Skip to content

NAT (Network Address Translation)

Definition

A mechanism by which a router replaces private source IP addresses with a single public IP address before forwarding packets to the internet, and reverses the mapping for returning traffic. NAT is the reason a single ISP-assigned IP may represent many users, and its internal port-mapping logs are essential for per-device attribution.

Function
Maps private internal IPs to a shared public IP
Common types
Static NAT, dynamic NAT, PAT (port address translation)
Investigative role
Router/ISP NAT logs link a public IP and port to one internal device
Common devices
Home routers, corporate gateways, carrier-grade NAT (CGNAT)

Common questions

Why does NAT complicate attributing an online action to one person?+

Many devices behind the same router, or even many customers behind an ISP's carrier-grade NAT, can share one public IP simultaneously. Without the port number and exact timestamp from the service provider's logs, investigators cannot narrow the public IP down to a single device or user.

What log data is needed to reverse a NAT mapping?+

The ISP or router needs to have retained a mapping of public IP plus source port plus timestamp to the internal private IP and device or account. Without that retained mapping, the public IP alone cannot be traced back to an individual subscriber.

Related terms

Anchor Event
A log entry that can be identified with high confidence across two or more log sources, used to verify relative clock offsets...
Autonomous System (AS)
A collection of IP networks operated under a single routing policy and identified by a unique Autonomous System Number (ASN). ISPs, large...
BGP (Border Gateway Protocol)
The routing protocol that autonomous systems use to advertise the IP address ranges they control to one another. BGP is the mechanism...
CIDR (Classless Inter-Domain Routing)
A compact notation for IP address ranges that appends a prefix length to the address, such as 192.168.1.0/24. The prefix length states...
Clock Skew
The difference between a device's local clock and a trusted reference time such as UTC. Skew accumulates due to hardware drift, timezone...
DHCP Lease Log
A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
IPv6 Privacy Extensions (RFC 8981)
A mechanism defined in RFC 8981 (formerly RFC 4941) by which IPv6 hosts generate temporary randomised addresses for outbound connections, rotating them...
Log Normalisation
The conversion of log entries from their native format into a common schema, typically a structured record with a corrected UTC timestamp,...
RIR (Regional Internet Registry)
One of five organisations that allocate IP address blocks by region: ARIN (Americas), RIPE NCC (Europe, Middle East, Central Asia), APNIC (Asia-Pacific),...
Session Tuple
The five-element identifier for a network session: source IP, source port, destination IP, destination port, and protocol. The session tuple is the...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.