Zihan Chen 0003

dblp:139/3503-3 · DBLP profile ↗
← Back
16ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0001-5871-7766ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 3 first-author · 11 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SNAKE: A sustainable and multi-functional traffic analysis system utilizing specialized large-scale models with a mixture of experts architecture
Guang Cheng 0001, Zihan Chen 0003, Xing Luan
Comput. Networks4
2026 Ultimate Encrypted Traffic Feature Engineering: HTTPS Encrypted Traffic Classification Using Restored Application Data Unit Length
abstract
Over-the-top (OTT) applications mainly communicate through HTTPS, the most famous encryption protocol family on the Internet. The classification of HTTPS encrypted traffic can effectively obtain fine-grained OTT application information for network management and cyber security. As the most expressive feature, the side-channel length sequence is widely used by current research, especially the packet length sequence. However, these attempts ignored interferences from protocol piecewise decoupling and encryption covering, leading to poor performance. Based on the application layer feature engineering theory, we proposed a new metric called Application Data Unit (ADU) length to eliminate the interferences. However, ADU length cannot be obtained directly from packets as the TLS encryption protocol covers the entire application layer, which contains an intrusive and variable HTTP header. Hence, we designed a Length-Correction Multiple Regression Neural Network (LCMRNN) algorithm to restore the real ADU length sequences accurately. Exhaustive experiments in two scenarios of the real CERNET network show that no matter the HTTP-1.1 or HTTP2.0 protocol, the LC-MRNN model can achieve significantly accurate ADU length restoration. In classification, with the assistance of the LS-LSTM classifier, our method outperforms the state-of-the-art methods with about 4.2% improvement in F1-score (93.52%).
Zihan Chen 0003, Guang Cheng 0001, Dandan Niu, Yuyu Zhao, Shanqing Jiang
IEEE Trans. Dependable Secur. Comput.1
2025 Early Classification and Improved Performance: A Multi-Model Serial Encrypted Traffic Classification Framework
abstract
Early classification of encrypted traffic is crucial for time-sensitive tasks such as intrusion detection and cyberspace situation awareness. Dissimilar flows can be distinguished with a small number of packets, while similar flows require more packets. The existing early classification methods use the same number of packets to classify all flows, which leads to many flows cannot be classified early. In this paper, we propose a method to classify TLS flows by concatenation of multiple models. For flows that fail to be classified, a larger number of packets are used to classify them in the subsequent models in turn until they are successfully classified. Compared with existing methods that rely on unstable features such as time series, the proposed method can accurately classify flows by features that are easy to extract and maintain stable values. Experiments show that the proposed framework has the highest classification efficiency and accuracy compared with three baseline methods, including a state-of-the-art early classification method.
Guang Cheng 0001, Zihan Chen 0003
TrustCom3
2025 ITD: A novel measure for detecting portable hotspot devices in modern cyberspace
XianLong Dai, Guang Cheng 0001, Zihan Chen 0003, Xuman Zhang, Bingjie Duan
Comput. Networks5
2024 Video stalling identification for web live streaming under HTTP-FLV
Dandan Niu, Guang Cheng 0001, Zihan Chen 0003, Xing Qiu
Comput. Networks3
2024 Classify Traffic Rather Than Flow: Versatile Multi-Flow Encrypted Traffic Classification With Flow Clustering
abstract
Encrypted Traffic Classification (ETC) can provide necessary information support for network management and security. The state-of-the-art ETC methods take a single flow as the unit and only use sequence features based on in-flow relationships. In an actual network, one-time access to an application will generate multiple flows. Taking a single flow as the classification unit will produce many repeated and potentially erroneous results, which dramatically reduces the classification efficiency and prevents the results from being used for effective network management and security. In this paper, we propose a multi-flow ETC method. Since multiple flows generated by an application cannot be directly bound in a complex multi-application scenario, we first cluster the encrypted traffic to acquire flow bunches through the proposed Time Sequential Hierarchical Clustering with Sliding Windows (TSHC-SW) algorithm. Then, based on the flow bunches, we propose five different multi-flow classification schemas that can realize multi-flow classification effectively with model-independent. Open-world experiments show that our method is versatile in that it can pursue classification accuracy, speed, or sample covering rate, respectively, according to the actual demand and network environment constraints. In flow clustering, we achieve 95% adjusted Rand Index and 98% purity. In the multi-flow classification, we have over 99% F1-score, 79% prediction time saving, and 5% sample covering rate increasing, which is far superior to the state-of-the-art single-flow methods.
Zihan Chen 0003, Guang Cheng 0001, Zijun Wei, Dandan Niu, Nan Fu
IEEE Trans. Netw. Serv. Manag.1
2023 Identifying Fine-Grained Douyin User Behaviors via Analyzing Encrypted Network Traffic
abstract
Smartphones and mobile Internet development have promoted the rise of short video applications. Douyin, the most popular short video application in China, has very complex in-app functions. Due to users’ need for privacy protection, encryption protocols are widely used. But it also makes it difficult to supervise malicious user behaviors. The encrypted traffic of Douyin user behaviors has the characteristics of a small sample and instantaneity. It is easy to be covered by the huge background traffic, which brings challenges to the research of Douyin user behavior identification. To solve this problem, we first proposed an automated method for labeling encrypted traffic of Douyin user behaviors based on multistage packet filtration technology, which can improve labeling efficiency and sample purity. Secondly, we propose a multi-layer identification method to identify Douyin user behaviors. Specifically, we first analyze the global and local characteristics of Douyin traffic to identify user behavior flows. Then, the user behavior flow is segmented into packet subsequences based on the local burstiness of the user behavior traffic. Finally, we extract the features of subsequences to identify Douyin user behaviors. The results can achieve an average of 0.980 precision, 0.966 recall, and 0.971 f1-score.
Yuhang Shan, Guang Cheng 0001, Zihan Chen 0003
MSN3
2023 A Hypernetwork-based Personalized Federated Learning Framework for Encrypted Traffic Classification
abstract
With the popularity of the Internet and the rapid development of software technology, the classification and analysis of encrypted traffic has become crucial. Due to the complexity of network environments and private encryption protocols, traffic data in the open world usually exhibit high statistical heterogeneity. Thus, traditional traffic classification methods trained by single dataset will encounter difficulties of misclassification. This paper proposed a hypemetwork-based personalized federated learning framework for encrypted traffic classification (ETC). In this framework, hypernetworks on the server side can generate layer-granularity weights for model aggregation. Clients can not only focus on improving the effect on local datasets but also aggregate models from other clients more appropriately guided by hypernetworks. Experimental evaluations are conducted on real-world encrypted traffic datasets under different heterogeneous scenarios. The results show that our framework gains a 2-8% improvement over the state-of-the-art methods on ETC tasks.
Guang Cheng 0001, Zihan Chen 0003
MSN4
2023 Snapshot for Power Grids IoT: Adaptive Measurement for Resilience Intelligent Internet of Things
abstract
With the wide application of Internet of Things (IoT) devices in the power grids, the sophisticated feedback on their operating status is of great significance for improving efficiency and reducing accidents. For exquisite management of the resilient intelligent IoT with flexible increase and decrease of devices and heterogeneous operating systems, this article proposes an adaptive measurement method “MRAM,” which can snapshot the multidimensional resource view (MRV) of all devices in the jurisdiction. Extensible gateway platform based on CPU, field-programmable gate array, and cloud computing is applied in MRAM, which liberates the local resources of monitored IoT devices. MRAM improves the long short-term memory algorithm called ELSTM. ELSTM can accommodate the current IoT devices’ state for detecting the mutation of MRV. The newly collected resources determined by ELSTM whether MRAM enters an abnormal state to drive the adaptive measurement state machine. According to the state machine which endeavors that the MRV is updated timely, MRAM adjusts the measurement granularity in real time. Simulations and experiments have tested the convergence time and occupied bandwidth of MRAM deployed in power grids. These evaluations confirmed MRAM’s practicality and robustness, as well as the MRV is genuine management data for the upper layer power grids applications. A real environment is built to test the performance of this method as well. MRAM has high measurement accuracy and the precision of mutation detection is 98.41%. It converges the update MRV of second level under the condition of IoT devices and the cloud’s low consumption of memory and CPU utilization.
Yuyu Zhao, Guang Cheng 0001, Chunxiang Liu, Zihan Chen 0003, Donglai Xu
IEEE Internet Things J.4
2023 TDS-KRFI: Reference Frame Identification for Live Web Streaming Toward HTTP Flash Video Protocol
abstract
Live Web streaming occupies a large proportion of network traffic, and various live streaming platforms use HTTP-FLV protocol to transmit streaming. The content-aware strategy that includes frame-skipping and frame-dropping mechanisms before client decoding is essential in providing high-quality live video services to improve QoE. Therefore, frame type identification is necessary for content-aware strategy and traffic engineering. The current studies focus on keyframe identification under single datasets. However, they failed to consider the actual scenarios where there are various types of live Web streaming with user interactions and only identify keyframes. After studying, we found a type of frame in normal video frames that contain image parameters for subsequent frames, which can also cause a stall if they are dropped or skipped during frame processing, and this type of frame is called a reference frame. To effectively identify keyframes and reference frames, we propose the TDS-KRFI, which extracts lightweight and effective streaming features from the encrypted traffic of live Web streaming. Then we use a two-layer double similarity measure to construct the spatio-temporal structure of dynamic data units and use the DGCNN model to identify frame types. In evaluation, we use various datasets with 6,532,890 frames containing user interactions under different webcasting platforms to conduct extensive experiments. It can achieve 99.9% (average 98.96%) accuracy in keyframe identification and 95.7% in all types of frames (keyframes, reference frames, and other frames) within 9.6% of the transmission time, demonstrating the robustness and effectiveness of our approach and outperforming the state-of-the-art research so far.
Dandan Niu, Guang Cheng 0001, Zihan Chen 0003
IEEE Trans. Netw. Serv. Manag.3
2022 Higher Layers, Better Results: Application Layer Feature Engineering in Encrypted Traffic Classification
Zihan Chen 0003, Guang Cheng 0001, Zijun Wei, Nan Fu
WASA (2)1
2022 Toward Proactive and Efficient DDoS Mitigation in IIoT Systems: A Moving Target Defense Approach
abstract
Nowadays, a large number of intelligent devices involved in the industrial Internet of Things (IIoT) environment lead to unprecedented challenges in security. Due to limited resources with weak security protection, the IIoT devices can be easily compromised to launch distributed denial-of-service (DDoS) attacks, resulting in catastrophic results. Although there are many DDoS mitigations of traditional static schemes, the proactive defense method to resist attacks has not been well studied. Furthermore, existing proactive schemes ignored the delay-sensitive characteristic of applications under the IIoT environments. To address these issues, we first adopt two kinds of moving target defense (MTD) techniques that dynamically control the admission of devices and migrate service replicas to isolate attackers on limited edge clouds and mitigate DDoS attacks early near its source. Then, we formulate a multistage optimization problem of MTD mechanisms deployment and model it as constrained Markov decision processes in order to maximize the available resources of the system under the limitations of the IIoT environments. Besides, we present an MTD optimal strategy algorithm to solve decision problems in a cost-effective manner. In this article, the proposed algorithm can achieve an optimal admission allocation by means of attackers gathering within the same service where the service migration decisions are assisted by means of value iteration. The experimental results verify that the proposed algorithm, compared with existing strategies, can effectively mitigate DDoS attacks with acceptable degradation of the quality of service.
Guang Cheng 0001, Yuyu Zhao, Zihan Chen 0003, Shanqing Jiang
IEEE Trans. Ind. Informatics4
2021 Snapshot for IoT: Adaptive Measurement for Multidimensional QoS Resources
abstract
With the increasing and extensive use of intelligent Internet of things (IoT) devices, its operational aspect in the network has become a significant dependent data for network QoS management and scheduling. For the resilient intelligent IoT cluster with flexible increase and decrease of devices and heterogeneous operating systems, this paper proposes an adaptive measurement method MRAM, which can snapshot the multidimensional QoS resources view (MRV) of the IoT devices in cluster. MRAM uses the measurement offloading architecture based on extensible gateway platform and cloud computing to liberate the local resources of monitored IoT devices. Based on the improved LSTM algorithm, the MRV’s mutations detection method ELSTM is designed. Newly collected QoS resource can be judged whether mutations have occurred and adaptive measurement state machine is enabled by ELSTM. According to the state machine which ensures that the MRV is updated timely and reflected the current status of the cluster, MRAM adjusts the measurement granularity in real time. This method provides a high time efficiency global profile for the upper QoS services and reduces the impact of measurement on the IoT devices. A real environment is built to test the performance of this method. MRAM has high measurement accuracy and the precision of mutations detection is 98.29%. It converges the update MRV of second level under the condition of IoT devices’ low consumption of storage and CPU utilization.
Yuyu Zhao, Guang Cheng 0001, Chunxiang Liu, Zihan Chen 0003
IWQoS4
2021 A DDoS protection method based on traffic scheduling and scrubbing in SDN
abstract
DDoS attacks have emerged as one of the most serious network security threats in 5G, IoT, multi-cloud, and other emerging technology scenarios. The bandwidth of DDoS attacks is increasing in the new scenario, but the current network structure and security devices are inflexible. We propose a DDoS protection method based on SDN multi-dimensional scheduling method and DDoS scrubbing policy, which not only plans the scheduling path, but also blocks and redirects different kinds of attack traffic that used dynamic residual bandwidth of links, the number of flow entries in OpenFlow switches, and scheduling path length. To flexibly protect against DDoS attacks, this method combines scheduling and protection means. The experimental results indicate that the scheduling is effective. The scheduling, path produced by this method outperforms ECMP and KSP approaches in throughput, packet loss rate, and jitter, and it can block L3/L4 attack traffic and redirect L7 attack traffic.
Yiwei Yu, Guang Cheng 0001, Zihan Chen 0003, Haoxuan Ding
MSN3
2020 Length Matters: Fast Internet Encrypted Traffic Service Classification based on Multi-PDU Lengths
abstract
Encryption of network traffic has become an inevitable trend. As an important link to Internet encrypted traffic analysis, encrypted traffic service classification can provide support for the coarse-grained network service traffic management and security supervision. But traditional DPI method cannot be effectively applied in an encrypted traffic environment, and the existing methods based on machine learning have two problems in feature selection. One is the complex feature classification over costing problem, the other is the TLS-1.2 suited method is no longer applicable to TLS-1.3 handshake encryption. To solve these problems, in this paper, we consider the differences among encryption network protocol stacks and propose a method of encrypted traffic service classification combining with capsule neural network in a multi-protocol environment by using multi-PDU lengths as the features, making full use of Markov property between PDU length sequences and being suitable to TLS1.3 environment. The feature makes our method much faster than others in feature extraction. Our control experiments on ISCX VPN-nonVPN dataset show that our method achieves a satisfactory performance (0.9860 Pr, 0.9856 Rc, 0.9855 F1), which is superior to the state-of-the-art methods.
Zihan Chen 0003, Guang Cheng 0001, Bomiao Jiang, Shuye Tang, Shuyi Guo
MSN1
2020 Cost-effective moving target defense against DDoS attacks using trilateral game and multi-objective Markov decision processes
Guang Cheng 0001, Shanqing Jiang, Yuyu Zhao, Zihan Chen 0003
Comput. Secur.5