Information outside encrypted content
Traffic analysis infers information from presence, absence, source, destination, path, time, duration, direction, size, frequency, burst, and protocol behavior. Encryption can hide content while leaving these patterns visible to network observers, intermediaries, endpoints, and service providers.
Observer and inference
Map observers at local network, DNS, proxy, gateway, cloud, provider, destination, and global positions. State which endpoints and identifiers they see and whether they can correlate time across locations.
Inferable facts can include who communicates, work schedule, application, request type, file class, incident activity, organization, device, relationship, and whether a sensitive event occurred.
Reduction controls
Minimize exposed identifiers and intermediaries. Encrypt names and content where protocols support it. Aggregate, batch, pad, multiplex, delay, or add cover traffic only when the threat and performance budget justify them. Separate routes and logs by purpose and limit retention and correlation.
Measure the resulting pattern. Padding only payload length can leave timing and count. A shared gateway can hide individual destination from one observer and centralize complete metadata for the gateway operator.
Failure and residual risk
Low-latency systems reveal timing. Cover traffic costs bandwidth and can have a recognizable pattern. Padding has buckets and overhead. Adversaries can combine network data with login, location, public events, and endpoint observations. A global observer can defeat controls designed for one local link.
Anonymity networks and relays change observer assumptions; they do not remove malicious endpoints, browser fingerprinting, or application identity.
Pomerium boundary
Pomerium terminates or proxies configured connections and therefore observes routing and access metadata needed for operation and evidence. It can reduce direct origin exposure but becomes a metadata processor. Operators must protect, minimize, and retain this data according to purpose. Pomerium does not make traffic patterns anonymous to all network observers.
Evaluation checklist
- Which local, provider, intermediary, destination, or global observer sees time, size, direction, names, and routes?
- What person, relationship, application, event, or content class can the observer infer?
- Which identifiers and logs let separate observations be correlated?
- Do padding, batching, multiplexing, or relays address the exact observer and pattern at acceptable cost?
- Which endpoint, fingerprint, timing, and external-data correlation remains after content encryption?
