Session trace — idle0 packets · 0.0s
payload: ·········· encrypted — size & timing only ··········
Outbound (client → server) Inbound (server → client) Mystery session (identity hidden until matched)

Encrypted Traffic Fingerprinting

TLS hides every byte of payload, but it can't hide the shape of the traffic: packet sizes, direction and timing are visible to anyone watching the wire. Record a few encrypted sessions to build a fingerprint library, then capture an unlabeled mystery session and watch it get matched against that library from metadata alone — no decryption involved. Toggle the padding/traffic-shaping defense to see fixed-size packets, timing jitter and dummy traffic blur that shape and drag the match confidence down.