A Generalizable Machine Learning Model for NAT Detection
Reem Nassar, Imad H. Elhajj, Ayman Kayssi, Samer Salam · 2023
Network Address Translation (NAT) aimed originally at resolving the issue of IPv4 address exhaustion. NAT allows multiple devices on a local network to share a single public IP address. This enables efficient utilization of the limited number of public IP addresses and allows devices on a local network to connect to the internet. However, NAT can lead to communication problems, security vulnerabilities, difficulties in network management, and challenges in identifying network issues. This paper proposes a novel approach for NAT detection using machine learning that overcomes the limitations of traditional NAT detection methods by building a generalizable model. The proposed method incorporates techniques to achieve generalization in the presence of obfuscation, a technique used by attackers to evade detection. The experimental results show the superiority of the proposed method over existing NAT detection techniques in terms of accuracy and generalization, even in the presence of obfuscation. A decline in the classification F1 score below 70% is observed when traffic data has multiple features obfuscated and when environment changes. To tackle this issue, transfer learning was applied to enhance the model’s efficiency and effectiveness. Transfer learning resulted in more promising results in new network environments and in case of obfuscation.