NAT Device Host Detection via IP Identification Sequences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting the number of host computers behind a Network Address Translator (NAT) device are ineffective when IP addresses are dynamically assigned, as they generate false detections and only work offline, failing to provide real-time detection.

Innovation Solution

A method and system that utilize packet identification sequences, dynamic IP addresses, and detection logic to accurately count non-overlapping sequences and group applications, allowing real-time detection of multiple host computers behind a NAT device by correcting for jitter, wrap-around, and missing numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing NAT detection methods are used, then detection can be performed, but they generate false detections when IP addresses are dynamically assigned and only work offline

Engineering Contradiction:
Improvedetection accuracyVSAvoidcompatibility with dynamic IP addressing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameter from relying on static IP address patterns to using IP identification field sequences that remain valid under dynamic IP assignment. By tracking the sequential nature of IP identification numbers rather than IP address patterns, the system maintains detection accuracy regardless of whether IPs are statically or dynamically assigned.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary analysis of IP identification field sequences to establish baseline patterns before making detection decisions. By pre-processing and storing sequence patterns in databases, the system can quickly compare live traffic against known multi-host patterns, enabling both offline and online detection modes with high reliability.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If existing NAT detection methods are used, then detection can be performed, but real-time detection is not realized

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoiddetection delay
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The detection system is segmented into multiple operational modes: offline analysis mode for comprehensive pattern recognition and online real-time mode for immediate detection. This segmentation allows the system to use computationally intensive analysis when time is not critical, while providing fast response when real-time detection is needed, thus achieving both high accuracy and real-time capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts its detection approach based on traffic conditions and requirements. It can switch between analyzing captured traces offline and processing live traffic in real-time, optimizing performance based on the operational context. This dynamic operation enables the system to provide real-time detection without sacrificing the analytical depth of offline processing.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If packet analysis is performed to detect multiple hosts, then the number of hosts can be identified, but bandwidth consumption increases and detection complexity increases

Engineering Contradiction:
Improvehost counting accuracyVSAvoiddetection algorithm complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential IP identification field from packets for analysis, rather than performing comprehensive packet inspection. By focusing specifically on the sequential IP identification numbers and their patterns, the system achieves accurate host counting with minimal processing overhead, reducing both algorithmic complexity and bandwidth consumption while maintaining high measurement precision.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8081567B2Method and apparatus for detecting wireless data subscribers using natted devices
Publication Date: 2011.12.20 WSOU INVESTMENTS LLC
  • US8081567B2 patent drawing
  • US8081567B2 patent drawing
  • US8081567B2 patent drawing

AI summary

A system and method for network based detection of wireless data subscribers using network address translation devices is provided. The method includes identifying a minimum number of devices showing the same internet protocol address. Packet identification sequences may include port numbers or internet protocol identification numbers. The method continues with grouping these applications by their packet identification sequences and applying detection logic where detection logic yields a conclusion that there are multiple host computers when a set of applications appears in a plurality of packet identification sequences. This method is particularly useful when internet protocol addresses are dynamic, as opposed to static. This method overcomes previous embodiments known in the art by being able to account for and work with live traffic, which enables real time detection.