Background
A network security vendor’s intrusion detection product relied on inspecting unencrypted packet content, but the rapid shift to encrypted traffic across client networks left the product blind to a growing share of malicious activity.
The Challenge
The vendor needed to detect malicious behaviour patterns without access to decrypted payload content, and it was unclear whether metadata-based signals alone could achieve acceptable detection accuracy at production traffic volumes.
Technological Uncertainty
It was not known in advance whether traffic metadata — timing, packet size distribution, connection patterns — contained enough signal to reliably distinguish malicious from benign encrypted sessions, or whether the approach would generate unacceptable false-positive rates at scale.
Experimental Development
The team systematically tested multiple metadata feature sets and classification approaches against labelled encrypted traffic samples, measuring detection accuracy and false-positive rate for each configuration under realistic production traffic conditions.
What Failed?
An initial feature set based on published research achieved reasonable accuracy on offline test data but degraded sharply under live traffic conditions with mixed application types, revealing that the approach needed to account for traffic-type variability the offline dataset hadn’t captured.
Technological Advancement
The team developed a refined feature set and classification approach that maintained detection accuracy across varied live traffic conditions without decrypting payload content, generating new technical knowledge about metadata-based threat detection at production scale.
Potentially Relevant SR&ED Activities
● Systematic testing of metadata feature sets against labelled encrypted traffic
● Classification model experiments under live production traffic conditions
● False-positive and detection-accuracy benchmarking across configurations
What Would Generally Not Qualify
Deploying the finalized detection model to monitor additional identical network segments would be routine operation and would not itself qualify as further eligible development.
Documentation
Detection accuracy benchmarks across feature sets, false-positive tracking under live conditions, and technical notes explaining why the offline-validated approach required revision would support this claim.




