Skip to main content

Traffic Analysis

Infer participants, relationships, activity, protocol, content class, and events from communication timing, direction, size, frequency, and routes.

Information outside encrypted content

Traffic analysis infers information from presence, absence, source, destination, path, time, duration, direction, size, frequency, burst, and protocol behavior. Encryption can hide content while leaving these patterns visible to network observers, intermediaries, endpoints, and service providers.

Observer and inference

Map observers at local network, DNS, proxy, gateway, cloud, provider, destination, and global positions. State which endpoints and identifiers they see and whether they can correlate time across locations.

Inferable facts can include who communicates, work schedule, application, request type, file class, incident activity, organization, device, relationship, and whether a sensitive event occurred.

Reduction controls

Minimize exposed identifiers and intermediaries. Encrypt names and content where protocols support it. Aggregate, batch, pad, multiplex, delay, or add cover traffic only when the threat and performance budget justify them. Separate routes and logs by purpose and limit retention and correlation.

Measure the resulting pattern. Padding only payload length can leave timing and count. A shared gateway can hide individual destination from one observer and centralize complete metadata for the gateway operator.

Failure and residual risk

Low-latency systems reveal timing. Cover traffic costs bandwidth and can have a recognizable pattern. Padding has buckets and overhead. Adversaries can combine network data with login, location, public events, and endpoint observations. A global observer can defeat controls designed for one local link.

Anonymity networks and relays change observer assumptions; they do not remove malicious endpoints, browser fingerprinting, or application identity.

Pomerium boundary

Pomerium terminates or proxies configured connections and therefore observes routing and access metadata needed for operation and evidence. It can reduce direct origin exposure but becomes a metadata processor. Operators must protect, minimize, and retain this data according to purpose. Pomerium does not make traffic patterns anonymous to all network observers.

Evaluation checklist

  • Which local, provider, intermediary, destination, or global observer sees time, size, direction, names, and routes?
  • What person, relationship, application, event, or content class can the observer infer?
  • Which identifiers and logs let separate observations be correlated?
  • Do padding, batching, multiplexing, or relays address the exact observer and pattern at acceptable cost?
  • Which endpoint, fingerprint, timing, and external-data correlation remains after content encryption?

Sources and further reading

Keep learning

Privacy EngineeringCryptography and Data Protection

Personal Data and Metadata

Treat identifiers, device facts, access events, relationships, timing, locations, and derived attributes as personal when context can link them to people.

Learn this term
Platform and Component SecurityCryptography and Data Protection

Side-Channel Attack

Analyze information leaked through time, caches, memory access, power, emissions, sound, faults, resources, and error behavior.

Learn this term
Security Operations and RiskStandards and Protocols

Encryption

Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo