Due to the rapid growth of the Internet, the last IPv4 address was exhausted by the end of 2019. Using Network Address Translation (NAT) technology is popular because it allows multiple network devices to share one or more IPv4 addresses without migrating to IPv6. However, when conducting black-box penetration testing outside of NAT networks, the original IP addresses have already been changed, which makes it hard to identify the source address of a device with potential threats. Therefore, it is necessary to detect whether a device with an IPv4 address uses NAT technology and further probe its internal network devices. This paper proposes a mechanism using deep packet inspection to detect the NAT box and the devices behind it. Penetration testers can use the method we propose to accurately identify potential Internet of Things (IoT) devices within the network, facilitating precise penetration testing.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Device Identification Technology Within the Network Address Translation Devices

  • Jia-Ning Luo,
  • Ying-Yi Yeh

摘要

Due to the rapid growth of the Internet, the last IPv4 address was exhausted by the end of 2019. Using Network Address Translation (NAT) technology is popular because it allows multiple network devices to share one or more IPv4 addresses without migrating to IPv6. However, when conducting black-box penetration testing outside of NAT networks, the original IP addresses have already been changed, which makes it hard to identify the source address of a device with potential threats. Therefore, it is necessary to detect whether a device with an IPv4 address uses NAT technology and further probe its internal network devices. This paper proposes a mechanism using deep packet inspection to detect the NAT box and the devices behind it. Penetration testers can use the method we propose to accurately identify potential Internet of Things (IoT) devices within the network, facilitating precise penetration testing.