Time-Dependent Classification of Encrypted Traffic Using LSTM Architecture and Comparative Evaluation with Current Models
Abstract
While the dark web is designed to protect user privacy, it is also susceptible to misuse by malicious actors. Therefore, the effective classification of dark web (Tor and NonTor) traffic is of significant importance in cybersecurity. Findings from the literature reveal that time series-based methods are rarely employed in the detection of Tor network traffic. In this study, the performance of a long short-term memory (LSTM)-based deep learning model—commonly used in time series analysis—is investigated for the classification of Tor and NonTor network traffic alongside traditional machine learning techniques. This approach, which is supported by existing research findings, is further implemented within a graphical user interface (GUI) developed in the MATLAB environment. This interface allows users to upload datasets, apply data filtering, and perform detection using the model of their choice. The proposed system’s accuracy and overall performance demonstrate successful outcomes compared with results reported in the literature. The scientific contribution of this study lies in the development of a time series-based, GUI-supported application that presents a comparative evaluation of LSTM and conventional ML methods. Furthermore, the system provides both theoretical and practical advancements for network traffic analysis by integrating these models into a user-friendly interface.
Keywords
References
- Abu Al-Haija, Q., Obaidat, M. J., Al-Syouf, I. A., Awawdeh, Y. F., & Masa'deh, A. E. (2025). SafeSurf Darknet 2025: A novel dataset for darknet traffic detection and analysis. Preprints, 2025071926. https://doi.org/10.20944/preprints202507.1926.v1 google scholar
- Alashjaee, A. (2025). Deep learning for network security: an Attention-CNN-LSTM model for accurate intrusion detection. Scientific Reports, 15. https://doi.org/10.1038/s41598-025-07706-yhttps://doi.org/10.1038/s41598-025-07706-y google scholar
- Asadi, M., Heidari, A., & Navimipour, N. (2025). A new flow-based approach for enhancing botnet detection efficiency using convolutional neural networks and long short-term memory. Knowledge and Information Systems, 67, 6139 - 6170. https://doi.org/10.1007/s10115-025-02410-9 google scholar
- Bakhshi, T., & Ghita, B. (2021). Anomaly detection in encrypted internet traffic using hybrid deep learning. Secur. Commun. Networks, 2021, 5363750:1-5363750:16. https://doi.org/10.1155/2021/5363750 google scholar
- Demirel, N. B., & Erden, A. (2025). Makine öğrenmesi algoritmaları ile şifreli trafiğin sınıflandırılması. Gazi Journal of Engineering Sciences, 11(1), 48–68. https://doi.org/10.30855/gmbd.070525n04 google scholar
- Etyang, F., Pavithran, P., Mwendwa, G., Mandela, N., & Hillary, M. (2024). Enhanced Deep Learning Approaches for Robust Darknet Traffic Classification. 2024 3rd Edition of IEEE Delhi Section Flagship Conference (DELCON), 1-7. https://doi.org/10.1109/delcon64804.2024.10866386 google scholar
- Gudla, R., Vollala, S., Srinivasa, K. G., & Amin, R. A. (2024). Novel approach for classification of Tor and Non-Tor traffic using efficient feature selection methods. Expert Syst. Appl.. https://doi.org/10.1016/j.eswa.2024.123544 (2024). google scholar
- Gueriani, A., Kheddar, H., & Mazari, A. (2024). Adaptive cyber-attack detection in IIoT using attention-based LSTM-CNN models. Proceedings of the 2024 International Conference on Telecommunications and Intelligent Systems (ICTIS), 1-6. https://doi.org/10.1109/ictis62692.2024.10894509https://doi.org/10.1109/ictis62692.2024.10894509 google scholar
Details
Primary Language
English
Subjects
Semi- and Unsupervised Learning
Journal Section
Research Article
Authors
Mehmet Sait Vural
0000-0003-2144-5474
Türkiye
Hicran Güneş
0000-0003-4626-1874
Türkiye
Cemal Aktürk
*
0000-0003-3764-3862
Türkiye
Publication Date
June 30, 2026
Submission Date
December 7, 2025
Acceptance Date
March 9, 2026
Published in Issue
Year 2026 Volume: 10 Number: 1