KNOWLEDGE — FUNDAMENTALS

Encrypted network traffic

The large majority of network traffic today is encrypted. That hides the content, not the circumstances: who communicates with whom, when, for how long, how often and at what volume all remain visible.

This is often taken to mean that analysing network traffic has become pointless. It holds for the payload only.

Encryption seals the envelope, not the postal system. Sender, recipient, weight, time and frequency remain on record. If a device that has only ever spoken to two internal servers suddenly opens a connection to an unfamiliar overseas address at the same time every night, that is observable without anyone reading the contents.

What gets evaluated are the characteristics of the connection: the systems involved, timing, duration, volumes transferred, regularity, ports and protocols in use, and properties of the connection setup and certificates. Over time these build a picture of normal operation. Deviation from it becomes visible regardless of what the encrypted portion contains. Connections recurring at a conspicuously steady interval are a known pattern for communication between a compromised system and its control server.

Network visibility stays effective under full encryption, with no need to intercept or break the traffic. The limit is equally clear: the content stays hidden. Establishing which specific data was transferred requires other means. Network analysis answers that something unusual is happening, not in every case exactly what was sent.