Universal performance test and method for special product for network security
By designing a general performance testing system for network security special products, and using test hosts and virtualized container technologies, the problems of high cost and poor flexibility of hardware equipment in the existing test methods are solved, and a high-integrated test environment and a wide range of application are achieved.
Patent Information
- Application Number
- CN202510321633.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-05-13
AI Technical Summary
The existing performance testing methods for network security special products have problems such as high cost of hardware equipment, difficulty in obtaining, closed test environments, lack of openness and flexibility, and difficulty in deploying in cloud computing environments.
A general performance testing system for network security special products was designed. By connecting the test host to the test network security special products, the first physical network card and the second physical network card, bridge, network attack department, data sharding department, load testing department and application server components are used to achieve the testing and evaluation of performance indicators.
Through the integrated test environment, the number of hardware devices used is reduced, the cost is reduced, and the scope of application is improved, and the flexibility of existing testing methods and the deployment of cloud computing environments is solved.
Smart Images

Figure CN119996256A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security testing, and in particular to a network security dedicated product performance testing system and method. Background Art
[0002] With the rapid development of network technology, the importance of network security has become increasingly prominent. As the key to ensuring network security, the quality and performance of network security products are of vital importance. In order to accurately evaluate the performance of different types of network-specific products, relevant institutions have summarized and classified the performance requirements of products, covering key indicators such as throughput, latency, false interception rate (false alarm rate), missed interception rate (missed alarm rate), data collection speed, event recording speed, new connection rate and concurrent connection rate. These indicators basically cover the performance considerations of all network-specific products.
[0003] There are two main types of existing testing methods: one is to use instruments of different test types for testing. When operating this method, you must first obtain instruments that are suitable for testing different performance indicators, and then configure their functions. However, the instruments are expensive and difficult to obtain; the test environment is closed and lacks openness; secondary development and upgrading face many difficulties; it is difficult to deploy in a cloud computing environment, which greatly limits its application scenarios and flexibility. The other is to use multiple servers, computers, and test software to build a test environment, but the structure of the test environment is complex, and different test environments need to be built for different performance indicators. This not only increases the cost and difficulty of construction, but also has great problems in maintenance and mobility, making it difficult to meet the diverse needs and flexible deployment requirements in actual applications. Summary of the invention
[0004] The purpose of the present invention is to provide a universal performance testing system for network security special products to solve the above technical problems;
[0005] The present invention also aims to provide a universal performance testing method for network security special products to solve the above technical problems;
[0006] A universal performance test system for network security dedicated products, comprising a test host machine, wherein the test host machine is provided with a first physical network card and a second physical network card, wherein the first physical network card and the second physical network card are respectively connected to a first physical interface and a second physical interface of a network security dedicated product under test;
[0007] The test host includes:
[0008] A first bridge, connected to the second physical network card;
[0009] A second bridge, connected to the first physical network card;
[0010] A network attack unit, wherein an output end of the network attack unit is connected to the first bridge and is used to output a network attack message;
[0011] A data slicing unit, connected to the first bridge, the data slicing unit outputs a network attack message that evades detection;
[0012] A load testing unit, connected to the first bridge, and outputting a load testing message;
[0013] An application server is connected to the data segmentation unit and the load testing unit. The application server receives the network attack message for evading detection and the load testing message. The application server is also connected to the second bridge.
[0014] Preferably, the test host also includes:
[0015] A data replay unit, connected to the first bridge, the data replay unit outputs a hybrid network data packet;
[0016] The network bandwidth testing unit is connected to the first physical network card and the second physical network card, and the network bandwidth testing unit outputs network data with different bandwidths.
[0017] Preferably, the network bandwidth testing unit includes:
[0018] A first network bandwidth testing unit is connected to the first physical network card, and the first network bandwidth testing unit receives a first network data message;
[0019] The second network bandwidth testing unit is connected to the second physical network card, and the second network bandwidth testing unit sends the first network data message.
[0020] Preferably, the first network bandwidth testing unit is in a first host mode to share the network configuration of the first physical network card;
[0021] The second network bandwidth testing unit is in a second host mode to share the network configuration of the second physical network card.
[0022] Preferably, the test host also includes:
[0023] The network protocol analysis unit is connected to the network bandwidth testing unit. The network protocol analysis unit obtains and counts the sending time and receiving time of the network data on the first physical network card and the second physical network card to obtain the delay performance index of the tested network security dedicated product.
[0024] Preferably, the first network data message is a User Datagram Protocol message, and the data replay unit is a Transmission Control Protocol replay tool;
[0025] The network bandwidth testing unit calculates the throughput performance index of the tested network security dedicated product by receiving and counting the bandwidth and packet loss rate of the first network data message.
[0026] Preferably, the load testing unit is a stress testing tool, the data sharding unit is a shard router, and the application server is a WEB server.
[0027] Preferably, the false alarm rate and missed alarm rate performance indicators of the tested network security dedicated product are calculated according to the running carrier of the data slicing unit, the running carrier of the application server and the types and quantities of attacks detected on the tested network security dedicated product;
[0028] The operation carrier of the data replay unit sends a data message from the second physical network card to the network security dedicated product under test through network address translation, and calculates the data collection speed and event recording speed performance indicators of the network security dedicated product under test;
[0029] The running carrier of the load testing unit sends the load testing message from the second physical network card to the running carrier of the application server through network address translation, and the running carrier of the application server receives the load testing message from the first physical network card through network address translation, and calculates the new connection rate and concurrent connection rate performance indicators of the tested network security product.
[0030] Preferably, the running carrier of the first network bandwidth testing unit is a first virtualized container;
[0031] The running carrier of the second network bandwidth testing unit is a second virtualized container;
[0032] The operation carrier of the network attack unit is a third virtualized container;
[0033] The operation carrier of the data slicing part is a fourth virtualization container;
[0034] The running carrier of the application server is a fifth virtualization container;
[0035] The operation carrier of the data replay unit is a sixth virtualization container;
[0036] The operation carrier of the load testing unit is the seventh virtualization container.
[0037] A universal performance testing method for network security special products, used in the universal performance testing system for network security special products, comprising:
[0038] Step S1, the test host is connected to the first physical interface and the second physical interface of the tested network security dedicated product through the first physical network card and the second physical network card;
[0039] Step S2, the data segmentation unit receives the network attack message sent by the network attack unit, outputs the network attack message that evades detection, and the load testing unit outputs the load test message;
[0040] Step S3: the application server receives the network attack message for escaping detection and the load test message, and performs a performance index test on the tested network security dedicated product.
[0041] The beneficial effects of the present invention are: by connecting the tested network security dedicated product to the test host machine, the test environment has a high degree of integration, the number of hardware devices used is reduced, the cost is low, and the application range is wide. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a schematic diagram of the environment configuration of the universal performance testing system for network security special products of the present invention;
[0043] Figure 2 It is a schematic diagram of testing performed by the universal performance testing system for network security-specific products of the present invention;
[0044] Figure 3 It is a step diagram of the universal performance testing method of network security special products of the present invention.
[0045] In the accompanying drawings: 1. test host; 101. first physical network card; 102. second physical network card; 2. network security product under test; 21. first physical interface; 22. second physical interface; 3. first bridge; 4. network bandwidth test unit; 41. first network bandwidth test unit; 42. second network bandwidth test unit; 5. network attack unit; 6. data segmentation unit; 7. network protocol analysis unit; 8. data replay unit; 9. load test unit; 10. second bridge; 11. application server. DETAILED DESCRIPTION
[0046] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0047] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.
[0048] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, but they are not intended to limit the present invention.
[0049] A universal performance test system for network security products, referring to Figure 1 , Figure 2 , including a test host machine 1, on which a first physical network card 101 and a second physical network card 102 are provided, and the first physical network card 101 and the second physical network card 102 are respectively connected to a first physical interface 21 and a second physical interface 22 of a network security dedicated product 2 under test;
[0050] Test host 1 includes,
[0051] The first bridge 3 is connected to the second physical network card 102;
[0052] The second bridge 10 is connected to the first physical network card 101;
[0053] A network attack unit 5, the output end of which is connected to the first bridge 3, and is used to output the network attack message;
[0054] The data segmentation unit 6 is connected to the first bridge 3, and the data segmentation unit 6 outputs the network attack message that evades detection;
[0055] The load testing unit 9 is connected to the first bridge 3, and the load testing unit 9 outputs a load testing message;
[0056] The application server 11 is connected to the data segmentation unit 6 and the load testing unit 9 . The application server 11 receives the network attack message and the load testing message for escaping detection. The application server 11 is also connected to the second bridge 10 .
[0057] Specifically, the present invention provides a universal performance testing system for network security special products, which connects the tested network security special product 2 to the testing host machine 1, has a high test environment integration, reduces the number of hardware devices used, has a low cost, and has a wide range of applications.
[0058] In a preferred embodiment, the test host 1 further includes:
[0059] The data replay unit 8 is connected to the first bridge 3, and the data replay unit 8 outputs a mixed network data packet;
[0060] The network bandwidth testing unit 4 is connected to the first physical network card 101 and the second physical network card 102 , and the network bandwidth testing unit 4 outputs network data with different bandwidths.
[0061] Specifically, a data replay unit 8 and a network bandwidth test unit 4 are added. The data replay unit 8 is connected to the first bridge 3 to output a mixed network data packet, and the network bandwidth test unit 4 is connected to the first and second physical network cards to output network data with different bandwidths.
[0062] The data replay unit 8 outputs mixed network data packets, which can simulate data traffic in a complex network environment, so that the product under test can be tested in an environment closer to the real environment, thereby improving the reliability of the test results. By generating data packets of various types and rates, various data situations that may occur in the network are simulated, and the product under test is allowed to process these data, thereby more comprehensively testing its performance.
[0063] The network bandwidth testing unit 4 outputs network data of different bandwidths, and can directly test the performance of the product under test under different network bandwidths.
[0064] In a preferred embodiment, the network bandwidth testing unit 4 includes:
[0065] The first network bandwidth testing unit 41 is connected to the first physical network card 101, and the first network bandwidth testing unit 41 receives the first network data message;
[0066] The second network bandwidth testing unit 42 is connected to the second physical network card 102 , and the second network bandwidth testing unit 42 sends a first network data message.
[0067] Specifically, the first network bandwidth test unit 41 is connected to the first physical network card 101 to receive the first network data message, and the second network bandwidth test unit 42 is connected to the second physical network card 102 to send the first network data message, and they are in different host modes and share the corresponding network card network configuration, which can more accurately control and measure the transmission of network data and improve the accuracy of the test. The network bandwidth test function is subdivided, and by sending and receiving data in two directions respectively, the transmission of data in the tested product can be observed more carefully.
[0068] For example, when testing throughput performance indicators, precise control of data transmission in both directions can more accurately measure the data packet bandwidth and packet loss rate, thereby obtaining more accurate throughput performance indicators for the product under test.
[0069] In a preferred embodiment, the test host 1 further includes:
[0070] The network protocol analysis unit 7 is connected to the network bandwidth testing unit 4. The network protocol analysis unit 7 obtains and counts the sending time and receiving time of the network data on the first physical network card 101 and the second physical network card 102 to obtain the delay performance index of the tested network security dedicated product 2.
[0071] Specifically, the test host 1 adds a network protocol analysis unit 7 to connect to the network bandwidth test unit 4 to output the delay performance index. The network protocol analysis unit 7 can capture and analyze the data packets sent and received by the first and second physical network cards using the network bandwidth test unit 4, and calculate the delay performance index of the network security dedicated product. This enables the system to quantitatively evaluate the delay performance of the product under test. By accurately capturing and analyzing the sending and receiving time of the data packet, the time spent on the data transmission in the product under test is calculated, thereby obtaining the delay performance index.
[0072] In a preferred embodiment, the first network data message is a user datagram protocol message, and the data replay unit 8 is a transmission control protocol replay tool;
[0073] The network bandwidth testing unit 4 calculates the throughput performance index of the tested network security dedicated product 2 by receiving and counting the bandwidth and packet loss rate of the first network data message.
[0074] Specifically, the first network data message is a User Datagram Protocol (UDP) message. UDP messages have the characteristics of fast transmission speed and low overhead, but do not guarantee reliable data transmission. Using UDP messages in the test can test the performance of the product under test when processing high-speed, unreliable transmission data. Utilizing the characteristics of UDP messages, some network application scenarios with high real-time requirements but relatively low data accuracy requirements are simulated, such as network data transmission in scenarios such as video streaming and audio streaming transmission, and the processing capabilities of the product under test in such scenarios are detected, such as whether a large number of UDP messages can be processed in a timely manner, and the ability to cope with message loss.
[0075] In a preferred embodiment, the false alarm rate and missed alarm rate performance indicators of the tested network security dedicated product 2 are calculated based on the operation carrier of the data slicing unit 6, the operation carrier of the application server 11, and the attack types and quantities detected on the tested network security dedicated product 2;
[0076] The operation carrier of the data replay unit 8 sends data messages to the network security dedicated product 2 under test through the second physical network card 102 through network address translation, and calculates the data collection speed and event recording speed performance indicators of the network security dedicated product 2 under test;
[0077] The operation carrier of the load test unit 9 sends the load test message to the operation carrier of the application server 11 through the second physical network card 102 through the network address translation, and the operation carrier of the application server 11 receives the load test message through the first physical network card 101 through the network address translation, and calculates the new connection rate and concurrent connection rate performance indicators of the tested network security dedicated product 2;
[0078] The running carrier of the first network bandwidth testing unit 41 is the first virtualized container;
[0079] The running carrier of the second network bandwidth testing unit 42 is a second virtualized container;
[0080] The operation carrier of the network attack unit 5 is the third virtualization container;
[0081] The operation carrier of the data slicing unit 6 is the fourth virtualized container;
[0082] The running carrier of the application server 11 is the fifth virtualization container;
[0083] The operation carrier of the data playback unit 8 is the sixth virtualization container;
[0084] The operation carrier of the load testing unit 9 is the seventh virtualization container.
[0085] In a preferred embodiment, the load testing unit 9 is a stress testing tool, the data sharding unit 6 is a sharding router, and the application server 11 is a WEB server.
[0086] Specifically, the third virtualization container runs a network attack module, such as Blade, Nikto, Nmap, etc., and sends a certain type and number of network attack messages to the fifth virtualization container via the fourth virtualization container;
[0087] The fourth virtualized container runs a data fragmentation module, such as a fragmentation router Fragrouter, to fragment the network attack message received from the third virtualized container M103 to form a network attack message that evades detection;
[0088] The fifth virtualized container runs an application server, such as a WEB server, receives deformed network attack messages, and calculates the performance indicators of the false interception rate (false alarm rate) and the missed interception rate (missed alarm rate) by checking the types and quantities of attacks detected (blocked) on the tested network security dedicated product;
[0089] The networks of the third virtualized container and the fourth virtualized container communicate with each other by using the network configuration of the second physical network card 102 in the virtualized container network working mode bridge1, the fourth virtualized container shares the network configuration of the second physical network card 102 in the host1 mode, and the network of the fifth virtualized container uses the network configuration of the first physical network card 101 in the virtualized container network working mode bridge0;
[0090] The second physical network card 102 is connected to the second physical interface 22 of the network security dedicated product under test, and the first physical network card 101 is connected to the first physical interface 21 of the network security dedicated product under test.
[0091] The sixth virtualized container runs a data replay module, such as a transmission control protocol replay tool Tcpreplay, and sends a certain number and rate of constructed network data packets by testing the second physical network card 102 of the host machine 1;
[0092] The second physical interface 22 of the tested network security dedicated product monitors and receives network data packets sent by the sixth virtualized container, records the number of received network data packets and the sending speed, and calculates performance indicators of data collection speed and event recording speed;
[0093] The network of the sixth virtualized container uses the network configuration of the second physical network card 102 in a NAT (network address translation) manner through the virtualized container network working mode bridge1;
[0094] The second physical network card 102 is connected to the second physical interface 22 of the tested network security product.
[0095] The seventh virtualized container runs a load test module, such as a stress test tool JMeter, and sends a certain number and rate of load test messages to the fifth virtualized container;
[0096] The fifth virtualized container runs an application server as an application server, receives load test messages, and records performance indicators of new connection rate and concurrent connection rate by checking the number and rate of successful load connections established on the load test software.
[0097] The network of the seventh virtualized container uses the network configuration of the second physical network card 102 in NAT mode through the virtualized container network working mode bridge1;
[0098] The second physical network card 102 is connected to the second physical interface 22 of the network security dedicated product under test, and the first physical network card 101 is connected to the first physical interface 21 of the network security dedicated product under test.
[0099] The virtualization container used in the present application includes a first virtualization container and a second virtualization container, which runs a network bandwidth test unit 4 for setting the sending and receiving of a certain type and number of network data packets, and the network works in host mode;
[0100] The third virtualized container runs the network attack unit 5, which is set to send a certain type and number of network attack messages, and its network works in bridge mode;
[0101] The fourth virtualized container runs the data slicing unit 6, which is used to transform the network attack message sent by the third virtualized container to form a network attack message that evades detection, and sends the message, and its network works in bridge mode and host mode respectively;
[0102] The sixth virtualized container runs a data replay unit 8, which is used to send a certain number and rate of constructed hybrid network data packets, and its network works in bridge mode;
[0103] The seventh virtualized container runs a load testing unit 9, which is used to send a certain number and rate of load testing messages, and its network works in bridge mode, using the network configuration of the second physical network card in NAT mode;
[0104] The fifth virtualized container runs the application server 11 as a target machine, receives network attack messages and load test messages for evading detection, and its network works in bridge mode.
[0105] Among them, the third virtualized container and the fourth virtualized container use the bridge network for network communication, the fourth virtualized container uses the host mode to share the network configuration of the second physical network card 102, and the network of the fifth virtualized container works in the bridge mode and uses the network configuration of the first physical network card 101.
[0106] In a preferred embodiment, the first network bandwidth testing unit 41 is in the first host mode to share the network configuration of the first physical network card 101;
[0107] The second network bandwidth testing unit 42 is in the second host mode to share the network configuration of the second physical network card 102 .
[0108] Specifically, the virtualized container runs in different network modes according to different test requirements, including virtualized container network working mode host0, virtualized container network working mode host1, virtualized container network working mode bridge0, and virtualized container network working mode bridge1.
[0109] The network of the first virtualized container uses the virtualized container network working mode host0 to share the network configuration of the first physical network card 101 , and the network of the second virtualized container uses the virtualized container network working mode host1 to share the network configuration of the second physical network card 102 .
[0110] The present invention uses a single test host machine 1 with a unified time source and high test accuracy, which solves the problem of complex environment and difficult maintenance. By using virtualization container technology, each test unit can be operated in isolation, which solves the problem of mutual influence between different test software and unstable test system. In addition, when testing different performance indicators, different virtualization containers can be selected to be opened, thereby improving test efficiency.
[0111] Reference Figure 2, this application uses a test host 1, installs 2 physical network cards on the test host 1, loads 7 virtualization container modules, and installs a network protocol analysis unit 7. Use a physical server to complete the performance index test of different network security products. The system described in this application that uses a physical server to deploy a test environment can make full use of resources, reduce the demand for test equipment, and use container technology to make the test environment more independent and stable.
[0112] Specifically, it includes: a test host machine 1, two physical network cards (a first physical network card 101, a second physical network card 102), a network bandwidth test unit 4 deployed through a virtualized container, a network attack unit 5, a data segmentation unit 6, a data replay unit 8, a load test unit 9, an application server 11, and a network protocol analysis unit 7.
[0113] The virtualized container runs in different network modes according to the test requirements, including virtualized container network working mode host0, virtualized container network working mode host1, virtualized container network working mode bridge0, and virtualized container network working mode bridge1;
[0114] The first physical network card 101 and the second physical network card 102 provide a sharing or NAT working mode for the virtualized container according to the network working mode of the virtualized container.
[0115] The first virtualized container runs a network bandwidth test unit 4, such as iPerf, to receive data packets sent by the second virtualized container through the first physical network card 101 of the test host machine 1;
[0116] The second virtualized container runs a network bandwidth testing unit 4, such as iPerf, and sends a data message to the first virtualized container by testing the second physical network card 102 of the host machine 1;
[0117] The first virtualized container receives and counts data packets of different network bandwidths sent by the second virtualized container, usually using UDP packets, to obtain a throughput performance index of the tested network security dedicated product;
[0118] The network of the first virtualized container uses the host working mode to share the network configuration of the first physical network card 101, and the network of the second virtualized container uses the host working mode to share the network configuration of the second physical network card 102;
[0119] The network protocol analysis unit 7, such as Wireshark or Tcpdump, captures network data packets on the first physical network card 101 and the second physical network card 102 respectively during the process of testing the throughput index of the first virtualized container and the second virtualized container, and calculates the time difference between the same data packet leaving the second virtualized container and arriving at the first virtualized container, and obtains the delay performance index of the tested network security dedicated product;
[0120] The second physical network card 102 is connected to the second physical interface 22 of the network security dedicated product under test, and the first physical network card 101 is connected to the first physical interface 21 of the network security dedicated product under test.
[0121] A general performance test method for network security special products, referring to Figure 3 , used for general performance test system of network security special products, including,
[0122] Step S1, the test host machine 1 is connected to the first physical interface 21 and the second physical interface 22 of the tested network security dedicated product 2 through the first physical network card 101 and the second physical network card 102;
[0123] Step S2, the data segmentation unit 6 receives the network attack message sent by the network attack unit 5, outputs the network attack message that evades detection, and the load testing unit 9 outputs the load test message;
[0124] Step S3, the application server 11 receives the network attack message and the load test message for escaping detection, and performs a performance index test on the tested network security dedicated product 2.
[0125] Specifically, the present application deploys a container operating environment for running a virtualized container, and the first physical network card 101 and the second physical network card 102 are respectively connected to different network interfaces of the network security dedicated product under test (i.e., the network security dedicated product under test 2), for sending and receiving test messages to the network security dedicated product under test.
[0126] More specifically, the sixth virtualized container runs the data replay unit 8, and sends a certain number and rate of constructed network data packets through the second physical network card 102 of the test host machine 1;
[0127] The physical interface of the tested network security dedicated product 2 monitors and receives the network data packet sent by the sixth virtualized container;
[0128] The network of the sixth virtualized container works in bridge mode and uses the network configuration of the second physical network card 102 .
[0129] More specifically, the seventh virtualized container runs the load testing unit 9 to send a certain number and rate of load testing messages to the fifth virtualized container;
[0130] The network of the seventh virtualized container works in bridge mode, using the network configuration of the second physical network card 102 .
[0131] The physical interface of the tested network security dedicated product 2 monitors and receives network data packets sent by the sixth virtualization container, records the number and speed of received network data packets, and calculates performance indicators of data collection speed and event recording speed of the network security dedicated product.
[0132] By checking the number and rate of successful load connections established on the seventh virtualization container load testing software, the performance indicators of the new connection rate and concurrent connection rate of the network security dedicated product are obtained.
[0133] The first virtualized container enables the bandwidth test module, and uses the bandwidth test module to receive data packets sent by the second virtualized container through the first physical network card 101. The second virtualized container module enables the bandwidth test module, and uses the bandwidth test module sending function to send data packets to the first virtualized container through the second physical network card 102, and counts the statistical data packet bandwidth and packet loss rate to test the throughput performance indicators of network-specific products.
[0134] In the process of testing the throughput index of the first virtualized container and the second virtualized container, network data packets are captured on the first physical network card 101 and the second physical network card 102 respectively, and the time difference between the same data packet leaving the second virtualized container and arriving at the first virtualized container is calculated to obtain the delay performance index of the tested network security dedicated product 2.
[0135] The network protocol analysis unit 7 monitors and captures the data packets sent and received by the first physical network card 101 and the second physical network card 102 using the bandwidth test module, and tests the delay performance index of the network-specific product through calculation.
[0136] The network attack unit 5 is deployed through the third virtualization container, the data segmentation unit 6 is deployed through the fourth virtualization container, and the application server 11 is deployed through the fifth virtualization container. The application server 11 builds a network application.
[0137] The third virtualized container enables the network attack unit 5 to use the bridge network mode to send a network attack message to the fourth virtualized container. The fourth virtualized container enables the data slicing unit 6, uses the bridge network mode to slice the network attack message sent by the third virtualized container, and uses the network configuration of the second physical network card 102 shared by the host network mode to send the sliced data message to the first physical network card 101 through the second physical network card 102 through the tested network-specific product. The fifth virtualized container runs the application server 11 and receives the sliced network attack message arriving at the first physical network card 101 in NAT mode through the bridge network mode, and performs a performance indicator test of the false interception rate (false alarm rate) and missed interception rate (missed alarm rate) of the network-specific product. The third virtualized container can also directly send a network attack message that has not been deformed to the fifth virtualized container.
[0138] Among them, the network communication between the third virtualized container and the fourth virtualized container is completed through the network working mode bridge1, the network attack message sent by the fourth virtualized container to the fifth virtualized container uses the network configuration of the second physical network card 102 shared by host1, and the network of the fifth virtualized container uses the network configuration of the first physical network card 101 in NAT mode through the virtualized container network working mode bridge0;
[0139] The sixth virtualized container sends data packets to the network-specific product under test through the second physical network card 102 in NAT mode through the bridge network mode to perform performance index tests on the data collection speed and event recording speed of the network-specific product. The second physical interface 22 of the network security-specific product under test 2 monitors and receives network data packets sent by the sixth virtualized container, records the number of network data packets received and the sending speed, and calculates the performance indexes of the data collection speed and the event recording speed;
[0140] The network of the sixth virtualized container uses the network configuration of the second physical network card in NAT mode through the virtualized container network working mode bridge1;
[0141] The seventh virtualized container deploys the load testing unit 9. The seventh virtualized container uses the second physical network card 102 through the bridge network mode in NAT mode via the network product under test to send a load test message to the fifth virtualized container. The fifth virtualized container receives the load test data received by the first physical network card 101 through the bridge network mode in NAT mode, and performs performance indicator tests of the new connection rate and the concurrent connection rate.
[0142] By deploying a virtualized container on the test host 1, running different test modules on different virtualized containers, and setting different working modes of the virtualized container network and the data packet interaction method between virtualized containers, the performance testing problem of different network products is solved.
[0143] The above description is only a preferred embodiment of the present invention, and does not limit the implementation mode and protection scope of the present invention. For those skilled in the art, it should be aware that all solutions obtained by equivalent substitutions and obvious changes made using the description and illustrations of the present invention should be included in the protection scope of the present invention.
Claims
1. A universal performance testing system for network security products, characterized in that: A test host is included, wherein the test host is provided with a first physical network card and a second physical network card, wherein the first physical network card and the second physical network card are respectively connected to a first physical interface and a second physical interface of a network security dedicated product under test; The test host includes: A first bridge, connected to the second physical network card; A second bridge, connected to the first physical network card; A network attack unit, wherein an output end of the network attack unit is connected to the first bridge and is used to output a network attack message; A data slicing unit, connected to the first bridge, the data slicing unit outputs a network attack message that evades detection; A load testing unit, connected to the first bridge, and outputting a load testing message; An application server is connected to the data segmentation unit and the load testing unit. The application server receives the network attack message for evading detection and the load testing message. The application server is also connected to the second bridge.
2. The universal performance testing system for network security special products according to claim 1 is characterized in that: The test host also includes: A data replay unit, connected to the first bridge, the data replay unit outputs a hybrid network data packet; The network bandwidth testing unit is connected to the first physical network card and the second physical network card, and the network bandwidth testing unit outputs network data with different bandwidths.
3. The universal performance testing system for network security special products according to claim 2 is characterized in that: The network bandwidth testing unit comprises: A first network bandwidth testing unit is connected to the first physical network card, and the first network bandwidth testing unit receives a first network data message; The second network bandwidth testing unit is connected to the second physical network card, and the second network bandwidth testing unit sends the first network data message.
4. The universal performance testing system for network security special products according to claim 3 is characterized in that: The first network bandwidth testing unit is in a first host mode to share the network configuration of the first physical network card; The second network bandwidth testing unit is in a second host mode to share the network configuration of the second physical network card.
5. The universal performance testing system for network security special products according to claim 2 is characterized in that: The test host also includes: The network protocol analysis unit is connected to the network bandwidth testing unit. The network protocol analysis unit obtains and counts the sending time and receiving time of the network data on the first physical network card and the second physical network card to obtain the delay performance index of the tested network security dedicated product.
6. The universal performance testing system for network security special products according to claim 2 is characterized in that: The first network data message is a user datagram protocol message, and the data replay unit is a transmission control protocol replay tool; The network bandwidth testing unit calculates the throughput performance index of the tested network security dedicated product by receiving and counting the bandwidth and packet loss rate of the first network data message.
7. The universal performance testing system for network security special products according to claim 1 is characterized in that: The load testing unit is a stress testing tool, the data sharding unit is a sharding router, and the application server is a WEB server.
8. The universal performance testing system for network security special products according to claim 1 is characterized in that: Calculate the false alarm rate and missed alarm rate performance indicators of the tested network security dedicated product according to the running carrier of the data slicing unit, the running carrier of the application server, and the types and quantities of attacks detected on the tested network security dedicated product; The operation carrier of the data replay unit sends a data message from the second physical network card to the network security dedicated product under test through network address translation, and calculates the data collection speed and event recording speed performance indicators of the network security dedicated product under test; The running carrier of the load testing unit sends the load testing message from the second physical network card to the running carrier of the application server through network address translation, and the running carrier of the application server receives the load testing message from the first physical network card through network address translation, and calculates the new connection rate and concurrent connection rate performance indicators of the tested network security product.
9. The universal performance testing system for network security special products according to claim 3 is characterized in that: The running carrier of the first network bandwidth testing unit is a first virtualized container; The running carrier of the second network bandwidth testing unit is a second virtualized container; The operation carrier of the network attack unit is a third virtualized container; The operation carrier of the data slicing part is a fourth virtualization container; The running carrier of the application server is a fifth virtualization container; The operation carrier of the data replay unit is a sixth virtualization container; The operation carrier of the load testing unit is the seventh virtualization container.
10. A general performance testing method for network security products, characterized in that: The universal performance testing system for network security special products according to any one of claims 1 to 9 comprises: Step S1, the test host is connected to the first physical interface and the second physical interface of the tested network security dedicated product through the first physical network card and the second physical network card; Step S2, the data segmentation unit receives the network attack message sent by the network attack unit, outputs the network attack message that evades detection, and the load testing unit outputs the load test message; Step S3: the application server receives the network attack message for escaping detection and the load test message, and performs a performance index test on the tested network security dedicated product.