Detecting Network Address Translation Devices In A Network Based On Network Traffic Logs
    2.
    发明申请
    Detecting Network Address Translation Devices In A Network Based On Network Traffic Logs 有权
    基于网络流量日志检测网络中的网络地址转换设备

    公开(公告)号:US20160315952A1

    公开(公告)日:2016-10-27

    申请号:US14696947

    申请日:2015-04-27

    Abstract: Network traffic logs of network traffic to and from host devices connected to a network that were collected over time are accessed. For each host device identified in the logs, a set of network traffic features indicative of whether the host device behaves like a Network Address Translation (NAT) device or an end host device is extracted from the logs for the host device. Each feature has values that vary over time based on the logs. A trained host device behavior classifier classifies the host device as either a NAT device or an end host device based on one or more of the feature values.

    Abstract translation: 访问连接到网络的主机设备的网络流量的网络流量日志,这些网络流量记录随时间被收集。 对于在日志中标识的每个主机设备,指示主机设备是否像主机设备的日志中提取主机设备的行为类似于网络地址转换(NAT)设备或终端主机设备的一组网络流量特征。 每个功能的值都会根据日志随时间而变化。 经过训练的主机设备行为分类器基于一个或多个特征值将主机设备分类为NAT设备或终端主机设备。

Patent Agency Ranking