Test Device Bypasses Security IP Limits for Load Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional packet load testing schemes are limited by security systems that discard test packets due to source IP address limitations, requiring multiple testing devices and restricting test scenarios to simple authentication responses, thus incurring high costs and limited test capabilities.

Innovation Solution

A testing device that transmits test packets to simulate increased processing loads on security systems, using multiple source IP addresses, and responds to authentication requests to validate packets, while monitoring packet filtering and processing loads, allowing for comprehensive packet load testing beyond simple HTTP GET Flood scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single testing device uses a limited source IP address to transmit test packets, then the device complexity is reduced, but the productivity decreases because packets are discarded by the security system's filter

Engineering Contradiction:
Improvetesting device configurationVSAvoidpacket transmission effectiveness
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system dynamically changes the source IP address parameter of test packets to bypass the security system's packet filter. By rotating through multiple IP addresses from a pool, the testing device can transmit packets that would otherwise be discarded, thereby maintaining both device simplicity and high productivity

Inventive Principle:
Principle #35Parameter changes

2Productivity

If multiple testing devices are deployed to overcome packet filtering, then the productivity increases, but the device complexity and cost increase

Engineering Contradiction:
Improvepacket transmission effectivenessVSAvoidtesting system configuration
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines multiple IP address capabilities into a single testing device by implementing an IP address pool management system. This allows one device to perform the function of multiple devices by rotating through different source IP addresses, thereby achieving high productivity without increasing device complexity or cost

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the security system performs multi-stage authentication, then the reliability of security verification is improved, but the productivity of packet processing decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidpacket processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The testing device performs preliminary actions by responding to authentication challenges at each stage with valid credentials. By proactively completing the authentication process before packet filtering occurs, the system ensures packets are marked as legitimate, allowing both high security verification and maintained processing throughput

Inventive Principle:
Principle #10Preliminary action

4Reliability

If the testing device responds to authentication requests, then the packet validity is improved, but the device complexity increases due to response generation requirements

Engineering Contradiction:
Improvepacket authentication validityVSAvoidauthentication response capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The testing device implements self-service by automatically generating and managing authentication credentials without external assistance. The device autonomously handles the complete authentication workflow including credential generation, challenge response, and session management, thereby ensuring packet validity while keeping the system self-contained and manageable

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11943250B2Test device
Publication Date: 2024.03.26 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11943250B2 patent drawing
  • US11943250B2 patent drawing
  • US11943250B2 patent drawing

AI summary

A testing device (10) transmits a test packet that increases processing load to a device protected by a security system, the security system performing authentication of a packet transmitted to a to-be-protected device and a packet limit per source IP address. In addition, the testing device (10) generates a test session according to a scenario when transmitting the test packet and configures a packet so that the test packet uses a plurality of source IP addresses. In addition, the testing device (10) responds to a response request up to a predetermined stage of authentication among a plurality of stages of authentication performed by the security system so that the security system authenticates the test packet to be valid. In addition, the testing device (10) monitors, at a predetermined stage, packet filtering situation and processing load of the security system to which the test packet is transmitted.