Test Device Bypasses Security IP Limits for Load Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional packet load testing schemes are limited by security systems that discard test packets due to source IP address limitations, requiring multiple testing devices and restricting test scenarios to simple authentication responses, thus incurring high costs and limited test capabilities.
Innovation Solution
A testing device that transmits test packets to simulate increased processing loads on security systems, using multiple source IP addresses, and responds to authentication requests to validate packets, while monitoring packet filtering and processing loads, allowing for comprehensive packet load testing beyond simple HTTP GET Flood scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single testing device uses a limited source IP address to transmit test packets, then the device complexity is reduced, but the productivity decreases because packets are discarded by the security system's filter
Solution Approach 1:
The system dynamically changes the source IP address parameter of test packets to bypass the security system's packet filter. By rotating through multiple IP addresses from a pool, the testing device can transmit packets that would otherwise be discarded, thereby maintaining both device simplicity and high productivity
2Productivity
If multiple testing devices are deployed to overcome packet filtering, then the productivity increases, but the device complexity and cost increase
Solution Approach 1:
The patent combines multiple IP address capabilities into a single testing device by implementing an IP address pool management system. This allows one device to perform the function of multiple devices by rotating through different source IP addresses, thereby achieving high productivity without increasing device complexity or cost
3Reliability
If the security system performs multi-stage authentication, then the reliability of security verification is improved, but the productivity of packet processing decreases
Solution Approach 1:
The testing device performs preliminary actions by responding to authentication challenges at each stage with valid credentials. By proactively completing the authentication process before packet filtering occurs, the system ensures packets are marked as legitimate, allowing both high security verification and maintained processing throughput
4Reliability
If the testing device responds to authentication requests, then the packet validity is improved, but the device complexity increases due to response generation requirements
Solution Approach 1:
The testing device implements self-service by automatically generating and managing authentication credentials without external assistance. The device autonomously handles the complete authentication workflow including credential generation, challenge response, and session management, thereby ensuring packet validity while keeping the system self-contained and manageable
Data Source
AI summary
A testing device (10) transmits a test packet that increases processing load to a device protected by a security system, the security system performing authentication of a packet transmitted to a to-be-protected device and a packet limit per source IP address. In addition, the testing device (10) generates a test session according to a scenario when transmitting the test packet and configures a packet so that the test packet uses a plurality of source IP addresses. In addition, the testing device (10) responds to a response request up to a predetermined stage of authentication among a plurality of stages of authentication performed by the security system so that the security system authenticates the test packet to be valid. In addition, the testing device (10) monitors, at a predetermined stage, packet filtering situation and processing load of the security system to which the test packet is transmitted.


