Network traffic analysis is the practice of examining traffic as it crosses the network to establish how systems are actually behaving, rather than how they report they are behaving. It covers performance, availability and security, and its defining characteristic is that the measurement is taken from the wire rather than from the endpoints.
Flow-based versus packet-based analysis
Flow-based analysis summarises conversations: source, destination, port, byte and packet counts over an interval. It is cheap, it scales easily, and it answers questions about who talked to whom and how much.
Packet-based analysis keeps the content and the timing. It is more demanding to collect and store, and it answers a different class of question: not how much traffic there was, but why a specific transaction was slow, which side gave up first, and what was actually in the message.
What it is used for
Three uses dominate. Performance work, where the question is where latency accumulates along a path. Fault diagnosis, where the question is which component failed and in what order events occurred. And security, where the question is whether observed behaviour matches what the systems are supposed to do.
These share a requirement: the evidence has to exist before the question is asked. Traffic analysis is only as good as what was retained at the moment the event occurred.
Limits of flow data
Flow records are averages over an interval, usually one minute. Anything shorter than the interval disappears into it. For enterprise capacity planning that is a reasonable trade. For a trading system where the entire event lasted 200 microseconds, a one-minute average is not a lower-resolution answer so much as no answer at all.
In trading infrastructure
This is why packet-level analysis is the norm in electronic trading rather than a specialist option. Corvil network analytics derives measurements continuously from captured traffic, so a question raised after the event can still be answered from the record.