Can We Identify NAT Behavior by Analyzing Traffic Flows?
Yasemin Gokcen, Vahid Aghaei Foroushani, A. Nur Zincir Heywood · 2014
It is shown in the literature that network address translation devices have become a convenient way to hide the source of malicious behaviors. In this research, we explore how far we can push a machine learning (ML) approach to identify such behaviors using only network flows. We evaluate our proposed approach on different traffic data sets against passive fingerprinting approaches and show that the performance of a machine learning approach is very promising even without using any payload (application layer) information.