Traffic Fingerprinting
Definition
The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions, inter-arrival times, flow duration, and burst structure, without inspecting the payload. Machine-learning classifiers trained on known traffic samples are the most common implementation.
- Basis
- Packet size, timing, duration, burst structure
- Target
- Identifying apps or actions in encrypted flows
- Payload access needed
- None
- Common implementation
- Machine-learning classifiers
Common questions
How can an application be identified without decrypting its traffic?+
Different apps and user actions produce distinctive statistical signatures, such as characteristic packet size sequences, that classifiers trained on known samples can match even when the payload itself stays unreadable.
What limits the reliability of traffic fingerprinting as evidence?+
Padding, traffic shaping, or similar-looking protocols can blur these statistical signatures, and classifier accuracy depends heavily on how closely the training samples matched the real-world conditions being analyzed.
Related terms
- Flow Record
- A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count...
- JA3 Fingerprint
- An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve...
- Server Name Indication (SNI)
- A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
- SSL Inspection (TLS Interception)
- A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using...
- SSLKEYLOGFILE
- A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as...