Identifying Devices Behind NATs Using TCP Timestamp Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network address translators (NATs) obscure the identification of devices behind them, making it challenging to monitor communication and determine which devices belong to a particular local area network (LAN), especially when devices use multiple networks and NATs at different times.

Innovation Solution

A system that aggregates packets from unknown devices using TCP timestamps and receipt times to partition TCP connections into subsets, associating each subset with a single device by calculating deviations from linear relationships and setting threshold deviations, allowing for effective identification of devices despite NAT obfuscation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network address translators (NATs) are used to enable multiple devices to share a single public IP address, then network connectivity and resource sharing are improved, but device identification and communication monitoring become obscured and difficult

Engineering Contradiction:
Improvenetwork connectivityVSAvoiddevice identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses TCP timestamps as a unique identifier or 'color' for each device, allowing differentiation of devices behind NATs. Each device's TCP timestamp pattern serves as a distinctive marker that can be tracked through the NAT, enabling identification despite the shared public IP address.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces an intermediary analysis system that sits between the NAT and the monitoring point, analyzing packet metadata (TCP timestamps, IP IDs) to identify devices. This intermediary layer translates the obscured NAT traffic into identifiable device-specific patterns without requiring changes to the NAT itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If devices use multiple networks and NATs at different times, then network flexibility and adaptability are improved, but consistent device identification across networks becomes more difficult

Engineering Contradiction:
Improvenetwork flexibilityVSAvoiddevice identification consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal identification mechanism using TCP timestamp patterns that works across multiple networks and NATs. The system analyzes the universal characteristics of TCP timestamp generation that are consistent across different operating systems and networks, enabling reliable device identification regardless of which network or NAT the device is behind.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary analysis of TCP timestamp patterns during normal traffic flow to establish device identification profiles before monitoring or security actions are needed. By continuously analyzing and building device profiles in advance, the system maintains reliable identification even when devices move between networks and NATs.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If packet aggregation is performed using traditional methods without TCP timestamp analysis, then processing simplicity is maintained, but accuracy in identifying devices behind NATs deteriorates

Engineering Contradiction:
Improveprocessing simplicityVSAvoiddevice identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces traditional packet aggregation methods that rely on simple header field matching with a more sophisticated analysis system that examines TCP timestamp patterns. Instead of using basic mechanical rules for packet grouping, the system substitutes a pattern-recognition approach that analyzes the temporal characteristics of TCP timestamps to accurately identify devices behind NATs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11303736B2System and method for identifying devices behind network address translators based on TCP timestamps
Publication Date: 2022.04.12 COGNYTE TECH ISRAEL LTD
  • US11303736B2 patent drawing
  • US11303736B2 patent drawing
  • US11303736B2 patent drawing

AI summary

Methods and systems for monitoring activity on a local area networks (LAN). In particular, embodiments described herein provide systems and methods for associating packets with the devices from which they were communicated, despite the obfuscatory behavior of any network address translators (NAT). A processor first receives packets that were collectively communicated, by a plurality of devices, via a NAT-serviced LAN. The processor aggregates the packets into multiple packet aggregations on a per device basis. Fields that are contained in the respective packet headers of the packets are used. The packet aggregations may be grouped. The embodiments use unencrypted lower-level information (including, for example, IPIDs and domain names), such that aggregation and grouping may be successfully performed even if information in the application layer is encrypted.