Automatic test method and system for TCP (Transmission Control Protocol) creation and concurrency performance of firewall

By building a time model and connection model, the firewall parameters are automatically configured, which solves the problem of complex configuration of existing firewall testing methods, and realizes efficient automated testing of the new construction and concurrent performance of firewall TCP.

CN120017392APending Publication Date: 2025-05-16THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510205202.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The configuration process of existing firewall testing methods is complicated and requires manual initialization of configuration, such as setting IP addresses and packet filtering policies, which leads to inconvenience in use.

Method used

Provides an automated testing method, which automatically configures the parameters of the firewall by building a time model and connection model, and realizes automated testing of TCP new and concurrent performance.

Benefits of technology

Simplifies the test configuration process, improves testing efficiency, reduces human errors, and achieves accurate and efficient testing of firewall performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017392A_ABST
    Figure CN120017392A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automatic testing, in particular to an automatic testing method and system for TCP (Transmission Control Protocol) establishment and concurrency performance of a firewall, which comprises the following steps of: establishing a first virtual connection based on a first time model and a first connection model to carry out connection rate testing on a firewall to be tested, and sampling to obtain a connection rate testing result; and creating a second virtual connection based on the second time model and the second connection model to perform concurrent testing on the firewall to be tested, and sampling to obtain a concurrent testing result. In order to solve the problem that in the prior art, related parameters need to be configured automatically in the firewall testing process, so that use is inconvenient, an automatic model generation process and a parameter configuration process are designed, an automatic model generation process and an automatic parameter configuration process are designed, and a time model is a change model of the testing process which changes along with time and is generated according to different testing requirements. The connection model is a model for the change process of the test parameters generated in different stages, automatic configuration of the parameters is achieved through the setting, and the test efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of automated testing technology, and in particular to an automated testing method and system for firewall TCP new creation and concurrent performance. Background Art

[0002] Firewall testing is mainly a test process for the network firewall's processing performance for various types of connections and data requests. It tests the firewall's carrying capacity by creating virtual network traffic. TCP new connection and concurrency are performance tests for network connections at the transport layer, and are the most commonly used transport layer performance indicators proposed in RFC 3511. The TCP new connection rate refers to the maximum rate at which the firewall updates the state table. It reflects the scheduling status of the firewall's CPU resources and reflects the firewall's real-time response capabilities to connection requests. The number of TCP concurrent connections refers to the maximum number of connections that can be established simultaneously between hosts that pass through the firewall or between a host and a firewall. It reflects the firewall's processing status of its business information flow and reflects the firewall's access control capabilities and connection status tracking capabilities for multiple connections.

[0003] For example, Chinese patent CN202011643051.8 discloses a firewall testing method, including controlling the timing of each of the first device and the second device sending a session message in the process of testing the firewall based on the TCP session state, so as to collect the session state of the firewall at different times in the process; controlling the firewall to collect the session state of the firewall at different times in the process, and testing the firewall by comparing the collected session state with the expected state. By controlling the timing of each of the first device and the second device sending a session message, the interaction process of the first device and the second device in the session process is controllable, so that there is enough time to collect the session state of the firewall at different times in the process, so that the intermediate state of the firewall session can be observed and analyzed in real time, solving the problem of inaccurate test results.

[0004] However, during the actual implementation, the inventors found that the configuration process of this type of technical solution is relatively complicated and requires manual initialization configuration, such as setting the IP addresses and packet filtering policies of each interface of the firewall, and configuring the IP addresses of each port of the test tool, setting target values, traffic models and related parameters, which makes it inconvenient to use. Summary of the invention

[0005] In view of the above problems existing in the prior art, an automated testing method for TCP new establishment and concurrent performance of a firewall is now provided;

[0006] On the other hand, an automated testing system for implementing the automated testing method is also provided.

[0007] The specific technical solutions are as follows:

[0008] An automated test method for firewall TCP new establishment and concurrent performance, comprising:

[0009] Step S1: Initialize parameters of the firewall to be tested, and construct a first time model and a first connection model;

[0010] Step S2: creating a first virtual connection based on the first time model and the first connection model, using the first virtual connection to perform a connection rate test on the firewall to be tested, and performing sampling to obtain a connection rate test result.

[0011] Step S3: Initializing parameters of the firewall to be tested, and constructing a second time model and a second connection model;

[0012] Step S4: creating a second virtual connection based on the second time model and the second connection model, using the second virtual connection to perform a concurrent test on the firewall to be tested, and performing sampling to obtain a concurrent test result.

[0013] On the other hand, the step S1 comprises:

[0014] Step S11: Initializing the filtering policy and interface address of the firewall to be tested, and receiving a first test requirement;

[0015] Step S12: constructing the first climbing phase, the first stable phase and the first descending phase of the first time model respectively according to the first test requirement;

[0016] In the first ramp-up phase, the number of data packets generated by the first virtual connection per unit time increases;

[0017] In the first stable phase, the number of data packets generated by the first virtual connection per unit time remains unchanged;

[0018] In the first descending phase, the number of data packets generated by the first virtual connection per unit time decreases;

[0019] Step S13: According to the first test requirement and the first time model, respectively configure the packet flow change rates of the first climbing phase and the first descending phase, and the peak rate of the first stable phase as the first connection model.

[0020] On the other hand, the step S2 comprises:

[0021] Step S21: creating the first virtual connection according to the first climbing stage and the corresponding data packet flow rate change rate and interacting with the firewall to be tested;

[0022] Step S22: after the first climbing phase ends, entering the first stabilization phase and maintaining the peak rate created by the first virtual connection;

[0023] Step S23: sampling the connection status between the client and the server in the first virtual connection to obtain a first sampling result;

[0024] Step S24: calculating the deviation value and the mean value of the first sampling result to obtain the connection rate test result;

[0025] Step S25: Entering the first descending phase, adjusting the first virtual connection according to the corresponding data packet flow rate change and interacting with the firewall to be tested.

[0026] On the other hand, the step S3 comprises:

[0027] Step S31: Initializing the filtering policy and interface address of the firewall to be tested, and receiving a second test requirement;

[0028] Step S32: constructing the second climbing phase, the second stable phase and the second descending phase of the second time model respectively according to the second test requirement;

[0029] In the second ramp-up phase, the number of concurrent connections generated by the second virtual connection per unit time increases;

[0030] In the second stable phase, the number of concurrent connections generated by the second virtual connection per unit time remains unchanged;

[0031] In the second decreasing phase, the number of concurrent connections generated by the second virtual connection per unit time decreases;

[0032] Step S33: According to the second test requirement and the second time model, respectively configure the concurrent connection number change rate of the second climbing phase and the second descending phase, and the peak connection number of the second stable phase as the second connection model.

[0033] On the other hand, the step S4 comprises:

[0034] Step S41: creating the second virtual connection according to the second climbing stage and the corresponding concurrent connection number change rate and interacting with the firewall to be tested;

[0035] Step S42: after the second climbing phase ends, entering the second stable phase and maintaining the peak number of connections created by the second virtual connection;

[0036] Step S43: sampling the connection status between the client and the server in the second virtual connection to obtain a second sampling result;

[0037] Step S44: calculating the deviation value and the mean value of the second sampling result to obtain the concurrent test result;

[0038] Step S45: Entering the second descending phase, adjusting the second virtual connection according to the corresponding concurrent connection number change rate and interacting with the firewall to be tested.

[0039] An automated testing system for TCP new creation and concurrent performance of a firewall, used to implement the automated testing method described above;

[0040] The automated testing system comprises:

[0041] A first initialization module, which performs parameter initialization on the firewall to be tested and constructs a first time model and a first connection model;

[0042] A first testing module, wherein the first testing module is connected to the first initialization module;

[0043] The first test module creates a first virtual connection based on the first time model and the first connection model, uses the first virtual connection to perform a connection rate test on the firewall to be tested, and performs sampling to obtain a connection rate test result.

[0044] A second initialization module, wherein the second initialization module is connected to the first test module;

[0045] The second initialization module initializes parameters of the firewall to be tested, and constructs a second time model and a second connection model;

[0046] A second testing module, wherein the second testing module is connected to the second initialization module;

[0047] The second test module creates a second virtual connection based on the second time model and the second connection model, uses the second virtual connection to perform a concurrent test on the firewall to be tested, and performs sampling to obtain a concurrent test result.

[0048] On the other hand, the first initialization module includes:

[0049] A first firewall control module, which initializes the filtering policy and interface address of the firewall to be tested and receives a first test requirement;

[0050] A first time model configuration module, the first time model configuration module is connected to the first firewall control module;

[0051] The first time model configuration module respectively constructs the first climbing phase, the first stable phase and the first descending phase of the first time model according to the first test requirement;

[0052] In the first ramp-up phase, the number of data packets generated by the first virtual connection per unit time increases;

[0053] In the first stable phase, the number of data packets generated by the first virtual connection per unit time remains unchanged;

[0054] In the first descending phase, the number of data packets generated by the first virtual connection per unit time decreases;

[0055] a first connection model configuration module, the first connection model configuration module being connected to the first time model configuration module;

[0056] The first connection model configuration module configures the packet flow change rates of the first climbing phase and the first descending phase, and the peak rate of the first stable phase as the first connection model according to the first test requirement and the first time model.

[0057] On the other hand, the first test module includes:

[0058] a first connection control module, which creates the first virtual connection and interacts with the firewall to be tested according to the first climbing stage and the corresponding data packet flow rate change rate;

[0059] a second connection control module, wherein the second connection control module is connected to the first connection control module;

[0060] After the first climbing phase ends, the second connection control module enters a first stable phase and maintains the peak rate created by the first virtual connection;

[0061] a first sampling module, wherein the first sampling module is connected to the second connection control module;

[0062] The first sampling module samples the connection status between the client and the server in the first virtual connection to obtain a first sampling result;

[0063] A first sampling calculation module, wherein the first sampling calculation module is connected to the first sampling module;

[0064] The first sampling calculation module calculates the deviation value and the mean value of the first sampling result to obtain the connection rate test result;

[0065] a third connection control module, the third connection control module being connected to the first sampling calculation module;

[0066] The third connection control module enters the first descending phase, adjusts the first virtual connection according to the corresponding data packet flow rate change, and interacts with the firewall to be tested.

[0067] On the other hand, the second initialization module includes:

[0068] A first firewall control module, which initializes the filtering policy and interface address of the firewall to be tested and receives a second test requirement;

[0069] a second time model configuration module, the second time model configuration module being connected to the first firewall control module;

[0070] The second time model configuration module respectively constructs the second climbing phase, the second stable phase and the second descending phase of the second time model according to the second test requirement;

[0071] In the second ramp-up phase, the number of concurrent connections generated by the second virtual connection per unit time increases;

[0072] In the second stable phase, the number of concurrent connections generated by the second virtual connection per unit time remains unchanged;

[0073] In the second decreasing phase, the number of concurrent connections generated by the second virtual connection per unit time decreases;

[0074] a second connection model configuration module, wherein the second connection model configuration module is connected to the second time model configuration module;

[0075] The second connection model configuration module configures the concurrent connection number change rate in the second climbing phase and the second descending phase, and the peak connection number in the second stable phase as the second connection model according to the second test requirement and the second time model.

[0076] On the other hand, the second test module comprises:

[0077] a fourth connection control module, wherein the fourth connection control module creates the second virtual connection according to the second climbing stage and the corresponding concurrent connection number change rate and interacts with the firewall to be tested;

[0078] a fifth connection control module, the fifth connection control module being connected to the fourth connection control module;

[0079] After the second climbing phase ends, the fifth connection control module enters a second stable phase and maintains the peak number of connections created by the second virtual connection;

[0080] a second sampling module, wherein the second sampling module is connected to the fifth connection control module;

[0081] The second sampling module samples the connection status between the client and the server in the second virtual connection to obtain a second sampling result;

[0082] A second sampling calculation module, wherein the second sampling calculation module is connected to the second sampling module;

[0083] The second sampling calculation module calculates the deviation value and the mean value of the second sampling result to obtain the concurrent test result;

[0084] a sixth connection control module, the sixth connection control module being connected to the second sampling calculation module;

[0085] The sixth connection control module enters the second descending phase, adjusts the second virtual connection according to the corresponding concurrent connection number change rate, and interacts with the firewall to be tested.

[0086] The above technical solution has the following advantages or beneficial effects:

[0087] In view of the problem that the firewall testing process in the prior art requires self-configuration of relevant parameters, which causes inconvenience in use, in this solution, automated model generation process and parameter configuration process are designed for the two test processes of connection rate and concurrent connection number, respectively. Among them, the time model is a changing model of the test process that changes over time generated for different test requirements, and the connection model is a model of the changing process of test parameters generated at different stages. The above settings are used to realize automatic configuration of parameters and improve test efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0088] The embodiments of the present invention will be described more fully with reference to the attached drawings, which are provided for illustration and description only and are not intended to limit the scope of the present invention.

[0089] Figure 1 It is an overall schematic diagram of an embodiment of the present invention;

[0090] Figure 2 This is a schematic diagram of step S1 in an embodiment of the present invention;

[0091] Figure 3 This is a schematic diagram of step S2 in an embodiment of the present invention;

[0092] Figure 4This is a schematic diagram of step S3 in an embodiment of the present invention;

[0093] Figure 5 This is a schematic diagram of step S4 in an embodiment of the present invention;

[0094] Figure 6 A schematic diagram of a system in an embodiment of the present invention;

[0095] Figure 7 This is a schematic diagram of a first initialization module in an embodiment of the present invention;

[0096] Figure 8 This is a schematic diagram of a first test module in an embodiment of the present invention;

[0097] Fig. 9 This is a schematic diagram of a second initialization module in an embodiment of the present invention;

[0098] Fig.10 Schematic diagram of the second test module in an embodiment of the present invention. DETAILED DESCRIPTION

[0099] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0100] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.

[0101] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, but they are not intended to limit the present invention.

[0102] The present invention comprises:

[0103] An automated test method for firewall TCP new establishment and concurrent performance, such as Figure 1 As shown, including:

[0104] Step S1: Initialize parameters of the firewall to be tested, and construct a first time model and a first connection model;

[0105] Step S2: creating a first virtual connection based on the first time model and the first connection model, using the first virtual connection to perform a connection rate test on the firewall to be tested, and performing sampling to obtain a connection rate test result.

[0106] Step S3: Initializing parameters of the firewall to be tested, and constructing a second time model and a second connection model;

[0107] Step S4: creating a second virtual connection based on the second time model and the second connection model, using the second virtual connection to perform a concurrent test on the firewall to be tested, and performing sampling to obtain a concurrent test result.

[0108] Specifically, in order to solve the problem that the firewall testing process in the prior art requires self-configuration of relevant parameters, which causes inconvenience in use, in this solution, automated model generation process and parameter configuration process are designed for the two testing processes of connection rate and number of concurrent connections respectively.

[0109] Specifically, the test process of the firewall to be tested involves the test process of two performances, the maximum connection rate and the maximum number of concurrent connections. For these two test processes, this embodiment introduces two test steps that are performed successively.

[0110] In each test step, the firewall is first configured through the configuration file, and its port and other information are modified to the default state. Then, the time model and connection model are constructed respectively according to the test requirements.

[0111] The time model is a time-varying model configured for the overall test process. It is used to characterize the changes in test parameters, such as real-time traffic or real-time concurrent numbers, in different test time periods.

[0112] The connection model is built based on the above-mentioned changing requirements and can be used to build relevant configuration files of virtual connections, including data packet examples, message types, IP pools, and valid port information, etc.

[0113] According to the above two parts of information, a virtual connection can be created during the test. The virtual connection includes creating at least one pair of client and server for interaction according to the relevant parameters provided in the connection model, including IP addresses, messages, etc. The client and server are located on both sides of the firewall to be tested.

[0114] During the test process, virtual connections are created according to the connection model, and the parameters of the virtual connections at multiple test time nodes are controlled according to the time model, including the number of data packets generated, the number of concurrent connections, etc., so as to realize the test process.

[0115] In one embodiment, Figure 2 As shown, step S1 includes:

[0116] Step S11: Initialize the filtering policy and interface address of the firewall to be tested, and receive the first test requirement;

[0117] Step S12: constructing the first climbing phase, the first stable phase and the first descending phase of the first time model respectively according to the first test requirement;

[0118] In the first ramp-up phase, the number of data packets generated by the first virtual connection per unit time increases;

[0119] In the first stable phase, the number of data packets generated by the first virtual connection per unit time remains unchanged;

[0120] In the first descending phase, the number of data packets generated by the first virtual connection per unit time decreases;

[0121] Step S13: According to the first test requirement and the first time model, the packet flow change rates of the first climbing phase and the first descending phase, and the peak rate of the first stable phase are respectively configured as the first connection model.

[0122] Specifically, in order to achieve a better configuration effect, in this embodiment, after receiving the first test requirement corresponding to the connection rate test, the firewall to be tested is firstly subjected to the first test requirement, and the time length of each stage of the first climbing stage, the first stable stage and the first descending stage of the first time model is respectively constructed based on the first test requirement;

[0123] Then, for the first time model, first configure the virtual connection parameters between the client and the server in the virtual connection, and then combine the first test requirements and the first time model to configure the packet flow change rate of the first climbing phase and the first descending phase, as well as the peak rate of the first stable phase as a complete first connection model.

[0124] Specifically, during the initialization of the firewall to be tested, the policy and session are first cleared;

[0125] Then set the address FW_IP1 of interface 1, preferably 192.168.11.1 / 24, and set the address FW_IP2 of interface 2, preferably 192.168.12.1 / 24;

[0126] Finally, set the packet filtering policy to bidirectional full pass and disable the attack protection policy;

[0127] For the first climbing stage and the first descending stage, a 30-second ascending and descending cycle is usually configured to avoid large jitters, while for the first stable stage, a longer cycle, such as 180 seconds, can be configured to achieve a better sampling process.

[0128] For the first connection model, the interaction process between the server and the client is first agreed upon, including:

[0129] a) The client IP address is Client_IP (same network segment as FW_IP1, preferably a random value between 192.168.11.2 and 192.168.11.254)

[0130] b) The client port is Client_Port (preferably a random value between 1 and 65535)

[0131] c) The server IP address is Server_IP (same network segment as FW_IP2, preferably a random value between 192.168.12.2 and 192.168.12.254)

[0132] d) The server port is Server_Port (preferably a random value between 1 and 65535)

[0133] e) The client and the server establish a TCP connection through a three-way handshake

[0134] f) The Client sends RST to close the TCP connection.

[0135] Then, the first connection model is constructed as follows in combination with the first time model:

[0136] a) During the RampUP_Time period, TCP connection model traffic is initiated from the Client to the Server, and the rate increases linearly from 0 to R (1+10%) (the result value may fluctuate during the test, so the actual test target value is increased by a certain value, preferably 10%, to ensure that all results during the test are not less than R)

[0137] b) During the SteadyState_Time period in the stable phase, TCP connection model traffic is initiated from the Client to the Server, and the rate is R (1+10%) and remains unchanged.

[0138] c) During the RampDown_Time period in the descending phase, the TCP connection model traffic is initiated from the Client to the Server, and the rate decreases linearly from R (1+10%) to 0

[0139] In one embodiment, Figure 3 As shown, step S2 includes:

[0140] Step S21: creating a first virtual connection according to the first climbing stage and the corresponding data packet flow rate change rate and interacting with the firewall to be tested;

[0141] Step S22: after the first climbing phase is over, entering the first stabilization phase and maintaining the peak rate of the first virtual connection creation;

[0142] Step S23: sampling the connection status between the client and the server in the first virtual connection to obtain a first sampling result;

[0143] Step S24: Calculate the deviation value and the mean value of the first sampling result to obtain a connection rate test result;

[0144] Step S25: Entering the first descending phase, adjusting the first virtual connection according to the corresponding data packet flow rate change and interacting with the firewall to be tested.

[0145] Specifically, in order to achieve a better test process, in this embodiment, the above test process is constructed and sampling is performed in the stable phase. In the sampling process, a corresponding sampling formula is also designed to achieve a better evaluation effect.

[0146] Specifically, in order to better simulate the load change process of the firewall, first in the first climbing stage, according to the corresponding packet flow change rate, a first virtual connection is created and interacted with the firewall to be tested, so that a predetermined number of packets pass through the firewall to be tested in turn to the server on the other side. When the flow climbs to the peak rate and the first climbing stage ends, it enters the first stable stage and maintains the peak rate created by the first virtual connection.

[0147] Then, the connection status between the client and the server in the first virtual connection is sampled. The sampling content mainly includes the number of TCP connections that successfully complete an interaction cycle between the client and the server, including establishing a connection, handshaking, and disconnecting after the interaction ends, which is denoted as r, and is collected at a specific sampling frequency.

[0148] Before the test begins, the corresponding expected number of connections has been pre-configured, denoted as R. For each sampling process, the deviation rate between each sampling value and the test target value is calculated:

[0149] D=|rR(1+10%)| / [R(1+10%)];

[0150] In the formula, D is the deviation rate, R is the expected number of connections, and r is the number of sampled TCP connections;

[0151] Subsequently, after the first stable phase, the arithmetic mean of all sampling values ​​r is calculated and the deviation rate is measured. When the deviation rate is not higher than the threshold, such as 5%, the current test result is considered valid and the arithmetic mean of the sampling values ​​is output as the connection rate test result.

[0152] In some embodiments, the above test results may be repeated multiple times to obtain an averaged connection rate test result output.

[0153] In one embodiment, Figure 4 As shown, step S3 includes:

[0154] Step S31: Initialize the filtering policy and interface address of the firewall to be tested, and receive the second test requirement;

[0155] Step S32: constructing the second climbing phase, the second stable phase and the second descending phase of the second time model respectively according to the second test requirement;

[0156] In the second ramp-up phase, the number of concurrent connections generated by the second virtual connection per unit time increases;

[0157] In the second stable stage, the number of concurrent connections generated by the second virtual connection per unit time remains unchanged;

[0158] In the second decreasing phase, the number of concurrent connections generated by the second virtual connection per unit time decreases;

[0159] Step S33: According to the second test requirement and the second time model, respectively configure the concurrent connection number change rate in the second climbing phase and the second descending phase, and the peak connection number in the second stable phase as the second connection model.

[0160] Specifically, in order to achieve a better configuration effect, in this embodiment, first, after receiving the second test requirement corresponding to the concurrent connection number test, the time length of each stage of the second climbing stage, the second stable stage and the second descending stage of the second time model is respectively constructed based on the second test requirement for the firewall to be tested;

[0161] Then, for the second time model, first configure the virtual connection parameters between the client and the server in the virtual connection, and then, in combination with the second test requirements and the second time model, respectively configure the packet flow change rate of the second climbing phase and the second descending phase, and the peak rate of the second stable phase as a complete second connection model.

[0162] Specifically, during the initialization of the firewall to be tested, the policy and session are first cleared;

[0163] Then, for the second climbing stage and the second descending stage, a 30-second ascending and descending cycle is usually configured to avoid large jitters, while for the second stabilizing stage, a longer cycle, such as 180 seconds, can be configured to achieve a better sampling process.

[0164] In addition, in some embodiments, during the execution of step S2, the connection success rate in the first climbing stage is also counted and compared with the connection success rate threshold;

[0165] When the connection success rate is less than the connection success rate threshold, adjust the duration of the second ramp-up phase, configure the expected number of valid connections C, and then calculate the time to select the larger of C(1+10%) / R and 30 seconds. The result value may fluctuate during the test, so the actual test target value is increased by a certain value, preferably 10%, to ensure that all valid connections during the test are not less than C.

[0166] For the second connection model, the interaction process between the server and the client is first agreed upon, including:

[0167] a) The client IP address is Client_IP (same network segment as FW_IP1, preferably a random value between 192.168.11.2 and 192.168.11.254)

[0168] b) The client port is Client_Port (preferably a random value between 1 and 65535)

[0169] c) The server IP address is Server_IP (same network segment as FW_IP2, preferably a random value between 192.168.12.2 and 192.168.12.254)

[0170] d) The server port is Server_Port (preferably a random value between 1 and 65535)

[0171] e) The client and the server establish a TCP connection through a three-way handshake

[0172] f) Keep the TCP connection open.

[0173] Then, the second connection model is constructed as follows in combination with the second time model:

[0174] a) During the RampUP_Time period, the TCP connection model traffic is initiated from the Client to the Server at a rate of R(1+10%) (ensuring that even if jitter occurs, it can reach C(1+10%)); when the number of concurrent TCP connections reaches C(1+10%), the rate drops to 0

[0175] b) During the SteadyState_Time period in the stable phase, the rate of TCP connection model traffic initiated from the client to the server is 0

[0176] c) During the RampDown_Time period in the descending phase, the established TCP connections between the client and the server are closed until the number of concurrent TCP connections reaches 0.

[0177] In one embodiment, Figure 5 As shown, step S4 includes:

[0178] Step S41: creating a second virtual connection according to the second climbing stage and the corresponding concurrent connection number change rate and interacting with the firewall to be tested;

[0179] Step S42: after the second climbing phase ends, entering the second stable phase and maintaining the peak number of connections created by the second virtual connection;

[0180] Step S43: sampling the connection status between the client and the server in the second virtual connection to obtain a second sampling result;

[0181] Step S44: Calculate the deviation value and the mean value of the second sampling result to obtain a concurrent test result;

[0182] Step S45: Entering the second descending phase, adjusting the second virtual connection according to the corresponding concurrent connection number change rate and interacting with the firewall to be tested.

[0183] Specifically, in order to achieve a better test process, in this embodiment, the above test process is constructed and sampling is performed in the stable phase. In the sampling process, a corresponding sampling formula is also designed to achieve a better evaluation effect.

[0184] Specifically, in order to better simulate the load change process of the firewall, first in the second climbing stage, according to the corresponding concurrent connection number change rate, a second virtual connection is created and interacted with the firewall to be tested, and concurrent connections are established with the server through the firewall to be tested in turn. When the number of concurrent connections passing through at the same time reaches the peak number of connections and the second climbing stage ends, it enters the second stable stage and maintains the peak number of connections created by the second virtual connection.

[0185] Then, the connection status between the client and the server in the second virtual connection is sampled. The sampling content mainly includes the number of TCP connections that successfully complete an interaction cycle between the client and the server at the same time, including establishing a connection, handshaking, and disconnecting after the interaction ends, which is denoted as c and collected at a specific sampling frequency.

[0186] Then, the deviation rate of each sampling value from the target value is calculated:

[0187] D=|cC(1+10%)| / [C(1+10%)];

[0188] In the formula, D is the deviation rate, c is the number of successful concurrent connections, and C is the expected number of concurrent connections.

[0189] Then, the number of successful concurrent connections is averaged to obtain the test result.

[0190] An automated testing system for TCP new creation and concurrent performance of a firewall, used to implement the automated testing method described above;

[0191] like Figure 6 As shown, the automated testing system includes:

[0192] A first initialization module 1, the first initialization module 1 initializes parameters of the firewall to be tested, and constructs a first time model and a first connection model;

[0193] A first test module 2, the first test module 2 is connected to the first initialization module 1;

[0194] The first test module 2 creates a first virtual connection based on the first time model and the first connection model, uses the first virtual connection to perform a connection rate test on the firewall to be tested, and performs sampling to obtain a connection rate test result.

[0195] A second initialization module 3, the second initialization module 3 is connected to the first test module 2;

[0196] The second initialization module 3 performs parameter initialization on the firewall to be tested, and constructs a second time model and a second connection model;

[0197] A second testing module 4, the second testing module 4 is connected to the second initialization module 3;

[0198] The second testing module 4 creates a second virtual connection based on the second time model and the second connection model, uses the second virtual connection to perform a concurrent test on the firewall to be tested, and performs sampling to obtain a concurrent test result.

[0199] In one embodiment, Figure 7 As shown, the first initialization module 1 includes:

[0200] A first firewall control module 11, which initializes the filtering policy and interface address of the firewall to be tested, and receives a first test requirement;

[0201] A first time model configuration module 12, the first time model configuration module 12 is connected to the first firewall control module 11;

[0202] The first time model configuration module 12 constructs the first climbing phase, the first stable phase and the first descending phase of the first time model respectively according to the first test requirement;

[0203] In the first ramp-up phase, the number of data packets generated by the first virtual connection per unit time increases;

[0204] In the first stable phase, the number of data packets generated by the first virtual connection per unit time remains unchanged;

[0205] In the first descending phase, the number of data packets generated by the first virtual connection per unit time decreases;

[0206] A first connection model configuration module 13, the first connection model configuration module 13 is connected to the first time model configuration module 12;

[0207] The first connection model configuration module 13 configures the packet flow change rates of the first climbing phase and the first descending phase, and the peak rate of the first stable phase as the first connection model according to the first test requirement and the first time model.

[0208] In one embodiment, Figure 8 As shown, the first test module 2 includes:

[0209] A first connection control module 21, the first connection control module 21 creates a first virtual connection according to the first climbing stage and the corresponding data packet flow rate change rate and interacts with the firewall to be tested;

[0210] A second connection control module 22, the second connection control module 22 is connected to the first connection control module 21;

[0211] After the first climbing phase ends, the second connection control module 22 enters the first stable phase and maintains the peak rate of the first virtual connection creation;

[0212] A first sampling module 23, the first sampling module 23 is connected to the second connection control module 22;

[0213] The first sampling module 23 samples the connection status between the client and the server in the first virtual connection to obtain a first sampling result;

[0214] A first sampling calculation module 24, the first sampling calculation module 24 is connected to the first sampling module 23;

[0215] The first sampling calculation module 24 calculates the deviation value and the mean value of the first sampling result to obtain the connection rate test result;

[0216] A third connection control module 25, the third connection control module 25 is connected to the first sampling calculation module 24;

[0217] The third connection control module 25 enters the first descending phase, adjusts the first virtual connection according to the corresponding data packet flow rate change and interacts with the firewall to be tested.

[0218] In one embodiment, Fig. 9 As shown, the second initialization module 3 includes:

[0219] A second firewall control module 31, which initializes the filtering policy and interface address of the firewall to be tested, and receives a second test requirement;

[0220] A second time model configuration module 32, the second time model configuration module 32 is connected to the first firewall control module 31;

[0221] The second time model configuration module 32 constructs the second climbing phase, the second stable phase and the second descending phase of the second time model according to the second test requirement;

[0222] In the second ramp-up phase, the number of concurrent connections generated by the second virtual connection per unit time increases;

[0223] In the second stable stage, the number of concurrent connections generated by the second virtual connection per unit time remains unchanged;

[0224] In the second decreasing phase, the number of concurrent connections generated by the second virtual connection per unit time decreases;

[0225] A second connection model configuration module 33, the second connection model configuration module 33 is connected to the second time model configuration module 32;

[0226] The second connection model configuration module 33 configures the concurrent connection number change rate in the second climbing phase and the second descending phase, and the peak connection number in the second stable phase as the second connection model according to the second test requirement and the second time model.

[0227] In one embodiment, Fig.10 As shown, the second test module 4 includes:

[0228] A fourth connection control module 41, the fourth connection control module 41 creates a second virtual connection according to the second climbing stage and the corresponding concurrent connection number change rate and interacts with the firewall to be tested;

[0229] A fifth connection control module 42, the fifth connection control module 42 is connected to the fourth connection control module 41;

[0230] After the second climbing phase ends, the fifth connection control module 42 enters the second stable phase and maintains the peak number of connections created by the second virtual connection;

[0231] A second sampling module 43, the second sampling module 43 is connected to the fifth connection control module 42;

[0232] The second sampling module 43 samples the connection status between the client and the server in the second virtual connection to obtain a second sampling result;

[0233] A second sampling calculation module 44, the second sampling calculation module 44 is connected to the second sampling module 43;

[0234] The second sampling calculation module 44 calculates the deviation value and the mean value of the second sampling result to obtain the concurrent test result;

[0235] A sixth connection control module 45, the sixth connection control module 45 is connected to the second sampling calculation module 44;

[0236] The sixth connection control module 45 enters the second descending phase, adjusts the second virtual connection according to the corresponding concurrent connection number change rate, and interacts with the firewall to be tested.

[0237] The above are only preferred embodiments of the present invention, and are not intended to limit the implementation methods and protection scope of the present invention. Those skilled in the art should be aware that all solutions obtained by equivalent substitutions and obvious changes made using the description and illustrations of the present invention should be included in the protection scope of the present invention.

Claims

1. An automated test method for TCP new creation and concurrent performance of a firewall, characterized in that: include: Step S1: Initialize parameters of the firewall to be tested, and construct a first time model and a first connection model; Step S2: creating a first virtual connection based on the first time model and the first connection model, using the first virtual connection to perform a connection rate test on the firewall to be tested, and performing sampling to obtain a connection rate test result; Step S3: Initializing parameters of the firewall to be tested, and constructing a second time model and a second connection model; Step S4: creating a second virtual connection based on the second time model and the second connection model, using the second virtual connection to perform a concurrent test on the firewall to be tested, and performing sampling to obtain a concurrent test result.

2. The automated testing method according to claim 1, characterized in that: The step S1 comprises: Step S11: Initializing the filtering policy and interface address of the firewall to be tested, and receiving a first test requirement; Step S12: constructing the first climbing phase, the first stable phase and the first descending phase of the first time model respectively according to the first test requirement; In the first ramp-up phase, the number of data packets generated by the first virtual connection per unit time increases; In the first stable phase, the number of data packets generated by the first virtual connection per unit time remains unchanged; In the first descending phase, the number of data packets generated by the first virtual connection per unit time decreases; Step S13: According to the first test requirement and the first time model, respectively configure the packet flow change rates of the first climbing phase and the first descending phase, and the peak rate of the first stable phase as the first connection model.

3. The automated testing method according to claim 2, characterized in that: The step S2 comprises: Step S21: creating the first virtual connection according to the first climbing stage and the corresponding data packet flow rate change rate and interacting with the firewall to be tested; Step S22: after the first climbing phase ends, entering the first stabilization phase and maintaining the peak rate created by the first virtual connection; Step S23: sampling the connection status between the client and the server in the first virtual connection to obtain a first sampling result; Step S24: calculating the deviation value and the mean value of the first sampling result to obtain the connection rate test result; Step S25: Entering the first descending phase, adjusting the first virtual connection according to the corresponding data packet flow rate change and interacting with the firewall to be tested.

4. The automated testing method according to claim 1, characterized in that: The step S3 comprises: Step S31: Initializing the filtering policy and interface address of the firewall to be tested, and receiving a second test requirement; Step S32: constructing the second climbing phase, the second stable phase and the second descending phase of the second time model respectively according to the second test requirement; In the second ramp-up phase, the number of concurrent connections generated by the second virtual connection per unit time increases; In the second stable phase, the number of concurrent connections generated by the second virtual connection per unit time remains unchanged; In the second decreasing phase, the number of concurrent connections generated by the second virtual connection per unit time decreases; Step S33: According to the second test requirement and the second time model, respectively configure the concurrent connection number change rate of the second climbing phase and the second descending phase, and the peak connection number of the second stable phase as the second connection model.

5. The automated testing method according to claim 4, characterized in that: The step S4 comprises: Step S41: creating the second virtual connection according to the second climbing stage and the corresponding concurrent connection number change rate and interacting with the firewall to be tested; Step S42: after the second climbing phase ends, entering the second stable phase and maintaining the peak number of connections created by the second virtual connection; Step S43: sampling the connection status between the client and the server in the second virtual connection to obtain a second sampling result; Step S44: calculating the deviation value and the mean value of the second sampling result to obtain the concurrent test result; Step S45: Entering the second descending phase, adjusting the second virtual connection according to the corresponding concurrent connection number change rate and interacting with the firewall to be tested.

6. An automated test system for TCP creation and concurrent performance of a firewall, characterized in that: Used to implement the automated testing method according to any one of claims 1 to 5; The automated testing system comprises: A first initialization module, which performs parameter initialization on the firewall to be tested and constructs a first time model and a first connection model; A first testing module, wherein the first testing module is connected to the first initialization module; The first test module creates a first virtual connection based on the first time model and the first connection model, uses the first virtual connection to perform a connection rate test on the firewall to be tested, and performs sampling to obtain a connection rate test result; A second initialization module, wherein the second initialization module is connected to the first test module; The second initialization module initializes parameters of the firewall to be tested, and constructs a second time model and a second connection model; A second testing module, wherein the second testing module is connected to the second initialization module; The second test module creates a second virtual connection based on the second time model and the second connection model, uses the second virtual connection to perform a concurrent test on the firewall to be tested, and performs sampling to obtain a concurrent test result.

7. The automated testing system according to claim 6, characterized in that: The first initialization module includes: A first firewall control module, which initializes the filtering policy and interface address of the firewall to be tested and receives a first test requirement; A first time model configuration module, the first time model configuration module is connected to the first firewall control module; The first time model configuration module respectively constructs the first climbing phase, the first stable phase and the first descending phase of the first time model according to the first test requirement; In the first ramp-up phase, the number of data packets generated by the first virtual connection per unit time increases; In the first stable phase, the number of data packets generated by the first virtual connection per unit time remains unchanged; In the first descending phase, the number of data packets generated by the first virtual connection per unit time decreases; a first connection model configuration module, the first connection model configuration module being connected to the first time model configuration module; The first connection model configuration module configures the packet flow change rates of the first climbing phase and the first descending phase, and the peak rate of the first stable phase as the first connection model according to the first test requirement and the first time model.

8. The automated testing system according to claim 7, characterized in that: The first test module includes: a first connection control module, which creates the first virtual connection and interacts with the firewall to be tested according to the first climbing stage and the corresponding data packet flow rate change rate; a second connection control module, wherein the second connection control module is connected to the first connection control module; After the first climbing phase ends, the second connection control module enters a first stable phase and maintains the peak rate created by the first virtual connection; a first sampling module, wherein the first sampling module is connected to the second connection control module; The first sampling module samples the connection status between the client and the server in the first virtual connection to obtain a first sampling result; A first sampling calculation module, wherein the first sampling calculation module is connected to the first sampling module; The first sampling calculation module calculates the deviation value and the mean value of the first sampling result to obtain the connection rate test result; a third connection control module, the third connection control module being connected to the first sampling calculation module; The third connection control module enters the first descending phase, adjusts the first virtual connection according to the corresponding data packet flow rate change, and interacts with the firewall to be tested.

9. The automated testing system according to claim 6, characterized in that: The second initialization module includes: A second firewall control module, which initializes the filtering policy and interface address of the firewall to be tested and receives a second test requirement; A second time model configuration module, the second time model configuration module is connected to the second firewall control module; The second time model configuration module respectively constructs the second climbing phase, the second stable phase and the second descending phase of the second time model according to the second test requirement; In the second ramp-up phase, the number of concurrent connections generated by the second virtual connection per unit time increases; In the second stable phase, the number of concurrent connections generated by the second virtual connection per unit time remains unchanged; In the second decreasing phase, the number of concurrent connections generated by the second virtual connection per unit time decreases; a second connection model configuration module, wherein the second connection model configuration module is connected to the second time model configuration module; The second connection model configuration module configures the concurrent connection number change rate in the second climbing phase and the second descending phase, and the peak connection number in the second stable phase as the second connection model according to the second test requirement and the second time model.

10. The automated testing system according to claim 9, characterized in that: The second test module includes: a fourth connection control module, wherein the fourth connection control module creates the second virtual connection according to the second climbing stage and the corresponding concurrent connection number change rate and interacts with the firewall to be tested; a fifth connection control module, the fifth connection control module being connected to the fourth connection control module; After the second climbing phase ends, the fifth connection control module enters a second stable phase and maintains the peak number of connections created by the second virtual connection; a second sampling module, wherein the second sampling module is connected to the fifth connection control module; The second sampling module samples the connection status between the client and the server in the second virtual connection to obtain a second sampling result; A second sampling calculation module, wherein the second sampling calculation module is connected to the second sampling module; The second sampling calculation module calculates the deviation value and the mean value of the second sampling result to obtain the concurrent test result; a sixth connection control module, the sixth connection control module being connected to the second sampling calculation module; The sixth connection control module enters the second descending phase, adjusts the second virtual connection according to the corresponding concurrent connection number change rate, and interacts with the firewall to be tested.

Citation Information

Patent Citations

  • A firewall testing method, apparatus, electronic device, and storage medium

    CN112804220B