Article ID Journal Published Year Pages File Type
458009 Digital Investigation 2009 8 Pages PDF
Abstract

Network Address Translation (NAT) is a technology allowing a number of machines to share a single IP address. This presents a problem for network forensics since it is difficult to attribute observed traffic to specific hosts. We present a model and algorithm for disentangling observed traffic into discrete sources. Our model relies on correlation of a number of artifacts left over by the NAT gateway which allows identification of sources. The model works well for a small number of sources, as commonly found behind a home or small office NAT gateway.

Related Topics
Physical Sciences and Engineering Computer Science Computer Networks and Communications
Authors
,