Performance test system, method and device, electronic equipment and storage medium
By sending test traffic simulating normal business access and attack samples, and combining business success rate and attack interception rate, the performance of Web application firewall devices is evaluated. This solves the problem of inaccurate testing in existing technologies and improves the reliability of test results.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2026-01-13
- Publication Date
- 2026-04-24
AI Technical Summary
Existing technologies struggle to eliminate interference from bypass techniques and self-learning mechanisms when testing the forwarding performance of Web application firewall devices, making it impossible to accurately test their true performance.
By sending a first test traffic simulating normal business access and a second test traffic containing attack samples, the success rate of business access and the attack interception rate are statistically analyzed, and the device performance is evaluated in combination with preset thresholds to provide performance test results.
This enables accurate evaluation of the performance of Web application firewall devices in real-world application scenarios, improving the reliability of test results.
Smart Images

Figure CN121923892A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of cybersecurity technology, and in particular to a performance testing system, method, apparatus, electronic device, and storage medium. Background Technology
[0002] In the field of network security, the forwarding performance of Web Application Firewall (WAF) devices is an important indicator of their working capabilities and is directly related to the stable operation of network services. Therefore, testing the forwarding performance of WAF devices is a key step in device selection, deployment, and optimization.
[0003] However, with the increasing demands for the reliability and performance of WAF devices, WAF devices have introduced bypass technology (passing through traffic and stopping attack detection when the device fails or there is a business bottleneck) and self-learning mechanisms (directly forwarding traffic with duplicate source and destination Internet Protocol (IP) addresses or Uniform Resource Locators (URLs) without further detection). While bypass technology and self-learning mechanisms have improved the reliability of WAF devices, they have also brought new challenges to the forwarding performance testing of WAF devices. When conducting tests, relevant WAF forwarding performance testing methods cannot eliminate the interference of bypass technology and self-learning mechanisms on the test results, thus failing to accurately test the true forwarding performance of WAF devices. Summary of the Invention
[0004] This disclosure provides a performance testing system, method, apparatus, electronic device, and storage medium. Its main objective is to address the problem that existing technologies cannot accurately measure the true forwarding performance of the device under test.
[0005] According to a first aspect of this disclosure, a performance testing system is provided, comprising: a traffic distribution module, a statistics module, and an evaluation module; wherein, The traffic delivery module is used to send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to apply performance load to the device under test, and the second test traffic contains attack samples that can be identified by the device under test. The statistics module is used to calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic. The evaluation module is used to evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements and obtain the performance test results.
[0006] In some embodiments, the traffic distribution module includes: a first sending unit and a second sending unit; wherein, The first sending unit is used to generate and send the first test traffic based on normal business access traffic with different source addresses and different access target addresses; The second sending unit is used to generate and send the second test traffic based on the attack sample, the source address, and the access target address; wherein the source address is selected from the source address set of the first test traffic, the access target address is selected from the access target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
[0007] In some embodiments, the statistics module includes: a first receiving unit, a second receiving unit, and a monitoring unit; wherein, The first receiving unit is configured to receive the first test traffic forwarded by the device under test, and determine the service success rate based on the reception result of the first test traffic; The second receiving unit is used to receive the second test traffic intercepted by the device under test; and to send the interception result of the second test traffic to the monitoring unit. The monitoring unit is used to acquire the attack alarm logs generated by the device under test, and determine the attack interception rate based on the interception results of the second test traffic and the attack alarm logs.
[0008] In some embodiments, the evaluation module is configured to: The success rate of the business is compared with a preset first threshold to determine whether the success rate of the business has reached the preset first threshold. If the business success rate reaches the preset first threshold, the attack interception rate is compared with the preset second threshold to determine whether the attack interception rate has reached the second threshold. If the attack interception rate reaches the second threshold, the performance test result of the device under test under the performance load is determined to be valid.
[0009] According to a second aspect of this disclosure, a performance testing method is provided, the method being applied to the performance testing system described in the first aspect above, comprising: Send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to impose a performance load on the device under test, and the second test traffic contains attack samples that can be identified by the device under test; The success rate of the first test traffic and the attack interception rate of the second test traffic were statistically analyzed. Evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements, and obtain the performance test results.
[0010] In some embodiments, sending the first test traffic and the second test traffic to the device under test includes: The first test traffic is generated and sent based on normal business access traffic with different source addresses and different access destination addresses; Based on the attack sample, source address, and target address, the second test traffic is generated and sent; wherein the source address is selected from the set of source addresses of the first test traffic, the target address is selected from the set of target addresses of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
[0011] In some embodiments, evaluating whether the service success rate and attack interception rate of the device under test meet performance requirements to obtain performance test results includes: The success rate of the business is compared with a preset first threshold to determine whether the success rate of the business has reached the preset first threshold. If the business success rate reaches the preset first threshold, the attack interception rate is compared with the preset second threshold to determine whether the attack interception rate has reached the second threshold. If the attack interception rate reaches the second threshold, the performance test result of the device under test under the performance load is determined to be valid.
[0012] According to a third aspect of this disclosure, a performance testing apparatus is provided, the apparatus being configured in the performance testing system described in the first aspect above, comprising: The sending unit is used to send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to impose a performance load on the device under test, and the second test traffic contains attack samples that can be identified by the device under test; The statistics unit is used to calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic. The evaluation unit is used to evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements and obtain the performance test results.
[0013] In some embodiments, the transmitting unit includes: The first sending module is used to generate and send the first test traffic based on normal business access traffic with different source addresses and different access target addresses; The second sending module is used to generate and send the second test traffic based on the attack sample, the source address, and the access target address; wherein the source address is selected from the source address set of the first test traffic, the access target address is selected from the access target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
[0014] In some embodiments, the evaluation unit includes: The first comparison module is used to compare the business success rate with a preset first threshold to determine whether the business success rate reaches the preset first threshold. The second comparison module is used to compare the attack interception rate with a preset second threshold when the business success rate reaches the preset first threshold, and to determine whether the attack interception rate has reached the second threshold. The determination module is used to determine that the performance test result of the device under test under the performance load is valid when the attack interception rate reaches the second threshold.
[0015] According to a fourth aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the second aspect above.
[0016] According to a fifth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the second aspect above.
[0017] According to a sixth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the second aspect above.
[0018] In summary, the performance testing system, method, apparatus, electronic device, and storage medium provided in this disclosure include: a traffic distribution module, a statistics module, and an evaluation module. The traffic distribution module sends a first test traffic and a second test traffic to the device under test (DUT). The first test traffic simulates normal business access to impose a performance load on the DUT, while the second test traffic contains attack samples that can be identified by the DUT. The statistics module calculates the business success rate of the first test traffic and the attack interception rate of the second test traffic. The evaluation module evaluates whether the business success rate and attack interception rate of the DUT meet performance requirements, thereby obtaining performance test results. Compared with related technologies, the solution in this disclosure, by simultaneously sending two types of test traffic and combining dual-index evaluation, ensures that the performance test results conform to the actual application scenario of the DUT, thus improving the reliability of the test results.
[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0020] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is a schematic diagram of the structure of a performance testing system provided in an embodiment of the present disclosure; Figure 2 This is a schematic diagram of another performance testing system provided in an embodiment of the present disclosure; Figure 3 This is a schematic diagram of the overall framework of a performance testing system provided in an embodiment of this disclosure; Figure 4 This is a schematic flowchart of a performance testing method provided in an embodiment of the present disclosure; Figure 5 This is a flowchart illustrating another performance testing method provided in an embodiment of this disclosure; Figure 6 This is a flowchart illustrating another performance testing method provided in an embodiment of this disclosure; Figure 7 This is a schematic diagram of a WAF device forwarding performance testing process provided in an embodiment of this disclosure; Figure 8 This is a schematic diagram of the structure of a performance testing device provided in an embodiment of the present disclosure; Figure 9 This is a schematic diagram of another performance testing device provided in an embodiment of the present disclosure; Figure 10This is a schematic block diagram of an example electronic device provided in an embodiment of this disclosure. Detailed Implementation
[0021] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0022] The performance testing system, method, apparatus, electronic device, and storage medium of this disclosure are described below with reference to the accompanying drawings.
[0023] Figure 1 This is a schematic diagram of the structure of a performance testing system provided in an embodiment of this disclosure.
[0024] like Figure 1 As shown, the system includes a traffic distribution module 11, a statistics module 12, and an evaluation module 13; among which, The traffic distribution module 11 is used to send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to apply performance load to the device under test, and the second test traffic contains attack samples that can be identified by the device under test.
[0025] In some embodiments, the first test traffic simulates traffic generated by normal business access in a network environment. Its purpose is to apply a continuous performance load to the device under test (DUT), keeping it in a business operation state. The type of the first test traffic includes, but is not limited to, HTTP traffic and HTTPS traffic. The second test traffic contains attack samples. The attack samples are attack types that the DUT has been able to identify in previous attack detection function tests. Attack types include, but are not limited to, Structured Query Language (SQL) injection attacks, cross-site scripting attacks, command injection attacks, and Webshell upload attacks. The method for selecting attack samples for the second test traffic includes, but is not limited to, obtaining identified attack samples by analyzing the attack interception logs and attack fields of the DUT. The traffic distribution module sends the first and second test traffic simultaneously and continuously, ensuring that the DUT faces the attack sample detection requirements while carrying a normal business load.
[0026] The traffic distribution module can simultaneously provide the device under test with normal business load and attack detection scenarios, making the operating status of the device under test consistent with the actual application scenario, and providing a basis for subsequent performance data statistics and evaluation.
[0027] The statistics module 12 is used to calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic.
[0028] In some embodiments, the service success rate is a parameter calculated based on the sending and receiving status of the first test traffic. The calculation method is: service success rate equals the number of successful connections of the first test traffic divided by the total number of connections sent by the first test traffic. The attack interception rate is a parameter calculated based on the processing status of the second test traffic. The calculation method is: attack interception rate equals the number of intercepted attacks of the second test traffic divided by the number of sent attacks of the second test traffic. The statistics module obtains the sending and receiving status of the first test traffic and the processing status of the second test traffic in ways including, but not limited to, obtaining the sending and receiving data of the traffic through traffic acquisition tools, or obtaining the traffic processing records by establishing data interaction with the device under test.
[0029] The statistics module can accurately obtain data related to the operational effectiveness of the first test traffic and the interception effectiveness of the second test traffic, providing data support for the evaluation module.
[0030] The evaluation module 13 is used to evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements and obtain the performance test results.
[0031] In some embodiments, performance requirements are pre-defined standards for judging whether the performance of the device under test meets the criteria. The evaluation process involves verifying the statistically obtained service success rate and attack interception rate to confirm whether both parameters meet the corresponding settings in the performance requirements. The evaluation module performs the evaluation operation in ways including but not limited to automatically completing the verification through a preset logical judgment program, or manually verifying it according to pre-stored judgment rules. After the verification is completed, the corresponding performance test results are output. The performance test results are used to reflect the performance of the device under test under the current service load and attack detection scenario.
[0032] The evaluation module can assess the performance of the tested device based on the statistically obtained business success rate and attack interception rate, and output clear performance test results.
[0033] In summary, the performance testing system provided in this disclosure can improve the reliability of test results by synchronously sending two types of test traffic and combining dual-index evaluation, so that the performance test results conform to the actual application scenario of the device under test.
[0034] Figure 2 A schematic diagram of the structure of a performance testing system provided in an embodiment of this disclosure is further shown, such as... Figure 2As shown, the traffic distribution module 11 includes: a first sending unit 111 and a second sending unit 112; wherein, The first sending unit 111 is used to generate and send the first test traffic based on normal service access traffic with different source addresses and different access target addresses.
[0035] In some embodiments, different source addresses refer to multiple distributed network addresses and corresponding source port numbers, and different access destination addresses include multiple Uniform Resource Locators (URLs) and destination network addresses. The performance load parameters of the first test traffic include the number of new connections per second (Q), the number of concurrent users per second (C), and the throughput per second (T). The first test traffic is generated by mapping the aforementioned performance load parameters, different source addresses, and different access destination addresses to a testing tool, forming a first test traffic model L1={[Q,C,T],SClient1,DServer1}, where SClient1 is a set of different source addresses and DServer1 is a set of different access destination addresses. The first sending unit sends the first test traffic continuously, with the sending duration preset according to the testing requirements.
[0036] The second sending unit 112 is used to generate and send the second test traffic based on the attack sample, the source address and the access target address; wherein the source address is selected from the source address set of the first test traffic, the access target address is selected from the access target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
[0037] In some embodiments, the source address set of the first test traffic is the entirety of all different source addresses used by the first sending unit 111, and the destination address set of the first test traffic is the entirety of all different destination addresses used by the first sending unit 111. The source addresses of the second test traffic are randomly selected from a subset of the source address set of the first test traffic, and the destination addresses of the second test traffic are also randomly selected from a subset of the destination addresses of the first test traffic. The scale of the second test traffic is determined by a performance load parameter ratio, where the performance load parameter of the second test traffic is... , where x is a preset coefficient (e.g., x equals 5% or lower), the second test traffic is generated by mapping the above performance load parameters, the selected source address, the selected access target address, and the attack sample to the testing tool, forming the second test traffic model L2={ The second sending unit 112 continuously sends traffic synchronously with the first sending unit 111, and the sending duration is the same as the sending duration of the first test traffic. (The text also includes a random subset of SClient1 and DServer1, and a definition of "Sample function already identified," which refers to attack samples already identified by the device under test.)
[0038] The above method enables the first test traffic to realistically simulate normal business access scenarios, while the second test traffic is correlated with the first test traffic and does not interfere with the performance load applied by the first test traffic. This ensures that the device under test faces the attack detection requirements targeting the same source address and access target address while bearing normal business load, thus providing conditions for accurate subsequent statistics on business success rate and attack interception rate.
[0039] like Figure 2 As shown, the statistics module 12 includes: a first receiving unit 121, a second receiving unit 122, and a monitoring unit 123; wherein, The first receiving unit 121 is used to receive the first test traffic forwarded by the device under test, and determine the service success rate based on the reception result of the first test traffic.
[0040] In some embodiments, the receiving result includes the total number of connections sent for the first test traffic and the number of successful connections. The total number of connections sent is the total number of connections recorded by the traffic distribution module 11 when sending the first test traffic. The number of successful connections is the number of connections corresponding to the first test traffic actually received by the first receiving unit 121 and normally forwarded by the device under test. The service success rate is calculated by dividing the number of successful connections by the total number of connections sent. The first receiving unit 121 obtains the total number of connections sent by means including but not limited to establishing data interaction with the traffic distribution module 11 or deriving it from its own recorded receiving logs.
[0041] The second receiving unit 122 is used to receive the second test traffic intercepted by the device under test; and to send the interception result of the second test traffic to the monitoring unit 123.
[0042] In some embodiments, the interception result includes the number of second test traffic flows sent and the initial interception count. The number of flows sent is the total number recorded by the traffic distribution module 11 when sending the second test traffic, and the initial interception count is the number of second test traffic flows received by the second receiving unit 122 that are intercepted by the device under test. The second receiving unit 122 receives the second test traffic intercepted by the device under test in ways including, but not limited to, receiving the intercepted traffic data fed back by the device under test through a network port, or capturing the intercepted second test traffic through a traffic acquisition tool. The second receiving unit 122 sends the interception result to the monitoring unit 123 in ways including, but not limited to, wired data transmission, wireless signal transmission, and other data interaction methods.
[0043] The monitoring unit 123 is used to acquire the attack alarm logs generated by the device under test, and determine the attack interception rate based on the interception result of the second test traffic and the attack alarm logs.
[0044] In some embodiments, the attack alarm log is a record file generated by the device under test when it detects attack traffic, containing information such as the attack occurrence time, attack sample type, attack source address, attack target address, and whether it was blocked. The monitoring unit 123 obtains the attack alarm log in ways including, but not limited to, reading the log file after establishing a communication connection with the device under test, or receiving log data pushed by the device under test in real time. The process of determining the attack interception rate is as follows: first, extract the number of transmissions from the interception results; then, based on the attack alarm log, verify the accuracy of the initial interception count, remove incorrectly counted interception data or supplement missing interception data to obtain the final interception count; and finally, calculate the attack interception rate by dividing the final interception count by the number of transmissions.
[0045] The above methods enable the statistical analysis of the business operation status of the first test traffic and the interception status of the second test traffic. At the same time, the interception results of the second test traffic can be verified by using attack alarm logs, ensuring the statistical accuracy of the business success rate and attack interception rate, and providing a reliable data foundation for the performance evaluation of subsequent evaluation modules.
[0046] In some possible implementations, the evaluation module 13 is used to: The success rate of the business is compared with a preset first threshold to determine whether the success rate of the business has reached the preset first threshold.
[0047] In some embodiments, the first threshold is a parameter pre-set according to the application scenario and performance requirements of the device under test. The setting method includes, but is not limited to, pre-storing it in the evaluation module or configuring it through an external input device. The value of the first threshold includes, but is not limited to, 98% and 100%, and is determined based on the deployment scenario of the device under test to meet the requirements for normal business operation in different scenarios. The comparison process involves comparing the business success rate value obtained by the statistics module 12 with the first threshold value to determine whether the business success rate value is greater than or equal to the first threshold value.
[0048] If the success rate of the service reaches the preset first threshold, the attack interception rate is compared with the preset second threshold to determine whether the attack interception rate has reached the second threshold.
[0049] In some embodiments, the second threshold is a parameter pre-set according to the security protection requirements of the device under test. The setting method is consistent with the setting method of the first threshold, including but not limited to pre-storage and external configuration. The value of the second threshold includes, but is not limited to, 98% and 100%, corresponding to the value of the first threshold, and together meeting the requirements of the device under test in terms of both business operation and security protection. When the business success rate reaches the first threshold, the attack interception rate is compared with the second threshold. The comparison process involves comparing the attack interception rate value obtained by the statistics module 12 with the second threshold value to determine whether the attack interception rate value is greater than or equal to the second threshold value. If the business success rate does not reach the first threshold, the evaluation process ends directly without further comparison.
[0050] If the attack interception rate reaches the second threshold, the performance test result of the device under test under the performance load is determined to be valid.
[0051] In some embodiments, a valid performance test result indicates that the device under test, under the performance load corresponding to the current first test traffic, can simultaneously meet the requirements of normal business operation and attack protection, and its performance meets the preset standards. If the attack interception rate does not reach the second threshold, the performance test result is invalid, indicating that the device under test's attack protection capability under the current performance load does not meet the preset requirements. The evaluation module outputs performance test results in ways including but not limited to generating text reports, outputting identification signals, and storing result data for subsequent querying and use.
[0052] By using the above method, the success rate of business operations and the attack interception rate are verified step by step according to the preset thresholds, the validity criteria for performance test results are clarified, the evaluation process is logically clear and the results are accurate, and a clear basis is provided for the performance evaluation of the tested equipment.
[0053] In some possible ways, Figure 3 This is a schematic diagram of the overall framework of a performance testing system provided in an embodiment of this disclosure, as shown below. Figure 3 As shown, the traffic delivery module (Client) includes a first sending unit and a second sending unit. Both the first and second sending units are connected to the device under test (DUT) and are used to transmit the first test traffic and the second test traffic to the DUT. The DUT is connected to the first receiving unit and the second receiving unit in the statistics module (Server), and is also connected to the monitoring unit. The statistics module (Server) includes the first receiving unit, the second receiving unit, and the monitoring unit, and is connected to the evaluation module.
[0054] The specific data flow is as follows: the first sending unit sends the first test traffic to the device under test (DUT), and the DUT forwards the first test traffic to the first receiving unit; the second sending unit sends the second test traffic to the DUT, and the DUT intercepts the second test traffic and transmits it to the second receiving unit; the attack alarm log generated by the DUT is transmitted to the monitoring unit. The first receiving unit, the second receiving unit, and the monitoring unit aggregate the data they acquire to the statistics module (Server). The statistics module (Server) transmits the calculated service success rate and attack interception rate to the evaluation module, which then determines the performance test results based on preset thresholds.
[0055] Corresponding to the performance testing system described above, this invention also proposes a performance testing method. Since the method embodiments of this invention correspond to the system embodiments described above, details not disclosed in the method embodiments can be referred to in the system embodiments described above, and will not be repeated here.
[0056] Figure 4 This is a flowchart illustrating a performance testing method provided in an embodiment of the present disclosure, wherein the performance testing method is applied to the aforementioned performance testing system.
[0057] like Figure 4 As shown, the method includes steps 101-103.
[0058] Step 101: Send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to impose a performance load on the device under test, and the second test traffic contains attack samples that can be identified by the device under test.
[0059] In some embodiments, the sending operation involves simultaneously transmitting two types of traffic to the device under test (DUT). The first test traffic simulates the traffic generated during normal business access in a network environment, and its purpose is to put the DUT in a state of carrying business load. The second test traffic contains attack samples, which are attack types that the DUT has been able to identify in the attack detection function test. Both types of traffic are continuously transmitted during the sending process to ensure that the DUT faces the need for attack detection while carrying normal business.
[0060] Step 102: Calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic.
[0061] In some embodiments, statistical operations are calculated based on the processing data of two types of traffic. The service success rate is calculated based on the total number of connections sent and the number of successful connections for the first test traffic. The total number of connections sent is the total number of connections recorded when the traffic distribution module sends the first test traffic, and the number of successful connections is the number of connections actually received after the first test traffic is normally forwarded by the device under test. The attack interception rate is calculated based on the number of second test traffic sent and the number of intercepted traffic. The number of sent traffic is the total number recorded when the traffic distribution module sends the second test traffic, and the number of intercepted traffic is the number of second test traffic traffic intercepted by the device under test. The statistical process requires obtaining the transmission and reception records of the two types of traffic and the relevant processing information of the device under test to obtain accurate calculation parameters.
[0062] Step 103: Evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements, and obtain the performance test results.
[0063] In some embodiments, the evaluation operation compares the statistically obtained service success rate and attack interception rate with preset performance requirements. The performance requirements include thresholds for the two types of parameters, which are preset based on the application scenario and performance requirements of the device under test. After comparison, the corresponding performance test results are determined and output based on whether the service success rate and attack interception rate reach the corresponding thresholds. These performance test results reflect whether the performance of the device under test meets the preset standards under the current service load and attack detection scenario.
[0064] In summary, the performance testing method provided by the embodiments of this disclosure can improve the reliability of the test results by synchronously sending two types of test traffic and combining dual-index evaluation, so that the performance test results conform to the actual application scenario of the device under test.
[0065] Figure 5 A flowchart illustrating a performance testing method provided in this disclosure embodiment is further shown, based on... Figure 4 The illustrated embodiment further explains step 101. Figure 5 This may include the following steps: Step 201: Generate and send the first test traffic based on normal business access traffic from different source addresses and different access target addresses.
[0066] Step 202: Based on the attack sample, source address, and access target address, generate and send the second test traffic; wherein the source address is selected from the source address set of the first test traffic, the access target address is selected from the access target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
[0067] For instructions on steps 201-202, please refer to [link / reference needed]. Figure 2 The detailed descriptions of the relevant embodiments are not repeated here.
[0068] The above method enables the first test traffic to realistically simulate normal business access scenarios, while the second test traffic is correlated with the first test traffic and does not interfere with the performance load applied by the first test traffic. This ensures that the device under test faces the attack detection requirements targeting the same source address and access target address while carrying normal business load, thus providing conditions for accurate subsequent statistics on business success rate and attack interception rate.
[0069] Figure 6 A flowchart illustrating a performance testing method provided in this disclosure embodiment is further shown, based on... Figure 4 The illustrated embodiment further explains step 103. Figure 6 This may include the following steps: Step 301: Compare the business success rate with a preset first threshold to determine whether the business success rate has reached the preset first threshold.
[0070] Step 302: If the business success rate reaches the preset first threshold, compare the attack interception rate with the preset second threshold to determine whether the attack interception rate has reached the second threshold.
[0071] Step 303: If the attack interception rate reaches the second threshold, determine that the performance test result of the device under test under the performance load is valid.
[0072] For explanations of steps 301-303, please refer to [link / reference needed]. Figure 2 The detailed descriptions of the relevant embodiments are not repeated here.
[0073] By using the above method, the success rate of business operations and the attack interception rate are verified step by step according to the preset threshold, the validity criteria for performance test results are clarified, the evaluation process is logically clear and the results are accurate, and a clear basis is provided for the performance evaluation of the tested equipment.
[0074] Figure 7 This is a schematic diagram of a WAF device forwarding performance testing process provided in an embodiment of this disclosure, as shown below. Figure 7 As shown, this process outlines the specific steps for conducting WAF device forwarding performance testing based on the aforementioned performance testing system. The process begins at the "Start" node and executes the following operations sequentially: First, execute the "Build Test Topology" operation. This operation corresponds to the physical environment for deploying the performance testing system. Connect the device under test (WAF) between the traffic distribution module and the statistics module, and deploy a monitoring unit to achieve connectivity between the traffic distribution module, the device under test, and the statistics module. At the same time, ensure that the monitoring unit can receive attack alarm logs generated by the device under test.
[0075] Then, the "Configure WAF Device Protection" operation is performed. This operation enables the bidirectional protection mode of the device under test and configures the connectivity between the device under test and the ports of the traffic distribution module and the statistics module. This ensures that the device under test can receive the test traffic sent by the traffic distribution module and transmit the processed traffic and log data to the statistics module.
[0076] Next, the "Traffic Model Distribution" operation is executed. This operation determines the performance load parameters of the first test traffic (including the number of new connections per second Q, the number of concurrent users per second C, and the throughput per second T), multiple dispersed source address sets, and multiple access target address sets to form the first test traffic model. At the same time, the performance parameter scale of the second test traffic is determined to be a preset proportion of the parameter scale of the first test traffic (in some possible implementations, this preset proportion is less than 5%), the source addresses are a random subset of the source address set of the first test traffic, the access target addresses are a random subset of the access target address set of the first test traffic, and the attack samples are attack types already identified by the device under test, thus forming the second test traffic model.
[0077] Then, the "send first test traffic" and "send second test traffic" operations are executed, and the two types of test traffic are transmitted synchronously and continuously to the device under test. During the transmission, a "whether the set time has been reached" judgment operation is executed. The set time is the pre-configured traffic transmission duration (such as 1800 seconds, which is only an example and not a specific duration limit). If the set time has not been reached, the two types of test traffic will continue to be sent. If the set time has been reached, the "stop traffic" operation is executed to terminate the transmission of the two types of test traffic.
[0078] After the traffic stops, the "Statistics on Traffic Sending and Receiving" operation is executed. This operation counts the total number of connections sent and the number of successful connections for the first test traffic, and calculates the service success rate. At the same time, it counts the number of times the second test traffic was sent and the number of initial interceptions. The number of initial interceptions is verified by combining the attack alarm logs of the device under test. After obtaining the final number of interceptions, the attack interception rate is calculated.
[0079] Then, the "business success rate meets the requirements" judgment operation is performed, that is, to determine whether the business success rate has reached the preset first threshold. If it is not met, the test fails, and the expected value of throughput is reduced and the test is repeated. If it is met, the "attack interception rate meets the requirements" judgment operation is further performed, that is, to determine whether the attack interception rate has reached the preset second threshold. If it is not met, the test fails. If it is met, the test succeeds, and the effective forwarding performance data of the tested device under the current performance load is recorded.
[0080] Corresponding to the performance testing method described above, this invention also proposes a performance testing apparatus. Since the apparatus embodiments of this invention correspond to the method embodiments described above, details not disclosed in the apparatus embodiments can be referred to in the method embodiments described above, and will not be repeated here.
[0081] Figure 8 This is a schematic diagram of the structure of a performance testing device provided in an embodiment of this disclosure, as shown below. Figure 8 As shown, the device includes: The sending unit 41 is used to send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal service access to impose a performance load on the device under test, and the second test traffic contains attack samples that can be identified by the device under test; The statistics unit 42 is used to calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic. Evaluation unit 43 is used to evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements and obtain performance test results.
[0082] The performance testing apparatus provided in this disclosure can improve the reliability of the test results by simultaneously sending two types of test traffic and combining dual-index evaluation, so that the performance test results conform to the actual application scenario of the device under test.
[0083] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 9 As shown, the transmitting unit 41 includes: The first sending module 411 is used to generate and send the first test traffic based on normal business access traffic with different source addresses and different access target addresses; The second sending module 412 is used to generate and send the second test traffic based on the attack sample, the source address and the access target address; wherein the source address is selected from the source address set of the first test traffic, the access target address is selected from the access target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
[0084] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 9 As shown, the evaluation unit 43 includes: The first comparison module 431 is used to compare the business success rate with a preset first threshold to determine whether the business success rate reaches the preset first threshold. The second comparison module 432 is used to compare the attack interception rate with a preset second threshold when the business success rate reaches the preset first threshold, and determine whether the attack interception rate has reached the second threshold. The determination module 433 is used to determine that the performance test result of the device under test under the performance load is valid when the attack interception rate reaches the second threshold.
[0085] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of this disclosure, and the principle is the same. Therefore, the embodiments of this disclosure are not limited thereto.
[0086] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0087] Figure 10 A schematic block diagram of an example electronic device 900 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0088] like Figure 10 As shown, the electronic device 900 includes a computing unit 901, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 902 or a computer program loaded from storage unit 908 into RAM (Random Access Memory) 903. The RAM 903 can also store various programs and data required for the operation of the electronic device 900. The computing unit 901, ROM 902, and RAM 903 are interconnected via bus 904. An I / O (Input / Output) interface 905 is also connected to bus 904.
[0089] Multiple components in electronic device 900 are connected to I / O interface 905, including: input unit 906, such as keyboard, mouse, etc.; output unit 907, such as various types of displays, speakers, etc.; storage unit 908, such as disk, optical disk, etc.; and communication unit 909, such as network card, modem, wireless transceiver, etc. Communication unit 909 allows electronic device 900 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0090] The computing unit 901 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 901 performs the various methods and processes described above, such as performance testing methods. For example, in some embodiments, the performance testing method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 908. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 900 via ROM 902 and / or communication unit 909. When the computer program is loaded into RAM 903 and executed by the computing unit 901, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 901 may be configured to perform the aforementioned performance testing method by any other suitable means (e.g., by means of firmware).
[0091] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0092] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0093] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0094] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0095] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0096] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0097] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0098] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0099] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A performance testing system, characterized in that, include: The system includes a traffic distribution module, a statistics module, and an evaluation module; among which, The traffic delivery module is used to send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to apply performance load to the device under test, and the second test traffic contains attack samples that can be identified by the device under test. The statistics module is used to calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic. The evaluation module is used to evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements and obtain the performance test results.
2. The system according to claim 1, characterized in that, The traffic distribution module includes: a first sending unit and a second sending unit; wherein, The first sending unit is used to generate and send the first test traffic based on normal business access traffic with different source addresses and different access target addresses; The second sending unit is used to generate and send the second test traffic based on the attack sample, the source address, and the access target address; wherein the source address is selected from the source address set of the first test traffic, the access target address is selected from the access target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
3. The system according to claim 1, characterized in that, The statistical module includes: a first receiving unit, a second receiving unit, and a monitoring unit; wherein, The first receiving unit is configured to receive the first test traffic forwarded by the device under test, and determine the service success rate based on the reception result of the first test traffic; The second receiving unit is used to receive the second test traffic intercepted by the device under test; and to send the interception result of the second test traffic to the monitoring unit. The monitoring unit is used to acquire the attack alarm logs generated by the device under test, and determine the attack interception rate based on the interception results of the second test traffic and the attack alarm logs.
4. The system according to claim 1, characterized in that, The evaluation module is used for: The success rate of the business is compared with a preset first threshold to determine whether the success rate of the business has reached the preset first threshold. If the business success rate reaches the preset first threshold, the attack interception rate is compared with the preset second threshold to determine whether the attack interception rate has reached the second threshold. If the attack interception rate reaches the second threshold, the performance test result of the device under test under the performance load is determined to be valid.
5. A performance testing method, characterized in that, The method, when applied to the system according to any one of claims 1-4, includes: Send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to impose a performance load on the device under test, and the second test traffic contains attack samples that can be identified by the device under test; The success rate of the first test traffic and the attack interception rate of the second test traffic were statistically analyzed. Evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements, and obtain the performance test results.
6. The method according to claim 5, characterized in that, Sending the first test traffic and the second test traffic to the device under test includes: The first test traffic is generated and sent based on normal business access traffic with different source addresses and different access destination addresses; Based on the attack sample, source address, and target address, the second test traffic is generated and sent; wherein the source address is selected from the source address set of the first test traffic, the target address is selected from the target address set of the first test traffic, and the size of the second test traffic is smaller than the size of the first test traffic.
7. The method according to claim 5, characterized in that, The evaluation process assesses whether the service success rate and attack interception rate of the device under test meet the performance requirements, and obtains performance test results, including: The success rate of the business is compared with a preset first threshold to determine whether the success rate of the business has reached the preset first threshold. If the business success rate reaches the preset first threshold, the attack interception rate is compared with the preset second threshold to determine whether the attack interception rate has reached the second threshold. If the attack interception rate reaches the second threshold, the performance test result of the device under test under the performance load is determined to be valid.
8. A performance testing device, characterized in that, The device is configured in the system of any one of claims 1-4, comprising: The sending unit is used to send a first test traffic and a second test traffic to the device under test; wherein, the first test traffic is used to simulate normal business access to impose a performance load on the device under test, and the second test traffic contains attack samples that can be identified by the device under test; The statistics unit is used to calculate the service success rate of the first test traffic and the attack interception rate of the second test traffic. The evaluation unit is used to evaluate whether the service success rate and attack interception rate of the device under test meet the performance requirements and obtain the performance test results.
9. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the method of any one of claims 5-7.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 5-7.
11. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the method as described in any one of claims 5-7.