Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Encrypted Traffic Analysis: Mitigating Against The Risk Of Encryption
Articles

Encrypted Traffic Analysis: Mitigating Against The Risk Of Encryption

Simon MullisBy Simon MullisAugust 22, 2022Updated:December 15, 20224 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Unable to Provide Access to Encrypted Data
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

All global organisations are now responsible for preserving and maintaining the privacy of clients, employees and other forms of business-critical data. Governments and regulators are also mandating organisations to implement best-practice encryption, with financial ramifications for data leaks. This has subsequently driven a massive uptake in end-to-end encryption to ensure compliance and the support of customer data privacy while in transit and at rest.  

TLS 1.3 – the current standard that ensures strongly encrypted communications – is now widely by 62% of the top 1,000 internet websites. Nevertheless, some aspects of applying strong encryption are poorly understood – and this is becoming a growing issue for security teams. 

Data is put at risk when organisations have an inadequate configuration of encryption protocols. However, in many cases, companies in highly regulated industries do not have a full view of what is or isn’t encrypted and whether they meet the standards set by regulators and governments. This is sometimes due to legacy infrastructure, but it is often because nobody ‘owns’ encryption within an enterprise. Therefore, ultimately no one ends up as accountable.  

Encrypted communications challenge many organisations, even those implementing strong encryption standards across the board. The sheer volume of encrypted traffic they must contend with makes it impossible for security teams to gain visibility through decryption alone. Instead, we need to find new ways to analyse and understand this traffic, as organisations cannot mitigate the cyber risk in the areas of their network they can’t see.  

Reducing the risk of encrypted traffic 

We are increasingly seeing attackers that breach an organisation’s perimeter hide malicious activity within legitimate encrypted network traffic. This introduces a substantial blind spot for security teams. In the first three quarters of 2021 alone, attacks over encrypted channels increased by 314% from the previous year. These attacks aren’t cutting edge, but the lack of visibility into encrypted traffic gives intruders free licence to operate on private networks. So, active decryption and inspection could be the answer. However, significant costs and complexity are created by trying to decrypt vast traffic volumes and modern-day encryption protocols use Perfect Forward Secrecy, which forces strong encryption between the client and server. 

Attackers now use encrypted communications to hide, breach organisations and laterally move around once a beachhead has been established. The challenge now is how to spot suspicious encrypted communications within the enterprise.    

The only way organisations can hope to reduce this risk is if they can measure and understand the encrypted communication on the network traffic without relying on decryption. To achieve this, security teams need to shift their approach towards a deeper analysis of encrypted communications, guaranteeing greater certainty about what is happening within encrypted traffic flows.  

Encrypted Traffic Analysis (ETA) is an emerging method of identifying and detecting suspicious or anomalous behaviour hidden in encrypted traffic without decryption. It uses a combination of artificial intelligence, machine learning, and behavioural analytics to analyse encrypted traffic without decryption. It ultimately improves encrypted network traffic visibility while causing no impact on latency or privacy infringement. It also understands the behaviour of traffic across networks and provides alerts in near real-time, allowing security teams to react immediately rather than after the fact. This significantly increases the rate at which suspicious activity can be identified in encrypted traffic, thereby reducing business risk.  

The network visibility gained by employing an ETA platform can also help organisations to ensure that their encrypted estate is as secure as they intend. Many organisations will use static analysis to understand the certificate, but this approach does not provide critical information required on what is actively negotiated and used for the individual sessions. 

Learning to measure and mitigate  

There is no immediate solution to entirely protecting the privacy of our data. However, the shift to using best practices and strong encryption will most definitely play a crucial role in minimising employee and customer risk of enterprise data breaches.  

Visibility is a virtue in this new encrypted world, so organisations must start to implement a ‘measure and mitigate’ approach rather than one of ‘detect and decrypt’. Thus, this will allow enterprises to understand what is happening at this present time and better detect activity on their encrypted networks.  

Simon Mullis

Simon Mullis, Chief Technology Officer at Venari Security

  • Simon Mullis
    An Olympic Effort? Ensuring Security In A Rising Threat Landscape

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}