Paper 2026/149

Private IP Address Inference in NAT Networks via Off-Path TCP Control-Plane Attack

Suraj Sharma, Ashoka University
Adityavir Singh, Ashoka University
Mahabir Prasad Jhanwar, Ashoka University
Abstract

NAT is widely assumed to conceal the private IP addresses of internal clients from both off-path attackers within the same LAN and external observers. We show that this assumption does not hold. We present a novel off-path deanonymization attack that infers the private IP addresses of NATed clients engaged in active TCP connections with a remote server. Our attack builds on known NAT behaviors in real-world Wi-Fi routers, such as port preservation, insufficient reverse-path validation, and the absence of TCP window tracking, previously shown to enable off-path TCP hijacking. By inferring a NATed client’s private IP address, our attack defeats the anonymity commonly attributed to NAT, creating a persistent privacy leak that enables deanonymization and user profiling. We validate the attack on 6 Wi-Fi routers and 2 real-world Wi-Fi networks using SSH and HTTP/HTTPS traffic over TCP, finding that 5 of the 6 routers and both networks are vulnerable.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
TCP hijackingNetwork Address Translationoff-path attacksclient deanonymization
Contact author(s)
suraj sharma @ ashoka edu in
adityavir singh_phd22 @ ashoka edu in
mahavir jhawar @ ashoka edu in
History
2026-07-11: last of 3 revisions
2026-01-30: received
See all versions
Short URL
https://ia.cr/2026/149
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/149,
      author = {Suraj Sharma and Adityavir Singh and Mahabir Prasad Jhanwar},
      title = {Private {IP} Address Inference in {NAT} Networks via Off-Path {TCP} Control-Plane Attack},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/149},
      year = {2026},
      url = {https://eprint.iacr.org/2026/149}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.