Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk

preprint OA: closed
Full text JSON View at publisher
AI-generated summary by claude@2026-07, 2026-07-17

This paper proposes the Only Header framework, using a twice segmentation mechanism and capsule neural networks on flow headers to classify encrypted traffic without privacy risk or manual feature extraction.

One-sentence paraphrase of the abstract; not a substitute for reading it. No clinical advice. How this works

AI-generated deep summary by claude@2026-07, 2026-07-17 · read from full text

The paper studies encrypted traffic classification for network management tasks such as Quality-of-Service provisioning and network intrusion detection, aiming to overcome limitations of port-based methods and deep packet inspection for encrypted payloads. Using two public ISCX datasets (VPN-nonVPN and Tor-nonTor), the authors propose an “Only Header” framework that relies solely on encrypted flow header information, introduces a twice segmentation mechanism to reduce interference traffic, and applies capsule neural networks to learn spatial and byte-related header features while avoiding privacy risk and reducing storage pressure from massive payloads. They compare the effectiveness of Only Header against other approaches using these datasets. The authors explicitly note this work is a preprint under review and not yet peer reviewed, and no further limitations are stated in the provided text. This paper does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Abstract Encrypted traffic classification plays a critical role in network management, providing appropriate Quality-of-Service and Network Intrusion Detection. Conventional port-based and deep packet inspection (DPI) approaches cannot classify encrypted traffic effectively. Methods based on machine learning can classify encrypted traffic by extracting statistical features of the flow. However, they require manual extraction of features. Recent studies show that the approaches based on deep learning are compelling for the task. They can automatically learn raw traffic features without manual feature extraction. However, these studies still take the payload of encrypted traffic as the model input, which may cause privacy risks. Besides, a massive encrypted payload causes great storage pressure on traffic classification. In this paper, we propose a reliable encrypted traffic classification framework by only using the flow header called Only Header, which avoids privacy risks and achieves lightweight storage. Firstly, we introduce a twice segmentation mechanism to dilute the interference traffic and increase the weight of effective traffic. Then we use capsule neural networks (CapsNet) to learn spatial and byte features of the flow header. The Only Header's effectiveness is compared with other methods using two public datasets, including ISCX VPN-nonVPN and ISCX Tor-nonTor datasets.
Full text 12,268 characters · extracted from preprint-html · click to expand
Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk Susu Cui, Jian Liu, Cong Dong, Zhigang Lu, Dan DU This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-745961/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 4 You are reading this latest preprint version Abstract Encrypted traffic classification plays a critical role in network management, providing appropriate Quality-of-Service and Network Intrusion Detection. Conventional port-based and deep packet inspection (DPI) approaches cannot classify encrypted traffic effectively. Methods based on machine learning can classify encrypted traffic by extracting statistical features of the flow. However, they require manual extraction of features. Recent studies show that the approaches based on deep learning are compelling for the task. They can automatically learn raw traffic features without manual feature extraction. However, these studies still take the payload of encrypted traffic as the model input, which may cause privacy risks. Besides, a massive encrypted payload causes great storage pressure on traffic classification. In this paper, we propose a reliable encrypted traffic classification framework by only using the flow header called Only Header, which avoids privacy risks and achieves lightweight storage. Firstly, we introduce a twice segmentation mechanism to dilute the interference traffic and increase the weight of effective traffic. Then we use capsule neural networks (CapsNet) to learn spatial and byte features of the flow header. The Only Header's effectiveness is compared with other methods using two public datasets, including ISCX VPN-nonVPN and ISCX Tor-nonTor datasets. encrypted traffic classification capsule neural networks. twice segmentation mechanism privacy risk Full Text Cite Share Download PDF Status: Under Review Version 1 posted Reviews received at journal 11 Feb, 2022 Reviewers invited by journal 11 Feb, 2022 Editor assigned by journal 26 Jul, 2021 First submitted to journal 22 Jul, 2021 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-745961","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":83100272,"identity":"62730666-9a4b-4443-9fb3-6faf58d2f0bf","order_by":0,"name":"Susu Cui","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAtklEQVRIiWNgGAWjYFACxgYQKcfGTKoWY1K0QEBiA9FK+WckN3/m+XM4vY+d+QDDjxoGeXNCWiRuJLZJ87Ydzm1jZktg7DnGYLiTkH0GEoltzLwNIC08Bgy8DQwJBgcIa4E4jI2Z/wPjXyK1NEjzsB1OYGPmYWAmyhaJMw/bJOe2pRsC/WJwWOaYhOEGQlr429Mff3jzx1pevv/ww4dvamzkCdqCAoCKJUhRPwpGwSgYBaMAFwAAEs83rqmpTnYAAAAASUVORK5CYII=","orcid":"https://orcid.org/0000-0001-5249-5699","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Susu","middleName":"","lastName":"Cui","suffix":""},{"id":83100273,"identity":"38f9e279-bfc8-4b1c-acfd-8174068e12c9","order_by":1,"name":"Jian Liu","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Jian","middleName":"","lastName":"Liu","suffix":""},{"id":83100274,"identity":"efd7b619-0b4c-4fc9-9f92-d6da572dd6fc","order_by":2,"name":"Cong Dong","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Cong","middleName":"","lastName":"Dong","suffix":""},{"id":83100275,"identity":"0c3e5cfc-4c84-472d-b500-fdfb5da51973","order_by":3,"name":"Zhigang Lu","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Zhigang","middleName":"","lastName":"Lu","suffix":""},{"id":83100276,"identity":"82c5a5d8-0f80-42b8-ab5e-10d4c86ed36a","order_by":4,"name":"Dan DU","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Dan","middleName":"","lastName":"DU","suffix":""}],"badges":[],"createdAt":"2021-07-24 08:55:50","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-745961/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-745961/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":18213605,"identity":"82dee529-16a1-4b50-9b9f-1e0317825182","added_by":"auto","created_at":"2022-02-15 00:17:36","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":3122637,"visible":true,"origin":"","legend":"","description":"","filename":"OnlyHeader.pdf","url":"https://assets-eu.researchsquare.com/files/rs-745961/v1_covered.pdf"}],"financialInterests":"","formattedTitle":"Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk","fulltext":[{"header":"Full Text","content":"This preprint is available for \u003ca href='/article/rs-745961/latest.pdf' target='_blank'\u003edownload as a PDF\u003c/a\u003e."}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":true,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"soft-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"soco","sideBox":"Learn more about [Soft Computing](https://www.springer.com/journal/500)","snPcode":"500","submissionUrl":"https://submission.nature.com/new-submission/500/3","title":"Soft Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"encrypted traffic classification, capsule neural networks. twice segmentation mechanism, privacy risk","lastPublishedDoi":"10.21203/rs.3.rs-745961/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-745961/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Encrypted traffic classification plays a critical role in network management, providing appropriate Quality-of-Service and Network Intrusion Detection. Conventional port-based and deep packet inspection (DPI) approaches cannot classify encrypted traffic effectively. Methods based on machine learning can classify encrypted traffic by extracting statistical features of the flow. However, they require manual extraction of features. Recent studies show that the approaches based on deep learning are compelling for the task. They can automatically learn raw traffic features without manual feature extraction. However, these studies still take the payload of encrypted traffic as the model input, which may cause privacy risks. Besides, a massive encrypted payload causes great storage pressure on traffic classification. In this paper, we propose a reliable encrypted traffic classification framework by only using the flow header called Only Header, which avoids privacy risks and achieves lightweight storage. Firstly, we introduce a twice segmentation mechanism to dilute the interference traffic and increase the weight of effective traffic. Then we use capsule neural networks (CapsNet) to learn spatial and byte features of the flow header. The Only Header's effectiveness is compared with other methods using two public datasets, including ISCX VPN-nonVPN and ISCX Tor-nonTor datasets.","manuscriptTitle":"Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2022-02-15 00:17:15","doi":"10.21203/rs.3.rs-745961/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"editorInvitedReview","content":"","date":"2022-02-11T13:09:00+00:00","index":0,"fulltext":""},{"type":"reviewersInvited","content":"","date":"2022-02-11T08:31:40+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2021-07-26T11:40:47+00:00","index":"","fulltext":""},{"type":"submitted","content":"Soft Computing","date":"2021-07-23T03:45:14+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"soft-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"soco","sideBox":"Learn more about [Soft Computing](https://www.springer.com/journal/500)","snPcode":"500","submissionUrl":"https://submission.nature.com/new-submission/500/3","title":"Soft Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"768b68b5-4ad2-44cd-beb6-81fee14cb781","owner":[],"postedDate":"February 15th, 2022","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2022-07-14T11:05:36+00:00","versionOfRecord":[],"versionCreatedAt":"2022-02-15 00:17:15","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-745961","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-745961","identity":"rs-745961","version":["v1"]},"buildId":"FbvkV6FR0MCFSLy54lSbu","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.

Source provenance

europepmc
last seen: 2026-05-19T01:45:01.086888+00:00