ASIF: A Resource-Aware Selective Network Traffic Inspection Framework Integrating Certificate Screening, Targeted Decryption, and Feature Fusion
The widespread use of TLS in IoT and networked systems increases inspection cost while restricting direct access to payload content. This paper presents the Adaptive Secure Inspection Framework (ASIF), a resource-aware selective network traffic inspection framework that coordinates certificate-based routing, authorized targeted decryption, known-signature matching, and learned flow classification. ASIF contains three components: (1) a Certificate Screening Module (CSM), which applies configured checks of root trust, chain integrity, and leaf-certificate validity as an early routing signal; (2) a Targeted Decryption and Signature Matching Module (TDSMM), which directs certificate-suspicious traffic to authorized Mitmproxy interception and Snort inspection; and (3) an Attentive Feature Fusion Network (AFFN), which combines global and local representations for network-flow classification. The evaluation covers controlled certificate cases, selective-decryption overhead, known-signature matching, learned classification on three intrusion datasets, a supplementary VPN/non-VPN task, held-out attack families, and the integrated pipeline. The intrusion-dataset labels do not establish that every flow is encrypted. Several models obtain near-ceiling scores under the balanced grouped protocol, while AFFN achieves a macro-F1 of 0.639 ± 0.149 on the supplementary ISCX VPN/non-VPN task and does not outperform all baselines. Across held-out attack families, recall averages 0.527 ± 0.466, indicating strong family dependence. In the controlled end-to-end experiment, complete ASIF decrypts 50% of requests and reduces mean latency from 278.78 to 164.19 ms/request relative to full decryption, while malicious-class recall decreases to 0.500 and macro-F1 to 0.733 because valid-certificate malicious traffic bypasses deeper inspection. These results characterize ASIF as a resource-aware selective inspection strategy with explicit coverage limitations rather than a universal encrypted-malicious-traffic detector.
Authors
- Lulu Liu (ORCID: https://orcid.org/0000-0003-1937-6027)
- Liangbin Yang (ORCID: https://orcid.org/0000-0001-7214-9750)
- Jing Bai
- Xiaomei Liu
- Lizhen Liu
Institutions
- University of International Relations (CN)
Publication Details
- Journal
- Network
- Published
- 2026-09-28
- DOI
- https://doi.org/10.3390/network6040082
- Primary Topic
- Internet Traffic Analysis and Secure E-voting
- Type
- article
- Field-Weighted Citation Impact
- 0.00