> I've always wondered how often timing analysis is used in practice by surveillence big tech
Temporal correlation is the difference between regular network analysis, and dynamic network analysis. Just search "dynamic network analysis" on Google Scholar, and look at who's writing the papers :)
But to back up a step — every SaaS company does this on some level. If you have an backend audit-log for e.g. user registrations, and you eyeball it every so often to notice event clusters of people trying to bulk-register accounts in order to block their IPs — well, that's timing analysis!
Temporal correlation is the difference between regular network analysis, and dynamic network analysis. Just search "dynamic network analysis" on Google Scholar, and look at who's writing the papers :)
But to back up a step — every SaaS company does this on some level. If you have an backend audit-log for e.g. user registrations, and you eyeball it every so often to notice event clusters of people trying to bulk-register accounts in order to block their IPs — well, that's timing analysis!