Friday, May 2, 2003

Detectecting NAT Devices

Here's another method for detecting NAT devices. Based on Steve Belovin's paper, "A Technique for Counting NATted Hosts" and Toby Miller's "Passive OS Fingerprinting: Details and Techniques, this technique uses the sflow tool.

It makes some assumptions about operating systems and where in a network you are able to capture traffic but should be a good starting point for gathering an in-depth picture of, at least, your own network.

