NAT Device Host Detection via IP Identification Sequences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting the number of host computers behind a Network Address Translator (NAT) device are ineffective when IP addresses are dynamically assigned, as they generate false detections and only work offline, failing to provide real-time detection.
Innovation Solution
A method and system that utilize packet identification sequences, dynamic IP addresses, and detection logic to accurately count non-overlapping sequences and group applications, allowing real-time detection of multiple host computers behind a NAT device by correcting for jitter, wrap-around, and missing numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing NAT detection methods are used, then detection can be performed, but they generate false detections when IP addresses are dynamically assigned and only work offline
Solution Approach 1:
The patent changes the detection parameter from relying on static IP address patterns to using IP identification field sequences that remain valid under dynamic IP assignment. By tracking the sequential nature of IP identification numbers rather than IP address patterns, the system maintains detection accuracy regardless of whether IPs are statically or dynamically assigned.
Solution Approach 2:
The system performs preliminary analysis of IP identification field sequences to establish baseline patterns before making detection decisions. By pre-processing and storing sequence patterns in databases, the system can quickly compare live traffic against known multi-host patterns, enabling both offline and online detection modes with high reliability.
2Productivity
If existing NAT detection methods are used, then detection can be performed, but real-time detection is not realized
Solution Approach 1:
The detection system is segmented into multiple operational modes: offline analysis mode for comprehensive pattern recognition and online real-time mode for immediate detection. This segmentation allows the system to use computationally intensive analysis when time is not critical, while providing fast response when real-time detection is needed, thus achieving both high accuracy and real-time capability.
Solution Approach 2:
The system dynamically adjusts its detection approach based on traffic conditions and requirements. It can switch between analyzing captured traces offline and processing live traffic in real-time, optimizing performance based on the operational context. This dynamic operation enables the system to provide real-time detection without sacrificing the analytical depth of offline processing.
3Measurement precision
If packet analysis is performed to detect multiple hosts, then the number of hosts can be identified, but bandwidth consumption increases and detection complexity increases
Solution Approach 1:
The patent extracts only the essential IP identification field from packets for analysis, rather than performing comprehensive packet inspection. By focusing specifically on the sequential IP identification numbers and their patterns, the system achieves accurate host counting with minimal processing overhead, reducing both algorithmic complexity and bandwidth consumption while maintaining high measurement precision.
Data Source
AI summary
A system and method for network based detection of wireless data subscribers using network address translation devices is provided. The method includes identifying a minimum number of devices showing the same internet protocol address. Packet identification sequences may include port numbers or internet protocol identification numbers. The method continues with grouping these applications by their packet identification sequences and applying detection logic where detection logic yields a conclusion that there are multiple host computers when a set of applications appears in a plurality of packet identification sequences. This method is particularly useful when internet protocol addresses are dynamic, as opposed to static. This method overcomes previous embodiments known in the art by being able to account for and work with live traffic, which enables real time detection.


