-
1.
公开(公告)号:US20170230395A1
公开(公告)日:2017-08-10
申请号:US15496683
申请日:2017-04-25
Applicant: Cisco Technology, Inc.
Inventor: Tomás Komárek , Martin Grill , Tomás Pevny
CPC classification number: H04L63/1425 , G06F17/30185 , G06F17/30979 , G06N99/005 , H04L41/142 , H04L41/16 , H04L43/00 , H04L43/04 , H04L61/2514 , H04L63/1408
Abstract: Actual traffic logs of network traffic to and from host devices in a network are collected over time. Artificial traffic logs for each of multiple artificial network address translation (NAT) devices are generated from the actual traffic logs. The actual traffic logs and the artificial traffic logs are labeled as being indicative of non-NAT devices and NAT devices, respectively, to produce labeled traffic logs. From the labeled traffic logs for each artificial NAT device and each non-NAT device, respective, correspondingly labeled, network traffic features indicative of whether the device behaves like a NAT device or a non-NAT device are extracted. A classifier device is trained using the network traffic features extracted for each artificial NAT device and each non-NAT device to classify between an actual NAT device and an actual non-NAT device based on further actual traffic logs.