Test Equipment
The test device addresses the limitations of conventional methods by automating the process of identifying and testing resistance to denial-of-service attacks across multiple network devices, ensuring comprehensive and efficient security assessments.
Patent Information
- Application Number
- JP2024556883
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-11-08
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2042-11-08
AI Technical Summary
Conventional methods for testing resistance to denial-of-service attacks in the upper layers of multiple devices within a network are limited by the need to manually check and prepare test devices and scenarios, lacking a comprehensive solution for sending test packets to multiple devices.
A test device equipped with an access investigation unit to identify accessible devices, a test scenario unit to generate packets, a transmission unit to send packets, and a log analysis unit to analyze responses, enabling simultaneous testing of multiple devices.
Enables efficient testing of resistance to denial-of-service attacks across multiple devices by automatically identifying and sending test packets, monitoring load status, and analyzing responses, thereby enhancing network security.
Smart Images

Figure 0007782725000001 
Figure 0007782725000002 
Figure 0007782725000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a test device. [Background technology]
[0002] Conventionally, a method has been proposed for conducting a packet load test by transmitting packets for applying a load to a device (see, for example, Non-Patent Document 1). Patent Document 1 also proposes a method for conducting a packet load test by having a test device transmit test packets that increase the processing load to a device protected by a security system. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2020-129736 [Non-patent literature]
[0004] [Non-Patent Document 1] IXIA, “Denial of Service (DOS) Testing” [online], [Retrieved October 24, 2022], Internet<URL:https: / / support.ixiacom.com / sites / default / files / resources / test-plan / dos_0.pdf> Summary of the Invention [Problem to be solved by the invention]
[0005] To test resistance to denial-of-service attacks targeting multiple devices within a network, such as carpet bombing attacks, which have become increasingly common in recent years, it is necessary to send test packets to the upper layers of multiple devices that are reachable from the outside. For example, upper layers are layers 5 and above.
[0006] However, the above-mentioned conventional method has a problem that when testing resistance to denial-of-service attacks in the upper layer, the destination of the test packet is limited to one in the network under test.
[0007] Currently, in order to test the resistance to denial-of-service attacks against the upper layers of multiple devices, it is necessary to first check the multiple devices that can be reached from the outside and their access information, then prepare multiple test devices and create test scenarios for the multiple test devices.
[0008] The present invention has been made in consideration of the above, and aims to provide a test device that can send test packets to upper layers of multiple devices and test resistance to denial-of-service attacks. [Means for solving the problem]
[0009] In order to solve the above-mentioned problems and achieve the objectives, the test device comprises an access investigation unit that investigates access methods for multiple devices present in the network to be tested, a test scenario unit that generates test packets based on the results of the access method investigation and a scenario that describes the procedures for generating test packets, a transmission unit that transmits the test packets, and a log analysis unit that collects logs from devices to which test packets are sent, among the multiple devices present in the network to be tested, and analyzes the collected logs. [Effects of the Invention]
[0010] According to the present invention, it is possible to send test packets to the upper layers of a plurality of devices and test their resistance to denial-of-service attacks. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a network including a test device according to this embodiment. [Figure 2]FIG. 2 is a functional block diagram showing the configuration of the test device according to this embodiment. [Figure 3] FIG. 3 is a flowchart showing the processing procedure of the test device according to this embodiment. [Figure 4] FIG. 4 is a flowchart showing the procedure of the test packet generation process. [Figure 5] FIG. 5 is a diagram illustrating an example of a computer that executes a test program. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the testing device disclosed in the present application will be described in detail with reference to the accompanying drawings, although the present invention is not limited to these embodiments. [Example]
[0013] 1 is a diagram showing an example of the configuration of a network including a test device according to this embodiment. As shown in Fig. 1, a test environment 1 includes a test device 100, a DNS (Domain Name System) server 31, a search server 32, and a test target network 20.
[0014] The network under test 20 includes a network device 21 and servers 22 and 23. Although not shown in FIG.
[0015] The test environment 1 includes a test device 10, a DNS server 31, a search server 32, and a test target network 20, which are connected by any type of communication network such as a wired or wireless LAN (Local Area Network) or VPN (Virtual Private Network).
[0016] The network device 21 connects the test device 100 with the servers 22 and 23 in the network under test 20. The network device 21 is a router, a firewall, or the like.
[0017] When the servers 22 and 23 receive access, they provide a service to the device that made the access.
[0018] The DNS server 31 provides a mechanism for converting domain names and IP (Internet Protocol) addresses. In this embodiment, when the DNS server 31 receives IP address information from the test device 100, it performs a reverse DNS lookup, extracts the domain name corresponding to the IP address, and transmits the extracted domain name information to the test device 100.
[0019] When the search server 32 receives specification of text data to be searched, it extracts URLs (Uniform Resource Locators) accessible via HTTP (Hypertext Transfer Protocol). In this embodiment, when the search server 32 receives domain name information from the test device 100, it extracts HTTP-accessible URLs including subdomain names of the domain name, and transmits the extracted URL information to the test device 100.
[0020] The test device 100 is a device that transmits test packets to devices such as servers 22 and 23 included in the network under test 20, and executes security resistance tests against denial-of-service attacks, etc. The test device 100 receives packets transmitted from the network under test 20, and monitors the load status of each device (servers 22, 23, etc.) included in the network under test 20.
[0021] Next, an example of the configuration of the test apparatus 100 shown in Fig. 1 will be described. Fig. 2 is a functional block diagram showing the configuration of the test apparatus according to this embodiment. As shown in Fig. 2, the test apparatus 100 includes an interface unit 110, a control unit 120, and a storage unit 130.
[0022] The interface unit 110 is an interface that controls communications with other devices. For example, the interface unit 110 transmits and receives packets to and from other devices via a network. The interface unit 110 is a network interface such as a LAN card.
[0023] The interface unit 110 includes a test packet interface 111 and a monitoring interface 112 .
[0024] The test packet interface 111 transmits and receives packets in accordance with the execution of the test packet transmission and reception function. The monitoring interface 112 transmits and receives packets in accordance with the execution of the monitoring unit 122, which will be described later.
[0025] The control unit 120 controls the entire test apparatus 10. The control unit 120 includes a test packet transmitting / receiving unit 121, a monitoring unit 122, and a log analyzing unit 123. The control unit 120 is a processor such as a CPU (Central Processing Unit) or an MPU (Micro Processing Unit).
[0026] The test packet transmitting / receiving unit 121 transmits test packets to devices such as the servers 22 and 23 included in the test target network 20, and performs security resistance tests against denial-of-service attacks, etc. The test packet transmitting / receiving unit 121 includes an access investigation unit 121a, a test scenario unit 121b, and a transmitting unit 121c.
[0027] The access inspection unit 121a is a processing unit that inspects access methods to the servers 22 and 23 and other servers (not shown) included in the test target network 20. For example, the access inspection unit 121a executes a first inspection process and a second inspection process.
[0028] The "first investigation process" executed by the access investigation unit 121a will be described. The access investigation unit 121a investigates whether a TCP (Transmission Control Protocol) connection can be established using a specified destination port number for all IP addresses included in the IP address range of the test target network 20. Information on the IP address range of the test target network 20 is set in advance in the storage unit 130. The specified destination port numbers are "443" and "80", but are not limited to these.
[0029] The access inspection unit 121a executes a three-way handshake to check whether a TCP connection can be established. Specifically, the access inspection unit 121a sends TCP SYN packets with a specified destination port number set to all IP addresses in the test target network 20. The access inspection unit 121a records the destination IP addresses from which a SYN / ACK response is returned in the IP address table 130a of the storage unit 130 as IP address accessible targets.
[0030] The IP addresses recorded in the IP address table 130a are IP addresses to which a TCP connection can be established using a specified destination port number. Using such IP addresses makes it possible to test the resistance to denial-of-service attacks against multiple destination IP addresses using TCP. Furthermore, if destination port numbers 443 and 80 are used, it is possible to test the resistance to denial-of-service attacks against multiple destination IP addresses by substituting IP addresses for FQDNs (Fully Qualified Domain Names) for websites.
[0031] Next, the "second investigation process" executed by the access investigation unit 121a will be described. The access investigation unit 121a searches for URLs within the entire IP address range of the network 20 under test.
[0032] Specifically, the access inspection unit 121a transmits information on all IP addresses in the IP address range of the network under test 20 to the DNS server 31, and receives domain names for all IP addresses in the IP address range of the network under test 20 from the DNS server 31. The access inspection unit 121a transmits the received domain name information to the search server 32, and receives from the search server 32 an HTTP-accessible URL that includes a subdomain name of the domain name.
[0033] The access inspection unit 121a accesses the received URL and receives a response packet from the access destination. If the IP address (source IP address) of the response packet is included in the IP address range of the test target network 20, the access inspection unit 121a records the URL used for the access (the URL including the FQDN) as an accessible URL in the URL table 130b of the storage unit 130. The access inspection unit 121a repeatedly performs the above process for multiple HTTP-accessible URLs that include subdomain names of the domain name.
[0034] In this way, the access investigation unit 121a investigates whether HTTP access is possible using a URL containing an FQDN to the servers 22 and 23 in the test target network 20. This makes it possible to test resistance to denial of service attacks against multiple destination IP addresses by HTTP access with an FQDN in the URL, even if the website is set not to respond to HTTP requests with an IP address in the URL.
[0035] Based on the investigation results of the access investigation unit 121a and a preset scenario, the test scenario unit 121b establishes a TCP connection with the test target network 20 at a specified destination port number and generates a test packet. The scenario is information in which the procedure for generating a test packet is described using a script or the like.
[0036] Based on the investigation results of the access investigation unit 121a, IP addresses within the IP address range of the test target network 20 to which a TCP connection can be established and which are accessible as IP addresses are recorded in the IP address table 130a. The test scenario unit 121b establishes a TCP connection with the IP addresses recorded in the IP address table 130a, and then generates an HTTP request packet for testing resistance to denial of service attacks using HTTP. In the following description, the HTTP request packet for testing resistance to denial of service attacks using HTTP will be referred to as a "test packet" where appropriate.
[0037] If the servers 22, 23 of the network 20 under test are websites and the websites are accessible via IP addresses, the test scenario unit 121b generates test packets for the websites by setting the IP addresses instead of the FQDNs as HTTP request packets.
[0038] Meanwhile, based on the URL table 130b, if the servers 22 and 23 in the test target network 20 are websites and are URL-accessible targets, the test scenario unit 121b generates a test packet for the website using a URL containing the FQDN (a URL recorded in the URL table 130b) as an HTTP request packet.
[0039] The transmitting unit 121c transmits the test packets generated by the test scenario unit 121b to the servers 22 and 23 (or other servers) of the test target network 20. For example, the transmitting unit 121c increases the processing load on the servers 22 and 23 by gradually increasing the number of test packets to be transmitted based on the scenario set in the test scenario unit 121b.
[0040] When transmitting test packets, the transmitting unit 121c may transmit packets generated by operating a web browser to the same device as the test packets. The packets generated by operating a web browser are assumed to be recorded in advance in the storage unit 130.
[0041] The monitoring unit 122 monitors the packet filter status and processing load status of the servers 22 and 23. To monitor the packet filter status, the monitoring unit 122 monitors the number of test packets, byte volume, and number of sessions per unit time for each source IP address, as well as response packets from the network under test 20, and identifies a source IP address from which response packets have stopped arriving despite test packets being sent, even though response packets have arrived for test packets from other source IP addresses. The monitoring unit 122 records the number of test packets, byte volume, number of sessions, and timestamp sent to the source IP address just before response packets stopped arriving as the packet filter threshold for the network under test 20, and notifies the control unit 120.
[0042] After the test, the log analysis unit 123 collects logs from each device, such as the servers 22 and 23, on the path through which the test packet flowed, including the network under test 20, and checks the response of each device to the test packet to analyze whether the processing load has increased or whether normal packets have been discarded. The log analysis unit 123 may record the analysis results in the storage unit 130.
[0043] For example, based on the log, the log analysis unit 123 determines that the processing load of the server 22, 23, etc. through which the test packet has flowed has increased if the time from receiving a packet to transmitting a response packet is equal to or greater than a threshold. The log analysis unit 123 stores information for identifying normal packets, and determines whether the log contains a history of discarding a normal packet.
[0044] The storage unit 130 stores various types of information used when the control unit 120 executes processing. For example, the storage unit 130 stores the above-mentioned IP address table 130a, URL table 130b, etc. The storage unit 130 is realized by, for example, a semiconductor memory element such as a flash memory, or a storage device such as a hard disk.
[0045] Next, an example of the processing procedure of the test device 100 according to this embodiment will be described. Fig. 3 is a flowchart showing the processing procedure of the test device according to this embodiment. As shown in Fig. 3, the access investigation unit 121a of the test device 100 executes a first investigation process to identify IP addresses that are accessible to the IP address, and records the IP addresses in the IP address table 130a (step S101).
[0046] The access check unit 121a executes the second check process to identify URLs that are URL accessible, and records the URLs in the URL table 130b (step S102).
[0047] The test scenario unit 121b of the test device 100 executes a test packet generation process (step S103). The transmission unit 121c of the test device 100 transmits test packets to each device in the test target network 20 based on the scenario (step S104).
[0048] The monitoring unit 122 of the test device 100 performs monitoring of each device in the test target network 20 (step S105). The log analysis unit 123 of the test device 100 collects logs from each device in the test target network 20 and performs log analysis (step S106).
[0049] Next, the processing procedure of the test packet generation processing shown in step S103 of Fig. 3 will be described. Fig. 4 is a flowchart showing the processing procedure of the test packet generation processing. The processing procedure of Fig. 4 is processing based on a scenario set in advance. The test scenario unit 121b of the test device 100 acquires from the IP address table 130a IP addresses that are TCP connectable and IP address accessible within the IP address range of the test target network 20 (step S201).
[0050] The test scenario unit 121b generates a test packet by setting an IP address instead of an FQDN as an HTTP request packet (step S202).
[0051] The test scenario unit 121b acquires URLs related to IP addresses from the range of IP addresses in the test target network 20 that are domain extractable, URL extractable, and URL accessible from the URL table 130b (step S203).
[0052] The test scenario unit 121b generates a test packet by setting a URL including an FQDN as an HTTP request packet (step S204).
[0053] Next, the effects of the test device 100 according to this embodiment will be described. The test device 100 investigates access methods for multiple devices present in the network under test 20, generates test packets based on the results of the access method investigation and a scenario describing the procedure for generating test packets, transmits the test packets, collects logs from devices that have transmitted the test packets among the multiple devices present in the network under test, and analyzes the collected logs. This makes it possible to send test packets to the upper layers of multiple devices and test their resistance to denial-of-service attacks.
[0054] The test device 100 performs a three-way handshake with IP addresses included in the IP address range of the test target network 20 to check whether a TCP connection can be established, and records the IP addresses with which a TCP connection can be established in the IP address table 130a. The test device 100 also establishes a TCP connection based on the IP addresses recorded in the IP address table 130a and a predetermined destination port number, and generates a test packet by setting the IP address recorded in the IP address table 130a in an HTTP request packet. In this way, by using the IP addresses in the IP address table 130a, it is possible to test the resistance to denial-of-service attacks using TCP against multiple destination IP addresses. Furthermore, when destination port numbers 443 and 80 are used, it is possible to test the resistance to denial-of-service attacks against multiple destination IP addresses by substituting IP addresses for FQDNs for websites.
[0055] The test device 100 extracts URLs corresponding to domain names of IP addresses included in the IP address range of the network under test 20, and if the IP address of a response packet received when the extracted URL is accessed is included in the IP address range of the network under test 20, executes a process of recording the extracted URL in the URL table 130b. Furthermore, if the URLs of sites of multiple devices present in the network under test 20 are recorded in the URL table 130b, the test device 100 generates a test packet by setting the URL recorded in the URL table 130b in an HTTP request packet. This makes it possible to test denial-of-service attack resistance against multiple destination IP addresses by HTTP access with an FQDN in the URL, even if the website is configured not to respond to HTTP requests with an IP address in the URL.
[0056] The test device 100 transmits test packets and packets generated by operating a web browser to the network under test 20. This makes it possible to test the response of each device in the network under test 20 when the web browser operation is added in addition to the test packets.
[0057] The test device 100 analyzes whether or not the processing load of the device to which the test packets are sent has increased and whether or not normal packets have been discarded, based on the logs collected from the test target network 20. This makes it possible to obtain the analysis results of the test of resistance to denial of service attacks.
[0058] Incidentally, when the server 22 or 23 is a server other than a web server, such as a DNS server, or when an investigation is performed on the network device 21, the test device 100 transmits denial-of-service attack packets and normal packets according to the protocols and applications provided by the device under test. This allows the security resistance investigation and bottleneck investigation of all the devices under test in the network under test 20 to proceed.
[0059] Next, an example of a computer that executes a test program will be described. Fig. 5 is a diagram showing an example of a computer that executes a test program. A computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0060] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores, for example, a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1031. The disk drive interface 1040 is connected to a disk drive 1041. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1041. The serial port interface 1050 is connected to, for example, a mouse 1051 and a keyboard 1052. The video adapter 1060 is connected to, for example, a display 1061.
[0061] Here, the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. Each piece of information described in the above embodiment is stored in the hard disk drive 1031 or memory 1010, for example.
[0062] The test program is stored in the hard disk drive 1031 as a program module 1093 in which commands to be executed by the computer 1000 are written. Specifically, the program module 1093 in which processes for executing the test packet transmitting / receiving unit 121, the monitoring unit 122, and the log analyzing unit 123 described in the above embodiment are written is stored in the hard disk drive 1031.
[0063] Furthermore, data used for information processing by the test program is stored as program data 1094, for example, in the hard disk drive 1031. Then, the CPU 1020 reads the program module 1093 and the program data 1094 stored in the hard disk drive 1031 into the RAM 1012 as necessary, and executes each of the above-described procedures.
[0064] The program module 1093 and program data 1094 related to the test program are not limited to being stored in the hard disk drive 1031, but may be stored in a removable storage medium and read by the CPU 1020 via the disk drive 1041, etc. Alternatively, the program module 1093 and program data 1094 related to the test program may be stored in another computer connected via a network such as a LAN or a WAN (Wide Area Network), and read by the CPU 1020 via the network interface 1070.
[0065] Although the present invention has been described above as an embodiment, the present invention is not limited to the description and drawings that form part of the disclosure of the present invention. In other words, other embodiments, examples, and operational techniques that can be made by those skilled in the art based on the present invention are all included in the scope of the present invention. [Explanation of symbols]
[0066] 1 Test environment 20 Test Network 21 Network equipment 22,23 Server 31 DNS Server 32 Search Server 100 Test Equipment 110 Interface section 111 Test packet interface 112 Monitoring Interface 120 control section 121 Test packet transmission / reception unit 121a Access Research Department 121b Test Scenario Section 121c transmitter 122 Monitoring Department 123 Log Analysis Unit
Claims
1. an access investigation unit that investigates whether a TCP (Transmission Control Protocol) connection can be established by executing a three-way handshake with an IP address included in the IP address range of the network to be tested, and records the IP addresses that can establish the TCP connection as investigation results in an IP address table; a test scenario unit that generates the test packets based on the results of the investigation and a scenario that describes a procedure for generating test packets; a transmitter for transmitting the test packet; a log analysis unit that collects logs from a device to which the test packet is transmitted among a plurality of devices present in the network under test and analyzes the collected logs; A test device comprising:
2. 2. The test device according to claim 1, wherein the access investigation unit extracts a URL (Uniform Resource Locator) corresponding to a domain name of an IP address included in the IP address range of the network under test, and if the IP address of a response packet received when the extracted URL is accessed is included in the IP address range of the network under test, records the extracted URL in a URL table.
3. The test device according to claim 2, characterized in that the test scenario unit establishes a TCP connection based on an IP address recorded in the IP address table and a predetermined destination port number, and generates the test packet by setting the IP address recorded in the IP address table in an HTTP (Hypertext Transfer Protocol) request packet.
4. The test device according to claim 3, characterized in that, when the URLs of the sites of multiple devices present on the network to be tested are recorded in the URL table, the test scenario unit generates the test packet by setting the URL recorded in the URL table in the HTTP request packet.
5. 2. The test device according to claim 1, wherein the transmission unit transmits the test packets and packets generated by operating a web browser to the network under test.
6. 2. The test device according to claim 1, wherein the log analysis unit analyzes, based on the collected logs, whether or not the processing load of the device to which the test packets are sent has increased, and whether or not normal packets have been discarded.
Citation Information
Patent Citations
Test device
JP2020129736A
Testing device, testing method, and testing program
WO2022070425A1