Patent · US Active

Identifying IP traffic from multiple hosts behind a network address translation device

US9577898B1 · kind B1 · utility

12Cited by
2References
19Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 31, 2013
Grant dateFeb 21, 2017
Priority date
Expiry dateMay 19, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L47/2416
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for profiling network traffic of a network. The method includes capturing packets based at least on a common source IP address shared by each of the packets, where said each packet is assigned a source timestamp by a source of said each packet and further assigned a capture timestamp by a packet capturing device, identifying a first portion of the packets as a first flow and a second portion of the packets as a second flow, extracting a first monotonic timestamp-pair (MTSP) sequence and a second MTSP sequence from the first flow and the second flow, respectively, comparing the first MTSP sequence and the second MTSP sequence to generate a result, and determining, based on the result, whether the first flow and the second flow are generated by a single host of the network.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.