CLD-Based TCP Assembly for Line-Speed Network Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current testing solutions for content-aware network devices are inadequate, failing to rigorously test performance and security under real-world conditions, especially at line speeds, due to their focus on traditional IP network testing and lack of consideration for Layers 4-7 attributes, leading to deployment challenges and potential failures.
Innovation Solution
A network testing system that includes a configurable logic device (CLD) to parse and assemble network packets, allowing for realistic simulation of application workloads and security attacks at line speed, and emulating various application protocols across Layers 2-7 to ensure comprehensive testing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional testing solutions are used to test content-aware network devices, then the testing process is simple and familiar, but the testing capability is insufficient and cannot rigorously test performance and security under real-world conditions at line speeds
Solution Approach 1:
The testing system is segmented into multiple specialized components: a traffic generator for creating test traffic, a CLD-based testing device for high-speed packet processing and assembly, and a protocol analyzer for verification. This segmentation allows each component to be optimized for its specific function, enabling rigorous line-speed testing without overwhelming system complexity
Solution Approach 2:
The configurable logic device (CLD) acts as an intermediary between the traffic generator and the protocol analyzer. It receives partially assembled packets, completes the assembly process at high speed, and forwards fully assembled packets for analysis. This intermediary component enables the system to bridge the gap between simplified testing approaches and comprehensive testing requirements
2Adaptability or versatility
If legacy testing solutions focusing on IP network connection are used, then the testing approach is straightforward, but the functionality is insufficient to properly test content-aware/DPI-capable devices and Layers 4-7 attributes
Solution Approach 1:
The CLD-based testing device is designed with multi-functionality to handle various testing requirements: it can generate traffic, assemble TCP packets from segments, perform deep packet inspection, and analyze Layers 4-7 protocols. This universal testing platform can adapt to test different content-aware devices and protocols without requiring separate specialized systems for each function
Solution Approach 2:
The testing system employs dynamic configuration capabilities where the CLD can be reprogrammed to adapt to different protocol requirements and testing scenarios. This dynamic nature allows the system to evolve with emerging protocols and testing needs, providing versatile functionality while maintaining a relatively simple base architecture
3Measurement precision
If comprehensive testing of Layers 4-7 attributes is implemented, then the testing thoroughness is improved, but the testing complexity and difficulty increase significantly
Solution Approach 1:
The system replaces complex software-based packet assembly and analysis mechanisms with hardware-based CLD implementations. This substitution enables precise measurement of Layers 4-7 attributes at line speeds without the computational complexity and timing issues that would arise from software-based approaches
Data Source
AI summary
A method offloading data intensive tasks from a processor comprises receiving at a configurable logic device (CLD) a network packet, parsing the network packet to determine that the packet is a TCP segment, searching a partially assembled packet table to locate an associated partially assembled packet data structure, inserting the network packet into the associated partially assembled packet data structure, recognizing that the partially assembled packet data structure contains every segment produced from an original TCP packet, assembling a fully assembled TCP packet from the data in the partially assembled packet data structure, and transmitting the fully assembled TCP packet to a processor in the same computer system as the CLD.


