{"id":"https://openalex.org/W7160531575","doi":"https://doi.org/10.1007/s10922-026-10069-y","title":"Unveiling Hidden Patterns: Self-Similarity and Entropy for Robust Encrypted DNS Traffic Security","display_name":"Unveiling Hidden Patterns: Self-Similarity and Entropy for Robust Encrypted DNS Traffic Security","publication_year":2026,"publication_date":"2026-05-08","ids":{"openalex":"https://openalex.org/W7160531575","doi":"https://doi.org/10.1007/s10922-026-10069-y"},"language":"en","primary_location":{"id":"doi:10.1007/s10922-026-10069-y","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10922-026-10069-y","pdf_url":null,"source":{"id":"https://openalex.org/S67072002","display_name":"Journal of Network and Systems Management","issn_l":"1064-7570","issn":["1064-7570","1573-7705"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Network and Systems Management","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1007/s10922-026-10069-y","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5039026107","display_name":"Marta Moure-Garrido","orcid":"https://orcid.org/0000-0001-6068-6233"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Marta Moure-Garrido","raw_affiliation_strings":[],"raw_orcid":"https://orcid.org/0000-0001-6068-6233","affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135590643","display_name":"Carlos Garcia-Rubio","orcid":"https://orcid.org/0000-0002-4635-722X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Carlos Garcia-Rubio","raw_affiliation_strings":[],"raw_orcid":"https://orcid.org/0000-0002-4635-722X","affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5135605986","display_name":"Celeste Campo","orcid":"https://orcid.org/0000-0003-1788-890X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Celeste Campo","raw_affiliation_strings":[],"raw_orcid":"https://orcid.org/0000-0003-1788-890X","affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5039026107"],"corresponding_institution_ids":[],"apc_list":{"value":2190,"currency":"EUR","value_usd":2790},"apc_paid":{"value":2190,"currency":"EUR","value_usd":2790},"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.83966346,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"34","issue":"3","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9379000067710876,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9379000067710876,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.04919999837875366,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10138","display_name":"Network Traffic and Congestion Control","score":0.002400000113993883,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.6491000056266785},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.5389000177383423},{"id":"https://openalex.org/keywords/entropy","display_name":"Entropy (arrow of time)","score":0.512499988079071},{"id":"https://openalex.org/keywords/predictability","display_name":"Predictability","score":0.5031999945640564},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.4652000069618225},{"id":"https://openalex.org/keywords/traffic-analysis","display_name":"Traffic analysis","score":0.4277999997138977},{"id":"https://openalex.org/keywords/covert","display_name":"Covert","score":0.40779998898506165},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.40369999408721924}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8507999777793884},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.6491000056266785},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5389000177383423},{"id":"https://openalex.org/C106301342","wikidata":"https://www.wikidata.org/wiki/Q4117933","display_name":"Entropy (arrow of time)","level":2,"score":0.512499988079071},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.503600001335144},{"id":"https://openalex.org/C197640229","wikidata":"https://www.wikidata.org/wiki/Q2534066","display_name":"Predictability","level":2,"score":0.5031999945640564},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.4652000069618225},{"id":"https://openalex.org/C2781317605","wikidata":"https://www.wikidata.org/wiki/Q7832483","display_name":"Traffic analysis","level":2,"score":0.4277999997138977},{"id":"https://openalex.org/C2779338814","wikidata":"https://www.wikidata.org/wiki/Q5179285","display_name":"Covert","level":2,"score":0.40779998898506165},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4052000045776367},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.40369999408721924},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.3783999979496002},{"id":"https://openalex.org/C29024540","wikidata":"https://www.wikidata.org/wiki/Q1476964","display_name":"Covert channel","level":5,"score":0.37540000677108765},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.3483000099658966},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.32089999318122864},{"id":"https://openalex.org/C204679922","wikidata":"https://www.wikidata.org/wiki/Q734252","display_name":"Deep packet inspection","level":3,"score":0.3034000098705292},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3019999861717224},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.30070000886917114},{"id":"https://openalex.org/C96835011","wikidata":"https://www.wikidata.org/wiki/Q1638718","display_name":"Hurst exponent","level":2,"score":0.2824999988079071},{"id":"https://openalex.org/C35026560","wikidata":"https://www.wikidata.org/wiki/Q8767","display_name":"Domain Name System","level":3,"score":0.28200000524520874},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.28200000524520874},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.27079999446868896},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.26809999346733093}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1007/s10922-026-10069-y","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10922-026-10069-y","pdf_url":null,"source":{"id":"https://openalex.org/S67072002","display_name":"Journal of Network and Systems Management","issn_l":"1064-7570","issn":["1064-7570","1573-7705"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Network and Systems Management","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1007/s10922-026-10069-y","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10922-026-10069-y","pdf_url":null,"source":{"id":"https://openalex.org/S67072002","display_name":"Journal of Network and Systems Management","issn_l":"1064-7570","issn":["1064-7570","1573-7705"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Network and Systems Management","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","display_name":"Reduced inequalities","score":0.7224485278129578}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":58,"referenced_works":["https://openalex.org/W1925630500","https://openalex.org/W1964146567","https://openalex.org/W1995875735","https://openalex.org/W2019853444","https://openalex.org/W2031753087","https://openalex.org/W2048027256","https://openalex.org/W2105818147","https://openalex.org/W2111779554","https://openalex.org/W2115122866","https://openalex.org/W2119635640","https://openalex.org/W2134211228","https://openalex.org/W2141910941","https://openalex.org/W2144328044","https://openalex.org/W2151402192","https://openalex.org/W2155915275","https://openalex.org/W2157416927","https://openalex.org/W2162443378","https://openalex.org/W2165773639","https://openalex.org/W2170125123","https://openalex.org/W2171873915","https://openalex.org/W2341760625","https://openalex.org/W2613715541","https://openalex.org/W2902372528","https://openalex.org/W2912386632","https://openalex.org/W3008176860","https://openalex.org/W3091640033","https://openalex.org/W3105087971","https://openalex.org/W3120774524","https://openalex.org/W3161677312","https://openalex.org/W3184417104","https://openalex.org/W4214937762","https://openalex.org/W4230133813","https://openalex.org/W4236030294","https://openalex.org/W4239856175","https://openalex.org/W4252032939","https://openalex.org/W4285160154","https://openalex.org/W4285184946","https://openalex.org/W4306824696","https://openalex.org/W4321496630","https://openalex.org/W4382753153","https://openalex.org/W4389791575","https://openalex.org/W4393379748","https://openalex.org/W4401478730","https://openalex.org/W4402283956","https://openalex.org/W4403213156","https://openalex.org/W4405014478","https://openalex.org/W4407783299","https://openalex.org/W4408283015","https://openalex.org/W4409760249","https://openalex.org/W4410474757","https://openalex.org/W4412038333","https://openalex.org/W4412445116","https://openalex.org/W4412446464","https://openalex.org/W7116721806","https://openalex.org/W7116733521","https://openalex.org/W7116795362","https://openalex.org/W7118570464","https://openalex.org/W7134110283"],"related_works":[],"abstract_inverted_index":{"Abstract":[0],"The":[1],"increasing":[2],"complexity":[3],"and":[4,52,71,83,137,149],"volume":[5],"of":[6,14,56,85,133,153],"modern":[7],"network":[8,146],"traffic,":[9,59,73],"specifically":[10],"within":[11,156],"the":[12,49,80,131,151],"context":[13],"encrypted":[15,57,157],"Domain":[16],"Name":[17],"System":[18],"(DNS)":[19],"protocols,":[20],"particularly":[21],"DNS":[22,58],"over":[23],"HTTPS":[24],"(DoH),":[25],"pose":[26],"significant":[27],"challenges":[28],"to":[29,37,120,144],"traditional":[30],"traffic":[31],"analysis":[32,91],"methods,":[33],"making":[34],"it":[35],"difficult":[36],"discern":[38],"legitimate":[39],"activity":[40],"from":[41,124],"covert":[42],"or":[43],"malicious":[44,72,86,123],"communications.":[45],"This":[46],"paper":[47],"explores":[48],"intrinsic":[50],"self-similarity":[51],"long-term":[53],"memory":[54],"properties":[55],"employing":[60],"multiple":[61],"statistical":[62,113],"methods":[63],"for":[64],"Hurst":[65],"parameter":[66],"estimation.":[67],"By":[68],"comparing":[69],"benign":[70,125],"we":[74,104],"uncover":[75],"distinct":[76],"temporal":[77],"structures,":[78],"revealing":[79],"heightened":[81],"predictability":[82],"persistence":[84],"traffic.":[87,126],"Furthermore,":[88],"our":[89],"entropy":[90],"quantifies":[92],"packet":[93],"inter-arrival":[94],"randomness,":[95],"providing":[96],"additional":[97],"discriminatory":[98],"insights.":[99],"Based":[100],"on":[101,111],"these":[102,112],"findings,":[103],"propose":[105],"an":[106],"anomaly":[107],"detector":[108],"founded":[109],"exclusively":[110],"features,":[114],"demonstrating":[115],"that":[116],"they":[117],"are":[118],"sufficient":[119],"robustly":[121],"differentiate":[122],"These":[127],"findings":[128],"significantly":[129],"enhance":[130,145],"understanding":[132],"how":[134],"long-range":[135],"dependencies":[136],"variations":[138],"in":[139],"unpredictability":[140],"can":[141],"be":[142],"leveraged":[143],"security":[147],"protocols":[148],"improve":[150],"detection":[152],"hidden":[154],"threats":[155],"channels.":[158]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-05-08T00:00:00"}
