ESTK-JC: Encrypted malicious traffic detection fusing spatio-temporal features and JointCloud entity knowledge for JointCloud environment

Rongwei Yu, Zijian Zhou, Yuhao Zhang, Lina Wang, Qiyun Shao · Computer Networks · 2025

JointCloud computing is a new cloud computing paradigm that enables interconnection between clouds. Compared with other network environments, large-scale diverse data interactions and data collaboration have become the norm in the JointCloud environment based on JointCloud computing. The complex behaviors between entities in the JointCloud environment are realized through the interaction of network traffic. Attackers often mix malicious traffic with benign network traffic to break the JointCloud ecosystem. Among them, encrypted malicious traffic poses a huge security risk to JointCloud environments due to its strong invisibility and fast propagation speeds. Currently, there is a gap in researches on malicious traffic detection in the JointCloud environment, especially encrypted malicious traffic detection. To the best of our knowledge, this paper is the first research work to conduct encrypted malicious traffic detection for JointCloud environment. Specifically, to cope with the complex network traffic data in the JointCloud environment, this paper proposes a spatio-temporal feature extraction method for encrypted traffic to enrich the features of the original traffic. Subsequently, we propose a method of mining JointCloud entity knowledge based on the characteristics of traffic distribution in the JointCloud environment, which can improve detection performance. Finally, we construct an encrypted malicious traffic detection model fusing spatio-temporal features and JointCloud entity knowledge for JointCloud environment (ESTK-JC). In experiments in a simulated JointCloud environment, ESTK-JC exhibits detection performance superior to current state-of-the-art models.

Read the paper · More papers on PaperTik