Invention Grant
- Patent Title: System and method for identifying devices behind network address translators based on TCP timestamps
-
Application No.: US16262001Application Date: 2019-01-30
-
Publication No.: US10715641B2Publication Date: 2020-07-14
- Inventor: Yitshak Yishay
- Applicant: Verint Systems LTD.
- Applicant Address: IL Herzelia Pituach
- Assignee: VERINT SYSTEMS LTD.
- Current Assignee: VERINT SYSTEMS LTD.
- Current Assignee Address: IL Herzelia Pituach
- Agency: Meunier Carlin & Curfman LLC
- Priority: com.zzzhc.datahub.patent.etl.us.BibliographicData$PriorityClaim@41d2ef0f
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; H04L12/26

Abstract:
Methods and systems for monitoring activity on a local area networks (LAN). In particular, embodiments described herein provide systems and methods for associating packets with the devices from which they were communicated, despite the obfuscatory behavior of any network address translators (NAT). A processor first receives packets that were collectively communicated, by a plurality of devices, via a NAT-serviced LAN. The processor aggregates the packets into multiple packet aggregations on a per device basis. Fields that are contained in the respective packet headers of the packets are used. The packet aggregations may be grouped. The embodiments use unencrypted lower-level information (including, for example, IPIDs and domain names), such that aggregation and grouping may be successfully performed even if information in the application layer is encrypted.
Public/Granted literature
- US20190238663A1 SYSTEM AND METHOD FOR IDENTIFYING DEVICES BEHIND NETWORK ADDRESS TRANSLATORS BASED ON TCP TIMESTAMPS Public/Granted day:2019-08-01
Information query