被动式远程网络地址翻译器识别系统

Novel Passive Remote Network Address Translation Detecting System

  • 摘要: 源自不同终端的数据报中隐含了发送源彼此各异的特征,设计实现了基于数据报外部特征的被动式远程网络地址翻译器识别系统(NDS)。该系统以IP数据报和TCP分组头部信息为研究对象,通过综合检测IP生存时间(TTL)初始值、IP标示(IPid)和TCP时间戳等3种参数的时间序列异常,完成对网络地址翻译器快速、准确的识别。真实环境下的测试结果表明,NDS能有效地检测NAT设备,拥有较高的NAT识别准确率,具有良好的使用价值。

     

    Abstract: Network address translation detection is the key in Internet administration and security field. Based on the observation that packets from different source devices have different characteristics, a passive remote network address translation detection system (NDS) is designed. IP identification and TCP timestamp time series are established by suitable processing of the headers of trace data. The tested results in real environment on aggregated local trace data shows that NDS could effectively detect network address translation remotely and has relative high detection rate.

     

/

返回文章
返回