Counting Malicious Host Behind NAT Using Ensemble Machine Learning Approach
Sanjeev Kumar Shukla, Manoj Kumar Misra, Gaurav Varshney · 2024
Network Address Translation (NAT) is widely used to map private IP addresses to public ones, offering anonymity that not only benefits legitimate users by protecting their internal IP addresses but also poses a challenge by enabling malicious users to obscure their identities during cyber-attacks. Identifying the actual host behind NAT involved in such activities is critical for effective forensic analysis. In this study, we introduce a novel, passive, and non-intrusive technique that leverages ensemble machine learning (ML) to pinpoint and characterize malicious hosts behind NAT. By analyzing network traffic patterns at the flow level, our method successfully penetrates the veil of anonymity NAT provides. Designed to be operating system-agnostic and independent of IP addresses, our approach addresses privacy concerns while maintaining high efficacy. Demonstrating a remarkable accuracy rate of 99.12%, our technique not only outperforms existing ML and non-ML-based methods but also sets a new benchmark in detecting malicious entities operating behind NAT.