Flow Record
Definition
A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count in each direction, and packet count. Flow records (NetFlow, IPFIX, sFlow) are generated by routers and switches and provide traffic metadata without storing payload content.
- Contents
- Source/destination IP and port, protocol, duration, byte and packet counts
- Common formats
- NetFlow, IPFIX, sFlow
- Source device
- Routers and switches
- Payload
- Not captured; metadata only
Common questions
What can a flow record tell an investigator that a full packet capture cannot?+
Flow records are compact enough to retain for months across an entire network, where full packet capture is not, so they let an analyst reconstruct who talked to whom, when, and how much data moved, over a much longer retention window than payload capture typically allows.
Why are flow records useful when traffic is encrypted?+
Because they record connection metadata rather than content, they remain fully readable even when the payload is encrypted with TLS or a VPN. Timing, volume and destination patterns in the flow data can still reveal command-and-control beaconing or data exfiltration.
Is a flow record admissible on its own to prove what data was transferred?+
It shows that a connection occurred and its volume, but not the content exchanged. Courts typically treat it as circumstantial evidence of communication or transfer, usually corroborated with host logs, DNS records or other artefacts rather than standing alone.
Related terms
- JA3 Fingerprint
- An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve...
- Server Name Indication (SNI)
- A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
- SSL Inspection (TLS Interception)
- A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using...
- SSLKEYLOGFILE
- A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as...
- Traffic Fingerprinting
- The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions,...