Device testing method, apparatus, and electronic device
By establishing control and data channels and employing multi-dimensional testing methods to evaluate the stability of IPsec tunnels, the problem of inaccurate stability testing of IPsec tunnels in existing technologies is solved, achieving more reliable network device testing and security assurance.
Patent Information
- Application Number
- CN202411796246.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-06
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-12-06
AI Technical Summary
Existing technologies for testing the stability of IPsec tunnels are ineffective due to overly simplistic testing methods, leading to inaccurate results.
By establishing control and data channels, the second device was monitored for IPsec protocol security parameters, device status information, performance fluctuation information, and packet replay protection. Various simulated attack scenarios and abnormal data transmission methods were used to comprehensively evaluate the device's stability.
It improves the accuracy and comprehensiveness of IPsec tunnel stability testing, effectively detecting the equipment's handling capabilities and stability under various abnormal conditions, ensuring network security and data transmission stability.
Smart Images

Figure CN119728188B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a device testing method and device and electronic equipment. BACKGROUND
[0002] With the development of network communication technology, various security protocols have emerged. IPsec (Internet Protocol Security) is a set of protocols for securing Internet communication. IPsec protocol is designed to provide security for data packets at the network layer, including data encryption, data source authentication, data integrity, and anti-replay protection.
[0003] IPsec protocol is widely used as an important means to ensure data transmission security. However, the stability of IPsec tunnel may be affected by changes in network environment, sudden load increase, etc. The existing technology has the problem of poor IPsec tunnel stability test effect.
[0004] In view of the above problems, no effective solution has been proposed so far. SUMMARY
[0005] The embodiments of the present application provide a device testing method, device and electronic equipment to at least solve the technical problem of inaccurate IPsec tunnel stability test due to too single stability detection dimension of IPsec tunnel.
[0006] According to an aspect of an embodiment of the present application, a device testing method is provided, comprising: establishing a control channel and a data channel by a first device and a second device, wherein the first device is used to test the second device, the data channel is used to encrypt and decrypt data according to IPsec protocol, and the control channel is used to determine security parameters according to IPsec protocol; testing the control channel by the first device initiating data connection and / or sending abnormal data to the second device, and obtaining a test result of the control channel, wherein the test result of the control channel at least includes device state information and / or performance fluctuation information of the second device in the test process; testing the data channel by the first device sending a message to the second device, and obtaining a test result of the data channel, wherein the test result of the data channel at least includes test information of the message anti-replay function of the second device; and determining a test result of the second device according to the test result of the control channel and the test result of the data channel.
[0007] Optionally, the control channel is tested in a manner of initiating a data connection by the first device to the second device, and a test result of the control channel is obtained, including: controlling the first device to initiate a semi-connection request to the second device for multiple times continuously within a preset time length by using the control channel, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length, wherein the semi-connection request is used to simulate a semi-connection attack scene in a network; and / or controlling the first device to initiate a full-connection request to the second device for multiple times continuously within a preset time length by using the control channel, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length, wherein the full-connection request is used to simulate a full-connection attack scene in a network.
[0008] Optionally, the control channel is tested in a manner of sending abnormal data by the first device to the second device, and a test result of the control channel is obtained, including at least one of the following test manners:
[0009] The first test manner is used for controlling the first device to continuously send packet data that does not conform to a specification condition of the IPsec protocol to the second device within a preset time length by using the control channel, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length;
[0010] The second test manner is used for controlling the first device to continuously send packet data that conforms to the specification condition of the IPsec protocol but has abnormal data content to the second device within a preset time length by using the control channel, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length;
[0011] The third test manner is used for controlling the first device to continuously send different types of abnormal data defined by the IPsec protocol to the second device within a preset time length based on multiple control channels by using the control channel, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length.
[0012] Optionally, the data channel is tested by sending a message from the first device to the second device, and a test result of the data channel is obtained, including: determining X sequence numbers by the first device, where X is an integer greater than 1; constructing X first messages according to the X sequence numbers, where each first message carries one of the X sequence numbers, and different first messages carry different sequence numbers; encapsulating each first message into a second message to obtain X second messages, where the sequence number in the header data of each second message and the sequence number in the payload data of each second message are the sequence number carried by the first message corresponding to the second message; sending the X second messages from the first device to the second device, and receiving at least one third message generated by the second device after processing the X second messages using the message anti-replay function; and determining test information of the message anti-replay function of the second device according to the at least one third message.
[0013] Optionally, the test information of the message anti-replay function of the second device is determined according to the at least one third message, including: detecting whether the sequence number in the third message conforms to the sequence number usage rule followed by the first device; in the case where the sequence number in the third message does not conform to the sequence number usage rule followed by the first device, determining that the third message is an abnormal message; in the case where the sequence number in the third message conforms to the sequence number usage rule followed by the first device, determining that the third message is a normal message; and determining the test information of the message anti-replay function of the second device according to the number of abnormal messages and the number of normal messages in the at least one third message.
[0014] Optionally, the data channel is tested by sending a message from the first device to the second device, and a test result of the data channel is obtained, including at least one of the following test operations:
[0015] The first test operation is used to continuously send first type IPsec data messages from the first device to the second device within a preset time period by using the data channel, and monitor device state information and / or performance fluctuation information of the second device within the preset time period, where the first type IPsec data message is an IPsec data message with format error, and / or random length, and / or carrying random content.
[0016] a second test operation, for continuously sending, by the first device, a second type of IPsec data packet to the second device within a preset time length via the data channel, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length, wherein the second type of IPsec data packet is a packet generated after a key field defined according to an IPsec protocol is mutated;
[0017] a third test operation, for continuously sending, by the first device, an encapsulated abnormal IPsec data packet to the second device within a preset time length via the data channel, and monitoring whether the second device identifies abnormal information of the abnormal IPsec data packet, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length.
[0018] Optionally, the control channel is tested in a manner that the first device initiates a data connection and / or sends abnormal data to the second device, and a test result of the control channel is obtained, including: controlling the first device to establish a plurality of target connections with the second device, and counting a time length required for each target connection to be successfully established, wherein the target connection is used to simulate a normal IPsec connection scenario in a network; determining establishment time fluctuation information of the target connection according to the time length required for each target connection to be successfully established; and taking the establishment time fluctuation information of the target connection as performance fluctuation information of the second device.
[0019] Optionally, the device state information at least includes detection information about whether the second device is restarted and / or detection information about whether a service on the second device is abnormal; and the performance fluctuation information at least includes fluctuation information about a memory utilization rate of the second device and / or fluctuation information about a CPU utilization rate of the second device.
[0020] According to another aspect of the present application, there is also provided an apparatus testing device, comprising: a first processing unit configured to establish a control channel and a data channel between a first apparatus and a second apparatus, wherein the first apparatus is configured to test the second apparatus, the data channel is configured to encrypt and decrypt data according to an IPsec protocol, and the control channel is configured to determine security parameters according to the IPsec protocol; a first testing unit configured to test the control channel by initiating a data connection and / or sending abnormal data from the first apparatus to the second apparatus, and obtain a testing result of the control channel, wherein the testing result of the control channel comprises at least device state information and / or performance fluctuation information of the second apparatus during the testing; a second testing unit configured to test the data channel by sending a message from the first apparatus to the second apparatus, and obtain a testing result of the data channel, wherein the testing result of the data channel comprises at least testing information of a message anti-replay function of the second apparatus; and a determining unit configured to determine a testing result of the second apparatus according to the testing result of the control channel and the testing result of the data channel.
[0021] According to another aspect of the present application, there is also provided a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program, when executed, causes an apparatus in which the computer readable storage medium is located to perform the apparatus testing method.
[0022] According to another aspect of the present application, there is also provided an electronic apparatus, comprising one or more processors and a memory, wherein the memory is configured to store one or more programs, and the one or more programs, when executed by the one or more processors, cause the one or more processors to perform the apparatus testing method.
[0023] From the above, the application establishes a control channel and a data channel by a first device and a second device, wherein the first device is used to test the second device, the data channel is used to encrypt and decrypt data according to the IPsec protocol, and the control channel is used to determine security parameters according to the IPsec protocol. The control channel is tested by the first device initiating a data connection and / or sending abnormal data to the second device, and the test result of the control channel is obtained, wherein the test result of the control channel at least includes device state information and / or performance fluctuation information of the second device in the test process. The data channel is tested by the first device sending a message to the second device, and the test result of the data channel is obtained, wherein the test result of the data channel at least includes test information of the message anti-replay function of the second device. Finally, the test result of the second device is determined according to the test result of the control channel and the test result of the data channel.
[0024] The application tests the control function and the data processing function of the second device by establishing a control channel and a data channel, considers not only the device state information and / or performance fluctuation information, but also specially tests the message anti-replay function of the data channel, thereby evaluating the stability of the second device when using the IPsec tunnel to process the message transmission in multiple dimensions, improving the accuracy and comprehensiveness of the test. In practical application, this method can effectively detect the processing capacity and stability of the second device when facing various abnormal situations, provide a more reliable test basis for the IPsec message processing function of the network device, ensure the network security and the stability of data transmission, and further solve the technical problem that the stability test of the IPsec tunnel is inaccurate due to the single dimension of the stability detection of the IPsec tunnel. BRIEF DESCRIPTION OF DRAWINGS
[0025] The accompanying drawings, which are included to provide a further understanding of the application, constitute a part of the application and illustrate the illustrative embodiments of the application and its description, and do not constitute an improper limitation of the application. In the drawings:
[0026] Figure 1 is a flowchart of an optional device test method according to an embodiment of the application;
[0027] Figure 2 is an optional device test topology diagram according to an embodiment of the application;
[0028] Figure 3 is a whole flowchart of an optional device test process according to an embodiment of the application;
[0029] Figure 4is a schematic diagram of an optional control channel stability test according to an embodiment of the present application;
[0030] Figure 5 is a flow chart of an optional data channel stability test according to an embodiment of the present application;
[0031] Figure 6 is a flow chart of a test procedure of an optional message anti-replay function according to an embodiment of the present application;
[0032] Figure 7 is a schematic diagram of an optional first message according to an embodiment of the present application;
[0033] Figure 8 is a schematic diagram of an optional second message according to an embodiment of the present application;
[0034] Figure 9 is a schematic diagram of an optional device test apparatus according to an embodiment of the present application. DETAILED DESCRIPTION
[0035] In order to enable persons skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative work should fall within the scope of protection of the present application.
[0036] It should be noted that the terms "first", "second", and the like in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to the process, method, product or device.
[0037] It should be noted that the information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) collected by the present application are information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards in the relevant region, necessary security measures are taken, do not violate public order and good customs, and provide corresponding operation portal for user to choose authorization or refusal. For example, the system and related users or institutions are provided with an interface, and before obtaining the relevant information, the interface needs to send a request to the aforementioned user or institution, and after receiving the consent information feedback from the aforementioned user or institution, the relevant information is obtained.
[0038] According to an embodiment of the present application, an embodiment of a device testing method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from here.
[0039] Figure 1 is a flowchart of an optional device testing method according to an embodiment of the present application, as shown in Figure 1 , the method comprises the following steps:
[0040] Step S101, establishing a control channel and a data channel through the first device and the second device.
[0041] In step S101, the first device is used to test the second device, the data channel is used to encrypt and decrypt data according to the IPsec protocol, and the control channel is used to determine the security parameters according to the IPsec protocol.
[0042] Optionally, Figure 2 is an optional device testing topology diagram according to an embodiment of the present application, wherein, Figure 2 the device to be tested (also referred to as: the device under test) in is the second device described above, Figure 2 the testing device in is the first device described above. The testing device can be a virtual machine, a server executing a test task, and the device under test is a terminal device, a virtual machine or a server with IPsec communication function. The data transmission channel based on the IPsec protocol is established between the device to be tested and the testing device through the network.
[0043] Optionally, as Figure 2As shown, the test device includes a configuration module, a topology generation module, a test and collection module, and an analysis and display module. The configuration module is configured to configure environment parameters and test parameters related to the test task of the IPsec message processing function of the device. The topology generation module is configured to construct a test network topology (including but not limited to IP addresses of related network cards, routing information, etc.) according to the parameters configured by the configuration module. The test and collection module is configured to perform related tests on the tested device according to the parameters configured by the configuration module, and collect related information during the test. The analysis and display module is configured to integrate the collected test information, display the related test data through a UI interface, determine the test score by analyzing the test data, and give optimization suggestions.
[0044] In step S102, the control channel is tested by initiating a data connection and / or sending abnormal data from the first device to the second device, and a test result of the control channel is obtained.
[0045] In step S102, the test result of the control channel includes at least device state information and / or performance fluctuation information of the second device during the test.
[0046] Optionally, the control channel refers to a channel for security parameter negotiation and management under the IPsec protocol, and is used for the process of establishing and maintaining an IPsec secure connection. The control channel ensures the security of the data channel by negotiating key and security policy parameters, and is also used for monitoring and managing the state of the IPsec connection. During the test of the control channel, the first device periodically collects device state information and / or performance fluctuation information of the second device during the test, wherein the device state information at least includes detection information of whether the second device restarts and / or detection information of whether services on the second device appear abnormal; and the performance fluctuation information at least includes fluctuation information of memory utilization of the second device and / or fluctuation information of CPU utilization of the second device.
[0047] In step S103, the data channel is tested by sending a message from the first device to the second device, and a test result of the data channel is obtained.
[0048] In step S103, the test result of the data channel at least includes test information of a message anti-replay function of the second device.
[0049] Optionally, the data channel refers to a channel for transmitting data under the IPsec protocol, and is used for encrypting and decrypting data to protect the confidentiality and integrity of communication. The data channel protects the security of data by using encryption algorithms and authentication algorithms to ensure that data is not stolen or tampered with during transmission.
[0050] Optionally, the message anti-replay function is a network security mechanism for preventing an attacker from performing malicious behavior by copying and resending (replaying) previously captured valid messages (e.g., authentication messages). Such an attack is called a replay attack.
[0051] In some application scenarios, such as online authentication, electronic payment, and network communication, it is necessary to authenticate and authorize the data transmission process to ensure the security and integrity of the data. The message anti-replay function aims to prevent attackers from using these authentication and authorization information to carry out attacks.
[0052] In step S104, the test result of the second device is determined according to the test result of the control channel and the test result of the data channel.
[0053] Optionally, the first device can comprehensively determine the final test result of the second device by combining the test result of the control channel and the test result of the data channel, for example, assigning and allocating corresponding weights to each test result data of the control channel, and assigning and allocating corresponding weights to each test result data of the data channel, and finally obtaining a comprehensive test score of the second device through weighted calculation, which is used to evaluate the IPsec message processing performance of the second device.
[0054] Figure 3 is an overall flowchart of an optional device test process according to an embodiment of the present application, as shown in Figure 3 First, the test parameters are set by the first device, and then the test environment is constructed according to the test parameters. Subsequently, the stability of the IPsec control channel between the first device and the second device is tested, and the stability of the IPsec data channel between the first device and the second device is tested. During the test process, test data is collected, and finally, a test score is given to the current test of the second device according to the analysis result of the test data, and an optimization suggestion is generated.
[0055] From the above content, it can be seen that the present application tests the control function and data processing function of the tested device by establishing a control channel and a data channel, not only considers the device state information and / or performance fluctuation information, but also specially tests the message anti-replay function of the data channel, thereby evaluating the stability of the tested device when using the IPsec tunnel for message processing and transmission in multiple dimensions, improving the accuracy and comprehensiveness of the test. In practical applications, this method can effectively detect the processing capacity and stability of the tested device when facing various abnormal situations, providing a more reliable test basis for the IPsec function of network devices, ensuring network security and data transmission stability, and thereby solving the technical problem of inaccurate IPsec tunnel stability test due to too single test dimension of IPsec tunnel stability.
[0056] In an optional embodiment, the control channel is tested by initiating a data connection from the first device to the second device, and the test result of the control channel is obtained, including the following ways:
[0057] The control channel is used to control the first device to initiate a semi-connection request to the second device for multiple times within a preset time length, and the device state information and / or performance fluctuation information of the second device within the preset time length is monitored, wherein the semi-connection request is used to simulate a semi-connection attack scenario in the network; and / or the control channel is used to control the first device to initiate a full-connection request to the second device for multiple times within a preset time length using the same IP address, and the device state information and / or performance fluctuation information of the second device within the preset time length is monitored, wherein the full-connection request is used to simulate a full-connection attack scenario in the network.
[0058] Optionally, Figure 4 is a schematic diagram of an optional control channel stability test according to an embodiment of the present application, as Figure 4 shown, the control channel is tested by initiating a data connection from the first device to the second device, including but not limited to a semi-connection attack test initiated by the first device to the second device and a full-connection attack test initiated by the first device to the second device.
[0059] Optionally, the semi-connection attack test: the first device continuously initiates a semi-connection request to the second device at a configured rate to simulate a scenario in which the second device is subjected to a semi-connection attack in the network, until the test time length of the test reaches a preset time length, and the test is completed. During the test, every interval, the first device establishes a normal connection with the second device, and records the total time required for the successful establishment of the connection. At the same time, the first device also regularly collects the CPU utilization and memory utilization of the second device during the test to determine the performance fluctuation information of the second device during the semi-connection attack test.
[0060] In addition, during the semi-connection attack test, the first device also monitors the device state information of the second device, for example, whether the second device restarts or services abnormally due to the semi-connection attack, if the device restarts or services abnormally, it indicates that the second device fails to effectively defend against the semi-connection attack.
[0061] Optionally, the full-connection attack test: the first device performs multiple full-connection negotiations with the second device at a configured rate using the same IP address, until the test time length reaches a preset time length, and the test is completed. The full-connection attack test is used to simulate a full-connection attack scenario in the network.
[0062] Similarly, during the full connection attack test, the first device establishes a normal connection with the second device every interval, and records the total time required for the successful establishment of the connection. At the same time, the first device also regularly collects the CPU utilization and memory utilization of the second device during the test, to determine the performance fluctuation information of the second device during the full connection attack test. In addition, during the full connection attack test, the first device also monitors the device state information of the second device.
[0063] It should be noted that in the above manner, the response capability and stability of the tested device when facing different types of network attacks can be effectively evaluated, providing a quantitative basis for the protection capability of the network device, and being particularly suitable for IPsec function test of enterprise-level firewall and router.
[0064] In an optional embodiment, the control channel is tested by sending abnormal data from the first device to the second device, and the test result of the control channel is obtained, including at least one of the following test methods:
[0065] The first test method is used to control the first device to continuously send packet data that does not meet the specification conditions of the IPsec protocol to the second device within a preset time interval using the control channel, and monitor the device state information and / or performance fluctuation information of the second device within the preset time interval;
[0066] The second test method is used to control the first device to continuously send packet data that meets the specification conditions of the IPsec protocol but has abnormal data content to the second device within a preset time interval using the control channel, and monitor the device state information and / or performance fluctuation information of the second device within the preset time interval;
[0067] The third test method is used to control the first device to continuously send different types of abnormal data defined by the IPsec protocol to the second device within a preset time interval based on multiple control channels using the control channel, and monitor the device state information and / or performance fluctuation information of the second device within the preset time interval.
[0068] Optionally, as shown in Figure 4 The control channel is tested by sending abnormal data from the first device to the second device, including but not limited to the following test methods: the first device initiates an abnormal packet attack test on the second device, the first device initiates a protocol abnormal data attack test on the second device, and the first device initiates other types of message attack tests on the second device.
[0069] Among them, the abnormal message attack test (corresponding to the first test method described above): the first device continuously sends control protocol messages that do not meet the specification conditions of the IPsec protocol (for example, abnormal messages in the IKE negotiation process, messages with random content) to the second device at the configured rate until the test reaches the preset time length, and the test is completed. In particular, if the second device appears abnormal during the test, the test is terminated.
[0070] Optionally, during the abnormal message attack test, the first device periodically establishes a normal connection with the second device and records the connection establishment state (normal if successful within a certain time, failed if unsuccessful within a certain time). In addition, during the test, the first device also periodically collects the CPU utilization and memory utilization of the second device and collects the device state information of the second device.
[0071] Optionally, the protocol abnormal data attack test (corresponding to the second test method described above): the first device sends protocol abnormal data messages (i.e., messages that meet the specification conditions of the IPsec protocol, but the data content is abnormal) to the second device at the configured rate until the test time reaches the preset time length, and the test is completed.
[0072] Among them, the protocol abnormal data message can be a specially constructed message that meets the protocol standard, but the related content contains protocol undefined values, length exceeding expectations, field order rearrangement, format replacement (string replaced by non-string format). If the second device appears abnormal during the test, the test is terminated.
[0073] Optionally, during the protocol abnormal data attack test, the first device periodically establishes a normal connection with the second device and records the connection establishment state (normal if successful within a certain time, failed if unsuccessful within a certain time). In addition, during the test, the first device also periodically collects the CPU utilization and memory utilization of the second device and collects the device state information of the second device.
[0074] Optionally, other types of message attack test (corresponding to the third test method described above): the first device establishes multiple different IPsec channels with the second device, and the first device continuously sends different types of notification messages and / or probe messages defined by the protocol at the configured rate, and the message content can be randomly set until the test time reaches the preset time length, and the test is completed. During the test, the first device also periodically collects the CPU utilization and memory utilization of the second device and collects the device state information of the second device.
[0075] It should be noted that the above various test methods can cover various abnormal situations that the tested device may encounter when processing IPsec packets, including protocol errors, data abnormalities and multi-channel concurrent abnormalities, which helps to comprehensively evaluate the robustness and anti-interference ability of the tested device when processing IPsec packets, and is suitable for production testing and maintenance inspection of network devices.
[0076] In an optional embodiment, the data channel is tested by sending packets from the first device to the second device, and the test result of the data channel is obtained, including: determining X sequence numbers by the first device, where X is an integer greater than 1. Then, X first packets are constructed according to the X sequence numbers, where each first packet carries one of the X sequence numbers, and different first packets carry different sequence numbers. Subsequently, each first packet is encapsulated into a second packet to obtain X second packets, where the sequence number in the header data and the sequence number in the payload data of each second packet are the sequence number carried by the first packet corresponding to the second packet; X second packets are sent from the first device to the second device, and at least one third packet generated by the second device after processing X second packets using the packet anti-replay function is received. Finally, the test information of the packet anti-replay function of the second device is determined according to the at least one third packet.
[0077] Optionally, Figure 5 is a flowchart of an optional data channel stability test according to an embodiment of the present application, as Figure 5 indicated, the stability test of the data channel at least includes the test of the packet anti-replay function of the second device.
[0078] The packet anti-replay function can be used to protect the security and integrity of network communication and maintain network stability. Ensuring the normality of the packet anti-replay function plays an important role in ensuring the stability of the network device when processing IPsec packets.
[0079] The test process of the packet anti-replay function is as Figure 6 indicated:
[0080] 1、First, the first device and the second device establish an IPsec connection.
[0081] 2、Then the first device generates X sequence numbers by an algorithm (optional random generation algorithm, sequence increment algorithm, etc., which is not particularly specified in the present application).
[0082] 3、The first device selects a sequence number from the X sequence numbers in order to construct a first packet, where the constructed first packet carries sequence number information, and the packet is as Figure 7 indicated, where, Figure 7The message in the first device is composed of an ETH header, an IP header (marked as IP_1 for distinguishing), a sequence number, and random content with random length.
[0083] 4. The first device encapsulates the first message into a second message and sends the second message to the second device, wherein the sequence number in the header data of the encapsulated second message is consistent with the sequence number carried by the first message, as shown in the following table: Figure 8 The encapsulated second message is composed of an ETH (Ethernet) header, an IP header, an ESP (Encapsulating Security Payload) header, and an ESP payload, wherein the ESP payload is Figure 7 The data starting from the IP in the constructed message, and the sequence number in the ESP header is consistent with the sequence number in the first message in Figure 7 .
[0084] 5. The second device processes the received second message through the message anti-replay function.
[0085] 6. If the second device generates a new message (i.e., a third message) based on the second message when processing the second message through the message anti-replay function, the second device sends the third message to the first device, and the first device extracts the sequence number from the received third message.
[0086] 7. The first device checks the extracted sequence number from the third message according to the sequence number usage rule, and if the sequence number meets the sequence number usage rule, step 8 is performed, otherwise, step 9 is performed.
[0087] 8. The number of normally processed messages is increased by 1, and the execution continues from step 3 until all X sequence numbers are tested.
[0088] 9. The number of abnormally processed messages is increased by 1, and the execution continues from step 3 until all X sequence numbers are tested.
[0089] It should be noted that by constructing a message with a specific sequence number, the message anti-replay function of the second device can be accurately tested, ensuring the security and integrity of data transmission, and the message anti-replay function of the second device can also be quantitatively evaluated, helping network administrators or device manufacturers to identify and improve potential security vulnerabilities, ensuring the security of network communication.
[0090] In an optional embodiment, the test information of the message anti-replay function of the second device is determined according to at least one third message, including: detecting whether the sequence number in the third message conforms to the sequence number use rule followed by the first device. In the case that the sequence number in the third message does not conform to the sequence number use rule followed by the first device, it is determined that the third message belongs to an abnormal message; in the case that the sequence number in the third message conforms to the sequence number use rule followed by the first device, it is determined that the third message belongs to a normal message. The test information of the message anti-replay function of the second device is determined according to the number of abnormal messages and the number of normal messages in the at least one third message.
[0091] Optionally, during the test, the number of abnormal messages and the number of normal messages in all the third messages returned by the second device to the first device can be counted, and then the proportion of the number of abnormal messages in all the third messages is calculated. If the data proportion is higher, it means that the probability of abnormality of the message anti-replay function of the second device is higher.
[0092] In an optional embodiment, the data channel is tested by sending messages from the first device to the second device to obtain the test result of the data channel, including at least one of the following test operations:
[0093] The first test operation is configured to continuously send first type of IPsec data messages to the second device within a preset time period by the first device through the data channel, and monitor the device state information and / or performance fluctuation information of the second device within the preset time period, wherein the first type of IPsec data messages are IPsec data messages with format errors, and / or random lengths, and / or carrying random contents.
[0094] The second test operation is configured to continuously send second type of IPsec data messages to the second device within a preset time period by the first device through the data channel, and monitor the device state information and / or performance fluctuation information of the second device within the preset time period, wherein the second type of IPsec data messages are messages generated by varying the key fields defined according to the IPsec protocol.
[0095] The third test operation is configured to continuously send encapsulated abnormal IPsec data messages to the second device within a preset time period by the first device through the data channel, and monitor whether the second device recognizes the abnormal information of the abnormal IPsec data messages, and monitor the device state information and / or performance fluctuation information of the second device within the preset time period.
[0096] Optionally, as Figure 5As shown, in addition to testing the anti-replay function of the second device, the data channel of the second device can be tested using abnormal packets, the data channel of the second device can be tested using ESP packets including abnormal fields, and the data channel of the second device can be tested using abnormal ESP encapsulation packets.
[0097] Optionally, in order to test the processing capability of the second device for malicious attack packets, the data channel of the second device can be tested using abnormal packets (corresponding to the first test operation described above). The first device can construct IPsec data packets of a first type that are format incorrect, and / or have random lengths, and / or carry random contents, and send the IPsec data packets of the first type to the second device until the test duration reaches a preset duration, and complete the test. During the test, the first device also periodically collects the CPU utilization and memory utilization of the second device to determine the performance fluctuation information of the second device during the test. In addition, the first device also monitors the device state information of the second device.
[0098] Optionally, in the test of the data channel of the second device using ESP packets including abnormal fields (corresponding to the second test operation described above), the first device varies the key fields according to the packet format defined by the IPsec ESP protocol, thereby constructing IPsec data packets of a second type and sending them to the device to be tested, for testing the processing capability of the second device for such abnormal packets. During the test, the first device periodically collects the CPU utilization and memory utilization of the second device to determine the performance fluctuation information of the second device during the test. In addition, the first device also monitors the device state information of the second device.
[0099] Optionally, in the test of the data channel of the second device using abnormal ESP encapsulation packets (corresponding to the third test operation described above), in order to test the ability of the second device to filter abnormal packets when processing decrypted packets, the first device can construct abnormal IPsec data packets with random contents and / or random lengths, and send them to the second device after normal encapsulation, for testing the ability of the second device to identify abnormal packets after completing the decapsulation of the encapsulation packets.
[0100] It should be noted that the above test operations can evaluate the data processing capability and robustness of the second device when processing IPsec packets from multiple angles, and are suitable for performance testing and security function verification of network devices, to ensure that the device can effectively cope with various data abnormalities and attacks in actual deployment.
[0101] In an optional embodiment, the control channel is tested in a manner that the first device initiates a data connection and / or sends abnormal data to the second device, and a test result of the control channel is obtained, including: controlling the first device to establish a plurality of target connections with the second device, and counting a time length required for each target connection to be successfully established, wherein the target connection is used to simulate a normal IPsec connection scenario in the network; determining establishment time fluctuation information of the target connection according to the time length required for each target connection to be successfully established; and taking the establishment time fluctuation information of the target connection as the performance fluctuation information of the second device.
[0102] Optionally, when the control channel is tested, the first device can initiate a request for establishing a target connection every interval, which is used to simulate a normal IPsec connection scenario in the model network, and the time consumed for establishing each target connection can be counted to determine the establishment time fluctuation information of the target connection between the first device and the second device.
[0103] In an optional embodiment, the test result of the second device is determined according to the test result of the control channel and the test result of the data channel, including: determining a test score of the second device according to the test result of the control channel, the test result of the data channel, a weight corresponding to the test result of the control channel, and a weight corresponding to the test result of the data channel, wherein the test score quantitatively represents the test result of the second device in the form of a score.
[0104] It should be noted that by comprehensively considering the test results of the control channel and the data channel, the overall performance and stability of the second device can be comprehensively evaluated, which is suitable for comprehensive testing and evaluation of network devices, and provides data support for performance optimization and security reinforcement of network devices.
[0105] Optionally, the present application proposes a calculation method of a device test score, specifically including the following rules:
[0106] Rule one, if the second device has a device state exception, the second device is directly assigned a score of 0;
[0107] Rule two, if a fluctuation change (for example, variance, standard deviation) of a memory utilization rate of the second device during a certain test exceeds a preset threshold, a specific score is deducted, and if the fluctuation change of the memory utilization rate does not exceed the preset threshold, no score is deducted;
[0108] Rule three, if a fluctuation change (for example, variance, standard deviation) of a CPU utilization rate of the second device during a certain test exceeds a preset threshold, a specific score is deducted, and if the fluctuation change of the CPU utilization rate does not exceed the preset threshold, no score is deducted;
[0109] Rule four, during the test of the control channel, the fluctuation information of the establishment time of the target connection between the first device and the second device is determined (which can be represented by calculating the variance or standard deviation), if the fluctuation of the establishment time of the target connection exceeds the preset threshold, a certain score is deducted; if the fluctuation of the establishment time of the target connection does not exceed the preset threshold, no score is deducted.
[0110] Rule five, when testing the message anti-replay function of the second device, the proportion of the number of abnormal messages in all third messages is calculated, and then the test score C of the message anti-replay function of the second device is determined according to formula (1) as follows:
[0111] (1)
[0112] The final test evaluation calculation formula is formula (2), and the higher the score S is, the higher the stability of the second device in processing IPsec messages is.
[0113] (2)
[0114] Wherein: is the i-th test score, is the weight corresponding to the i-th test, wherein any one test in the test is 0 points, which means that the second device has a serious problem affecting the stability when processing IPsec messages, and is directly assigned 0 points.
[0115] Finally, the score of each test item and the overall score can be displayed through the UI, and the deduction of each test item can be displayed.
[0116] In an optional embodiment, Table 1 shows related suggestions for some specific problem items, and when any one of the following problems of the second device is detected, the related suggestions can be displayed in the UI interface.
[0117] Table 1
[0118]
[0119] Optionally, when a certain round of test of a certain item fails, the related data of the failure can be automatically formed into a test set for testing reproduction, testing verification and testing regression of the problem, so that the stability of the second device in processing IPsec messages can be continuously maintained and improved.
[0120] From the foregoing, the application tests by simulating common attack scenarios of the control channel and the data channel, collects relevant data during the testing process for scoring, and thereby evaluates the stability of the second device in processing IPsec packets. Meanwhile, optimization suggestions are given for the testing problems, and a test set is automatically generated to improve the problem reproduction verification efficiency and continuously improve the stability of the second device in processing IPsec packets.
[0121] Based on the device testing method provided in the foregoing embodiments, the embodiments of the application further provide a device testing apparatus. Figure 9 is a schematic diagram of an optional device testing apparatus according to an embodiment of the application, as shown in Figure 9 includes a first processing unit 901, a first testing unit 902, a second testing unit 903, and a determination unit 904.
[0122] Optionally, the first processing unit 901 is configured to establish a control channel and a data channel between the first device and the second device, where the first device is configured to test the second device, the data channel is configured to encrypt and decrypt data according to an IPsec protocol, and the control channel is configured to determine security parameters according to the IPsec protocol. The first testing unit 902 is configured to test the control channel by initiating a data connection and / or sending abnormal data from the first device to the second device, and obtain a test result of the control channel, where the test result of the control channel at least includes device state information and / or performance fluctuation information of the second device during the testing process. The second testing unit 903 is configured to test the data channel by sending packets from the first device to the second device, and obtain a test result of the data channel, where the test result of the data channel at least includes test information of a packet anti-replay function of the second device. The determination unit 904 is configured to determine a test result of the second device according to the test result of the control channel and the test result of the data channel.
[0123] Optionally, the first testing unit 902 is further configured to control the first device to initiate a half-connection request to the second device for multiple times within a preset time period and monitor device state information and / or performance fluctuation information of the second device within the preset time period by using the control channel, where the half-connection request is configured to simulate a half-connection attack scenario in a network; and / or control the first device to initiate a full-connection request to the second device for multiple times within a preset time period using the same IP address and monitor device state information and / or performance fluctuation information of the second device within the preset time period by using the control channel, where the full-connection request is configured to simulate a full-connection attack scenario in the network.
[0124] Optionally, the first testing unit 902 is further configured to perform at least one of the following test modes:
[0125] The first test mode is used for controlling the first device to continuously send packet data that does not conform to the specification condition of the IPsec protocol to the second device within a preset time length by using the control channel, and monitoring the device state information and / or performance fluctuation information of the second device within the preset time length.
[0126] The second test mode is used for controlling the first device to continuously send packet data that conforms to the specification condition of the IPsec protocol but has abnormal data content to the second device within a preset time length by using the control channel, and monitoring the device state information and / or performance fluctuation information of the second device within the preset time length.
[0127] The third test mode is used for controlling the first device to continuously send different types of abnormal data defined by the IPsec protocol to the second device within a preset time length based on a plurality of control channels by using the control channel, and monitoring the device state information and / or performance fluctuation information of the second device within the preset time length.
[0128] Optionally, the second test unit 903 comprises a first determination subunit, a packet construction subunit, a packet encapsulation subunit, a packet sending subunit, and a second determination subunit. The first determination subunit is configured to determine X sequence numbers by the first device, where X is an integer greater than 1. The packet construction subunit is configured to construct X first packets according to the X sequence numbers, where each first packet carries one sequence number of the X sequence numbers, and different first packets carry different sequence numbers. The packet encapsulation subunit is configured to encapsulate each first packet into a second packet to obtain X second packets, where the sequence number in the header data of each second packet and the sequence number in the payload data of the second packet are both the sequence number carried by the first packet corresponding to the second packet. The packet sending subunit is configured to send the X second packets to the second device by the first device, and receive at least one third packet generated by the second device after processing the X second packets by using the packet anti-replay function. The second determination subunit is configured to determine test information of the packet anti-replay function of the second device according to the at least one third packet.
[0129] Optionally, the second determination subunit comprises a detection module, a first determination module, a second determination module, and a third determination module. The detection module is configured to detect whether the sequence number in the third packet conforms to the sequence number usage rule followed by the first device. The first determination module is configured to determine that the third packet is an abnormal packet in a case where the sequence number in the third packet does not conform to the sequence number usage rule followed by the first device. The second determination module is configured to determine that the third packet is a normal packet in a case where the sequence number in the third packet conforms to the sequence number usage rule followed by the first device. The third determination module is configured to determine the test information of the packet anti-replay function of the second device according to the number of abnormal packets and the number of normal packets in the at least one third packet.
[0130] Optionally, the second test unit 903 further performs at least one of the following test operations:
[0131] A first test operation, for continuously sending, by the first device, first type of IPsec data packets to the second device through the data channel within a preset time length, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length, wherein the first type of IPsec data packets are IPsec data packets with format errors, and / or random lengths, and / or carrying random contents.
[0132] A second test operation, for continuously sending, by the first device, second type of IPsec data packets to the second device through the data channel within a preset time length, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length, wherein the second type of IPsec data packets are generated by mutating key fields defined according to the IPsec protocol.
[0133] A third test operation, for continuously sending, by the first device, encapsulated abnormal IPsec data packets to the second device through the data channel within a preset time length, and monitoring whether the second device identifies abnormal information of the abnormal IPsec data packets, and monitoring device state information and / or performance fluctuation information of the second device within the preset time length.
[0134] Optionally, the first test unit 902 comprises a first control subunit, a third determination subunit, and a fourth determination subunit. The first control subunit is configured to control the first device to establish multiple target connections with the second device, and to count time lengths required for each target connection to be successfully established, wherein the target connection is used to simulate a normal IPsec connection scenario in a network. The third determination subunit is configured to determine establishment time fluctuation information of the target connection according to the time lengths required for each target connection to be successfully established. The fourth determination subunit is configured to take the establishment time fluctuation information of the target connection as the performance fluctuation information of the second device.
[0135] Optionally, the determination unit 904 comprises a score determination subunit configured to determine a test score of the second device according to the test result of the control channel, the test result of the data channel, a weight corresponding to the test result of the control channel, and a weight corresponding to the test result of the data channel, wherein the test score quantitatively represents the test result of the second device in the form of a score.
[0136] Optionally, the device state information at least includes: detection information of whether the second device is restarted, and / or detection information of whether a service on the second device is abnormal; and the performance fluctuation information at least includes: fluctuation information of a memory utilization rate of the second device, and / or fluctuation information of a CPU utilization rate of the second device.
[0137] According to another aspect of the present application, a computer readable storage medium is also provided, wherein the computer readable storage medium stores a computer program, and when the computer program is executed, the computer readable storage medium causes the device where the computer readable storage medium is located to perform the device testing method.
[0138] According to another aspect of the present application, an electronic device is also provided, wherein the electronic device includes one or more processors and a memory, and the memory is configured to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors perform the device testing method.
[0139] The above-mentioned embodiments or examples disclosed in the present application are not exhaustive, and are only a part of the embodiments or examples, and are not specific limitations on the protection scope of the present application. In the case of no contradiction, each step in a certain embodiment or example in the present application can be implemented as an independent example, and the steps can be combined arbitrarily, for example, the scheme after removing part of the steps in a certain embodiment or example can be implemented as an independent example, and the order of the steps in a certain embodiment or example can be exchanged arbitrarily, in addition, the optional mode or optional example in a certain embodiment or example can be combined arbitrarily; in addition, the embodiments or examples can be combined arbitrarily, for example, the steps of different embodiments or examples can be combined arbitrarily, a certain embodiment or example can be combined with the optional mode or optional example of other embodiments or examples.
[0140] The above-mentioned embodiment numbers of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.
[0141] In the above-mentioned embodiments of the present application, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0142] In several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of units can be a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.
[0143] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e. they can be located in one place or distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0144] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0145] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the technical solutions or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0146] The above is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should be considered as the protection scope of the present application.
Claims
1. A device testing method, characterized in that, include: A control channel and a data channel are established between the first device and the second device, wherein the first device is used to test the second device, the data channel is used to encrypt and decrypt data according to the IPsec protocol, and the control channel is used to determine security parameters according to the IPsec protocol. The control channel is tested by having the first device initiate a data connection to the second device and / or send abnormal data, and the test results of the control channel are obtained. The test results of the control channel include at least the device status information and / or performance fluctuation information of the second device during the test. The data channel is tested by sending messages from the first device to the second device to obtain the test results of the data channel. The test results of the data channel include at least the test information of the message anti-replay function of the second device. The test results of the second device are determined based on the test results of the control channel and the test results of the data channel.
2. The equipment testing method according to claim 1, characterized in that, The control channel is tested by initiating a data connection from the first device to the second device, and the test results of the control channel are obtained, including: Using the control channel, the first device is controlled to continuously send multiple half-connection requests to the second device within a preset time period, and the device status information and / or performance fluctuation information of the second device within the preset time period are monitored. The half-connection requests are used to simulate half-connection attack scenarios in the network. and / or; Using the control channel, the first device is controlled to continuously send multiple full-connection requests to the second device using the same IP address within a preset time period, and the device status information and / or performance fluctuation information of the second device within the preset time period are monitored. The full-connection requests are used to simulate a full-connection attack scenario in the network.
3. The equipment testing method according to claim 1, characterized in that, The control channel is tested by sending abnormal data from the first device to the second device, and the test results of the control channel are obtained, including at least one of the following test methods: The first test method is used to control the first device to continuously send message data that does not conform to the specification conditions of the IPsec protocol to the second device within a preset time period using the control channel, and to monitor the device status information and / or performance fluctuation information of the second device within the preset time period. The second testing method is used to control the first device to continuously send message data that conforms to the specifications of the IPsec protocol but has abnormal data content to the second device within a preset time period using the control channel, and to monitor the device status information and / or performance fluctuation information of the second device within the preset time period. The third testing method is used to control the first device to continuously send different types of abnormal data defined by the IPsec protocol to the second device through multiple control channels within a preset time period, and to monitor the device status information and / or performance fluctuation information of the second device within the preset time period.
4. The equipment testing method according to claim 1, characterized in that, The data channel is tested by sending messages from the first device to the second device, and the test results of the data channel are obtained, including: X serial numbers are determined using the first device, where X is an integer greater than 1; X first messages are constructed based on the X sequence numbers, wherein each first message carries one of the X sequence numbers, and different first messages carry different sequence numbers: Each first message is encapsulated into a second message to obtain X second messages. The sequence number in the header data and the sequence number in the payload data of each second message are the sequence numbers carried by the first message corresponding to that second message. The first device sends the X second messages to the second device and receives at least one third message generated by the second device after processing the X second messages using the message anti-replay function; The test information for the message replay protection function of the second device is determined based on at least one of the third messages.
5. The equipment testing method according to claim 4, characterized in that, The test information for the message replay protection function of the second device is determined based on the at least one third message, including: Detect whether the sequence number in the third message conforms to the sequence number usage rules followed by the first device; If the serial number in the third message does not conform to the serial number usage rules followed by the first device, the third message is determined to be an abnormal message. If the serial number in the third message conforms to the serial number usage rules followed by the first device, the third message is determined to be a normal message. The test information for the message replay protection function of the second device is determined based on the number of abnormal messages and the number of normal messages in the at least one third message.
6. The equipment testing method according to claim 1, characterized in that, The data channel is tested by sending messages from the first device to the second device to obtain the test results, including at least one of the following test operations: The first test operation is used to continuously send a first type of IPsec data packet to the second device through the first device within a preset time period using the data channel, and to monitor the device status information and / or performance fluctuation information of the second device within the preset time period, wherein the first type of IPsec data packet is an IPsec data packet with a format error, and / or random length, and / or carrying random content. The second test operation is used to use the data channel to continuously send a second type of IPsec data packet to the second device through the first device within a preset time period, and to monitor the device status information and / or performance fluctuation information of the second device within the preset time period. The second type of IPsec data packet is a packet generated after modifying the defined key fields according to the IPsec protocol. The third test operation is used to continuously send encapsulated abnormal IPsec data packets to the second device through the first device within a preset time period using the data channel, and to monitor whether the second device recognizes the abnormal information of the abnormal IPsec data packets, as well as to monitor the device status information and / or performance fluctuation information of the second device within the preset time period.
7. The equipment testing method according to claim 1, characterized in that, The control channel is tested by having the first device initiate a data connection to the second device and / or send abnormal data, and the test results of the control channel are obtained, including: The system controls the first device to establish multiple target connections with the second device and calculates the time required for each target connection to be successfully established. The target connections are used to simulate normal IPsec connection scenarios in a network. Based on the time required for each successful establishment of the target connection, determine the establishment time fluctuation information of the target connection; The establishment time fluctuation information of the target connection is used as the performance fluctuation information of the second device.
8. The equipment testing method according to any one of claims 1-7, characterized in that, The device status information includes at least: detection information on whether the second device has restarted, and / or detection information on whether the services on the second device are abnormal; the performance fluctuation information also includes at least: fluctuation information on the memory utilization rate of the second device, and / or fluctuation information on the CPU utilization rate of the second device.
9. A device for testing equipment, characterized in that, include: The first processing unit is used to establish a control channel and a data channel with the second device through the first device, wherein the first device is used to test the second device, the data channel is used to encrypt and decrypt data according to the IPsec protocol, and the control channel is used to determine security parameters according to the IPsec protocol. The first testing unit is used to test the control channel by initiating a data connection from the first device to the second device and / or sending abnormal data, and to obtain the test results of the control channel. The test results of the control channel include at least the device status information and / or performance fluctuation information of the second device during the test. The second test unit is used to test the data channel by sending messages from the first device to the second device, and to obtain the test results of the data channel. The test results of the data channel include at least the test information of the message anti-replay function of the second device. The determining unit is used to determine the test results of the second device based on the test results of the control channel and the test results of the data channel.
10. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to perform the device testing method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Performance monitoring device, system and method based on WebSocket protocol
CN106161130A
Universal full-automatic array transceiving module amplitude and phase test system and test method thereof
CN108768553A