Simulating Customer Deployment Environments for Network Security Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security testing faces challenges in simulating the customer series deployment environment, leading to poor environment applicability and incomplete testing, which affects the operation stability of security protection devices.

Innovation Solution

A test method and device that obtain traffic data from an on-site protected host, extract session data, and transmit application layer data to a local test environment for simulation, using techniques like IP address configuration, filtering with tools like Wireshark, and parsing TCP sessions to accurately replicate the customer site environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If series monitoring mode is used to test customer site environment, then the security protection device can be deployed in a realistic scenario, but it is difficult to fully simulate the same test environment due to variety of customer site environments

Engineering Contradiction:
Improveenvironment applicabilityVSAvoidtest environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the customer site environment by capturing actual traffic data from the customer site and reconstructing it in a local test environment. This allows the test environment to replicate the real customer environment without physically being at the customer site, solving the contradiction between realistic testing and environment complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the test environment from a physical customer site to a local virtual environment by changing key parameters such as location, network configuration, and data representation. This allows the same security protection device to be tested in a controlled local environment that mirrors the customer site conditions.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If bypass monitoring mode is used, then the test deployment is simple, but the testing is incomplete and environment applicability is poor

Engineering Contradiction:
Improvetest deployment easeVSAvoidtesting completeness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary component (the traffic data capture and processing system) that bridges the gap between the simple bypass monitoring mode and the comprehensive series monitoring mode. This intermediary captures traffic data in bypass mode but processes and analyzes it as if in series mode, achieving both ease of deployment and testing completeness.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If complete TCP session data is captured and analyzed, then the simulation accuracy is improved, but the data processing time and complexity increase

Engineering Contradiction:
Improvesimulation accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the essential elements needed for accurate simulation (application layer data from TCP sessions) rather than processing all raw traffic data. By taking out and focusing on the critical data components, it achieves high simulation accuracy without the time penalty of processing complete raw session data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11956128B2Test method and device for simulating customer series deployment environment
Publication Date: 2024.04.09 DBAPPSECURITY CO LTD
  • US11956128B2 patent drawing
  • US11956128B2 patent drawing
  • US11956128B2 patent drawing

AI summary

A test method and device for simulating a customer series deployment environment, an electronic device, and a storage medium are provided. The test method for simulating a customer series deployment environment includes: obtaining traffic data of an on-site protected host; obtaining session data between the on-site protected host and a server on the basis of the traffic data, and extracting application layer data from the session data; and transmitting and receiving the application layer data in a local test environment to carry out simulation test.