Repository logo
 

Exploring NAT detection and host identification

dc.contributor.authorZhang, Lan
dc.contributor.copyright-releaseNot Applicableen_US
dc.contributor.degreeMaster of Computer Scienceen_US
dc.contributor.departmentFaculty of Computer Scienceen_US
dc.contributor.ethics-approvalNot Applicableen_US
dc.contributor.external-examinern/aen_US
dc.contributor.graduate-coordinatorNorbert Zehen_US
dc.contributor.manuscriptsNot Applicableen_US
dc.contributor.thesis-readerIsraat Haqueen_US
dc.contributor.thesis-readerSrinivas Sampallien_US
dc.contributor.thesis-supervisorNur Zincir-Heywooden_US
dc.contributor.thesis-supervisorKhurram Azizen_US
dc.date.accessioned2018-08-23T18:09:28Z
dc.date.available2018-08-23T18:09:28Z
dc.date.defence2018-08-15
dc.date.issued2018-08-23T18:09:28Z
dc.description.abstractThis thesis explores NAT detection and host identification. The NAT detection approach is processed by supervised machine learning algorithms on HTTP attributes. Three classifiers are employed on training datasets labelled by artificial NAT generation method in NAT detection. This research demonstrates that AD Tree performs best in NAT detection and selects five effective attributes for it. AD Tree can detect NAT devices with an accuracy approximately of 100% on five datasets. The impact of difference in sizes of datasets in NAT detection is also observed in this thesis. Host identification is based on TCP timestamp values and system uptime values of TCP packets. This research identifies end hosts behind a detected NAT device using an improved artificial line generation method and an improved line distance calculation method. It also provides a new evaluation method for host identification. These two tasks are combined in this research for forensic analysis in order to analyze cybersecurity incidents that could occur from unknown NAT devices in the incoming traffic to an organization.en_US
dc.identifier.urihttp://hdl.handle.net/10222/74135
dc.language.isoenen_US
dc.subjectNAT detectionen_US
dc.subjecthost identificationen_US
dc.subjectTCP timestampen_US
dc.subjectAD Treeen_US
dc.titleExploring NAT detection and host identificationen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Zhang-Lan-MCSc-CSCI-August-2018.pdf
Size:
4.65 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: