SR&ED Case Study: Intrusion Detection for Encrypted Traffic

Troubled software developer reviewing error logs

Background

A network security vendor’s intrusion detection product relied on inspecting unencrypted packet content, but the rapid shift to encrypted traffic across client networks left the product blind to a growing share of malicious activity.

The Challenge

The vendor needed to detect malicious behaviour patterns without access to decrypted payload content, and it was unclear whether metadata-based signals alone could achieve acceptable detection accuracy at production traffic volumes.

Technological Uncertainty

It was not known in advance whether traffic metadata — timing, packet size distribution, connection patterns — contained enough signal to reliably distinguish malicious from benign encrypted sessions, or whether the approach would generate unacceptable false-positive rates at scale.

Experimental Development

The team systematically tested multiple metadata feature sets and classification approaches against labelled encrypted traffic samples, measuring detection accuracy and false-positive rate for each configuration under realistic production traffic conditions.

What Failed?

An initial feature set based on published research achieved reasonable accuracy on offline test data but degraded sharply under live traffic conditions with mixed application types, revealing that the approach needed to account for traffic-type variability the offline dataset hadn’t captured.

Technological Advancement

The team developed a refined feature set and classification approach that maintained detection accuracy across varied live traffic conditions without decrypting payload content, generating new technical knowledge about metadata-based threat detection at production scale.

Potentially Relevant SR&ED Activities

●  Systematic testing of metadata feature sets against labelled encrypted traffic

●  Classification model experiments under live production traffic conditions

●  False-positive and detection-accuracy benchmarking across configurations

What Would Generally Not Qualify

Deploying the finalized detection model to monitor additional identical network segments would be routine operation and would not itself qualify as further eligible development.

Documentation

Detection accuracy benchmarks across feature sets, false-positive tracking under live conditions, and technical notes explaining why the offline-validated approach required revision would support this claim.

About The Author

Dale Doering

Dale Doering is the owner of SRED Consultants Inc., helping businesses navigate the complexities of Scientific Research and Experimental Development (SR&ED) claims. With a strong understanding of the technical and interpretive requirements of the SR&ED program, Dale works with companies to identify eligible projects, document technological challenges, and clearly demonstrate the systematic experimentation or analysis undertaken to achieve advancement. His approach focuses on translating complex technical work into well-supported SR&ED claims, helping clients maximize eligible opportunities while maintaining a clear understanding of the program’s requirements.

Recent Posts

Frequently Asked Questions

What was the core technological uncertainty in this project?

The key uncertainty was whether network metadata—such as packet size distribution, timing, and connection patterns—contained a strong enough signal to reliably detect malicious activity in encrypted traffic without decrypting the payload, and whether this could be achieved at scale without generating excessive false positives.

The initial feature set, which was based on published academic research and validated on offline test data, failed because its accuracy degraded significantly when exposed to live production traffic with varied application types. This failure forced the team to conduct systematic experimental development to create a refined feature set capable of handling real-world traffic variability.

The team developed a refined feature set and classification model that successfully maintained high threat detection accuracy across diverse, live network environments without relying on payload decryption. This generated new technical knowledge regarding the boundaries and execution of metadata-based threat detection at production scale.

Eligible SR&ED activities include:

– Systematic testing and iteration of metadata feature sets against labeled encrypted traffic datasets.

– Running classification model experiments under live, production traffic conditions.

– Benchmarking detection accuracy and false-positive rates across different configurations.

Deploying the completed detection model to monitor additional identical network segments is considered routine operational work and would not qualify for SR&ED.

To support the claim, required documentation includes accuracy benchmark reports across feature sets, false-positive tracking logs under live conditions, and technical notes documenting why the offline-validated model failed and required further experimental revision.

Related Post