Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic Detection
Ziming Zhao, Zhaoxuan Li, Zhuoxue Song, Wenhao Li, Fan Zhang
Abstract
To detect unknown attack traffic, anomaly-based network intrusion detection systems (NIDSs) are widely used in Internet infrastructure. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained emerging attack detection and (ii) incremental updates/adaptations. To tackle these problems, we propose to decouple the need for model capabilities by transforming known/new class identification issues into multiple independent one-class learning tasks. Based on the above core ideas, we develop Trident, a universal framework for fine-grained unknown encrypted traffic detection. It consists of three main modules, i.e., tSieve, tScissors, and tMagnifier are used for profiling traffic, determining outlier thresholds, and clustering respectively, each of which supports custom configuration. Using four popular datasets of network traces, we show that Trident significantly outperforms 16 state-of-the-art (SOTA) methods. Furthermore, a series of experiments (concept drift, overhead/parameter evaluation) demonstrate the stability, scalability, and practicality of Trident.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8add4471-e48e-4dbc-a057-864f2e7f5380Cited by top-tier papers5
- Facing Anomalies Head-On: Network Traffic Anomaly Detection via Uncertainty-Inspired Inter-Sample DifferencesXinglin Lian, Chengtai Cao, Yan Liu, Xovee Xu et al.WWW 2025 · 11 citations
- Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic DetectionZhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie et al.WWW 2025 · 6 citations
- Towards Context-Aware Traffic Classification via Time-Wavelet Fusion NetworkZiming Zhao, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li et al.KDD 2025 · 5 citations
- Disentangling Multi-View Scanning in Mamba for Network Traffic Anomaly DetectionXinglin Lian, Chengtai Cao, Ting Zhong, Fan ZhouKDD 2026 · 2 citations
- CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality ShiftJiongchi Yu, Xiaofei Xie, Qiang Hu, Bowen Zhang et al.FSE 2025 · 1 citation
Related papers
- 3D-IDS: Doubly Disentangled Dynamic Intrusion DetectionChenyang Qiu, Yingsheng Geng, Junrui Lu, Kaida Chen et al.KDD 2023 · 15 citations
- Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph AnalysisChuanpu Fu, Qi Li, Ke XuNDSS 2023
- Adaptive Clustering-based Malicious Traffic Classification at the Network EdgeAlec F. Diallo, Paul PatrasINFOCOM 2021 · 64 citations
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
- Decompose to Understand, Fuse to Detect: Frequency-Decoupled Anomaly Detection for Encrypted Network TrafficXinglin Lian, Chengtai Cao, Ting Zhong, Yong Wang et al.INFOCOM 2026 · 8 citations
