Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk Susu Cui, Jian Liu, Cong Dong, Zhigang Lu, Dan DU This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-745961/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 4 You are reading this latest preprint version Abstract Encrypted traffic classification plays a critical role in network management, providing appropriate Quality-of-Service and Network Intrusion Detection. Conventional port-based and deep packet inspection (DPI) approaches cannot classify encrypted traffic effectively. Methods based on machine learning can classify encrypted traffic by extracting statistical features of the flow. However, they require manual extraction of features. Recent studies show that the approaches based on deep learning are compelling for the task. They can automatically learn raw traffic features without manual feature extraction. However, these studies still take the payload of encrypted traffic as the model input, which may cause privacy risks. Besides, a massive encrypted payload causes great storage pressure on traffic classification. In this paper, we propose a reliable encrypted traffic classification framework by only using the flow header called Only Header, which avoids privacy risks and achieves lightweight storage. Firstly, we introduce a twice segmentation mechanism to dilute the interference traffic and increase the weight of effective traffic. Then we use capsule neural networks (CapsNet) to learn spatial and byte features of the flow header. The Only Header's effectiveness is compared with other methods using two public datasets, including ISCX VPN-nonVPN and ISCX Tor-nonTor datasets. encrypted traffic classification capsule neural networks. twice segmentation mechanism privacy risk Full Text Cite Share Download PDF Status: Under Review Version 1 posted Reviews received at journal 11 Feb, 2022 Reviewers invited by journal 11 Feb, 2022 Editor assigned by journal 26 Jul, 2021 First submitted to journal 22 Jul, 2021 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-745961","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":83100272,"identity":"62730666-9a4b-4443-9fb3-6faf58d2f0bf","order_by":0,"name":"Susu Cui","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAtklEQVRIiWNgGAWjYFACxgYQKcfGTKoWY1K0QEBiA9FK+WckN3/m+XM4vY+d+QDDjxoGeXNCWiRuJLZJ87Ydzm1jZktg7DnGYLiTkH0GEoltzLwNIC08Bgy8DQwJBgcIa4E4jI2Z/wPjXyK1NEjzsB1OYGPmYWAmyhaJMw/bJOe2pRsC/WJwWOaYhOEGQlr429Mff3jzx1pevv/ww4dvamzkCdqCAoCKJUhRPwpGwSgYBaMAFwAAEs83rqmpTnYAAAAASUVORK5CYII=","orcid":"https://orcid.org/0000-0001-5249-5699","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Susu","middleName":"","lastName":"Cui","suffix":""},{"id":83100273,"identity":"38f9e279-bfc8-4b1c-acfd-8174068e12c9","order_by":1,"name":"Jian Liu","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Jian","middleName":"","lastName":"Liu","suffix":""},{"id":83100274,"identity":"efd7b619-0b4c-4fc9-9f92-d6da572dd6fc","order_by":2,"name":"Cong Dong","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Cong","middleName":"","lastName":"Dong","suffix":""},{"id":83100275,"identity":"0c3e5cfc-4c84-472d-b500-fdfb5da51973","order_by":3,"name":"Zhigang Lu","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Zhigang","middleName":"","lastName":"Lu","suffix":""},{"id":83100276,"identity":"82c5a5d8-0f80-42b8-ab5e-10d4c86ed36a","order_by":4,"name":"Dan DU","email":"","orcid":"","institution":"Institute of Information Engineering CAS: Chinese Academy of Sciences Institute of Information Engineering","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Dan","middleName":"","lastName":"DU","suffix":""}],"badges":[],"createdAt":"2021-07-24 08:55:50","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-745961/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-745961/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":18213605,"identity":"82dee529-16a1-4b50-9b9f-1e0317825182","added_by":"auto","created_at":"2022-02-15 00:17:36","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":3122637,"visible":true,"origin":"","legend":"","description":"","filename":"OnlyHeader.pdf","url":"https://assets-eu.researchsquare.com/files/rs-745961/v1_covered.pdf"}],"financialInterests":"","formattedTitle":"Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk","fulltext":[{"header":"Full Text","content":"This preprint is available for \u003ca href='/article/rs-745961/latest.pdf' target='_blank'\u003edownload as a PDF\u003c/a\u003e."}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":true,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"soft-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"soco","sideBox":"Learn more about [Soft Computing](https://www.springer.com/journal/500)","snPcode":"500","submissionUrl":"https://submission.nature.com/new-submission/500/3","title":"Soft Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"encrypted traffic classification, capsule neural networks. twice segmentation mechanism, privacy risk","lastPublishedDoi":"10.21203/rs.3.rs-745961/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-745961/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Encrypted traffic classification plays a critical role in network management, providing appropriate Quality-of-Service and Network Intrusion Detection. Conventional port-based and deep packet inspection (DPI) approaches cannot classify encrypted traffic effectively. Methods based on machine learning can classify encrypted traffic by extracting statistical features of the flow. However, they require manual extraction of features. Recent studies show that the approaches based on deep learning are compelling for the task. They can automatically learn raw traffic features without manual feature extraction. However, these studies still take the payload of encrypted traffic as the model input, which may cause privacy risks. Besides, a massive encrypted payload causes great storage pressure on traffic classification. In this paper, we propose a reliable encrypted traffic classification framework by only using the flow header called Only Header, which avoids privacy risks and achieves lightweight storage. Firstly, we introduce a twice segmentation mechanism to dilute the interference traffic and increase the weight of effective traffic. Then we use capsule neural networks (CapsNet) to learn spatial and byte features of the flow header. The Only Header's effectiveness is compared with other methods using two public datasets, including ISCX VPN-nonVPN and ISCX Tor-nonTor datasets.","manuscriptTitle":"Only Header: A Reliable Encrypted Traffic Classification Framework without Privacy Risk","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2022-02-15 00:17:15","doi":"10.21203/rs.3.rs-745961/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"editorInvitedReview","content":"","date":"2022-02-11T13:09:00+00:00","index":0,"fulltext":""},{"type":"reviewersInvited","content":"","date":"2022-02-11T08:31:40+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2021-07-26T11:40:47+00:00","index":"","fulltext":""},{"type":"submitted","content":"Soft Computing","date":"2021-07-23T03:45:14+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"soft-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"soco","sideBox":"Learn more about [Soft Computing](https://www.springer.com/journal/500)","snPcode":"500","submissionUrl":"https://submission.nature.com/new-submission/500/3","title":"Soft Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"768b68b5-4ad2-44cd-beb6-81fee14cb781","owner":[],"postedDate":"February 15th, 2022","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2022-07-14T11:05:36+00:00","versionOfRecord":[],"versionCreatedAt":"2022-02-15 00:17:15","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-745961","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-745961","identity":"rs-745961","version":["v1"]},"buildId":"FbvkV6FR0MCFSLy54lSbu","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.