Method for isolating communications of a configuration system from a test network isolated test bed
By separating the configuration network and test network in a tree structure within the network testbed, using different network interfaces and segments, and deploying traffic control strategies, the problem of secure isolation communication between the configuration system and the test network is solved. This achieves real-time, low-latency, and low-cost isolated communication, avoiding the spread of malicious traffic and interference with test tasks.
Patent Information
- Application Number
- CN202511262226.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Existing technologies for secure isolation communication between the configuration system and the test network in network testbeds suffer from problems such as complex implementation, high latency, high cost, poor scalability, and interference with test tasks. In particular, when facing malware attacks, malicious traffic can easily spread and affect the configuration system.
A tree-structured configuration network is used, connecting test network devices through firewalls, Ethernet switches, and serial switches. Different network interfaces and network segments are used for isolation, and traffic control policies are deployed to ensure that configuration data and test task traffic are separated. Configuration data is transmitted through the configuration network to prevent the spread of malicious traffic.
It enables real-time communication between the configuration system and the test network under secure isolation, preventing the spread of malicious traffic, reducing latency, supporting multi-task concurrency, without changing the test network topology, without requiring the installation of proxy software on the test equipment, and at a low cost.
Smart Images

Figure CN120811765B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method for isolating communication between a network testbed and a configuration system. Background Technology
[0002] Network testbeds are essential tools for network technology research, new product development, and the testing and verification of network infrastructure. To support a wide variety of testing tasks, network testbeds should possess flexible configuration capabilities. This means they should be able to flexibly configure various parameters, policies, and rules within the test network, such as network segments, IP addresses, VLANs, routing policies, and firewall rules, according to the needs of the testing task. To achieve this flexible configuration capability, the network testbed's configuration system should have a network connection to the test network devices to issue configuration commands. Furthermore, during the testing process, to control and direct the tasks, the configuration system and the test network devices should maintain constant network communication to support the real-time issuance of configuration commands.
[0003] However, when testing tasks involve network attacks or malware such as viruses, Trojans, and worms, the malicious traffic generated by these attacks or malware not only affects the test network devices but may also spread through network connections, impacting the configuration system and causing it to malfunction, potentially leading to test task failure. When multiple test tasks are running simultaneously on a network testbed, malicious traffic may also spread from one test network to another through the network channel between the test network and the configuration system, interfering with the test tasks. Therefore, enabling configuration protocol communication between the configuration system and the test network under secure isolation is of significant importance and practical value for network testbeds.
[0004] Several network security isolation and data exchange methods have been proposed in the industry. For example, the publicly available technical document "A Domestic Network Security Isolation and One-Way Import System and Method" (Authorization Announcement No. CN108449310B) proposes a network security isolation and one-way import method using a one-way fiber optic connection and a domestic Shenwei processor. By severing TCP / IP protocol communication, it achieves one-way import of network data and compliance checks. "A Network Security Isolation Device and Method with One-Way Import Function" (Authorization Announcement No. CN111556062B) proposes a method that strips data from network protocols in network packets and assembles the data into internal packets according to a preset private protocol format, achieving one-way import of network data and compliance checks. "A Network Security Isolation System" (Authorization Announcement No. CN114640497B) proposes a network security isolation system based on authentication certificates and trap servers, performing different security processing based on whether the access request has an authentication certificate. The document "Software-Defined Network Data Isolation and Exchange Method" (authorization announcement number CN109936541B) proposes a data isolation and exchange method based on software-defined network technology. By extracting the application identifier and management control layer policy set from the data exchange request, it enables data exchange services that can be customized on demand according to user needs.
[0005] Compared with the configuration system of the network testbed and the security isolation communication requirements of the test network, existing methods mainly have the following problems:
[0006] (1) The configuration system and the test network often communicate bidirectionally through configuration protocols such as Telnet, SSH, and SNMP. If a data isolation and exchange method that separates data from the network protocol and imports it in one direction is adopted, the system implementation will often become complicated in order to support bidirectional communication, and the exchange delay will be large, making it difficult to meet the real-time requirements of issuing configuration commands.
[0007] (2) Some data isolation and exchange methods also require the installation of supporting agent software on the test network equipment to realize functions such as identity authentication and application / protocol identification, which leads to changes in the status of the test network equipment and interferes with the test task.
[0008] (3) If security devices such as network gateways are used for logical isolation between the configuration system and the test network, the number of test network devices that can be supported is limited due to the limited number of network interfaces of the security devices. When applied to large-scale network test beds, the cost is high and the scalability is poor.
[0009] (4) If network devices such as switches and firewalls are used between the configuration system and the test network, and software-defined networking technology and firewall rules are used for logical isolation, when these switches and firewalls are visible to the test network devices, it is easy to cause changes in the test network topology and interfere with the test tasks. Summary of the Invention
[0010] To address the aforementioned issues, this invention proposes a network testbed isolation communication method that separates the configuration system from the test network, enabling the configuration system to issue configuration commands to the test network devices via network connection during the testing process.
[0011] The technical solution adopted in this invention is as follows:
[0012] A network testbed with a separate configuration system and test network includes a configuration system, a configuration network, M test network devices, and N test networks, where M and N are positive integers;
[0013] The configuration system configures network connections to test network devices and transmits configuration data.
[0014] The test network connects to test network devices and transmits test task traffic.
[0015] Furthermore, the configuration network includes a firewall, Ethernet switches, and serial switches; multiple Ethernet switches are interconnected in a tree structure, which includes a root node switch and several leaf node switches; one side of the firewall is connected to the configuration system, and the other side is connected to the root node switch, while the leaf node switches are connected to the test network device via serial switches or directly.
[0016] A network testbed isolation communication method, comprising:
[0017] Different devices are used to connect the configuration network and the test network.
[0018] The test network devices use different network interfaces to transmit configuration data and test task traffic respectively;
[0019] The configuration network and the test network use different network segments, and the IP addresses of the device interfaces of the two are isolated from each other;
[0020] Configure traffic control policies in the network so that configuration data can be transmitted through the network, but test task traffic cannot be spread to the network through the test network devices.
[0021] Furthermore, the test network device uses different network interfaces to transmit configuration data and test task traffic respectively, including:
[0022] The test network device connects to the configuration network through a configuration interface to transmit configuration data; the configuration interface includes an Ethernet interface and a console interface.
[0023] The test network device connects to the test network through the test task interface to transmit test task traffic.
[0024] Furthermore, the method for setting the configuration interface includes:
[0025] When a device has a console interface or Ethernet interface for device management, the console interface or Ethernet interface can be used as a configuration interface.
[0026] When a device does not have a console interface or Ethernet interface for device management, but has multiple ordinary Ethernet interfaces that can communicate externally, one of the ordinary Ethernet interfaces will be used as the configuration interface.
[0027] When a device does not have a console interface or Ethernet interface for device management, and only has a regular Ethernet interface that can communicate externally, a new Ethernet interface can be added by adding an Ethernet adapter, and the newly added Ethernet interface can be used as a configuration interface.
[0028] When a device has a console interface for device management, an Ethernet interface, and multiple ordinary Ethernet interfaces, the selection is made according to a preset priority. The preset priority includes: console interface for device management > Ethernet interface for device management > ordinary Ethernet interface.
[0029] Furthermore, the configuration network and the test network use different network segments, and their device interface IP addresses are isolated from each other, including:
[0030] When a network testbed supports multiple test tasks, each test task has its own test network. The network segment of the test network and the test task interface IP addresses of each device in the test network are flexibly allocated according to the requirements of the test task and are only valid within the lifecycle of the corresponding test task. When the test task ends, the test task interface IP addresses of these devices are reset to prepare for participation in the next test task.
[0031] Configure the network segment to be different from the test network of each task, and keep it fixed. The configuration interface IP address of each device also remains unchanged. When the test network device uses an Ethernet interface as the configuration interface, directly configure a fixed IP address for the Ethernet configuration interface of the test network device. When the test network device uses a console interface as the configuration interface, configure a fixed configuration interface IP address for the test network device on the serial switch connected to the test network device in the configuration network, so that the configuration system can communicate with the test network device.
[0032] Furthermore, the traffic control policy deployed in the configured network is implemented based on preset parameters, which include source IP address, destination IP address, source port number, destination port number, and protocol type.
[0033] Furthermore, the traffic control policies deployed in the configured network include:
[0034] When both the source node and the destination node are test network devices, they are not allowed to communicate with each other.
[0035] When one of the communication source node and the destination node is a test network device and the other is a configuration system, if the source port number, destination port number, and protocol type do not match the configuration protocol used, then the two are not allowed to communicate with each other; if they match completely, then the two are allowed to communicate with each other.
[0036] Furthermore, the test network devices connect to the configuration network through configuration interfaces: for test network devices using Ethernet interfaces as configuration interfaces, they are connected to the leaf node switches of the configuration network; for test network devices using console interfaces as configuration interfaces, multiple test network devices are connected to the serial port switches of the configuration network, and after being aggregated by the serial port switches, they are connected to the leaf node switches in the tree structure.
[0037] Furthermore, as the number of test network devices increases, the methods for expanding the configuration interface include: expanding the Ethernet interface scale of the configuration network by increasing the number of leaf node switches; when the number of leaf node switches exceeds the number that the root node switch can directly connect to, adding branch node switches for cascading between the leaf node switches and the root node switch; and expanding the console interface scale of the configuration network by increasing the number of serial port switches.
[0038] The beneficial effects of this invention are as follows:
[0039] (1) This invention enables configuration protocol communication between the configuration system and the test network under the premise of secure isolation. When the test task involves network attacks or malicious software such as viruses, Trojans, and worms, the malicious traffic generated by the attack or malicious software will not spread through the network connection and affect the configuration system. Furthermore, when multiple test tasks are carried out simultaneously in the network testbed and there are multiple test networks, the network channels between each test network and the configuration system are isolated from each other, so that malicious traffic will not spread from one test network to another.
[0040] (2) Compared with the data isolation and exchange method, the secure isolation communication method proposed in this invention has a smaller latency, which can better meet the real-time requirements of configuration command issuance, and does not require the installation of cross-network exchange agent software in the test network device, thus not interfering with the test task.
[0041] (3) The present invention implements security isolation from multiple aspects such as network interface, network segment and IP address, and traffic control, so that the test task traffic will not enter the configuration network, thereby not changing the test network topology and not interfering with the test task.
[0042] (4) The present invention can support the continuous expansion of the number of test network devices of the network test bed at a low cost and supports a variety of commonly used device configuration protocols such as Telnet, SSH, and SNMP. Attached Figure Description
[0043] Figure 1 This is a network testbed architecture diagram in Embodiment 1 of the present invention, which separates the configuration system from the test network.
[0044] Figure 2 This is a schematic diagram of the network structure configuration in Embodiment 1 of the present invention.
[0045] Figure 3 This is a schematic diagram of two types of interfaces of the test network device and their connection methods in Embodiment 2 of the present invention. Detailed Implementation
[0046] To provide a clearer understanding of the technical features, objectives, and effects of the present invention, specific embodiments are now described. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention; that is, the described embodiments are only a part of the embodiments of the invention, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0047] Example 1
[0048] like Figure 1As shown, this embodiment provides a network testbed with a separate configuration system and test network, including a configuration system, a configuration network, M test network devices, and N test networks, where M and N are positive integers; the configuration system connects to the test network devices through the configuration network and transmits configuration data; the test networks connect to the test network devices and transmit test task traffic.
[0049] It's important to note that within a network testbed, the configuration network is unique and shared by all test tasks. All test network devices connect to this configuration network and communicate with the configuration system through it. When a network testbed supports multiple test tasks running simultaneously, each test task has its own test network; therefore, there may be multiple test networks within a single network testbed. Test network devices participating in setting up test tasks connect to their respective test networks.
[0050] Preferably, such as Figure 2 As shown, the configuration network in this embodiment includes a firewall, Ethernet switches, and serial switches. Multiple Ethernet switches are interconnected in a tree structure, which includes a root node switch and several leaf node switches. One side of the firewall connects to the configuration system, and the other side connects to the root node switch. The leaf node switches are connected to the test network device either via serial switches or directly.
[0051] Preferably, the test network device connects to the configuration network via a configuration interface to transmit configuration data. Specifically, the configuration interface can be an Ethernet interface or a console interface.
[0052] More preferably, for test network devices that use Ethernet interfaces as configuration interfaces, they are connected to the leaf node switches of the configuration network; for test network devices that use console interfaces as configuration interfaces, multiple test network devices are connected to the serial switches of the configuration network, and after being aggregated by the serial switches, they are connected to the leaf node switches in the tree structure.
[0053] More preferably, as the number of test network devices increases, the Ethernet interface scale of the configuration network can be expanded by increasing the number of leaf node switches. If the number of leaf node switches exceeds the number that the root node switch can directly connect to, branch node switches can be added between the leaf node switches and the root node switch for cascading. In addition, the console interface scale of the configuration network can be expanded by increasing the number of serial port switches.
[0054] Example 2
[0055] This embodiment is based on embodiment 1:
[0056] This embodiment provides a network testbed isolated communication method, including:
[0057] (a) The configuration network and the test network are connected using different switches and other devices. The test network devices are connected to both the configuration network and the test network. Apart from this, the devices that make up the configuration network and the test network have no other overlap.
[0058] (b) The test network devices use different network interfaces to transmit configuration data and test task traffic respectively. The network interface specifically used for transmitting configuration data and communicating with the configuration system is called the configuration interface; other network interfaces used for transmitting test task traffic are called test task interfaces. The configuration interface connects to the configuration network, and the test task interface connects to the test network, such as... Figure 3 As shown.
[0059] (c) The configuration network and the test network use different network segments, and the device interface IP addresses of the two networks are isolated from each other. On the test network devices, routing policies that connect the configuration network segment and the test network segment are not allowed.
[0060] (d) Deploy traffic control policies based on source IP address, destination IP address, source port number, destination port number, and protocol type in the configuration network to ensure that only configuration data can be transmitted through the configuration network and that test task traffic will not spread to the configuration network through the test network device.
[0061] Preferably, the configuration interface of the test network device can be an Ethernet interface or a console interface, including the following:
[0062] (1) If the device has a console interface for device management, the console interface can be used as a configuration interface. This applies to most network devices such as switches and routers, as well as some network security devices such as firewalls and VPN gateways.
[0063] (2) If the device has a dedicated Ethernet interface for device management (i.e., management port), the management port can be used as a configuration interface. This applies to most network devices such as switches, routers, and firewalls, network security devices such as firewalls and VPN gateways, as well as some servers and network storage devices.
[0064] (3) If the device does not have a dedicated management port or console interface, but has multiple ordinary Ethernet interfaces that can communicate externally, one of the Ethernet interfaces can be used as the configuration interface. This applies to most servers, network storage devices, and security devices such as intrusion detection, intrusion prevention, antivirus gateways, web application firewalls, and authentication and authorization devices.
[0065] (4) If the device does not have a dedicated management port or console interface, and only has one Ethernet interface that can communicate externally, a new Ethernet port can be added by adding an Ethernet adapter to the device, and the newly added Ethernet interface can be used as a configuration interface. This situation applies to most computer terminal devices.
[0066] (5) If the device has several optional configuration interfaces such as console interface, management network port and multiple ordinary Ethernet interfaces, the selection shall be made in descending order of priority: "console interface > management network port > ordinary Ethernet interface".
[0067] Preferably, when the network testbed supports multiple test tasks, each test task has its own test network. The network segment of the test network and the test task interface IP addresses of each device in the test network are flexibly allocated according to the requirements of the test task and are only valid within the lifecycle of the corresponding test task. When the test task ends, the test task interface IP addresses of these devices should be reset to prepare for participation in the next test task.
[0068] Preferably, the configuration network should be assigned a network segment that is different from the test networks for each task, and this segment should remain fixed. The configuration interface IP addresses of each device should also remain unchanged. When a test network device uses an Ethernet interface as its configuration interface, a fixed IP address should be directly configured for that device's Ethernet configuration interface. When a test network device uses a console interface as its configuration interface, a fixed configuration interface IP address should be configured for that device on the serial switch it is connected to, for communication between the configuration system and the device.
[0069] Preferably, the network is configured to implement the following traffic control policies:
[0070] (1) When both the source node and the destination node are test network devices, if these two test network devices are connected to the same leaf node switch, including those connected to the same leaf node switch via a serial port switch, then the source node and the destination node are not allowed to communicate with each other.
[0071] (2) When both the source node and the destination node are test network devices, if these two test network devices are connected to different leaf node switches, including those connected to different leaf node switches via serial port switches, then the source node and the destination node are not allowed to communicate with each other.
[0072] (3) When one of the communication source node and the other of the destination node is a test network device and the other is a configuration system, if the communication source port number, destination port number, and protocol type do not match the configuration protocol used, the source node and the destination node are not allowed to communicate with each other.
[0073] (4) When one of the communication source node and the other of the communication destination node is a test network device and the other is a configuration system, if the communication source port number, destination port number, and protocol type are completely consistent with the configuration protocol used, then the source node and the destination node are allowed to communicate with each other.
[0074] It should be noted that various methods, such as Virtual LANs (VLANs), routing, switch access control lists (ACLs), and firewall packet filtering, can be used in combination to implement the above traffic control policies when configuring the network. For example, a feasible specific method is as follows:
[0075] (1) Configure VLANs on leaf node switches so that each test network device belongs to a different VLAN and do not allow any two test network devices to communicate with each other through Layer 2 switching in the configured network.
[0076] (2) Configure routing rules on leaf node switches, branch node switches, and root node switches. Each leaf node switch has a route to the root node switch, but no route to other leaf node switches. This allows each test network device to communicate with the configuration system via Layer 3 routing, but test network devices connected to each leaf node switch cannot communicate with test network devices connected to other leaf node switches via Layer 3 routing. Routing rules can be configured using static routes or by enabling dynamic routing protocols such as OSPF and IS-IS.
[0077] (3) Configure ACL rules on the leaf node switch so that any two test network devices connected to the same leaf node switch cannot communicate with each other through direct connection routes.
[0078] (4) Configure ACL rules on the leaf node switch so that only traffic that uses the IP address of the interface of the test network device connected to the switch and the IP address of the system as the source / destination IP address, and whose source / destination port number and protocol type match the configured protocol can be transmitted through the switch.
[0079] (5) Configure ACL rules on the root node switch so that only traffic with the IP address of the test network device configuration interface and the IP address of the configuration system as the source / destination IP address, and whose source / destination port number and protocol type match the configured protocol, can be transmitted through the switch.
[0080] (6) Configure packet filtering rules on the firewall so that only traffic with the IP address of the test network device configuration interface and the IP address of the configuration system as the source / destination IP address, and whose source / destination port number and protocol type match the configured protocol, can be transmitted through the firewall.
[0081] (7) If the firewall has malicious traffic detection and protection functions, enable the function to prevent malicious traffic generated by network attacks or malware from spreading to the configuration system.
[0082] In summary, the network testbed isolation communication method of this embodiment has the following characteristics:
[0083] (1) The configuration system and the test network can communicate using the configuration protocol while maintaining secure isolation. When the test task involves network attacks or malicious software such as viruses, Trojans, and worms, the malicious traffic generated by the attack or malicious software will not spread through the network connection and affect the configuration system.
[0084] (2) When multiple test tasks are carried out simultaneously in the network testbed and there are multiple test networks, the network channels between each test network and the configuration system are isolated from each other, so that malicious traffic will not spread from one test network to another test network and will not interfere with the test tasks.
[0085] (3) The latency of this isolation communication method is small, which can meet the real-time requirements of configuration command issuance.
[0086] (4) This isolated communication method does not require the installation of agent software in the test network equipment and does not interfere with the test task.
[0087] (5) This isolation communication method does not change the test network topology and does not interfere with the test task.
[0088] (6) This isolation communication method can support the continuous expansion of the number of test network devices.
[0089] (7) This isolation communication method can support multiple device configuration protocols such as Telnet, SSH, and SNMP.
[0090] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.
[0091] It should be noted that, for the sake of simplicity, the foregoing method embodiments are described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
Claims
1. A method for isolating and communicating with a network testbed by separating the configuration system and the test network, wherein the network testbed includes a configuration system, a configuration network, M test network devices, and N test networks, where M and N are positive integers; the configuration system connects to the test network devices through the configuration network and transmits configuration data; The test network connects to test network devices and transmits test task traffic; Its features are, The network testbed isolation communication method includes: Different devices are used to connect the configuration network and the test network. The test network devices use different network interfaces to transmit configuration data and test task traffic respectively; The configuration network and the test network use different network segments, and the IP addresses of the device interfaces of the two are isolated from each other; Configure traffic control policies in the network so that configuration data can be transmitted through the network, but test task traffic cannot be spread into the network through the test network devices. The configuration interface setup method includes: when the device has a console interface or Ethernet interface for device management, the console interface or Ethernet interface can be used as the configuration interface; when the device does not have a console interface or Ethernet interface for device management, but has multiple ordinary Ethernet interfaces capable of external communication, one of the ordinary Ethernet interfaces is used as the configuration interface; when the device does not have a console interface or Ethernet interface for device management, and only has one ordinary Ethernet interface capable of external communication, a new Ethernet interface is added by adding an Ethernet adapter, and the newly added Ethernet interface is used as the configuration interface; when the device has a console interface for device management, an Ethernet interface, and multiple ordinary Ethernet interfaces, they are selected according to a preset priority; the preset priority includes: console interface for device management > Ethernet interface for device management > ordinary Ethernet interface; The configuration network and the test network use different network segments, and the device interface IP addresses of the two are isolated from each other, including: When a network testbed supports multiple test tasks, each test task has its own test network. The network segment of the test network and the test task interface IP addresses of each device in the test network are flexibly allocated according to the requirements of the test task and are only valid within the lifecycle of the corresponding test task. When the test task ends, the test task interface IP addresses of these devices are reset to prepare for participation in the next test task. Configure the network segment to be different from the test network of each task, and keep it fixed. The configuration interface IP address of each device also remains unchanged. When the test network device uses an Ethernet interface as the configuration interface, directly configure a fixed IP address for the Ethernet configuration interface of the test network device. When the test network device uses a console interface as the configuration interface, configure a fixed configuration interface IP address for the test network device on the serial switch connected to the test network device in the configuration network, so that the configuration system can communicate with the test network device. The traffic control policies deployed in the configuration network include: when both the communication source node and the destination node are test network devices, they are not allowed to communicate with each other; when one of the communication source node and the destination node is a test network device and the other is a configuration system, if the source port number, destination port number, and protocol type do not match the configuration protocol used, they are not allowed to communicate with each other; if they match completely, they are allowed to communicate with each other.
2. The network testbed isolation communication method for separating the configuration system and the test network according to claim 1, characterized in that, The configuration network includes a firewall, Ethernet switches, and serial switches; multiple Ethernet switches are interconnected in a tree structure, which includes a root node switch and several leaf node switches; one side of the firewall is connected to the configuration system, and the other side is connected to the root node switch, while the leaf node switches are connected to the test network device via serial switches or directly.
3. The network testbed isolation communication method for separating the configuration system and the test network according to claim 1, characterized in that, The test network devices use different network interfaces to transmit configuration data and test task traffic, including: The test network device connects to the configuration network through a configuration interface to transmit configuration data; the configuration interface includes an Ethernet interface and a console interface. The test network device connects to the test network through the test task interface to transmit test task traffic.
4. The network testbed isolation communication method for separating the configuration system and the test network according to claim 1, characterized in that, The traffic control policy deployed in the configured network is implemented based on preset parameters, which include source IP address, destination IP address, source port number, destination port number, and protocol type.
Citation Information
Patent Citations
A domestically developed network security isolation and one-way import system and method
CN108449310B
Software-defined network data isolation and switching methods
CN109936541B
A network security isolation device and method with one-way import function
CN111556062B
Network testing system
CN104539483A