Invention Grant
- Patent Title: Detecting network address translation devices in a network based on network traffic logs
-
Application No.: US15496683Application Date: 2017-04-25
-
Publication No.: US09942256B2Publication Date: 2018-04-10
- Inventor: Tomá{hacek over (s)} Komárek , Martin Grill , Tomá{hacek over (s)} Pevný
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N99/00

Abstract:
Actual traffic logs of network traffic to and from host devices in a network are collected over time. Artificial traffic logs for each of multiple artificial network address translation (NAT) devices are generated from the actual traffic logs. The actual traffic logs and the artificial traffic logs are labeled as being indicative of non-NAT devices and NAT devices, respectively, to produce labeled traffic logs. From the labeled traffic logs for each artificial NAT device and each non-NAT device, respective, correspondingly labeled, network traffic features indicative of whether the device behaves like a NAT device or a non-NAT device are extracted. A classifier device is trained using the network traffic features extracted for each artificial NAT device and each non-NAT device to classify between an actual NAT device and an actual non-NAT device based on further actual traffic logs.
Public/Granted literature
- US20170230395A1 DETECTING NETWORK ADDRESS TRANSLATION DEVICES IN A NETWORK BASED ON NETWORK TRAFFIC LOGS Public/Granted day:2017-08-10
Information query