Network Traffic Profiling Tool Host Attribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network forensics face challenges in identifying the true origin of network traffic behind a Network Address Translation (NAT) device, as multiple host devices share the same source IP address, making it difficult to attribute traffic to individual hosts, which is crucial for security and forensic analysis.

Innovation Solution

A system and method that utilize a network traffic profiling tool to attribute network traffic to individual host devices by communicating with the NAT device to extract and process information for classification on a per-user or per-host basis, using a hardware processor separate from the NAT device to identify host devices through embedded data items and profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAT device translates IP addresses to hide multiple hosts behind a single public IP address, then IPv4 address exhaustion is alleviated and network privacy is protected, but network forensics capability deteriorates because the true origin of traffic cannot be identified

Engineering Contradiction:
Improvenumber of usable IP addressesVSAvoidtraffic origin identification accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary profiling tool that sits between the NAT device and external networks. This tool captures packets, extracts identifying data items inserted by the NAT device, and maintains profiles that map public IP addresses to individual host devices. The intermediary enables forensic identification without requiring changes to the NAT device's core address translation function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of direct IP address tracking with an information-based system. Instead of relying on IP addresses alone to identify hosts, the system uses data items embedded in packets by the NAT device, which are then extracted and processed by the profiling tool to create associative profiles linking traffic to specific hosts.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If NAT device uses higher level information like TCP/UDP ports to avoid ambiguity in translated packets, then packet routing accuracy is improved, but information availability outside NAT device deteriorates because translation table and port mappings are not accessible externally

Engineering Contradiction:
Improvepacket routing accuracyVSAvoidtranslation table accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the identifying information function from the NAT device's internal translation table. Instead of requiring external systems to access the NAT device's proprietary translation table, the profiling tool extracts data items directly from packet streams that contain the necessary identification information, making it accessible outside the NAT device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The profiling tool creates copies of identifying data items from the packet flows and stores them in external profiles. This copying mechanism allows the identification information to be preserved and accessed outside the NAT device without requiring access to the original translation table, effectively duplicating the identification functionality in an accessible form.

Inventive Principle:
Principle #26Copying

3Productivity

If multiple host devices share the same source IP address through NAT, then network address efficiency is improved, but network security analysis deteriorates because traffic attribution to individual hosts becomes difficult

Engineering Contradiction:
Improvenetwork address utilization efficiencyVSAvoidtraffic attribution complexity
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The NAT device performs self-service by inserting identifying data items into the packet streams it generates. This self-annotation allows the profiling tool to later extract and use these items for traffic attribution without requiring additional infrastructure or manual configuration, enabling the NAT device to assist in its own traffic identification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10498618B2Attributing network address translation device processed traffic to individual hosts
Publication Date: 2019.12.03 THE BOEING CO
  • US10498618B2 patent drawing
  • US10498618B2 patent drawing
  • US10498618B2 patent drawing

AI summary

A method for profiling network traffic. The method includes capturing, from the network traffic using a packet capturing device, a plurality of packets, identifying a first portion of the plurality of packets as a first flow based at least on a common Internet Protocol (IP) address assigned to each packet of the first flow by a network address translation (NAT) device, extracting, by a hardware processor separate from the NAT device and based on an NAT profile of the NAT device, a first data item from the first flow, wherein the first data item is inserted into the first flow by the NAT device for identifying a first host device coupled to the NAT device, and determining, by the hardware processor based on the first data item, that the first flow is generated by the first host device.