Jove
Visualize
Contact Us
JoVE
x logofacebook logolinkedin logoyoutube logo
ABOUT JoVE
OverviewLeadershipBlogJoVE Help Center
AUTHORS
Publishing ProcessEditorial BoardScope & PoliciesPeer ReviewFAQSubmit
LIBRARIANS
TestimonialsSubscriptionsAccessResourcesLibrary Advisory BoardFAQ
RESEARCH
JoVE JournalMethods CollectionsJoVE Encyclopedia of ExperimentsArchive
EDUCATION
JoVE CoreJoVE BusinessJoVE Science EducationJoVE Lab ManualFaculty Resource CenterFaculty Site
Terms & Conditions of Use
Privacy Policy
Policies

Related Experiment Video

Updated: Dec 22, 2025

Author Spotlight: AI-Driven Trypanosome Species Detection from Microscopic Images
08:20

Author Spotlight: AI-Driven Trypanosome Species Detection from Microscopic Images

Published on: October 27, 2023

2.3K

Two-layer detection framework with a high accuracy and efficiency for a malware family over the TLS protocol.

Rongfeng Zheng1, Jiayong Liu2, Liang Liu2

  • 1College of Electronics and Information Engineering, Sichuan University, Chengdu, China.

Plos One
|May 7, 2020
PubMed
Summary

Related Concept Videos

You might also read

Related Articles

Articles linked to this work by shared authors, journal, and citation graph.

Sort by
Same author

Prediction-Based Family Selection in Early Stage Sugarcane Breeding: Comparing BLUP, BLUE, Phenotypic Indices, and Machine Learning.

Plants (Basel, Switzerland)·2026
Same author

FDA-approved fulvestrant-induced CAR phase separation enables precise control of CAR T antitumor function.

Cell stem cell·2026
Same author

Titanium-coated PEEK versus 3D-printed porous titanium cages in transforaminal lumbar interbody fusion: A meta-analysis.

Journal of orthopaedics·2026
Same author

A novel nutritional tool to identify infants at risk of stunting.

Frontiers in pediatrics·2026
Same author

A mini-review of risk factors for developmental dysplasia of the hip: insights from multiple comparative cohort studies.

Journal of pediatric orthopedics. Part B·2026
Same author

Molecular mechanisms of KMT2C alterations in gastrointestinal cancers: enhancer network destabilization, lineage plasticity, and clinical translation.

Frontiers in immunology·2026

This study introduces a two-layer framework for detecting malicious Transport Layer Security (TLS) traffic. The system efficiently filters benign flows and accurately classifies malware families, achieving high detection rates.

Area of Science:

  • Cybersecurity
  • Network Security
  • Malware Analysis

Background:

  • Transport Layer Security (TLS) protocol is extensively used by both legitimate applications and malicious software.
  • The rapid increase in TLS traffic necessitates efficient and accurate methods for detecting malicious flows.
  • Existing detection methods often prioritize either accuracy or efficiency, neglecting a balanced approach.

Purpose of the Study:

  • To propose a novel two-layer detection framework for malicious TLS flows that considers both accuracy and efficiency.
  • To develop a filtering model (FM) for efficiently removing benign TLS traffic.
  • To create a malware family classification model (MFCM) for identifying malicious traffic.

Main Methods:

  • A two-layer framework comprising a filtering model (FM) and a malware family classification model (MFCM).

Related Experiment Videos

Last Updated: Dec 22, 2025

Author Spotlight: AI-Driven Trypanosome Species Detection from Microscopic Images
08:20

Author Spotlight: AI-Driven Trypanosome Species Detection from Microscopic Images

Published on: October 27, 2023

2.3K
  • The FM utilizes novel TLS handshake features to filter out a significant portion of benign TLS flows.
  • The MFCM employs both TLS handshake and statistical features, using a multiclassifier for enhanced malware family identification.
  • Main Results:

    • The filtering model (FM) successfully filters out 96.32% of benign TLS flows with minimal loss of malicious flows.
    • The two-layer framework achieves an average detection accuracy of 99.45%.
    • The proposed framework demonstrates a 188% increase in detection efficiency compared to single-layer approaches when benign and malicious flows are in a 10:1 ratio.

    Conclusions:

    • The proposed two-layer framework offers a highly accurate and efficient solution for detecting malicious TLS traffic.
    • The integration of a filtering model and a multiclassifier-based malware classification model significantly improves performance.
    • This approach addresses the limitations of existing methods by balancing detection accuracy and efficiency in the context of growing TLS traffic.