Test Method, Device, Test Platform and Storage Medium for TCP Sequence Number Checking Function

By designing test cases and automated scripts covering various out-of-order situations, combining multiple communication modules to interact with TCP packets, monitoring the processing results of the equipment under test, the problem of incomplete TCP serial number checking function testing scheme in the prior art is solved, and the comprehensiveness and flexibility of the test are achieved.

CN116132172BActive Publication Date: 2025-05-30BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310120549.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-15
Publication Date
2025-05-30
Estimated Expiration
2043-02-15

AI Technical Summary

Technical Problem

The test scheme for TCP serial number checking function in the prior art is incomplete, and there are problems of insufficient comprehensiveness and flexibility.

Method used

It provides a test method for TCP serial number checking function, which covers various out-of-order situations by designing test cases, uses automated scripts to achieve full coverage, combines multiple communication modules to interact with TCP packets, and monitors the processing results of the equipment under test to determine whether the test passes or not.

Benefits of technology

A comprehensive test of the TCP serial number check function is realized to ensure that it is correctly identified and processed in various out-of-order situations, and improve the comprehensiveness and flexibility of the test.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132172B_ABST
    Figure CN116132172B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a test method, device, test platform and storage medium for the TCP sequence number checking function, which are applied to a test platform. The platform includes multiple communication modules, and the platform is communicatively connected to a device under test equipped with a TCP sequence number checking function. The method includes: creating a test task according to the selection result of a test case; controlling multiple communication modules to perform TCP packet interaction through the device under test according to the test task; wherein at least some of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet; monitoring the processing result of the TCP packets when the device under test performs TCP sequence number checking, and determining whether the TCP sequence number checking function passes the test according to the processing result. By designing test cases to cover various out-of-order situations to test the TCP sequence number checking function, the comprehensiveness of the test is ensured and the flexibility of the test is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology. Specifically, it relates to a test method, device, test platform, and storage medium for TCP sequence number checking function. Background Art

[0002] TCP (Transmission Control Protocol) ensures the orderliness of TCP packets through the sequence number in the header. The TCP sequence number checking function can check the TCP online data stream to ensure the legality of each packet in the transmitted TCP data stream in the sequence. This function is applicable to scenarios with poor network environments where packet loss and out-of-order are likely to occur, as well as scenarios with TCP protocol stack attacks.

[0003] In the related art, it is necessary to test the TCP sequence number checking function. However, the test scheme for the TCP sequence number checking function is not perfect and has great limitations. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a test method, device, test platform, and storage medium for the TCP sequence number checking function to realize a comprehensive and flexible test of the TCP sequence number checking function.

[0005] The first aspect of the embodiments of this application provides a test method for the TCP sequence number checking function, which is applied to a test platform. The platform includes multiple communication modules, and the platform is communicatively connected to the device under test with the TCP sequence number checking function. The method includes:

[0006] Create a test task according to the selection result of the test case;

[0007] According to the test task, control multiple communication modules to perform TCP packet interaction through the device under test; wherein, at least part of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet;

[0008] Monitor the processing result of the TCP packets by the device under test when performing the TCP sequence number check, and determine whether the TCP sequence number checking function passes the test according to the processing result.

[0009] In the above implementation process, test cases are designed so that the test method can cover various out-of-order situations. All types of test scenarios exist in the form of automated scripts, comprehensively covering all test scenarios for TCP sequence number testing. Thus, it can be tested whether the TCP sequence number checking function can correctly identify and process various out-of-order situations, ensuring the comprehensiveness of the test. At the same time, the selectivity of the test cases also improves the flexibility of the test. The test plan for the TCP sequence number checking function is improved.

[0010] Furthermore, the relationship between the starting sequence number of the payload data in the TCP packet and the expected sequence number includes any of the following:

[0011] The starting sequence number is before the expected sequence number, and the payload data covers sequence number wrapping or no sequence number wrapping occurs;

[0012] The starting sequence number is equal to the expected sequence number, and the payload data covers sequence number wrapping or no sequence number wrapping occurs;

[0013] The starting sequence number is after the expected sequence number, and the payload data covers sequence number wrapping or no sequence number wrapping occurs.

[0014] In the above implementation process, the above 6 relationships between the starting sequence number and the expected sequence number cover all possible relationships between the starting sequence number and the expected sequence number. By designing test cases corresponding to each relationship, multiple TCP packets covering all relationships between the starting sequence number and the expected sequence number can be generated according to the test cases. All types of test scenarios exist in the form of automated scripts, comprehensively covering all test scenarios for TCP sequence number testing. Thus, it can be tested whether the TCP sequence number checking function can identify and process TCP packets corresponding to different relationships, achieving the comprehensiveness of the test.

[0015] Furthermore, the data feature also includes the relationship between the payload data in the TCP packet and the receive window; the relationship between the payload data and the receive window includes any of the following:

[0016] The payload data is completely outside the receive window;

[0017] The payload data is partially outside the receive window;

[0018] The payload data is completely inside the receive window.

[0019] In the above implementation process, the above relationships cover all possible relative relationships among the sequence number, payload data, and receive window in the TCP packet. By designing test cases corresponding to each relationship, multiple TCP packets covering all relative relationships among the sequence number, payload data, and receive window can be generated according to the test cases. Various test scenarios exist in the form of automated scripts, comprehensively covering various test scenarios for TCP sequence number testing, so as to test the recognition and processing of TCP packets corresponding to different relationships by the TCP sequence number check function, achieving the comprehensiveness of the test.

[0020] Further, the processing result includes releasing or discarding the TCP packet, and monitoring the processing result of the TCP packet by the DUT when performing the TCP sequence number check includes:

[0021] Monitoring the TCP packets discarded by the DUT and counting the number of packet losses.

[0022] In the above implementation process, by monitoring the TCP packets discarded by the DUT and counting the number of packet losses, it is possible to comprehensively test whether the TCP sequence number check function passes the test.

[0023] Further, monitoring the TCP packets discarded by the DUT and counting the number of packet losses includes:

[0024] Determining the target TCP packet to be discarded;

[0025] Monitoring the change in the number of packet losses before and after the target TCP packet is sent;

[0026] Determining whether the target TCP packet to be discarded is discarded according to the change situation.

[0027] In the above implementation process, first determine the target TCP packet to be discarded, so that by monitoring the change in the number of packet losses before and after the target TCP packet is sent, it can be known whether the DUT correctly identifies the target TCP packet and whether it can perform the discard processing on the target TCP packet. That is, only by monitoring the change in the number of packet losses, the monitoring of the recognition and discard processing can be completed.

[0028] Further, determining whether the TCP sequence number check function passes the test according to the processing result includes:

[0029] If the TCP packets discarded by the DUT are the preset target TCP packets and the number of packet losses is the preset number, it is determined that the TCP sequence number check function passes the test;

[0030] If the TCP packet discarded by the device under test is not the target TCP packet, or the number of lost packets is not the preset number, it is determined that the TCP sequence number check function fails the test.

[0031] In the above implementation process, by comparing the monitored processing result with the expected result, it is determined that the TCP sequence number check function passes the test when the processing result is consistent with the expected result, otherwise the test fails, thus completing the test process of the test platform for the TCP sequence number check function.

[0032] Further, the method further includes:

[0033] Obtain and store the TCP packet;

[0034] In the case that the TCP sequence number check function fails the test, analyze the test result by using the stored TCP packet.

[0035] In the above implementation process, by storing the TCP packets exchanged between multiple communication modules, it can provide specific detailed data support for the analysis and location of the later test results.

[0036] The second aspect of the embodiments of the present application provides a test device for the TCP sequence number check function, which is applied to a test platform. The platform includes multiple communication modules, and the platform is communicatively connected to the device under test with a TCP sequence number check function; the device includes:

[0037] A control module, configured to create a test task according to the selection result of the test case;

[0038] The control module is further configured to control multiple communication modules to perform TCP packet interaction through the device under test according to the test task; wherein, at least part of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet;

[0039] A monitoring module, configured to monitor the processing result of the TCP packet when the device under test performs the TCP sequence number check, and determine whether the TCP sequence number check function passes the test according to the processing result.

[0040] The third aspect of the embodiments of the present application provides a test platform, and the platform includes:

[0041] A processor;

[0042] A memory for storing instructions executable by the processor;

[0043] Wherein, when the processor calls the executable instructions, it implements the operations of any method in the first aspect.

[0044] In a fourth aspect of the embodiments of the present application, there is provided a computer-readable storage medium, on which computer instructions are stored, and when the computer instructions are executed by a processor, the steps of any of the methods in the first aspect are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can also be obtained based on these drawings without creative efforts.

[0046] Figure 1 An application scenario of the present application provided by the embodiments of the present application;

[0047] Figure 2 A flowchart of a test method for a TCP sequence number check function provided by the embodiments of the present application;

[0048] Figure 3 A flowchart of another test method for a TCP sequence number check function provided by the embodiments of the present application;

[0049] Figure 4 A flowchart of another test method for a TCP sequence number check function provided by the embodiments of the present application;

[0050] Figure 5 A flowchart of another test method for a TCP sequence number check function provided by the embodiments of the present application;

[0051] Figure 6 A flowchart of another test method for a TCP sequence number check function provided by the embodiments of the present application;

[0052] Figure 7 A flowchart of another test method for a TCP sequence number check function provided by the embodiments of the present application;

[0053] Figure 8 Another application scenario of the present application provided by the embodiments of the present application;

[0054] Figure 9 A block diagram of the structure of a test device for a TCP sequence number check function provided by the embodiments of the present application;

[0055] Figure 10 A hardware structure diagram of a test platform provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application.

[0057] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0058] The TCP protocol ensures the orderliness of TCP packets through the sequence numbers in the packet headers. The TCP sequence number check function can check the TCP online data stream to ensure the legality of each packet in the transmitted TCP data stream in the sequence. For example, for network devices on the TCP packet transmission link, the TCP sequence number check function can be deployed on the network devices. This function is applicable to scenarios with poor network environments where packet loss and out-of-order are likely to occur, as well as scenarios with TCP protocol stack attacks.

[0059] In the related art, it is necessary to conduct inspection and testing on the TCP sequence number check function. In particular, it is necessary to test whether the TCP sequence number check function can identify and process various out-of-order situations. If the inspection and testing fail, it indicates that the TCP sequence number check function may not be able to effectively identify or process out-of-order TCP packets. In the related art, for example, TCP packets exchanged between applications can be captured, modified and edited to make them out-of-order, and then the out-of-order TCP packets can be replayed into the transmission link to test whether the TCP sequence number check function deployed on the network device can correctly process the TCP packets. However, this testing method is difficult to comprehensively cover all out-of-order situations. For example, it is difficult to comprehensively cover the comprehensive relationship among TCP sequence numbers, payload data sizes, and window positions, resulting in insufficient testing comprehensiveness. In addition, this method has certain selectivity for the captured TCP packets, and the entire testing process requires capture, modification, and replay, resulting in low testing efficiency.

[0060] For another example, the test traffic suite of a test instrument can also be used to test the TCP sequence number check function. However, this testing method is not a test suite specifically developed for the TCP sequence number check function, and it also has problems of testing comprehensiveness and the cost of the test instrument.

[0061] It can be seen that the testing scheme for the TCP sequence number check function in the related art is not perfect and has great limitations. Therefore, the present application aims to provide a relatively perfect scheme for testing the TCP sequence number check function to solve the technical problem of limitations in the testing methods in the related art.

[0062] The first aspect of the present application provides a test method for TCP sequence number checking function, which is applied to a test platform, such as an automated test platform. As Figure 1 shown, the test platform 110 includes multiple communication modules, for example, including at least two communication modules. As Figure 1 shown, two communication modules are taken as examples. Of course, the number of communication modules is more than two, Figure 1 and the shown examples shall not limit the number of communication modules. For ease of description, Figure 1 the shown test platform 110 includes a first communication module 111 and a second communication module 112. Of course, "first" and "second" are only names used to distinguish the two communication modules and shall not limit their functions. The first communication module 111 and the second communication module 112 have no differences in other aspects such as the functions they implement. The communication modules are software-based communication modules in the test platform 110 and are used for data generation, sending, and receiving.

[0063] Continuing to refer to Figure 1 , the test platform 110 is communicatively connected to a device under test (DUT) 120. Among them, the DUT 120 is communicatively connected to the first communication module 111 and the second communication module 112 respectively. The communication connection method can be a wired connection or a wireless connection. The specific methods of wired connection and wireless connection can refer to the related technologies, and the present application will not expand on this here.

[0064] The DUT 120 is provided with a TCP sequence number checking function, so the TCP packets in the TCP sessions flowing through the DUT 120 can be checked for TCP sequence numbers by the DUT 120.

[0065] Exemplarily, the DUT 120 can be a gateway device provided with a TCP sequence number checking function, such as a network device like a firewall.

[0066] In addition to including multiple communication modules, the test platform 110 may also include other necessary functional modules. The other functional modules included in the test platform 110 will be described below and will not be expanded here first.

[0067] A test method for TCP sequence number checking function provided by the present application includes the steps as Figure 2 shown:

[0068] Step S1: Create a test task according to the selection result of the test case;

[0069] Step S2: According to the test task, control multiple communication modules to perform TCP packet interaction through the DUT.

[0070] Among them, at least part of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet;

[0071] Step S3: Monitor the processing result of the TCP packet by the device under test when performing the TCP sequence number check, and determine whether the TCP sequence number check function passes the test according to the processing result.

[0072] The test cases are selectable. After the user selects the required test cases in the test case library, the test platform creates a test task according to the selection result of the test cases. Subsequently, the test platform can execute the test script corresponding to the test case to start the test of the TCP sequence number check function.

[0073] During the test, multiple communication modules simulate the interaction process of TCP packets through the device under test. The communication module is used to generate TCP packets according to the control instruction and send the TCP packet to another communication module. During the transmission of the TCP packet, it will pass through the device under test and then reach another communication module. Therefore, the device under test is a network intermediate device during the TCP packet transmission process. As shown in Figure 1 In the example shown, the TCP packet sent by the first communication module 111 passes through the device under test 120. Conversely, the TCP packet sent by the second communication module 112 also passes through the device under test 120. Exemplarily, every two communication modules among the multiple communication modules perform TCP packet interaction.

[0074] The header of the TCP packet includes a sequence number and an expected sequence number. The sequence number in the header is used to represent the starting sequence number of the payload data. The expected sequence number is also called the acknowledgment number, which is used to represent the sequence number of the next packet segment expected by the receiver.

[0075] In an ideal situation, the sequence number of the TCP packet sent by the sender to the receiver is the same as the expected sequence number in the TCP packet sent by the receiver received by the sender previously. For example, device A sends a first TCP packet to device B at the first moment, and the expected sequence number in the first TCP packet is Y. Then, in the second TCP packet sent by device B to device A at the second moment, the sequence number is also Y. However, in a real scenario, the sequence number of the TCP packet is not necessarily the same as the expected sequence number of the receiver, resulting in out-of-order packets.

[0076] The TCP packets exchanged between multiple communication modules can be one or more, and at least part of the TCP packets are generated according to the data characteristics indicated by the test case. For example, at least part of the TCP packets are generated by the communication module according to the data characteristics indicated by the test case.

[0077] If there is one TCP packet exchanged between multiple communication modules, then this TCP packet is generated according to the data characteristics indicated by the test case.

[0078] If there are multiple TCP packets exchanged between multiple communication modules, then some or all of the TCP packets are generated according to the data characteristics indicated by the test case. For example, in Figure 1 the example shown, during the communication between the first communication module 111 and the second communication module 112, there are some TCP packets that are generated according to the data characteristics indicated by the test case, and the other packets are not generated according to the data characteristics indicated by the test case. Or, all the TCP packets in the communication between the first communication module 111 and the second communication module 112 are generated according to the data characteristics indicated by the test case.

[0079] The test case is used to indicate the data characteristics of the TCP packet, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet. That is, the test case is used to indicate the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet. And the sequence number and the expected sequence number of the TCP packet both comply with the requirements of the TCP protocol.

[0080] It should be noted that, as described above, the TCP packet header includes a sequence number and an expected sequence number. However, the expected sequence number in the above "relationship between the starting sequence number and the expected sequence number" is not the expected sequence number of this TCP packet. Or rather, the starting sequence number and the expected sequence number in the above relationship do not refer to the starting sequence number and the expected sequence number in the same TCP packet. The starting sequence number in the "relationship between the starting sequence number and the expected sequence number" refers to the sequence number in the header of the current TCP packet, which is the starting sequence number of the payload data of the current TCP packet. The expected sequence number in the "relationship between the starting sequence number and the expected sequence number" refers to the sequence number of the TCP packet that the communication module receiving the current TCP packet expects to receive.

[0081] For example, in the above example, the expected sequence number of the first TCP packet sent by device A at the first moment is Y, which means that device A expects to receive the next TCP packet with the sequence number Y. For the second TCP packet sent by device B to device A at the second moment, the "relationship between the starting sequence number and the expected sequence number" refers to the relationship between the starting sequence number of the payload data in the second TCP packet (i.e., the sequence number in the header of the second TCP packet) and the expected sequence number of the first TCP packet.

[0082] Since the test case is used to indicate the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet, TCP packets with this relationship can be generated according to the test case. Exemplarily, at least one communication module can generate and send TCP packets with this relationship according to the data characteristics indicated by the test case.

[0083] TCP packets will pass through the device under test during transmission. As mentioned above, the device under test is equipped with a TCP sequence number checking function. Therefore, when TCP packets exchanged between multiple communication modules pass through the device under test, the device under test will perform TCP sequence number checking on them. The test platform monitors this TCP sequence number checking process and determines whether the TCP sequence number checking function passes the test based on the processing results of the device under test on the TCP packets.

[0084] Thus, in a test method for the TCP sequence number checking function provided in this application, the test platform is used to test the TCP sequence number checking function of the device under test. Since test cases can indicate the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet, as long as test cases corresponding to different relationships between the starting sequence number and the expected sequence number are designed, TCP packets with different relationships between the starting sequence number and the expected sequence number can be generated through the test cases, so as to cover various out-of-order situations. Subsequently, when such TCP packets pass through the device under test, the device under test will perform TCP sequence number checking on the TCP packets, and at the same time, the test platform monitors the TCP sequence number checking process, so that the TCP sequence number checking function can be tested. It can be seen that this application makes the test method cover various out-of-order situations by designing test cases, and various test scenarios exist in the form of automated scripts, comprehensively covering various test scenarios of TCP sequence number testing. Thus, it can be tested whether the TCP sequence number checking function can correctly identify and process various out-of-order situations, ensuring the comprehensiveness of the test. At the same time, the selectivity of the test cases also improves the flexibility of the test. The test scheme for the TCP sequence number checking function is improved.

[0085] Regarding the above "relationship between the starting sequence number and the expected sequence number", in some embodiments, the above relationship may include any one of the following 6 relationships: the starting sequence number is before the expected sequence number and the payload data does not have sequence number wrapping, the starting sequence number is before the expected sequence number and the payload data covers sequence number wrapping, the starting sequence number is equal to the expected sequence number and the payload data does not have sequence number wrapping, the starting sequence number is equal to the expected sequence number and the payload data covers sequence number wrapping, the starting sequence number is after the expected sequence number and the payload data does not have sequence number wrapping, the starting sequence number is after the expected sequence number and the payload data covers sequence number wrapping.

[0086] The starting sequence number is before the expected sequence number, that is, the TCP packet includes data that the receiving party has already acknowledged receiving. The starting sequence number is equal to the expected sequence number, that is, the payload data in the TCP packet is the next part of the data immediately following the acknowledged received data, which is the data that the receiving party expects to receive. The starting sequence number is after the expected sequence number, that is, the payload data in the TCP packet is not immediately following the acknowledged received data, and there is still data that the receiving party has not received between the payload data and the acknowledged received data.

[0087] In addition, generally, there is a maximum value for the sequence number of TCP packets. When the sequence number reaches the maximum value, it will be reset to 0. Such a phenomenon is called sequence number wrapping. When sequence number wrapping occurs in the payload data, a certain bit of data in the payload data wraps around to 0, that is, the payload data covers the sequence number wrapping.

[0088] In this embodiment, the above six relationships between the starting sequence number and the expected sequence number cover all possible relationships between the starting sequence number and the expected sequence number. By designing test cases corresponding to each relationship, multiple TCP packets covering all relationships between the starting sequence number and the expected sequence number can be generated according to the test cases. Various test scenarios exist in the form of automated scripts, comprehensively covering various test scenarios of TCP sequence number testing. Thus, the recognition and processing of TCP packets corresponding to different relationships by the TCP sequence number check function can be tested, achieving the comprehensiveness of the test.

[0089] Based on this, in some embodiments, the process of TCP sequence number check executed in the device under test includes: determining whether to allow or discard the TCP packet according to the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet and a preset first rule.

[0090] Optionally, the first rule includes the relationship between the starting sequence number and the expected sequence number that meets the allow - release conditions. In this way, when the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet matches the first rule, it is determined to allow the TCP packet to pass, otherwise the TCP packet is discarded.

[0091] Optionally, the first rule includes the relationship between the starting sequence number and the expected sequence number that meets the discard conditions. In this way, when the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet matches the first rule, it is determined to discard the TCP packet, otherwise the TCP packet is allowed to pass.

[0092] Exemplarily, the first rule may vary in different devices under test, and the present application does not limit this.

[0093] In this embodiment, according to the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet and a preset first rule, it is determined whether to allow or discard the TCP packet. The test platform monitors the entire process of TCP sequence number check, thus realizing the verification test of the TCP sequence number check function.

[0094] As described above, test cases are used to indicate the data characteristics of TCP packets. In some embodiments, the data characteristics include, in addition to the "relationship between the starting sequence number and the expected sequence number" described above, the relationship between the payload data in the TCP packet and the receiving window. That is, the test case is used to indicate the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet, and the relationship between the payload data and the receiving window. Or rather, the test case is used to indicate the relative relationship among the sequence number, the payload data, and the receiving window in the TCP packet. When performing the TCP sequence number check function, considering the relationship between the payload data and the receiving window together can improve the accuracy of TCP packet processing.

[0095] The relationship between the payload data and the receiving window in the TCP packet includes any one of the following: the payload data is completely outside the receiving window, the payload data is partially outside the receiving window, and the payload data is completely inside the receiving window.

[0096] Among them, the payload data is partially outside the receiving window, that is, part of the payload data is outside the receiving window and the other part is inside the receiving window.

[0097] The test case is used to indicate the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet, and the relationship between the payload data and the receiving window, that is, the relative relationship among the sequence number, the payload data, and the receiving window in the TCP packet. Combining with the above embodiments, the relative relationship among the sequence number, the payload data, and the receiving window in the TCP packet includes any one of the 14 relationships shown in Table 1.

[0098] Table 1

[0099]

[0100] For each of the above 14 relationships, corresponding test cases can be designed to form a test case set. Among them, multiple test cases can be grouped according to the relationship between the starting sequence number and the expected sequence number, and / or whether sequence number wrapping occurs. In this way, a TCP packet with this relationship can be generated according to a certain test case, or multiple TCP packets can be generated according to a certain test case group.

[0101] In this embodiment, the above 14 relationships cover all possible relative relationships among the sequence number, the payload data, and the receiving window in the TCP packet. By designing test cases corresponding to each relationship, multiple TCP packets covering all relative relationships among the sequence number, the payload data, and the receiving window can be generated according to the test cases. Various test scenarios exist in the form of automated scripts, comprehensively covering various test scenarios of TCP sequence number testing, so that the TCP sequence number check function can be tested for the recognition and processing of TCP packets corresponding to different relationships, realizing the comprehensiveness of the test.

[0102] Based on this, in some embodiments, the process of TCP sequence number check performed in the device under test includes: determining whether to forward or discard a TCP packet according to the relationship between the starting sequence number of the payload data in the TCP packet and the expected sequence number, the relationship between the payload data and the receive window, and a preset second rule.

[0103] Optionally, the second rule includes the relationship between the starting sequence number and the expected sequence number that meets the forwarding conditions and the relationship between the payload data and the receive window. In this way, when the relationship between the starting sequence number of the payload data in the TCP packet and the expected sequence number, and the relationship between the payload data and the receive window match the second rule, it is determined to forward the TCP packet; otherwise, the TCP packet is discarded.

[0104] Optionally, the second rule includes the relationship between the starting sequence number and the expected sequence number that meets the discarding conditions and the relationship between the payload data and the receive window. In this way, when the relationship between the starting sequence number of the payload data in the TCP packet and the expected sequence number, and the relationship between the payload data and the receive window match the second rule, it is determined to discard the TCP packet; otherwise, the TCP packet is forwarded.

[0105] Similarly, the second rule may vary in different devices under test, and the present application does not limit this.

[0106] In this embodiment, determining whether to forward or discard a TCP packet according to the relationship between the starting sequence number of the payload data in the TCP packet and the expected sequence number, the relationship between the payload data and the receive window, and a preset second rule, the test platform monitors the entire process of TCP sequence number check, thereby realizing the verification test of the TCP sequence number check function.

[0107] Regarding the creation process of the test task, in some embodiments, the above step S1 includes the steps as Figure 3 shown:

[0108] Step S11: Select at least some test cases from the test case library according to the test requirements;

[0109] Step S12: Create a test task including the selected test cases.

[0110] As described above, corresponding test cases can be designed for each relationship. All test cases can form a test case set and be stored in the test case library. When creating a test task, test cases can be selected from the test case library according to the test requirements.

[0111] As an example, in order to meet the test requirements of comprehensive testing, all test cases can be selected from the use case library, and a test task including all test cases can be generated.

[0112] As an example, in some scenarios, only some sub-functions in the TCP sequence number checking function may be modified, and after the modification, it may only affect the recognition and processing of certain out-of-order situations by the TCP sequence number checking function. To meet the high-efficiency test requirements, relevant test cases can be selected from the test case library, and a test task including the selected test cases can be created.

[0113] In this embodiment, all or part of the test cases can be tested according to the test requirements, which not only meets the comprehensiveness of the test but also improves the flexibility of the test.

[0114] Regarding the interaction process of TCP packets, in some embodiments, the test platform further includes a control module. The control module and the communication module form a TCP communication end, and jointly initiate a TCP connection request to establish a TCP connection. Among them, the communication module is used to generate and send TCP packets according to the instructions sent by the control module. Thus, the above step S2 includes as Figure 4 The above steps:

[0115] Step S21: The control module and the communication module, as a TCP communication end, initiate a TCP connection request to another TCP communication end to establish a TCP connection;

[0116] Step S22: Control multiple said communication modules to perform said TCP packet interaction based on said TCP connection;

[0117] Step S23: After completing the interaction, end the TCP connection.

[0118] The transmission of TCP packets is based on a TCP connection. Therefore, before transmitting TCP packets with data characteristics, first, the control module and the communication module form a TCP communication end to establish a TCP connection with another TCP communication end. And end the established TCP connection after completing the interaction of TCP packets. Among them, the establishment process of the TCP connection refers to the three-way handshake of TCP in the related art; the termination process of the TCP connection refers to the four-way wave of TCP in the related art, which will not be elaborated in this application.

[0119] Among them, as described above, the device under test is a gateway device with a TCP sequence number checking function, such as a network device such as a firewall. In a real network environment, multiple TCP connections are maintained in the device under test. Therefore, before monitoring the device under test, first, the established TCP connections, that is, the TCP connections to be monitored, need to be queried on the device under test.

[0120] Exemplarily, according to the five-tuple features in the TCP packets created by the communication module, including the source IP (Internet Protocol) address, destination IP address, source port, destination port, and TCP protocol, the TCP connections to be monitored can be queried on the device under test.

[0121] Optionally, after querying the TCP connections to be monitored, check whether the TCP connections to be monitored have an identifier that matches the TCP sequence number checking function. This identifier is used to indicate that the TCP connection has entered the TCP sequence number checking function.

[0122] In this embodiment, through the establishment of TCP connections, the interaction of TCP packets, and the end of TCP connections, a complete TCP communication process is carried out. Therefore, the device under test can more comprehensively perform TCP sequence number checking on the entire TCP communication process, and the test platform can also completely test the identification and processing of various out-of-order situations by the TCP sequence number checking function at different stages of the TCP communication process.

[0123] In some embodiments, the processing of TCP packets by the device under test includes allowing or discarding. Thus, monitoring the processing result of the TCP packets by the device under test in step S3 above may include: monitoring the TCP packets discarded by the device under test and counting the number of lost packets.

[0124] It can be understood that the requirements for the TCP sequence number checking function involve two aspects. One is that the TCP sequence number checking function can correctly identify the target TCP packets to be discarded, and will not identify the target TCP packets as TCP packets that can be allowed to pass, or identify the TCP packets that can be allowed to pass as the target TCP packets to be discarded. The other is that it can correctly discard the target TCP packets, rather than allowing them to pass after identifying the target TCP packets to be discarded.

[0125] Based on the above two aspects of requirements, by monitoring the TCP packets discarded by the device under test, it can be determined whether the TCP sequence number checking function can correctly identify the target TCP packets to be discarded. By counting the number of lost packets, it can be determined whether the TCP sequence number checking function can correctly discard the target TCP packets.

[0126] It can be seen that in this embodiment, by monitoring the TCP packets discarded by the device under test and counting the number of lost packets, it is possible to comprehensively test whether the TCP sequence number checking function passes the test.

[0127] Furthermore, in some embodiments, monitoring the TCP packets discarded by the device under test and counting the number of lost packets may include the steps as Figure 5 shown:

[0128] Step S30: Determine the target TCP packet to be discarded;

[0129] Step S31: Monitor the change in the number of lost packets before and after the transmission of the target TCP packet;

[0130] Step S32: Determine whether the target TCP packet to be discarded is discarded according to the change;

[0131] Optionally, the communication module generates a TCP packet according to an instruction of the control module. In this way, the control module itself knows whether the TCP packet generated by the communication module is the target TCP packet to be discarded.

[0132] Optionally, the target TCP packet to be discarded in the TCP packet carries a flag. This flag is used to indicate that the TCP carrying this flag is the target TCP packet to be discarded. In this way, the target TCP packet to be discarded can be determined according to whether the TCP packet carries a flag.

[0133] If it is determined that the TCP packet to be sent is the target TCP packet, obtain the number of lost packets T of the DUT before the transmission of the target TCP packet 1 , and obtain the number of lost packets T of the DUT after the target TCP packet is sent to the receiver 2 . By comparing T 1 with T 2 , the change in the number of lost packets can be known. As an example, if T 1 = T 2 , it indicates that the DUT does not discard the target TCP packet. If T 1 < T 2 , it indicates that the target TCP packet has been discarded by the DUT. Thus, by monitoring the change in the number of lost packets before and after the transmission of the target TCP packet to be discarded, it can be monitored whether the DUT correctly identifies and discards the target TCP packet.

[0134] Optionally, if the TCP packet to be sent is not the target TCP packet, the change in the number of lost packets before and after the transmission of this TCP packet can also be monitored, and it is determined whether the TCP sequence number check function allows this TCP packet to pass according to the change. If the number of lost packets remains unchanged before and after the transmission of the TCP packet, it indicates that the DUT allows this TCP packet to pass, which is in line with the expected situation. If the number of lost packets increases, it indicates that the DUT wrongly discards this TCP packet, which does not conform to the expected situation.

[0135] It can be seen that in this embodiment, before sending a TCP packet, it is determined whether the TCP packet is a target TCP packet to be discarded. Thus, by monitoring the change in the number of lost packets of the target TCP packet before and after sending, it can be known whether the device under test can correctly identify the target TCP packet and whether it can discard the target TCP packet. That is, only by monitoring the change in the number of lost packets, the monitoring of the identification and discarding processes can be completed.

[0136] Based on this, in some embodiments, in step S3, determining whether the TCP sequence number check function passes the test according to the processing result includes the steps as Figure 6 shown:

[0137] Step S33: If the TCP packet discarded by the device under test is a preset target TCP packet and the number of lost packets is a preset number, determine that the TCP sequence number check function passes the test;

[0138] Step S34: If the TCP packet discarded by the device under test is not the target TCP packet, or the number of lost packets is not the preset number, determine that the TCP sequence number check function fails the test.

[0139] During the monitoring of the device under test by the test platform, the TCP packets discarded by the device under test are monitored and the number of lost packets is counted. When the TCP packets discarded by the device under test are preset target TCP packets and the number of lost packets is the preset number, it is determined that the TCP sequence number check function passes the test. That is, when the TCP sequence number check function can correctly identify all TCP packets to be discarded and discard all target TCP packets, it can be considered that the TCP sequence number check function can correctly identify all out-of-order situations and perform correct processing. Therefore, it is determined that the TCP sequence number check function test passes.

[0140] If the TCP packets discarded by the device under test are not preset target TCP packets, for example, TCP packets that do not need to be discarded, or the number of lost packets is not the preset number, for example, the number of lost packets is greater than or less than the preset number, it indicates that the device under test fails to correctly identify and process the target TCP packets to be discarded. Therefore, it is determined that the TCP sequence number check function test fails.

[0141] It should be noted that the judgment on whether the TCP sequence number check function passes the test can be carried out at any time during the monitoring process, without waiting until the monitoring ends. For example, in the above embodiment, by monitoring the change in the number of lost packets before and after sending the target TCP packet to be discarded, it is possible to determine whether the target TCP packet is discarded according to the change. In this way, whenever a target TCP packet is sent, if it is detected that the change in the number of lost packets does not match the expected situation, for example, the number of lost packets does not increase, it can be directly determined that the TCP sequence number check function test fails because the number of lost packets is not the preset number.

[0142] For another example, if it is detected that the number of lost packets of a non-target TCP packet changes before and after sending, for example, the number of lost packets increases, it can be directly determined that the TCP sequence number check function test fails because the TCP packet discarded by the device under test is not the target TCP packet, or the number of lost packets is not the preset number.

[0143] It can be seen that in this embodiment, by comparing the monitored processing result with the expected result, it is determined that the TCP sequence number check function test passes when the processing result matches the expected result, otherwise the test fails, thus completing the test process of the test platform for the TCP sequence number check function.

[0144] In some embodiments, a test method for the TCP sequence number check function provided by the present application further includes steps as Figure 7 shown:

[0145] Step S41: Obtain and store the TCP packet;

[0146] Step S42: When the TCP sequence number check function fails the test, use the stored TCP packet for test result analysis.

[0147] The TCP packet can be generated by a communication module. In order to retain the communication data between multiple communication modules, the TCP packet can be obtained and stored. For example, the TCP packets received and sent by the communication module can be stored in real time. When the TCP sequence number check function test fails, use the stored TCP packet for test result analysis.

[0148] In this way, in this embodiment, by storing the TCP packets exchanged between multiple communication modules, specific detailed data support can be provided for the analysis and positioning of the later test results.

[0149] In some embodiments, the above steps can be executed by different functional modules in the test platform. Such as Figure 8As shown in the figure, the test platform 110 includes a first communication module 111, a second communication module 112, a selection module 113, a control module 114, a first monitoring sub-module 115, and a second monitoring sub-module 116.

[0150] Among them, the selection module 113 is used to determine test cases, for example, to execute step S11 as shown in Figure 3 : Select at least some test cases from the test case library according to the test requirements.

[0151] The control module 114 is used to create a test task according to the selection result of the test case.

[0152] In addition, after creating the test task, the control module 114 is also used to issue the test task and execute the test script, and to uniformly schedule the sending order of TCP packets exchanged between multiple communication modules by sending instructions to the communication module.

[0153] The first communication module 111 and the second communication module 112 are used to establish a TCP connection according to the instructions of the control module 114, generate and send TCP packets indicated by each test case, and end the TCP connection.

[0154] The device under test 120 is used to initialize the packet loss statistics data in the TCP sequence number check function, enable the TCP sequence number check function, and perform TCP sequence number checks on the TCP packets flowing through according to the instructions of the control module 114.

[0155] The first monitoring sub-module 115 is used during the script execution. First, according to the five-tuple characteristics in the TCP packets created by the communication module, query the TCP connections to be monitored on the device under test, and check whether the TCP connections to be monitored have identifiers matching the TCP sequence number check function. Subsequently, continuously track whether the packet loss situation of the TCP connection to be monitored meets the expectations, and determine whether the TCP sequence number check function passes the test. For example, the first monitoring sub-module 115 can be used to execute steps S30 - S32 as shown in Figure 5 , and steps S33 - S34 as shown in Figure 6 .

[0156] The second monitoring sub-module 116 is used to save all the sent and received packets on the test interface of the communication module during the test, and store them as the detailed data of the operation result of this test, providing the sending and receiving details of the TCP packets for subsequent result analysis for verification. For example, the second monitoring sub-module 116 can execute steps S41 - S42 as shown in Figure 7 .

[0157] After the test work is completed, the device under test 120 turns off the TCP sequence number check function, the test platform 110 clears the statistical results of the number of lost packets, and the second monitoring sub-module 116 stops obtaining TCP packets and stores the obtained data in a file in the test result folder.

[0158] The following takes a specific test task process as an example for detailed description.

[0159] The selection module 113 selects two groups of test case groups. The first group of test case groups is "the starting sequence number of the payload data is before the expected sequence number and the payload data does not have a sequence number wrap-around". Referring to Table 1, it can be seen that there are 3 test cases in the first group of test cases. The second group of test case groups is "the starting sequence number of the payload data is equal to the expected sequence number and the payload data does not have a sequence number wrap-around". Referring to Table 1, it can be seen that there are 2 test cases in the second group of test cases. This test task includes a total of 5 test cases.

[0160] The control module 114 generates a test task and executes a test script according to the test cases selected by the selection module 113.

[0161] The device under test 120 initializes the lost packet statistics data in the TCP sequence number check and turns on the TCP sequence number check function according to the instruction of the control module 114. And the first communication module 111 and the second communication module 112 send and receive interactive TCP packets according to the instruction of the control module 114.

[0162] Synchronously, the second monitoring sub-module 116 turns on the packet capture function on the first communication module 111 and the second communication module 112, and stores the packets passing through the test port in real time.

[0163] The first monitoring sub-module 115 obtains the information of the TCP connection to be monitored established by the first communication module 111 and the second communication module 112 on the device under test 120, and checks whether its TCP status, five-tuple, and the identifier of the TCP sequence number check are correct.

[0164] Among them, the TCP interaction process between the first communication module 111 and the second communication module 112, and the working conditions of related modules are as follows.

[0165] A. The first communication module 111 and the second communication module 112 perform handshake packet interaction to establish a TCP connection.

[0166] B. Data transfer phase.

[0167] B1. The first communication module 111 sends the first TCP packet to the second communication module 112. Among them, the sequence number of the first TCP packet is before the sequence number expected by the second communication module 112, and the entire payload data is before the expected sequence number (that is, the entire payload data is before the receive window). According to the processing rules of the device under test, the first TCP packet is intercepted and discarded by the device under test 120. The first monitoring sub-module 115 finds that the number of lost packets increases by 1, which meets the expectation.

[0168] B2. The first communication module 111 sends the second TCP packet to the second communication module 112. Among them, the sequence number of the second TCP packet is before the sequence number expected by the second communication module 112, and part of the payload data is after the expected sequence number and within the receive window. According to the processing rules of the device under test, the second TCP packet is inspected and released by the device under test. Subsequently, the second communication module 112 responds with the corresponding ACK packet to the first communication module 111. The first monitoring sub-module 115 finds that the number of lost packets does not increase, which meets the expectation. The first communication module 111 moves the sequence number of the payload to be sent to the ACK position responded in the ACK packet.

[0169] B3. The first communication module 111 sends the third TCP packet to the second communication module 112. Among them, the sequence number of the third TCP packet is before the sequence number expected by the second communication module 112, and part of the payload data is after the expected sequence number and exceeds the receive window range. According to the processing rules of the device under test, the third TCP packet will be intercepted and discarded by the device under test 120. The first monitoring sub-module 115 finds that the number of lost packets increases by 1, which meets the expectation.

[0170] B4. The first communication module 111 sends the fourth TCP packet to the second communication module 112. Among them, the sequence number of the fourth TCP packet is equal to the expected sequence number, and the payload data is within the receive window. According to the processing rules of the device under test, the fourth TCP packet will be inspected and released by the device under test 120. Subsequently, the second communication module 112 responds with the corresponding ACK packet to the first communication module 111. The first monitoring sub-module 115 finds that the number of lost packets does not increase, which meets the expectation. The first communication module 111 moves the sequence number of the payload to be sent to the ACK position responded in the ACK packet.

[0171] B5. The first communication module 111 sends the fifth TCP packet to the second communication module 112. Among them, the sequence number of the fifth TCP packet is equal to the expected sequence number, and the payload data exceeds the receive window range. According to the processing rules of the device under test, the fifth TCP packet will be intercepted and discarded by the device under test 120. The first monitoring sub-module 115 finds that the number of lost packets increases by 1, which meets the expectation.

[0172] C. The first communication module 111 ends the TCP connection with the second communication module 112.

[0173] After the first communication module 111 and the second communication module 112 finish working, the second monitoring sub-module 116 stops working and stores the captured data in the test result folder in the form of a file. The device under test 120 turns off the TCP sequence number check function, and the test platform 110 clears the statistical result of the number of lost packets.

[0174] Any unexpected processing result that occurs during the monitoring process by the first monitoring sub-module 115 will be used as the basis for determining that the test fails. If all are as expected, it is determined that the test passes. When the test fails and cause localization is required, the detailed packet data retained by the second monitoring sub-module 116 can be viewed to assist in judgment and analysis.

[0175] Based on the test method for the TCP sequence number check function provided in any of the above embodiments, a second aspect of the present application further provides a test device for the TCP sequence number check function, which is applied to a test platform. The platform includes multiple communication modules, and the platform is communicatively connected to a device under test provided with a TCP sequence number check function. As Figure 9 described above, the test device 900 includes:

[0176] A control module 910, configured to create a test task according to the selection result of the test case;

[0177] The control module 910 is further configured to control the multiple communication modules to perform TCP packet interaction through the device under test according to the test task; wherein, at least part of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet;

[0178] A monitoring module 920, configured to monitor the processing result of the TCP packets by the device under test when performing the TCP sequence number check, and determine whether the TCP sequence number check function passes the test according to the processing result.

[0179] In some embodiments, the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet includes any one of the following:

[0180] The starting sequence number is before the expected sequence number, and the payload data covers sequence number wrapping or no sequence number wrapping occurs;

[0181] The starting sequence number is equal to the expected sequence number, and the payload data covers sequence number wrapping or no sequence number wrapping occurs;

[0182] The starting sequence number is after the expected sequence number, and the payload data covers sequence number wrapping or there is no sequence number wrapping.

[0183] In some embodiments, the data feature further includes the relationship between the payload data and the receive window in the TCP packet; the relationship between the payload data and the receive window includes any one of the following:

[0184] The payload data is completely outside the receive window;

[0185] The payload data is partially outside the receive window;

[0186] The payload data is completely within the receive window.

[0187] In some embodiments, the test device 900 further includes:

[0188] A selection module, such as the selection module 113 shown in Figure 8 , for selecting at least some test cases from the test case library according to test requirements.

[0189] In some embodiments, the processing result includes releasing or discarding the TCP packet, and the monitoring module 920 includes:

[0190] A first monitoring sub-module, such as the first monitoring sub-module 115 shown in Figure 8 , for monitoring the TCP packets discarded by the device under test and counting the number of lost packets.

[0191] In some embodiments, the first monitoring sub-module is specifically configured to:

[0192] Determine the target TCP packet to be discarded;

[0193] Monitor the change in the number of lost packets before and after the target TCP packet is sent;

[0194] Determine whether the target TCP packet to be discarded is discarded according to the change situation.

[0195] In some embodiments, the first monitoring sub-module is specifically configured to:

[0196] If the TCP packet discarded by the device under test is a preset target TCP packet and the number of lost packets is a preset number, determine that the TCP sequence number check function passes the test;

[0197] If the TCP packet discarded by the device under test is not the target TCP packet, or the number of lost packets is not the preset number, determine that the TCP sequence number check function fails the test.

[0198] In some embodiments, the monitoring module 920 includes:

[0199] A second monitoring sub-module, for example, the second monitoring sub-module 116 as shown in Figure 8 is used to:

[0200] Obtain and store the TCP packet;

[0201] In the case where the TCP sequence number check function fails the test, use the stored TCP packet to analyze the test results.

[0202] For the implementation processes of the functions and roles of each module in the above device, refer to the implementation processes of the corresponding steps in the above method for details, which will not be elaborated here.

[0203] Based on the test method for the TCP sequence number check function described in any of the above embodiments, the third aspect of the present application further provides a schematic structural diagram of a test platform as shown in Figure 10 . As shown in Figure 10 , at the hardware level, the test platform includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include other hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the test method for the TCP sequence number check function described in any of the above embodiments.

[0204] The fourth aspect of the present application further provides a computer storage medium, which stores a computer program. When the computer program is executed by a processor, it can be used to execute the test method for the TCP sequence number check function described in any of the above embodiments.

[0205] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0206] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0207] If the above functions are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0208] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0209] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, and all of them should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0210] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A test method for TCP sequence number checking function, characterized in that, it is applied to a test platform, the platform includes a plurality of communication modules, and the platform is communicatively connected to a device under test with a TCP sequence number checking function; the method includes: creating a test task according to the selection result of the test case; controlling a plurality of the communication modules to perform TCP packet interaction through the device under test according to the test task; wherein, at least part of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet, and the relationship between the payload data in the TCP packet and the receiving window; the relationship between the starting sequence number and the expected sequence number includes any one of the following: the starting sequence number is before the expected sequence number, the payload data covers sequence number wrapping or no sequence number wrapping occurs; the starting sequence number is equal to the expected sequence number, the payload data covers sequence number wrapping or no sequence number wrapping occurs; the starting sequence number is after the expected sequence number, the payload data covers sequence number wrapping or no sequence number wrapping occurs; the relationship between the payload data and the receiving window includes any one of the following: the payload data is completely outside the receiving window; the payload data is partially outside the receiving window; the payload data is completely within the receiving window; monitoring the processing result of the TCP packet by the device under test when performing the TCP sequence number check, and determining whether the TCP sequence number checking function passes the test according to the processing result.

2. The method according to claim 1, characterized in that, the processing result includes releasing or discarding the TCP packet, and the monitoring the processing result of the TCP packet by the device under test when performing the TCP sequence number check includes: monitoring the TCP packets discarded by the device under test and counting the number of lost packets.

3. The method according to claim 2, characterized in that, the monitoring the TCP packets discarded by the device under test and counting the number of lost packets includes: determining the target TCP packet to be discarded; monitoring the change in the number of lost packets before and after the target TCP packet is sent; determining whether the target TCP packet to be discarded is discarded according to the change situation.

4. The method according to any one of claims 2-3, characterized in that, the determining whether the TCP sequence number checking function passes the test according to the processing result includes: if the TCP packets discarded by the device under test are preset target TCP packets and the number of lost packets is a preset number, determining that the TCP sequence number checking function passes the test; if the TCP packets discarded by the device under test are not the target TCP packets, or the number of lost packets is not the preset number, determining that the TCP sequence number checking function fails the test.

5. The method according to claim 1, characterized in that, the method further includes: acquiring and storing the TCP packets; in the case that the TCP sequence number checking function fails the test, using the stored TCP packets for test result analysis.

6. A test device for TCP sequence number checking function Characterized in that It is applied to a test platform, the platform includes multiple communication modules, and the platform is communicatively connected to a device under test with TCP sequence number checking function; the device includes: A control module, configured to create a test task according to the selection result of a test case; The control module is further configured to, according to the test task, control multiple communication modules to perform TCP packet interaction through the device under test; wherein, at least part of the TCP packets are generated according to the data characteristics indicated by the test case, and the data characteristics include the relationship between the starting sequence number and the expected sequence number of the payload data in the TCP packet, and the relationship between the payload data in the TCP packet and the receive window; the relationship between the starting sequence number and the expected sequence number includes any one of the following: the starting sequence number is before the expected sequence number, the payload data covers sequence number wrapping or no sequence number wrapping occurs; the starting sequence number is equal to the expected sequence number, the payload data covers sequence number wrapping or no sequence number wrapping occurs; the starting sequence number is after the expected sequence number, the payload data covers sequence number wrapping or no sequence number wrapping occurs; the relationship between the payload data and the receive window includes any one of the following: the payload data is completely outside the receive window; the payload data is partially outside the receive window; the payload data is completely inside the receive window; A monitoring module, configured to monitor the processing result of the TCP packet by the device under test when performing the TCP sequence number check, and determine whether the TCP sequence number checking function passes the test according to the processing result.

7. A test platform Characterized in that The platform includes: A processor; A memory for storing instructions executable by the processor; Wherein, when the processor calls the executable instructions, it realizes the operations of any one of claims 1-5.

8. A computer-readable storage medium Characterized in that Computer instructions are stored thereon, and when the computer instructions are executed by a processor, the steps of any one of claims 1-5 are realized.

Citation Information

Patent Citations

  • TCP sequence number examination hardware implementing method based on TCAM order pair

    CN101321162A

  • Method for measuring downlink packet loss rate of access link of broadband network user

    CN102868576A