Endpoint Identification Using System Logs

Stephen W. Melvin · 2009

Typical logging of public Internet activity involves recording only the source IP address associated with a transaction or access. Unfortunately this is usually insufficient to identify a unique endpoint associated with the activity, mainly due to the common existence of one or more NAT gateways between the originating network and the Internet and the lack of specific logging at the originating end. Here we address the information needed to solve this problem, where it needs to come from, and various scenarios for how it can be managed. Specifically, in order to uniquely identify a specific endpoint, three related pieces of information need to be recorded: 1. the MAC address associated with the local IP address at the originating network (known by a DHCP daemon); 2. the association between the local IP address and port numbers at each NAT gateway (known by a NAT daemon); and 3. the source port number of the public access (known by the remote server). A related problem of MAC address validation, allowing the association of a specific hardware device with a MAC address in use, is discussed as well.

Read the paper · More papers on PaperTik