.org/10.1109/wf-iot62078.2024.10811218
Wu Hua , Liu Yujie , Cheng Guang , et al . Real-time identification of VPN traffic based on counting bloom filter and chained hash table from sampled data in high-speed networks [C ] // Proceedings of ICC 2022-IEEE International Conference on Communications . Piscataway : IEEE , 2022 : 5070 - 5075 . DOI: 10.1109/icc45855.2022.9839256 http://dx.doi.org/10.1109/icc45855.2022.9839256
Ramesh R , Evdokimov L , Xue Diwen , et al . VPNInspector: Systematic investigation of the VPN ecosystem [C ] // Proceedings of the Network and Distributed System Security (NDSS) Symposium . San Diego : The Internet Society , 2022 : 24285 . DOI: 10.14722/ndss.2022.24285 http://dx.doi.org/10.14722/ndss.2022.24285
Fesl J , Naas M . A comprehensive machine learning-based approach for virtual private network traffic detection, classification and hiding [J ] . Computer Networks , 2025 , 270 : 111530 . DOI: 10.1016/j.comnet.2025.111530 http://dx.doi.org/10.1016/j.comnet.2025.111530
Almomani A . Classification of virtual private networks encrypted traffic using ensemble learning algorithms [J ] . Egyptian Informatics Journal , 2022 , 23 ( 4 ): 57 - 68 . DOI: 10.1016/j.eij.2022.06.006 http://dx.doi.org/10.1016/j.eij.2022.06.006
Gupta A . VPN-nonVPN traffic classification using deep reinforced naive Bayes and fuzzy K-means clustering [C ] // Proceedings of 2021 IEEE 41st International Conference on Distributed Computing Systems Workshops (ICDCSW) . Piscataway : IEEE , 2021 : 00008 . DOI: 10.1109/icdcsw53096.2021.00008 http://dx.doi.org/10.1109/icdcsw53096.2021.00008
Abbas G , Farooq U , Singh P , et al . Feature engineering and ensemble learning-based classification of VPN and non-VPN-based network traffic over temporal features [J ] . SN Computer Science , 2023 , 4 ( 5 ): 546 . DOI: 10.1007/s42979-023-01944-5 http://dx.doi.org/10.1007/s42979-023-01944-5
Razooqi Y S , Pekar A . Binary VPN traffic detection using wavelet features and machine learning [C ] // Proceedings of 2025 International Conference on Software, Telecommunications and Computer Networks (SoftCOM) . Piscataway : IEEE , 2025 : 11197436 . DOI: 10.23919/softcom66362.2025.11197436 http://dx.doi.org/10.23919/softcom66362.2025.11197436
Fu Peipei , Liu Chang , Yang Qingya , et al . NSA-Net: A NetFlow sequence attention network for virtual private network traffic detection [C ] // Proceedings of the 21st International Conference on Web Information Systems Engineering (WISE) . Heidelberg : Springer , 2020 : 430 - 444 . DOI: 10.1007/978-3-030-62005-9_31 http://dx.doi.org/10.1007/978-3-030-62005-9_31
Miller S , Curran K , Lunney T . Multilayer perceptron neural network for detection of encrypted VPN network traffic [C ] // Proceedings of 2018 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA) . Piscataway : IEEE , 2018 : 8551395 . DOI: 10.1109/cybersa.2018.8551395 http://dx.doi.org/10.1109/cybersa.2018.8551395
Huang Kai , Zhou Ming , Zhang Peng , et al . Enhancing VPN traffic recognition through CatBoost feature extraction and stacking ensemble learning [C ] // Proceedings of ICC 2024 - IEEE International Conference on Communications . Piscataway : IEEE , 2024 : 79 - 84 . DOI: 10.1109/icc51166.2024.10622256 http://dx.doi.org/10.1109/icc51166.2024.10622256
Tang Jiyue , Yang Le , Liu Song , et al . Caps-LSTM: A novel hierarchical encrypted VPN network traffic identification using CapsNet and LSTM [C ] // Proceedings of the Third International Conference on Science of Cyber Security . Heidelberg : Springer , 2021 : 139 - 153 . DOI: 10.1007/978-3-030-89137-4_10 http://dx.doi.org/10.1007/978-3-030-89137-4_10
Balachandran A , Amritha P P . VPN network traffic classification using entropy estimation and time-related features [M ] // IOT with smart systems . Singapore : Springer Nature Singapore , 2022 : 509 - 520 . DOI: 10.1007/978-981-16-3945-6_50 http://dx.doi.org/10.1007/978-981-16-3945-6_50
Gudla R , Vollala S , Srinivasa K G , et al . TCC: Time constrained classification of VPN and Non-VPN traffic using machine learning algorithms [J ] . Wireless Networks , 2025 , 31 ( 4 ): 3415 - 3429 . DOI: 10.1007/s11276-025-03946-y http://dx.doi.org/10.1007/s11276-025-03946-y
Caicedo-Muñoz J A , Ledezma Espino A , Corrales J C , et al . QoS-Classifier for VPN and Non-VPN traffic based on time-related features [J ] . Computer Networks , 2018 , 144 : 271 - 279 . DOI: 10.1016/j.comnet.2018.08.008 http://dx.doi.org/10.1016/j.comnet.2018.08.008
Lv Sicai , Wang Chao , Wang Zibo , et al . AAE-DSVDD: A one-class classification model for VPN traffic identification [J ] . Computer Networks , 2023 , 236 : 109990 . DOI: 10.1016/j.comnet.2023.109990 http://dx.doi.org/10.1016/j.comnet.2023.109990
Habibi Lashkari A , Draper Gil G , Mamun M S I , et al . Characterization of Tor traffic using time based features [C ] // Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP) . Porto : SciTePress , 2017 : 253 - 262 . DOI: 10.5220/0006105602530262 http://dx.doi.org/10.5220/0006105602530262
Li Zhiyuan , Zhao Hongyi , Zhao Jingyu , et al . SAT-Net: A staggered attention network using graph neural networks for encrypted traffic classification [J ] . Journal of Network and Computer Applications , 2025 , 233 : 104069 . DOI: 10.1016/j.jnca.2024.104069 http://dx.doi.org/10.1016/j.jnca.2024.104069
Lin Xinjie , Xiong Gang , Gou Gaopeng , et al . ET-BERT: A contextualized datagram representation with pre-training transformers for encrypted traffic classification [C ] // Proceedings of the ACM Web Conference 2022 . New York : ACM , 2022 : 633 - 642 . DOI: 10.48550/arXiv.2202.06335 http://dx.doi.org/10.48550/arXiv.2202.06335
Liu Ya , Wang Xiao , Qu Bo , et al . ATVITSC: A novel encrypted traffic classification method based on deep learning [J ] . IEEE Transactions on Information Forensics and Security , 2024 , 19 : 9374 - 9389 . DOI: 10.1109/TIFS.2024.3433446 http://dx.doi.org/10.1109/TIFS.2024.3433446
Peng Quan , Fu Xingbing , Lin Fei , et al . Multi-scale convolutional neural networks optimized by elite strategy dung beetle optimization algorithm for encrypted traffic classification [J ] . Expert Systems with Applications , 2025 , 264 : 125729 . DOI: 10.1016/j.eswa.2024.125729 http://dx.doi.org/10.1016/j.eswa.2024.125729
Habibi L A , Kaur G , Rahali A . DIDarknet: A contemporary approach to detect and characterize the darknet traffic using deep image learning [C ] // Proceedings of the 2020 10th International Conference on Communication and Network Security (ICCNS) . New York : ACM , 2020 : 3442521 . DOI: 10.1145/3442520.3442521 http://dx.doi.org/10.1145/3442520.3442521
Aswad S A , Sonuç E . Classification of VPN network traffic flow using time related features on Apache Spark [C ] // Proceedings of 2020 4th International Symposium on Multidisciplinary Studies and Innovative Technologies (ISMSIT) . Piscataway : IEEE , 2020 : 9254893 . DOI: 10.1109/ismsit50672.2020.9254893 http://dx.doi.org/10.1109/ismsit50672.2020.9254893
郑晓峰 , 段海新 , 陈震宇 , 等 . DataCon: 面向安全研究的多领域大规模竞赛开放数据 [J ] . 信息安全学报 , 2024 , 9 ( 1 ): 123 - 136 .
Zheng Xiaofeng , Duan Haixin , Chen Zhenyu , et al . DataCon: Open dataset for large-scale multiple fields security research and competitions [J ] . Journal of Cyber Security , 2024 , 9 ( 1 ): 123 - 136 . (in Chinese)
Xu Hongbo , Li Shuhao , Cheng Zhenyu , et al . VT-GAT: A novel VPN encrypted traffic classification model based on graph attention neural network [C ] // Proceedings of the 18th EAI International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom) . Heidelberg : Springer , 2022 : 437 - 456 . DOI: 10.1007/978-3-031-24386-8_24 http://dx.doi.org/10.1007/978-3-031-24386-8_24
Jorgensen S , Holodnak J , Dempsey J , et al . Extensible machine learning for encrypted network traffic application labeling via uncertainty quantification [J ] . IEEE Transactions on Artificial Intelligence , 2024 , 5 ( 1 ): 420 - 433 . DOI: 10.1109/tai.2023.3244168 http://dx.doi.org/10.1109/tai.2023.3244168
Guo Xiaoguang , Yu Keyang , Li Qi , et al . VoiceAttack: Fingerprinting voice command on VPN-protected smart home speakers [C ] // Proceedings of the 11th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation . New York : ACM , 2024 : 55 - 65 . DOI: 10.1145/3671127.3698171 http://dx.doi.org/10.1145/3671127.3698171
Maghsoudlou A , Vermeulen L , Poese I , et al . Characterizing the VPN ecosystem in the wild [C ] // Proceedings of the 24th International Conference on Passive and Active Measurement . Heidelberg : Springer , 2023 : 18 - 45 . DOI: 10.48550/arXiv.2302.06566 http://dx.doi.org/10.48550/arXiv.2302.06566
Farnan O , Wright J , Darer A . Analysing censorship circumvention with VPNs via DNS cache snooping [C ] // Proceedings of 2019 IEEE Security and Privacy Workshops . Piscataway : IEEE , 2019 : 205 - 211 . DOI: 10.1109/spw.2019.00046 http://dx.doi.org/10.1109/spw.2019.00046
Schwartz T , Manor O , Otung A . SNITCH: Leveraging IP geolocation for active VPN detection [C ] // Proceedings of 2025 Workshop on Measurements, Attacks, and Defenses for the Web . NDSS Symposium , 2025 . DOI: 10.14722/madweb.2025.23008 http://dx.doi.org/10.14722/madweb.2025.23008 .
Telikani A , Gandomi A H , Choo K K R , et al . A cost-sensitive deep learning-based approach for network traffic classification [J ] . IEEE Transactions on Network and Service Management , 2022 , 19 ( 1 ): 661 - 670 . DOI: 10.1109/tnsm.2021.3112283 http://dx.doi.org/10.1109/tnsm.2021.3112283
Zhang Jielun , Li Fuhao , Wu Hongyu , et al . Autonomous model update scheme for deep learning based network traffic classifiers [C ] // Proceedings of 2019 IEEE Global Communications Conference (GLOBECOM) . Piscataway : IEEE , 2019 : 9014036 . DOI: 10.1109/globecom38437.2019.9014036 http://dx.doi.org/10.1109/globecom38437.2019.9014036
Zhang Jielun , Li Fuhao , Ye Feng , et al . Autonomous unknown-application filtering and labeling for DL-based traffic classifier update [C ] // Proceedings of IEEE INFOCOM 2020 - IEEE Conference on Computer Communications . Piscataway : IEEE , 2020 : 397 - 405 . DOI: 10.1109/infocom41043.2020.9155292 http://dx.doi.org/10.1109/infocom41043.2020.9155292
王琳 , 封化民 , 刘飚 , 等 . 基于混合方法的SSL VPN加密流量识别研究 [J ] . 计算机应用与软件 , 2019 , 36 ( 2 ): 315 - 322 . DOI: 10.3969/j.issn.1000-386x.2019.02.055 http://dx.doi.org/10.3969/j.issn.1000-386x.2019.02.055
Wang Lin , Feng Huamin , Liu Biao , et al . SSL VPN encrypted traffic identification based on hybrid method [J ] . Computer Applications and Software , 2019 , 36 ( 2 ): 315 - 322 . (in Chinese) . DOI: 10.3969/j.issn.1000-386x.2019.02.055 http://dx.doi.org/10.3969/j.issn.1000-386x.2019.02.055
周益旻 , 刘方正 , 王勇 . 基于混合方法的IPSec VPN加密流量识别 [J ] . 计算机科学 , 2021 , 48 ( 4 ): 295 - 302 . DOI: 10.11896/jsjkx.200700189 http://dx.doi.org/10.11896/jsjkx.200700189
Zhou Yimin , Liu Fangzheng , Wang Yong . IPSec VPN encrypted traffic identification based on hybrid method [J ] . Computer Science , 2021 , 48 ( 4 ): 295 - 302 . (in Chinese) . DOI: 10.11896/jsjkx.200700189 http://dx.doi.org/10.11896/jsjkx.200700189
Meng Yongwei , Qin Tao , Wang Haonian , et al . TPIPD: A robust model for online VPN traffic classification [C ] // Proceedings of 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) . Piscataway : IEEE , 2022 : 105 - 110 . DOI: 10.1109/trustcom56396.2022.00025 http://dx.doi.org/10.1109/trustcom56396.2022.00025
唐舒烨 , 程光 , 蒋泊淼 , 等 . 基于分段熵分布的VPN加密流量检测与识别方法 [J ] . 网络空间安全 , 2020 , 11 ( 8 ): 23 - 27 .
Tang Shuye , Cheng Guang , Jiang Bomiao , et al . Detection and recognition of VPN encrypted traffic based on segmented entropy distribution [J ] . Cyberspace Security , 2020 , 11 ( 8 ): 23 - 27 . (in Chinese)
Ling Zhen , Luo Junzhou , Xu Danni , et al . Novel and practical SDN-based traceback technique for malicious traffic over anonymous networks [C ] // Proceedings of the IEEE INFOCOM 2019 - IEEE Conference on Computer Communications . Piscataway : IEEE , 2019 : 1180 - 1188 . DOI: 10.1109/INFOCOM.2019.8737586 http://dx.doi.org/10.1109/INFOCOM.2019.8737586
Rajore T , Jithin S , Gupta A , et al . VPN or Vpwn How afraid should you be of VPN traffic identification? [C ] // Proceedings of 2025 9th Network Traffic Measurement and Analysis Conference (TMA) . Piscataway : IEEE , 2025 : 11096969 . DOI: 10.23919/tma66427.2025.11096969 http://dx.doi.org/10.23919/tma66427.2025.11096969
Almutairi S , Neumann Y , Harfoush K . Fingerprinting VPNs with custom router firmware: A new censorship threat model [C ] // Proceedings of 2024 IEEE 21st Consumer Communications & Networking Conference (CCNC) . Piscataway : IEEE , 2024 : 976 - 981 . DOI: 10.1109/ccnc51664.2024.10454833 http://dx.doi.org/10.1109/ccnc51664.2024.10454833
Yao Haipeng , Liu Chong , Zhang Peiying , et al . Identification of encrypted traffic through attention mechanism based long short term memory [J ] . IEEE Transactions on Big Data , 2022 , 8 ( 1 ): 241 - 252 . DOI: 10.1109/TBDATA.2019.2940675 http://dx.doi.org/10.1109/TBDATA.2019.2940675
Zhou Guangmeng , Guo Xiongwen , Liu Zhuotao , et al . TrafficFormer: An efficient pre-trained model for traffic data [C ] // Proceedings of 2025 IEEE Symposium on Security and Privacy (SP) . Piscataway : IEEE , 2025 : 1844 - 1860 . DOI: 10.1109/sp61157.2025.00102 http://dx.doi.org/10.1109/sp61157.2025.00102
Nascita A , Montieri A , Aceto G , et al . Improving performance, reliability, and feasibility in multimodal multitask traffic classification with XAI [J ] . IEEE Transactions on Network and Service Management , 2023 , 20 ( 2 ): 1267 - 1289 . DOI: 10.1109/tnsm.2023.3246794 http://dx.doi.org/10.1109/tnsm.2023.3246794
Cai Wei , Hou Chengshang , Cui Mingxin , et al . Incremental encrypted traffic classification via contrastive prototype networks [J ] . Computer Networks , 2024 , 250 : 110591 . DOI: 10.1016/j.comnet.2024.110591 http://dx.doi.org/10.1016/j.comnet.2024.110591
Kattadige C , Choi K N , Wijesinghe A , et al . SETA++: Real-time scalable encrypted traffic analytics in multi-Gbps networks [J ] . IEEE Transactions on Network and Service Management , 2021 , 18 ( 3 ): 3244 - 3259 . DOI: 10.1109/tnsm.2021.3085097 http://dx.doi.org/10.1109/tnsm.2021.3085097
Gao Bowen , Yang Yang , Gao Zhipeng , et al . Unsupervised network traffic classification based on multi-source synergistic distribution alignment [C ] // Proceedings of GLOBECOM 2023 - 2023 IEEE Global Communications Conference . Piscataway : IEEE , 2023 : 4313 - 4319 . DOI: 10.1109/globecom54140.2023.10437268 http://dx.doi.org/10.1109/globecom54140.2023.10437268
Shen Meng , Ji Kexin , Wu Jinhe , et al . Real-time website fingerprinting defense via traffic cluster anonymization [C ] // Proceedings of the 45th IEEE Symposium on Security and Privacy (SP) . Piscataway : IEEE , 2024 : 3238 - 3256 . DOI: 10.1109/sp54263.2024.00247 http://dx.doi.org/10.1109/sp54263.2024.00247
Shen Meng , Ji Kexin , Gao Zhenbo , et al . Subverting website fingerprinting defenses with robust traffic representation [C ] // Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim : USENIX Association , 2023 : 607 - 624 .
Shen Meng , Liu Yiting , Zhu Liehuang , et al . Fine-grained webpage fingerprinting using only packet length information of encrypted traffic [J ] . IEEE Transactions on Information Forensics and Security , 2021 , 16 : 2046 - 2059 . DOI: 10.1109/tifs.2020.3046876 http://dx.doi.org/10.1109/tifs.2020.3046876
Zhao Xiyuan , Deng Xinhao , Li Qi , et al . Towards fine-grained webpage fingerprinting at scale [C ] // Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS’24) . New York : ACM , 2024 : 423 - 436 . DOI: 10.1145/3658644.3690211 http://dx.doi.org/10.1145/3658644.3690211
Deng Xinhao , Yin Qilei , Liu Zhuotao , et al . Robust multi-tab website fingerprinting attacks in the wild [C ] // Proceedings of 2023 IEEE Symposium on Security and Privacy (SP) . Piscataway : IEEE , 2023 : 1005 - 1022 . DOI: 10.1109/sp46215.2023.10179464 http://dx.doi.org/10.1109/sp46215.2023.10179464
Kamal K M A , Almuhammadi S . Vulnerability of virtual private networks to web fingerprinting attack [M ] // Advances in security, networks, and internet of things . Cham : Springer International Publishing , 2021 : 147 - 165 . DOI: 10.1007/978-3-030-71017-0_11 http://dx.doi.org/10.1007/978-3-030-71017-0_11
Perdices D , López De Vergara J E , González I , et al . Web browsing privacy in the deep learning era: Beyond VPNs and encryption [J ] . Computer Networks , 2023 , 220 : 109471 . DOI: 10.1016/j.comnet.2022.109471 http://dx.doi.org/10.1016/j.comnet.2022.109471
Tolley W J , Kujath B , Khan M T , et al . Blind In/On-Path attacks and applications to VPNs [C ] // Proceedings of the 30th USENIX Security Symposium (USENIX Security 21) . Online : USENIX Association , 2021 : 3129 - 3146 .
Fu Chuanpu , Li Qi , Shen Meng , et al . Detecting tunneled flooding traffic via deep semantic analysis of packet length patterns [C ] // Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2024 : 3659 - 3673 . DOI: 10.1145/3658644.3670353 http://dx.doi.org/10.1145/3658644.3670353
Zhuo Zhongliu , Zhang Yang , Zhang Zhili , et al . Website fingerprinting attack on anonymity networks based on profile hidden Markov model [J ] . IEEE Transactions on Information Forensics and Security , 2018 , 13 ( 5 ): 1081 - 1095 . DOI: 10.1109/TIFS.2017.2762825 http://dx.doi.org/10.1109/TIFS.2017.2762825
Zeng Xuemei , Chen Xingshu , Shao Guolin , et al . Flow context and host behavior based Shadowsocks’s traffic identification [J ] . IEEE Access , 2019 , 7 : 41017 - 41032 . DOI: 10.1109/access.2019.2907149 http://dx.doi.org/10.1109/access.2019.2907149
Cheng Jiaxing , Li Ying , Huang Cheng , et al . ACER: Detecting Shadowsocks server based on active probe technology [J ] . Journal of Computer Virology and Hacking Techniques , 2020 , 16 ( 3 ): 217 - 227 . DOI: 10.1007/s11416-020-00353-z http://dx.doi.org/10.1007/s11416-020-00353-z
Ma Xiaobo , Qu Jian , Shi Mawei , et al . Website fingerprinting on encrypted proxies: A flow-context-aware approach and countermeasures [J ] . IEEE/ACM Transactions on Networking , 2024 , 32 ( 3 ): 1904 - 1919 . DOI: 10.1109/tnet.2023.3337270 http://dx.doi.org/10.1109/tnet.2023.3337270
Ma Xiaobo , Shi Mawei , An Bingyu , et al . Context-aware website fingerprinting over encrypted proxies [C ] // Proceedings of the IEEE INFOCOM 2021-IEEE Conference on Computer Communications . Piscataway : IEEE , 2021 : 9488676 . DOI: 10.1109/INFOCOM42981.2021.9488676 http://dx.doi.org/10.1109/INFOCOM42981.2021.9488676
Yang Mingshuo , Yu Yunnan , Mi Xianghang , et al . An extensive study of residential proxies in China [C ] // Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2022 : 3049 - 3062 . DOI: 10.1145/3548606.3559377 http://dx.doi.org/10.1145/3548606.3559377
Wang Suixing , Yang Chao , Guo Gang , et al . SSAPPIDENTIFY: A robust system identifies application over Shadowsocks’s traffic [J ] . Computer Networks , 2022 , 203 : 108659 . DOI: 10.1016/j.comnet.2021.108659 http://dx.doi.org/10.1016/j.comnet.2021.108659
Hartl A , Fabini J , Zseby T . Separating flows in encrypted tunnel traffic [C ] // Proceedings of 2022 21st IEEE International Conference on Machine Learning and Applications (ICMLA) . Piscataway : IEEE , 2022 : 609 - 616 . DOI: 10.1109/icmla55696.2022.00094 http://dx.doi.org/10.1109/icmla55696.2022.00094
Zhang Shunliang , Zhao Hongce , Fan Zuwei . Packet bytes-based abnormal encrypted proxy traffic identification [C ] // Proceedings of 2024 IEEE 30th International Conference on Telecommunications (ICT) . Piscataway : IEEE , 2024 : 10606114 . DOI: 10.1109/ict62760.2024.10606114 http://dx.doi.org/10.1109/ict62760.2024.10606114
Liu Mengyan , Gou Gaopeng , Xiong Gang , et al . Enhanced detection of obfuscated HTTPS tunnel traffic using heterogeneous information network [J ] . Computer Networks , 2025 , 257 : 110975 . DOI: 10.1016/j.comnet.2024.110975 http://dx.doi.org/10.1016/j.comnet.2024.110975
Zhang Yi , Xu Zhenyu , Ren Xurui , et al . SCEP-TI: A side-channel attack on encrypted proxy video streams for video title identification [J ] . Computer Networks , 2025 , 271 : 111630 . DOI: 10.1016/j.comnet.2025.111630 http://dx.doi.org/10.1016/j.comnet.2025.111630
Gu Zheyuan , Liu Chang , Zhang Xiyuan , et al . DecETT: Accurate app fingerprinting under encrypted tunnels via dual decouple-based semantic enhancement [C ] // Proceedings of the ACM on Web Conference 2025 . New York : ACM , 2025 : 2413 - 2423 . DOI: 10.1145/3696410.3714643 http://dx.doi.org/10.1145/3696410.3714643
Liu Mengyan , Gou Gaopeng , Xiong Gang , et al . ProxyCorr: Robust traffic correlation attacks via mixed spatio-temporal analysis in encrypted proxy networks [J ] . Computer Networks , 2025 , 273 : 111763 . DOI: 10.1016/j.comnet.2025.111763 http://dx.doi.org/10.1016/j.comnet.2025.111763
Perino D , Varvello M , Soriente C . ProxyTorrent: Untangling the free HTTP(S) proxy ecosystem [C ] // Proceedings of the 2018 World Wide Web Conference . New York : ACM , 2018 : 197 - 206 . DOI: 10.1145/3178876.3186086 http://dx.doi.org/10.1145/3178876.3186086
Li Jianfeng , Wang Dongliang , Liu Yixuan , et al . Cross-environmental website fingerprinting [C ] // Proceedings of the IEEE INFOCOM 2025 - IEEE Conference on Computer Communications . Piscataway : IEEE , 2025 : 11044569 . DOI: 10.1109/infocom55648.2025.11044569 http://dx.doi.org/10.1109/infocom55648.2025.11044569
Beckerle M , Magnusson J , Pulls T . Splitting hairs and network traces: Improved attacks against traffic splitting as a website fingerprinting defense [C ] // Proceedings of the 21st Workshop on Privacy in the Electronic Society . New York : ACM , 2022 : 15 - 27 . DOI: 10.1145/3559613.3563199 http://dx.doi.org/10.1145/3559613.3563199
Xu Hongbo , Cheng Zhenyu , Li Shuhao , et al . ProxyKiller: An anonymous proxy traffic attack model based on traffic behavior graphs [C ] // Proceedings of the 29th European Symposium on Research in Computer Security . Heidelberg : Springer , 2024 : 162 - 181 . DOI: 10.1007/978-3-031-70890-9_9 http://dx.doi.org/10.1007/978-3-031-70890-9_9
苟高鹏 . 加密应用识别与公害行为发现流量数据集 [DB/OL ] . ( 2025-03-31 )[ 2025-11-14 ] . https://cstr.cn/16666.11.nbsdc.jtMB7oBB https://cstr.cn/16666.11.nbsdc.jtMB7oBB .
Gou Gaopeng . Encrypted application identification and public nuisance behavior discovery traffic dataset: V1 [DB/OL ] . ( 2025-03-31 )[ 2025-11-14 ] . https://cstr.cn/16666.11.nbsdc.jtMB7oBB https://cstr.cn/16666.11.nbsdc.jtMB7oBB . (in Chinese)
Wang G , Sippe J , Chi Hai , et al . Chasing shadows: A security analysis of the ShadowTLS proxy [C ] // Proceedings of the 13th Free and Open Communications on the Internet (FOCI 23) . Online : The PETS Symposium , 2023 : 8 - 13 .
Aceto G , Ciuonzo D , Montieri A , et al . Multi-classification approaches for classifying mobile app traffic [J ] . Journal of Network and Computer Applications , 2018 , 103 : 131 - 145 . DOI: 10.1016/j.jnca.2017.11.007 http://dx.doi.org/10.1016/j.jnca.2017.11.007
Cui Simiao , Wang Dinghua , Zhang Xi , et al . Identifying mobile application over Shadowsocks with single-direction traffic [C ] // Proceedings of 2023 8th International Conference on Data Science in Cyberspace (DSC) . Piscataway : IEEE , 2023 : 551 - 558 . DOI: 10.1109/dsc59305.2023.00086 http://dx.doi.org/10.1109/dsc59305.2023.00086
Zhou Nanxin , Liu Yiwei , Li Yujun , et al . A generalization-enhanced method for encrypted proxy traffic identification based on autoencoder [C ] // Proceedings of 2024 2nd International Conference on Mobile Internet, Cloud Computing and Information Security (MICCIS) . Piscataway : IEEE , 2024 : 221 - 228 . DOI: 10.1109/miccis63508.2024.00043 http://dx.doi.org/10.1109/miccis63508.2024.00043
Zhang Junzhe . Research on Tor over SOCKS5 proxy anonymous communication behavior reconition [C ] // Proceedings of 2025 5th International Conference on Sensors and Information Technology (ICSIIT) . Piscataway : IEEE , 2025 : 307 - 312 . DOI: 10.1109/icsi64877.2025.11009624 http://dx.doi.org/10.1109/icsi64877.2025.11009624
Luo Yuantu , Tao Jun , Yu Linxiao , et al . Together may be better: A novel framework and high-consistency feature for proxy traffic analysis [J ] . Computer Networks , 2025 , 272 : 111672 . DOI: 10.1016/j.comnet.2025.111672 http://dx.doi.org/10.1016/j.comnet.2025.111672
Mühle A , Grüner A , Meinel C . Characterising proxy usage in the bitcoin peer-to-peer network [C ] // Proceedings of the 22nd International Conference on Distributed Computing and Networking . New York : ACM , 2021 : 176 - 185 . DOI: 10.1145/3427796.3427840 http://dx.doi.org/10.1145/3427796.3427840
Ji Qingbing , Deng Xiaoyan , Ni Lulin , et al . Research on ShadowsocksR traffic identification based on XGBoost algorithm [C ] // Proceedings of the 5th International Conference on Intelligent and Interactive Systems and Applications . Heidelberg : Springer , 2020 : 53 - 61 . DOI: 10.1007/978-3-030-63784-2_8 http://dx.doi.org/10.1007/978-3-030-63784-2_8
Luo Ping , Wang Fei , Chen Shuhui , et al . Behavior-based method for real-time identification of encrypted proxy traffic [C ] // Proceedings of 2021 13th International Conference on Communication Software and Networks (ICCSN) . Piscataway : IEEE , 2021 : 289 - 295 . DOI: 10.1109/ICCSN52437.2021.9463594 http://dx.doi.org/10.1109/ICCSN52437.2021.9463594
Ji Qingbing , Deng Xiaoyan , Ni Lulin . Research on ShadowsocksR traffic identification based on DART algorithm [C ] // Proceedings of 2021 7th Annual International Conference on Network and Information Systems for Computers (ICNISC) . Piscataway : IEEE , 2021 : 666 - 672 . DOI: 10.1109/icnisc54316.2021.00126 http://dx.doi.org/10.1109/icnisc54316.2021.00126
Zliang N , Wu Tiantian , Zhang Yuening , et al . Shadowsocks traffic identification based on convolutional neural network [C ] // Proceedings of 2020 International Conference on Information Science and Education (ICISE-IE) . Piscataway : IEEE , 2020 : 480 - 485 . DOI: 10.1109/icise51755.2020.00109 http://dx.doi.org/10.1109/icise51755.2020.00109
Xie Yanfeng . Automated encrypted proxy traffic classification via optimized 1D-CNN and feature attention [C ] // Proceedings of 2025 IEEE 5th International Conference on Electronic Technology, Communication and Information (ICETCI) . Piscataway : IEEE , 2025 : 1406 - 1410 . DOI: 10.1109/icetci64844.2025.11084031 http://dx.doi.org/10.1109/icetci64844.2025.11084031
Zhao Hongce , Zhang Shunliang , Qiao Zhuang , et al . On the performance of deep learning methods for identifying abnormal encrypted proxy traffic [C ] // Proceedings of 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) . Piscataway : IEEE , 2022 : 1416 - 1423 . DOI: 10.1109/trustcom56396.2022.00200 http://dx.doi.org/10.1109/trustcom56396.2022.00200
Janbeglou M , Brownlee N . Identifying tunnelled proxies through passively monitoring network traffic [C ] // Proceedings of 2016 IEEE 18th International Conference on High Performance Computing and Communications; IEEE 14th International Conference on Smart City; IEEE 2nd International Conference on Data Science and Systems (HPCC/SmartCity/DSS) . Piscataway : IEEE , 2016 : 63 - 69 . DOI: 10.1109/hpcc-smartcity-dss.2016.0020 http://dx.doi.org/10.1109/hpcc-smartcity-dss.2016.0020
Wang W , Xue Diwen , Kumar P , et al . Is custom congestion control a bad idea for circumvention tools [C ] // Proceedings of the 15th Free and Open Communications on the Internet (FOCI 25) . Online : The PETS Symposium , 2025 : 1 - 6 .
Spreitzer R , Griesmayr S , Korak T , et al . Exploiting data-usage statistics for website fingerprinting attacks on Android [C ] // Proceedings of the 9th ACM Conference on Security & Privacy in Wireless and Mobile Networks . New York : ACM , 2016 : 49 - 60 . DOI: 10.1145/2939918.2939922 http://dx.doi.org/10.1145/2939918.2939922
Luo Jie , Bao Liang , Ni Lvlin . A method of Shadowsocks (R) traffic identification based on protocol analysis [C ] // Proceedings of 2021 IEEE 21st International Conference on Communication Technology . Piscataway : IEEE , 2021 : 6 - 10 . DOI: 10.1109/icct52962.2021.9657982 http://dx.doi.org/10.1109/icct52962.2021.9657982
Litvinov V L . Research of methods for recognizing anonymized traffic [C ] // Proceedings of 2025 VI International Conference on Control in Technical Systems (CTS) . Piscataway : IEEE , 2025 : 127 - 130 . DOI: 10.1109/cts67336.2025.11196346 http://dx.doi.org/10.1109/cts67336.2025.11196346
Ejeta T G , Kim H J . Website fingerprinting attack on Psiphon and its forensic analysis [M ] // Digital forensics and watermarking . Cham : Springer International Publishing , 2017 : 42 - 51 . DOI: 10.1007/978-3-319-64185-0_4 http://dx.doi.org/10.1007/978-3-319-64185-0_4
Zhao Yankang , Ma Xiaobo , Li Jianfeng , et al . Revisiting website fingerprinting attacks in real-world scenarios: A case study of Shadowsocks [C ] // Proceedings of the 12th International Conference on Network and System Security (NSS) . Heidelberg : Springer , 2018 : 319 - 336 . DOI: 10.1007/978-3-030-02744-5_24 http://dx.doi.org/10.1007/978-3-030-02744-5_24
Deng Ziye , Liu Zihan , Chen Zhouguo , et al . The random forest based detection of Shadowsock’s traffic [C ] //Proceedings of 2017 9th International Conference on Intelligent Human-Machine Systems and Cybernetics (IHMSC): Vol. 2 . Piscataway : IEEE , 2017 : 75 - 78 . DOI: 10.1109/ihmsc.2017.132 http://dx.doi.org/10.1109/ihmsc.2017.132
Miller S , Curran K , Lunney T . Detection of anonymising proxies using machine learning [J ] . International Journal of Digital Crime and Forensics , 2021 , 13 ( 6 ): 1 - 17 . DOI: 10.4018/ijdcf.286756 http://dx.doi.org/10.4018/ijdcf.286756
Zhang Xianlei , Ma Xiaobo , Han Xiao , et al . An uncertainty-based traffic training approach to efficiently identifying encrypted proxies [C ] // Proceedings of 2020 12th International Conference on Advanced Infocomm Technology (ICAIT) . Piscataway : IEEE , 2020 : 95 - 99 . DOI: 10.1109/icait51223.2020.9315573 http://dx.doi.org/10.1109/icait51223.2020.9315573
Engelberg A , Wool A . Classification of encrypted IoT traffic despite padding and shaping [C ] // Proceedings of the 21st Workshop on Privacy in the Electronic Society . New York : ACM , 2022 : 3563191 . DOI: 10.1145/3559613.3563191 http://dx.doi.org/10.1145/3559613.3563191
Hu Xiaoyan , Lin Boquan , Cheng Guang , et al . Detecting cryptomining traffic over an encrypted proxy based on K-S test [C ] // Proceedings of the ICC 2023-IEEE International Conference on Communications . Piscataway : IEEE , 2023 : 3787 - 3792 . DOI: 10.1109/icc45041.2023.10279537 http://dx.doi.org/10.1109/icc45041.2023.10279537
Rahman M S , Imani M , Mathews N , et al . Mockingbird: Defending against deep-learning-based website fingerprinting attacks with adversarial traces [J ] . IEEE Transactions on Information Forensics and Security , 2021 , 16 : 1594 - 1609 . DOI: 10.1109/TIFS.2020.3039691 http://dx.doi.org/10.1109/TIFS.2020.3039691
Fu Chuanpu , Li Qi , Xu Ke . Detecting unknown encrypted malicious traffic in real time via flow interaction graph analysis [C ] // Proceedings of the Network and Distributed System Security Symposium (NDSS) . San Diego : The Internet Society , 2023 . DOI: 10.14722/ndss.2023.23080 http://dx.doi.org/10.14722/ndss.2023.23080
Zhou Yong , Liu Weiwei , Sun Jinsheng . A multi-modal learning-based behavior identification scheme for obfuscated tunneling traffic [C ] // Proceedings of the 2024 7th International Conference on Computer Information Science and Artificial Intelligence . New York : ACM , 2024 : 581 - 586 . DOI: 10.1145/3703187.3703285 http://dx.doi.org/10.1145/3703187.3703285
Sakamoto , Edwards E . Bleeding wall: A hematologic examination on the Great Firewall [C ] // Proceedings of the 14th Free and Open Communications on the Internet . Online : The PETS Symposium , 2024 : 13 - 21 .
Husák M , Čermák M , Jirsík T , et al . HTTPS traffic analysis and client identification using passive SSL/TLS fingerprinting [J ] . EURASIP Journal on Information Security , 2016 , 2016 ( 1 ): 6 . DOI: 10.1186/s13635-016-0030-7 http://dx.doi.org/10.1186/s13635-016-0030-7
Song Yafeng , Yang Ming , Chen Qi , et al . Evaluating the distinguishability of tor traffic over censorship circumvention tools [C ] // Proceedings of 2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD) . Piscataway : IEEE , 2023 : 917 - 922 . DOI: 10.1109/cscwd57460.2023.10152791 http://dx.doi.org/10.1109/cscwd57460.2023.10152791
Lange F , Niere N , Von Niessen J , et al . I(ra)nconsistencies: Novel insights into Iran’s censorship [C ] // Proceedings of the 15th Free and Open Communications on the Internet (FOCI 25) . Online : The PETS Symposium , 2025 : 7 - 12 .
Huang Shuangshuang , Ma Xiaobo , Bian Huafeng . Effectively and efficiently defending Shadowsocks against website fingerprinting attacks [C ] // Proceedings of 2021 8th International Conference on Dependable Systems and Their Applications (DSA) . Piscataway : IEEE , 2021 : 251 - 256 . DOI: 10.1109/dsa52907.2021.00038 http://dx.doi.org/10.1109/dsa52907.2021.00038
Ding Ke , Hu Xiaoyan , Shu Zhuozhuo , et al . NFT-AF: Multi-dimensional non-fungible token application fingerprinting over encrypted tunnels [J ] . IEEE Network , 2025 : 1 - 8 . DOI: 10.1109/mnet.2025.3637868 http://dx.doi.org/10.1109/mnet.2025.3637868
Kaplan I , Even R , Klein A . You can rand but you can’t hide: A holistic security analysis of Google Fuchsia’s (and gVisor’s) network stack [C ] // Proceedings of the 32nd Annual Network and Distributed System Security Symposium (NDSS) . San Diego : The Internet Society , 2025 . DOI: 10.14722/ndss.2025.240122 http://dx.doi.org/10.14722/ndss.2025.240122
Paolini E , De Marinis L , Scano D , et al . In-line any-depth deep neural networks using P4 switches [J ] . IEEE Open Journal of the Communications Society , 2024 , 5 : 3556 - 3567 . DOI: 10.1109/OJCOMS.2024.3411071 http://dx.doi.org/10.1109/OJCOMS.2024.3411071
Yan Jinzhu , Xu Haotian , Liu Zhuotao , et al . Brain-on-Switch: Towards advanced intelligent network data plane via NN-driven traffic analysis at line-speed [C ] // Proceedings of the 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI 24) . Santa Clara : USENIX Association , 2024 : 24 .
0
浏览量
10
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621