Device Identification Technology Within the Network Address Translation Devices
摘要
Due to the rapid growth of the Internet, the last IPv4 address was exhausted by the end of 2019. Using Network Address Translation (NAT) technology is popular because it allows multiple network devices to share one or more IPv4 addresses without migrating to IPv6. However, when conducting black-box penetration testing outside of NAT networks, the original IP addresses have already been changed, which makes it hard to identify the source address of a device with potential threats. Therefore, it is necessary to detect whether a device with an IPv4 address uses NAT technology and further probe its internal network devices. This paper proposes a mechanism using deep packet inspection to detect the NAT box and the devices behind it. Penetration testers can use the method we propose to accurately identify potential Internet of Things (IoT) devices within the network, facilitating precise penetration testing.