SoK: Decoding the Enigma of Encrypted Network Traffic Classifiers
Nimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. Jha
Abstract
The adoption of modern encryption protocols such as TLS 1.3 has significantly challenged traditional network traffic classification (NTC) methods. As a consequence, researchers are increasingly turning to machine learning (ML) approaches to overcome these obstacles. This paper analyses ML-based NTC studies by developing a taxonomy of their design choices, benchmarking suites, and prevalent assumptions impacting classifier performance. Through this systematization, we demonstrate widespread reliance on outdated datasets, oversights in design choices, and the consequences of unsubstantiated assumptions. Our evaluation reveals that the majority of proposed encrypted traffic classifiers have mistakenly utilized unencrypted traffic due to the use of legacy datasets. Furthermore, by conducting 348 feature occlusion experiments on state-of-the-art classifiers, we show how oversights in NTC design choices lead to overfitting and validate or refute prevailing assumptions with empirical evidence. By highlighting lessons learned, we offer strategic insights, identify emerging research directions, and recommend best practices to support the development of real-world applicable NTC methodologies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- The Sweet Danger of Sugar: Debunking Representation Learning for Encrypted Traffic ClassificationYuqi Zhao, Giovanni Dettori, Matteo Boffa, Luca Vassio et al.SIGCOMM 2025 · 17 citations
- Synecdoche: Efficient and Accurate In-Network Traffic Classification via Direct Packet Sequential Pattern MatchingMinyuan Xiao, Yunchun Li, Yuchen Zhao, Tong Guan et al.INFOCOM 2026 · 2 citations
- Disentangling Multi-View Scanning in Mamba for Network Traffic Anomaly DetectionXinglin Lian, Chengtai Cao, Ting Zhong, Fan ZhouKDD 2026 · 2 citations
- TDDM-Melatt: A Decoupled Memory and Diffusion Framework for Generalizable Encrypted Traffic ClassificationZe Chen, Qiming Yu, Zijia Song, Guozheng Yang et al.CCS 2026
Builds on15
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- ET-BERT: A Contextualized Datagram Representation with Pre-training Transformers for Encrypted Traffic ClassificationXinjie Lin, Gang Xiong, Gaopeng Gou, Zhen Li et al.WWW 2022 · 490 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- Yet Another Traffic Classifier: A Masked Autoencoder Based Traffic Transformer with Multi-Level Flow RepresentationRuijie Zhao, Mingwei Zhan, Xianwen Deng, Yanhao Wang et al.AAAI 2023 · 138 citations
- AI/ML for Network Security: The Emperor has no ClothesArthur Selle Jacobs, Roman Beltiukov, Walter Willinger, Ronaldo A. Ferreira et al.CCS 2022 · 76 citations
Related papers
- Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic AugmentationRenjie Xie, Jiahao Cao, Enhuan Dong, Mingwei Xu et al.USENIX Security 2023
- Training Robust Classifiers for Classifying Encrypted Traffic under Dynamic Network ConditionsYuqi Qing, Qilei Yin, Xinhao Deng, Xiaoli Zhang et al.CCS 2025
- Autonomous Unknown-Application Filtering and Labeling for DL-based Traffic Classifier UpdateJielun Zhang, Fuhao Li, Feng Ye, Hongyu WuINFOCOM 2020 · 120 citations
- Learning to Classify: A Flow-Based Relation Network for Encrypted Traffic ClassificationWenbo Zheng, Chao Gou, Lan Yan, Shaocong MoWWW 2020 · 100 citations
- Statistical Privacy for Streaming TrafficXiaokuan Zhang, Jihun Hamm, Michael K. Reiter, Yinqian ZhangNDSS 2019 · 49 citations
