ASIF: A Resource-Aware Selective Network Traffic Inspection Framework Integrating Certificate Screening, Targeted Decryption, and Feature Fusion

The widespread use of TLS in IoT and networked systems increases inspection cost while restricting direct access to payload content. This paper presents the Adaptive Secure Inspection Framework (ASIF), a resource-aware selective network traffic inspection framework that coordinates certificate-based routing, authorized targeted decryption, known-signature matching, and learned flow classification. ASIF contains three components: (1) a Certificate Screening Module (CSM), which applies configured checks of root trust, chain integrity, and leaf-certificate validity as an early routing signal; (2) a Targeted Decryption and Signature Matching Module (TDSMM), which directs certificate-suspicious traffic to authorized Mitmproxy interception and Snort inspection; and (3) an Attentive Feature Fusion Network (AFFN), which combines global and local representations for network-flow classification. The evaluation covers controlled certificate cases, selective-decryption overhead, known-signature matching, learned classification on three intrusion datasets, a supplementary VPN/non-VPN task, held-out attack families, and the integrated pipeline. The intrusion-dataset labels do not establish that every flow is encrypted. Several models obtain near-ceiling scores under the balanced grouped protocol, while AFFN achieves a macro-F1 of 0.639 ± 0.149 on the supplementary ISCX VPN/non-VPN task and does not outperform all baselines. Across held-out attack families, recall averages 0.527 ± 0.466, indicating strong family dependence. In the controlled end-to-end experiment, complete ASIF decrypts 50% of requests and reduces mean latency from 278.78 to 164.19 ms/request relative to full decryption, while malicious-class recall decreases to 0.500 and macro-F1 to 0.733 because valid-certificate malicious traffic bypasses deeper inspection. These results characterize ASIF as a resource-aware selective inspection strategy with explicit coverage limitations rather than a universal encrypted-malicious-traffic detector.

Authors

Institutions

Publication Details

Journal
Network
Published
2026-09-28
DOI
https://doi.org/10.3390/network6040082
Primary Topic
Internet Traffic Analysis and Secure E-voting
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

ASIF: A Resource-Aware Selective Network Traffic Inspection Framework Integrating Certificate Screening, Targeted Decryption, and Feature Fusion

Lulu Liu, Liangbin Yang, Jing Bai, Xiaomei Liu et al.
Network
Internet Traffic Analysis and Secure E-voting
article

ASIF: A Resource-Aware Selective Network Traffic Inspection Framework Integrating Certificate Screening, Targeted Decryption, and Feature Fusion

Lulu Liu, Liangbin Yang, Jing Bai, Xiaomei Liu, Lizhen Liu
article en

Abstract

The widespread use of TLS in IoT and networked systems increases inspection cost while restricting direct access to payload content. This paper presents the Adaptive Secure Inspection Framework (ASIF), a resource-aware selective network traffic inspection framework that coordinates certificate-based routing, authorized targeted decryption, known-signature matching, and learned flow classification. ASIF contains three components: (1) a Certificate Screening Module (CSM), which applies configured checks of root trust, chain integrity, and leaf-certificate validity as an early routing signal; (2) a Targeted Decryption and Signature Matching Module (TDSMM), which directs certificate-suspicious traffic to authorized Mitmproxy interception and Snort inspection; and (3) an Attentive Feature Fusion Network (AFFN), which combines global and local representations for network-flow classification. The evaluation covers controlled certificate cases, selective-decryption overhead, known-signature matching, learned classification on three intrusion datasets, a supplementary VPN/non-VPN task, held-out attack families, and the integrated pipeline. The intrusion-dataset labels do not establish that every flow is encrypted. Several models obtain near-ceiling scores under the balanced grouped protocol, while AFFN achieves a macro-F1 of 0.639 ± 0.149 on the supplementary ISCX VPN/non-VPN task and does not outperform all baselines. Across held-out attack families, recall averages 0.527 ± 0.466, indicating strong family dependence. In the controlled end-to-end experiment, complete ASIF decrypts 50% of requests and reduces mean latency from 278.78 to 164.19 ms/request relative to full decryption, while malicious-class recall decreases to 0.500 and macro-F1 to 0.733 because valid-certificate malicious traffic bypasses deeper inspection. These results characterize ASIF as a resource-aware selective inspection strategy with explicit coverage limitations rather than a universal encrypted-malicious-traffic detector.

NetworkVol. 6(4)
University of International Relations (CN)
Openalex Percentile: Top 9%
Internet Traffic Analysis and Secure E-voting
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.