Passive NATted Hosts Detect Algorithm Based on Directed Acyclic Graph Support Vector Machine

  • Authors:
  • Rui Li;Hongliang Zhu;Yang Xin;Shoushan Luo;Yixian Yang;Cong Wang

  • Affiliations:
  • -;-;-;-;-;-

  • Venue:
  • MINES '09 Proceedings of the 2009 International Conference on Multimedia Information Networking and Security - Volume 02
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Unauthorized network address translation (NAT) devices may be a significant security problem. They provide unrestricted access to any number of hosts connecting to them. Some attackers may use computers hidden behind NAT devices to conduct malicious activities such as denial of service. An algorithm is proposed in this work to detect hosts hidden behind NAT.Different from previous researches, the algorithm does not depend on any special field in any packet header. It is based on analyzing traffic features with directed acyclic graph support vector machine (DAGSVM). Firstly, traffic models of hosts are selected from training samples with DAGSVM. Then the models and classifier are used for predicting host number of unknown traces. What revealed by the experiment includes that the proposed algorithm is effective, even when there are more hosts in the test set than it is in the training set, and the accuracy will fall when there are more unknown hosts in the test traces.