Paper 2026/149
Private IP Address Inference in NAT Networks via Off-Path TCP Control-Plane Attack
Abstract
NAT is widely assumed to conceal the private IP addresses of internal clients from both off-path attackers within the same LAN and external observers. We show that this assumption does not hold. We present a novel off-path deanonymization attack that infers the private IP addresses of NATed clients engaged in active TCP connections with a remote server. Our attack builds on known NAT behaviors in real-world Wi-Fi routers, such as port preservation, insufficient reverse-path validation, and the absence of TCP window tracking, previously shown to enable off-path TCP hijacking. By inferring a NATed client’s private IP address, our attack defeats the anonymity commonly attributed to NAT, creating a persistent privacy leak that enables deanonymization and user profiling. We validate the attack on 6 Wi-Fi routers and 2 real-world Wi-Fi networks using SSH and HTTP/HTTPS traffic over TCP, finding that 5 of the 6 routers and both networks are vulnerable.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- TCP hijackingNetwork Address Translationoff-path attacksclient deanonymization
- Contact author(s)
-
suraj sharma @ ashoka edu in
adityavir singh_phd22 @ ashoka edu in
mahavir jhawar @ ashoka edu in - History
- 2026-07-11: last of 3 revisions
- 2026-01-30: received
- See all versions
- Short URL
- https://ia.cr/2026/149
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/149,
author = {Suraj Sharma and Adityavir Singh and Mahabir Prasad Jhanwar},
title = {Private {IP} Address Inference in {NAT} Networks via Off-Path {TCP} Control-Plane Attack},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/149},
year = {2026},
url = {https://eprint.iacr.org/2026/149}
}