Network address translation (NAT) equipment protocol port inference method, device, equipment and medium
By monitoring and analyzing the port allocation of NAT devices, marking suspicious behavior and taking defensive measures, the problem of inability to detect hidden attacks in the prior art is solved, network security is improved, and the risks of kernel port allocation mechanism are revealed.
Patent Information
- Application Number
- CN202510533052.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-08-22
AI Technical Summary
The existing NAT equipment protection measures cannot effectively detect and defend against hidden attacks carried out through the port allocation mechanism, which poses security risks.
By monitoring the port allocation of NAT devices, recording the port allocation and release process, marking suspicious behavior, and detecting exceptions of subsequent port allocation requests based on the port's characteristic information, and taking defense measures such as blocking and traffic restrictions.
Effectively detect and defend against attacks by manipulating the port allocation mechanism of NAT devices, improve network security, reveal the potential security risks of the NAT port allocation mechanism of Linux kernel, and provide tools for network security research.
Smart Images

Figure CN120528629A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer network security technology, and in particular to a NAT device protocol port inference method, apparatus, device and medium. Background Art
[0002] Network Address Translation (NAT) is a core component of the modern Internet architecture, primarily addressing the critical issues of IP address shortage and network security. NAT technology allows multiple clients within a private network to access the Internet through a single public IP address, effectively alleviating IPv4 address scarcity. By concealing the internal network structure, it enhances protection against external attacks. As a key component of the modern Internet architecture, NAT devices not only alleviate the IP address shortage problem but also meet fundamental network security requirements. To prevent attackers from predicting and exploiting these ports to launch network attacks, transport layer protocols typically use a randomized source port allocation strategy. However, while providing network address translation capabilities, NAT devices can also be exposed to various security threats. For example, attackers can manipulate the NAT device's port allocation mechanism to occupy a large number of external ports. By observing retransmissions and latency caused by allocation failures, attackers can infer the victim's source port and launch attacks against internal network devices.
[0003] Currently, although there are some security protection measures for NAT devices, these measures can often only detect obvious attack behaviors. For this type of covert attack carried out through the port allocation mechanism, existing protection measures may not be able to effectively detect and defend against it.
[0004] In summary, how to design a method to analyze the vulnerabilities in the Linux kernel NAT port allocation algorithm and reveal the potential security risks of the Linux kernel NAT port allocation mechanism is an urgent problem that needs to be solved. Summary of the Invention
[0005] The present application aims to solve one of the technical problems in the related art at least to a certain extent.
[0006] To this end, the first purpose of this application is to propose a NAT device protocol port inference method to solve the problem that existing technical means may not be able to effectively detect and defend against covert attacks carried out through the port allocation mechanism, and existing protection measures may not be able to effectively detect and defend against them.
[0007] The second object of this application is to provide a device.
[0008] The third objective of this application is to provide an electronic device.
[0009] The fourth object of this application is to provide a computer-readable storage medium.
[0010] A fifth object of this application is to provide a computer program.
[0011] To achieve the above objectives, the first embodiment of the present application proposes a NAT device protocol port inference method, including:
[0012] Monitor the port allocation of NAT devices and record the port allocation and release process;
[0013] When it is detected that the port of the NAT device is continuously occupied for a predetermined amount, characteristic information of the port is recorded;
[0014] Based on the characteristic information of the port, detecting whether a subsequent port allocation request is consistent with the recorded port information characteristics;
[0015] If the detection information is abnormal, the port allocation request is judged to be an attack behavior and corresponding defense measures are taken.
[0016] Preferably, the process of recording the allocation and release of the port includes: recording the allocation time, release time, occupation time, occupation source IP address and occupation source port information of the port.
[0017] Preferably, when it is detected that the port of the NAT device is continuously occupied and the amount of occupation reaches a preset value, recording the characteristic information of the port includes: when it is detected that the port of the NAT device is continuously occupied and the occupation amount reaches a preset value, marking the port as suspicious behavior, and recording the source IP address, source port range, port occupation duration and port occupation frequency of the port.
[0018] Preferably, the detecting, based on the characteristic information of the port, whether the subsequent port allocation request is consistent with the recorded port information characteristics comprises:
[0019] When checking subsequent ports, compare the source IP address and source port range of the allocation request for the current port to see if they are consistent with the port marked for suspicious behavior;
[0020] If the source IP address and source port range of the current port allocation request are consistent with the port marked with suspicious behavior, then check whether the port where the port allocation failure leads to retransmission and delay is abnormal.
[0021] Preferably, if the source IP address and source port range of the current port allocation request are consistent with the port marked with suspicious behavior, detecting whether the port causing the retransmission and delay phenomenon due to port allocation failure is abnormal includes:
[0022] If the source IP address and source port range of the current port allocation request are consistent with the port marked as suspicious, the number of port allocation failures, number of retransmissions, and latency changes are counted.
[0023] If the number of allocation failures exceeds a preset threshold, and the number of retransmissions and the delay change exceed a preset range, it is determined to be abnormal.
[0024] Preferably, the taking corresponding defense measures includes:
[0025] Block port allocation requests from suspicious source IP addresses;
[0026] Limit traffic flow to suspicious source IP addresses;
[0027] Discard packets with suspicious source IP addresses.
[0028] To achieve the above-mentioned purpose, the second embodiment of the present application proposes a NAT device protocol port inference device, including:
[0029] Port monitoring module monitors the port allocation of NAT devices and records the port allocation and release process;
[0030] A suspicious behavior marking module records characteristic information of the port when detecting that the port of the NAT device is continuously occupied for a predetermined amount;
[0031] an anomaly detection module, which detects whether a subsequent port allocation request is consistent with the recorded port information characteristics based on the characteristic information of the port;
[0032] The defense module, if the detection information is abnormal, determines that the port allocation request is an attack behavior and takes corresponding defense measures.
[0033] To achieve the above-mentioned purpose, a third embodiment of the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0034] The memory stores computer-executable instructions;
[0035] The processor executes the computer-executable instructions stored in the memory to implement any of the above methods.
[0036] To achieve the above-mentioned purpose, the fourth embodiment of the present application proposes a computer-readable storage medium, including computer-executable instructions stored in the computer-readable storage medium, and the computer-executable instructions are used to implement any of the methods described above when executed by a processor.
[0037] To achieve the above-mentioned objectives, the fifth embodiment of the present application proposes a computer program product, including a computer program, which implements any of the above-mentioned methods when executed by a processor.
[0038] This application provides a method for inferring protocol ports on NAT devices, leveraging the port allocation side channel of the Netfilter framework in the Linux kernel. By establishing a TCP connection to the source port of a server to be detected and then sending packets to a port on the server to which no TCP connection exists, the source port can be inferred. By deeply analyzing the Linux kernel's NAT port allocation algorithm, the method enables inferring the client's transport layer protocol source port in a NAT environment under specific conditions. This method reveals potential security risks in the Linux kernel's NAT port allocation mechanism, which is of great significance for understanding and improving the security of NAT devices and provides valuable information and tools for network security researchers.
[0039] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0041] Figure 1 A flowchart of a first specific embodiment of a NAT device protocol port inference method provided by the present invention;
[0042] Figure 2 A schematic diagram of a transport layer protocol port inference method for Linux-based NAT devices;
[0043] Figure 3 This is a structural block diagram of a NAT device protocol port inference device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0044] The core of the present invention is to provide a NAT device protocol port inference method, device, electronic device and medium. By deeply analyzing the NAT port allocation algorithm of the Linux kernel, it is possible to infer the transport layer protocol source port of the client in the NAT environment under specific conditions, revealing the potential security risks of the Linux kernel NAT port allocation mechanism.
[0045] In order to enable those skilled in the art to better understand the present invention, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0046] Please refer to Figure 1 , Figure 1 This is a flowchart of a first specific embodiment of a NAT device protocol port inference method provided by the present invention; the specific operation steps are as follows:
[0047] Step S101: monitor the port allocation of the NAT device and record the port allocation and release process;
[0048] In one embodiment, recording the port allocation and release process includes: recording the port allocation time, release time, occupation time, occupation source IP address and occupation source port information.
[0049] Step S102: When it is detected that the port of the NAT device is continuously occupied for a predetermined amount, characteristic information of the port is recorded;
[0050] In one embodiment, when it is detected that the port of the NAT device is continuously occupied and the occupation amount reaches a preset value, the port is marked as suspicious behavior, and the source IP address, source port range, port occupation duration and port occupation frequency of the port are recorded.
[0051] Step S103: Based on the characteristic information of the port, detecting whether the subsequent port allocation request is consistent with the recorded port information characteristics;
[0052] In one embodiment, when detecting subsequent ports, the source IP address and source port range of the allocation request of the current port are compared to see if they are consistent with the port marked for suspicious behavior;
[0053] If the source IP address and source port range of the current port allocation request are consistent with the port marked with suspicious behavior, then check whether the port where the port allocation failure leads to retransmission and delay is abnormal.
[0054] If the source IP address and source port range of the current port allocation request are consistent with the port marked as suspicious, the number of port allocation failures, the number of retransmissions, and the change in latency are counted.
[0055] If the number of allocation failures exceeds a preset threshold, and the number of retransmissions and the delay change exceed a preset range, it is determined to be abnormal.
[0056] Step S104: If the detection information is abnormal, the port allocation request is determined to be an attack behavior, and corresponding defense measures are taken.
[0057] Block port allocation requests from suspicious source IP addresses;
[0058] Limit traffic flow to suspicious source IP addresses;
[0059] Discard packets with suspicious source IP addresses.
[0060] Send an alert to the administrator to indicate that an attack has occurred.
[0061] This embodiment provides a method for inferring protocol ports on NAT devices. It utilizes the port allocation side channel of the Netfilter framework in the Linux kernel to perform port inference. By establishing a TCP connection to the source port of a server to be detected and then sending packets to a port on the server to which no TCP connection exists, the source port can be inferred. By deeply analyzing the Linux kernel's NAT port allocation algorithm, the method enables inferring the transport layer protocol source port of a client in a NAT environment under specific conditions. This method reveals potential security risks in the Linux kernel's NAT port allocation mechanism, which is of great significance for understanding and improving the security of NAT devices and provides valuable information and tools for network security researchers.
[0062] Based on the above embodiment, this embodiment describes a method for inferring a NAT device protocol port. Figure 2 As shown, the details are as follows:
[0063] The above-mentioned NAT device protocol port inference method is described in an attack manner as follows:
[0064] Establish a TCP connection to the source port of the server to be detected;
[0065] Optionally, in a possible implementation, this embodiment chooses to infer the TCP protocol port as an example of transport layer protocol port inference. In this embodiment, the attacker and the victim are located under the same Linux-based NAT device. When the victim connects to the corresponding victim server port, the attacker can infer the source port of the victim's TCP connection through this method. The attacker first sends a TCP connection with the source port in a continuous space to the victim server port and keeps the connection alive, which will occupy a continuous external port on the NAT device. Due to vulnerabilities in the Linux port allocation algorithm, continuous occupied external ports will cause the algorithm to fail, which will cause the NAT device to fail to allocate a new port for a new connection with a certain probability.
[0066] A message is sent to the port of the server to be detected that has no TCP connection to obtain the corresponding source port.
[0067] During this phase, if the victim initiates one or more TCP connections to the victim server, their source ports must be different from the ports occupied by the attacker during the preparation phase. The attacker then sends TCP SYN packets to the victim server port on the remaining ports. If a corresponding packet is received, the port is idle; otherwise, it indicates that the port is occupied by the victim, and the corresponding source port can be inferred. After the preparation phase is completed, the inference phase can be repeated multiple times to infer the victim's newly established connections and filter out possible noise.
[0068] In one embodiment,
[0069] Port allocation monitoring:
[0070] Deploy a port monitoring module on the NAT device to record port allocation and release in real time. For example, it records information such as the allocation time, release time, occupation time, occupied source IP address, and occupied source port number for ports 1024-50000.
[0071] Suspicious behavior flags:
[0072] When it is detected that the external ports 1024-50000 of the NAT device are continuously occupied in large quantities, the port occupation behavior is marked as suspicious behavior and relevant characteristic information is recorded, such as the source IP address of the suspicious behavior is 192.168.1.100, the source port range is 1024-50000, the port occupation duration is 10 minutes, and the port occupation frequency is 100 times per second.
[0073] Anomaly Detection:
[0074] For subsequent port allocation requests, check whether there are characteristics related to the marked suspicious behavior. For example, a new port allocation request is detected with a source IP address of 192.168.1.100 and a destination port range of 1024-50000, which matches the characteristics of the marked suspicious behavior.
[0075] Further detection of abnormal phenomena such as retransmission and delay caused by allocation failure. If the number of port allocation failures is 5, the number of retransmissions is 3, and the delay variation exceeds the preset range (for example, the delay increases from 10ms to 500ms), it is determined to be an abnormal phenomenon.
[0076] Defensive measures:
[0077] Block port allocation requests from the suspicious source IP address 192.168.1.100.
[0078] Perform traffic restriction on the suspicious source IP address 192.168.1.100 and discard its packets.
[0079] Send an alert to the administrator to indicate that an attack has occurred.
[0080] Through the above embodiments, the present invention can effectively detect and defend against attacks carried out by manipulating the port allocation mechanism of NAT devices, thereby improving network security.
[0081] This embodiment provides a method for inferring protocol ports on NAT devices. It utilizes the port allocation side channel of the Netfilter framework in the Linux kernel to perform port inference. By establishing a TCP connection to the source port of a server to be detected and then sending packets to a port on the server to which no TCP connection exists, the source port can be inferred. By deeply analyzing the Linux kernel's NAT port allocation algorithm, the method enables inferring the transport layer protocol source port of a client in a NAT environment under specific conditions. This method reveals potential security risks in the Linux kernel's NAT port allocation mechanism, which is of great significance for understanding and improving the security of NAT devices and provides valuable information and tools for network security researchers.
[0082] Please refer to Figure 3 , Figure 3 A structural block diagram of a NAT device protocol port inference device provided by an embodiment of the present invention; the specific device may include:
[0083] The port monitoring module 100 monitors the port allocation of the NAT device and records the port allocation and release process;
[0084] The suspicious behavior marking module 200 records characteristic information of the port when detecting that the port of the NAT device is continuously occupied for a predetermined amount of time;
[0085] The anomaly detection module 300 detects whether a subsequent port allocation request is consistent with the recorded port information characteristics based on the characteristic information of the port;
[0086] If the detection information is abnormal, the defense module 400 determines that the port allocation request is an attack behavior and takes corresponding defense measures.
[0087] A NAT device protocol port inference device in this embodiment is used to implement the aforementioned NAT device protocol port inference method. Therefore, the specific implementation method of a NAT device protocol port inference device can be seen in the embodiment part of a NAT device protocol port inference method in the above text. For example, the port monitoring module 100, the suspicious behavior marking module 200, the anomaly detection module 300, and the defense module 400 are respectively used to implement steps S101, S102, S103, and S104 in the aforementioned NAT device protocol port inference method. Therefore, its specific implementation method can refer to the description of the corresponding embodiments of each part and will not be repeated here.
[0088] In order to implement the above embodiments, the present application also proposes an electronic device, comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method provided by the above embodiments.
[0089] In order to implement the above embodiments, the present application also proposes a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the methods provided by the above embodiments.
[0090] In order to implement the above embodiments, the present application also proposes a computer program product, including a computer program, which implements the methods provided by the above embodiments when executed by a processor.
[0091] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this application are in compliance with relevant laws and regulations and do not violate public order and good morals.
[0092] It is important to note that personal information collected from users should be used for legitimate and reasonable purposes and should not be shared or sold beyond these legitimate uses. Furthermore, such collection / sharing should be conducted only after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign an agreement / authorization that includes the relevant user information before using the feature. Furthermore, any necessary steps must be taken to safeguard and secure access to such personal information and ensure that others with access to personal information comply with its privacy policy and procedures.
[0093] This application contemplates providing implementations that allow users to selectively block the use or access of personal information data. Specifically, this disclosure contemplates providing hardware and / or software to prevent or block access to such personal information data. Risks can be minimized by limiting data collection and deleting data once it is no longer needed. Furthermore, where applicable, such personal information can be de-identified to protect user privacy.
[0094] In the descriptions of the foregoing embodiments, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are mutually inconsistent.
[0095] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.
[0096] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.
[0097] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.
[0098] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0099] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.
[0100] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.
[0101] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
Claims
1. A NAT device protocol port inference method, characterized in that: include: Monitor the port allocation of NAT devices and record the port allocation and release process; When it is detected that the port of the NAT device is continuously occupied for a predetermined amount, characteristic information of the port is recorded; Based on the characteristic information of the port, detecting whether a subsequent port allocation request is consistent with the recorded port information characteristics; If the detection information is abnormal, the port allocation request is judged to be an attack behavior and corresponding defense measures are taken.
2. The NAT device protocol port inference method according to claim 1, characterized in that: The process of recording the allocation and release of the port includes: recording the allocation time, release time, occupation time, occupation source IP address and occupation source port information of the port.
3. The NAT device protocol port inference method according to claim 1, characterized in that: When it is detected that the port of the NAT device is continuously occupied for a period of time that reaches a preset value, recording characteristic information of the port includes: when it is detected that the port of the NAT device is continuously occupied and the occupation period reaches a preset value, marking the port as suspicious behavior, and recording the source IP address, source port range, port occupation duration, and port occupation frequency of the port.
4. The NAT device protocol port inference method according to claim 3, characterized in that: The detecting, based on the characteristic information of the port, whether a subsequent port allocation request is consistent with the recorded port information characteristics includes: When checking subsequent ports, compare the source IP address and source port range of the allocation request for the current port to see if they are consistent with the port marked for suspicious behavior; If the source IP address and source port range of the current port allocation request are consistent with the port marked with suspicious behavior, then check whether the port where the port allocation failure leads to retransmission and delay is abnormal.
5. The NAT device protocol port inference method according to claim 4, characterized in that: If the source IP address and source port range of the current port allocation request are consistent with the port marked with suspicious behavior, then detecting whether the port causing the retransmission and delay phenomenon due to port allocation failure is abnormal includes: If the source IP address and source port range of the current port allocation request are consistent with the port marked as suspicious, the number of port allocation failures, number of retransmissions, and latency changes are counted. If the number of allocation failures exceeds a preset threshold, and the number of retransmissions and the delay change exceed a preset range, it is determined to be abnormal.
6. The NAT device protocol port inference method according to claim 1, characterized in that: The corresponding defensive measures include: Block port allocation requests from suspicious source IP addresses; Limit traffic flow to suspicious source IP addresses; Discard packets with suspicious source IP addresses.
7. A NAT device protocol port inference device, characterized in that: include: Port monitoring module monitors the port allocation of NAT devices and records the port allocation and release process; A suspicious behavior marking module records characteristic information of the port when detecting that the port of the NAT device is continuously occupied for a predetermined amount; an anomaly detection module, which detects whether a subsequent port allocation request is consistent with the recorded port information characteristics based on the characteristic information of the port; The defense module, if the detection information is abnormal, determines that the port allocation request is an attack behavior and takes corresponding defense measures.
8. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.