¤Þ¨¥ :
À³¥Î¼h³]³Æªº©Ê¯à´ú¸Õ¬O¤@Ó½ÆÂøªº¥ô°È¡A»Ýn±Ä¥Î±M·~ªº°ª©Ê¯à¤u¨ãºc³y½ÆÂø©M¯u¹êªº¦³ª¬ºAÀ³¥Î¼h¬y¶qÅçÃÒ³]³Æªº²`¼h«Ê¥]ÀË´ú¡]DPI¡^¯à¤O¡C¯S§O¬O·s¤@¥NÀ³¥Î¼h³]³Æ¥i¥H³B²z¤W¤d¸U¯Å§Oªº¦P®ÉTCP ·|¸Ü¡A¶W¹L¦Ê¸U¯Å§OªºTCP·s«Ø³t«×¡B¶W¹L100GªºÀ³¥Î¼h§]¦R¶q©M¤d¸U¯Å§Oªº¥Î¤á¼Æ¶q¡C ³o¨Ç°ª©Ê¯à³]³Æ´N»Ýn±M·~ªº´ú¸Õ¤u¨ã¦P®É¥é¯u¦h«¼½©ñ¬y¶q¡]Mulitplay Traffic¡^¥þ±ÅçÃÒ¨ä©Ê¯à¥H¤Î¤ÀªRºÞ²z¬y¶qªº¯à¤O¡A¨Ã¥B¥i¥H±o¨ì¦UºØÀ³¥Îªº¥Î¤áÅéÅç«~½è¡]Quality of Experience - QoE¡^«ü¼Ð¡A³o¨ÇªA°Èµû©w«ü¼Ð¥]¬A¡G
-
HTTP¡G¨t²Î¯à°÷³B²z¦P®É³s±µ¼Æªº¼Æ¶q¡A¨t²Î¯à°÷³B²z³s±µ¼Æªº³t²v¥H¤Î¶±³X°Ýªº¤ÏÀ³®É¶¡¡C
-
FTP¡G¨t²Î¤W¶Ç©M/©Î¤U¸üÀɪº³Ì¤j¦³®Ä§]¦R¶q¡]Goodput¡^¡C
-
E-mail (POP3¡ASMTP¡AIMAP) ¡G¥Dnµû¦ôºô¸ô©M¨t²Î¯à°÷³B²z¶l¥óªº³t²v¡]¨C¬íÄÁµo°e©Î±µ¦¬¶l¥óªº¼Æ¶q¡Bµo°e©Î±µ¦¬ªþ¥óªº¼Æ¶qµ¥¡^¡C
-
Voice¡G¨t²Î³B²zªºIP¹q¸Ü©I¥sªº»yµ«~½è¡]MOS¡^¥H¤Î©I¥s«Ø¥ß®É¶¡¡C
-
Video¡G¨t²Î©Ò¤ä´©ªºVoDµøÀWÂI¼½ªºµøÀW«~½è¡]MDI¡AMOS_V¡^¡C
-
P2P¡GPeer-to-Peer¬y¶qªº§]¦R¶q
-
DNS¡G¨t²Î©Ò³B²zªºDNS¬d¸ß³t«×©M¤ÏÀ³®É¶¡
¥t¥~¡AÁÙ¥²¶·n¦Ò¼{¶i¦æ§ðÀ»¬y¶q¡]Attack Traffic¡^¤ñ¦p©Úµ´ªA°È§ðÀ»¡]DDoS¡^ªº´ú¸Õ¡A¥H«OÃÒ³o¨Ç²§±`¬y¶q¹ï¥¿±`·~°È¤£·|³y¦¨¼vÅT¡C
¥»¤å¥H·~¬É³Ì¬°¬y¦æ¡BÀ³¥Î³Ì¬°¼sªxªº¬ü°êIxia¤½¥q4-7¼hIxLoad´ú¸Õ¤u¨ã¬°¨Ò¡A¤¶²Ð³Ì¬°±`¨£ªºHTTP¨óij¬ÛÃö´ú¸Õ±M®×¡B´ú¸Õ¤èªk©M´ú¸Õµ²ªG¤ÀªRµ¥¡A³o¨Ç³£¬OÀ³¥Î¼h³]³Æ³Ì¬°°ò¥»¤]³Ì¬°±`¨£ªº´ú¸Õ¶µ¥Ø¡C»Ýn»¡©úªº¬O¡AÁöµM¬O¥HIxia IxLoad¬°¨Ò¶i¦æ¤¶²Ðªº¡A¦ý¬O¬ÛÀ³ªº´ú¸Õ¤èªk©Mµ²ªG¤ÀªR¬O³q¥Îªº¡C³o¨Ç´ú¸Õ±M®×¥]¬A¡G
- ³Ì¤jHTTP·s«Ø³s±µ³t²v¡]Maximum Connection per Second¡^
- ³Ì¤jHTTP¦P®É³s±µ¼Æ¶q¡]Maximum Concurrent Connection¡^
- ³Ì¤jHTTP ¨Æ°È¥æ©ö³t²v ¡]Maximum Transactions per Second¡^
- ³Ì¤jHTTP§]¦R¶q ¡]Maximum Throughput¡^
- ¦b¦³DDoS§ðÀ»¬y¶q¤Uªº©Ê¯à ¡]Application Forwarding Performance under DoS Attacks¡^
Ixia IxLoad¤ä´©¨ó©w¥H¤Î¯S©Ê¤¶²Ð®× :
¬ü°êIxia ¤½¥qIxLoad¬O¥Ø«e·~¬É³Ì¥þ±ªº´ú¸ÕÀ³¥Î¼h·~°Èªº¥iÂX®i©Ê¡B°ª¶°¦¨«×´ú¸Õ¤è®×¡A³Ì¬°ÅãµÛªº§Þ³N¯SÂI¥]¬A¡G
1.) ¤@ÓÀ³¥Îµ{¦¡¥é¯u¶W¹L20ºØÀ³¥Î¼hªA°È¡A¥]¬A¸ê®ÆªA°È
- TCP ¨ó©w©Ê¯à
- UDP¨ó©w©Ê¯à
- HTTP (1.0/1.1)
- SSLv2, SSLv3, TLSv1
- FTP
- SMTP
- POP3
- IMAP
- RTSP/RTP
- Telnet
- DNS
- DHCP
- LDAP
- Tracefile Replay
- SSH Client
- Radius Client
- Application Replay
- CIFS
- P2P
»yµªA°È
- SIP
- MGCP
- H.323
- H.248
- SGCP (Skinny)
DDoS©Mº|¬}±½´y¡]Vulnerability Attacks¡^
Web À³¥Î´ú¸Õ
µøÀWªA°È
- Channel zapping
- Broadcast TV and VoD
- IGMPv1/v2/v3, MLDv1/v2
- RTSP/RTP
°ª¯Åºô¸ô±µ¤J¤è¦¡
- PPPoE
- L2TP
- IPSec
- DHCP (including option 82)
- VLANs (802.1Q, QinQ, 802.1p)
- GTP
2.) ·¥°ªªº©Ê¯à¡A³Ì·s±À¥XªºAcceleron NP°ª©Ê¯à¼Ò²Õ¦b·J»E¼Ò¦¡¤U¡A¤@Óª«²z°ð¥i¥H²£¥Í¶W¹L80¸Uªº¯u¹ê§¹¾ãHTTP·s«Ø³s±µ³t²v¡A©ÎªÌ¤@¤d¸UªºHTTP¦P®É³s±µ¼Æ¡A¨Ã¥B¥i¤è«KÂX®i¨ì´X¦Ê¸U¥Î¤áªº¥é¯u¡A¦b¬Û¦Pªºª«²zªÅ¶¡¤U¡AIxia ¥i´£¨Ñ»·¶W¹LÄvª§¹ï¤âªº©Ê¯à«ü¼Ð¡C
3.) ©M²{¹êºô¸ô¤@¼Ë¡A¥é¯u¯u¹ê¥Î¤á¦æ¬°¡F¥i¥H°ò©ó¨C¤@ӥΤá¶i¦æ·~ªA°È¥é¯u©MQoE«~½è¤ÀªR
4.) ¹ïºô¸ô¬[ºc¤¤ªº«n²Õ¦¨³¡¤À¶i¦æ©Ê¯àµû¦ô¡F AAA/RADIUS services, DNS, DHCP, LDAP
5.) ¦P®É¥i¥H²£¥Í²§±`©ÎªÌ«Dªk¬y¶q¹ï³]³Æªº¦w¥þ©Ê¶i¦æµû¦ô¡C
¥Dn´ú¸Õ¶µ¥Ø :
3.1 ³Ì¤jHTTP·s«Ø³s±µ³t²v¡]Maximum Connection per Second¡^
¥Ñ©óTCP©î³s±µ¦³¦hºØ¤èªk¡A©Ò¥H¦³¦hºØ³~®|¨Ó´ú¸Õ³Ì¤jHTTP·s«Ø³s±µ³t²v¡G
- º¥ýTCP³s±µ«Ø¥ß¡]SYN,SYN-ACK,ACK¡^¡AµM«á¬O¤@Ó§¹¾ãªº¥]¬A½Ð¨D©M¦^À³ªº7¼h¥æ©ö¹Lµ{¡A³Ì«á¬°TCP©î°£³s±µ¡]FIN,ACK¡^¡C
- º¥ýTCP³s±µ«Ø¥ß¡]SYN,SYN-ACK,ACK¡^¡AµM«á¬O¤@Ó³¡¤À©ÎªÌ¤£§¹¾ãªº7¼h¥æ©ö½Ð¨D¡A³Ì«á¬°TCP©î°£³s±µ¡]FIN,ACK¡^¡C
- º¥ýTCP³s±µ«Ø¥ß¡]SYN,SYN-ACK,ACK¡^¡AµM«á¬O¤@Ó³¡¤À©ÎªÌ¤£§¹¾ãªº7¼h¥æ©ö½Ð¨D¡A³Ì«á¬°TCP³s±µª½±µ´_¦ì¡]Reset¡^¡C
³Ì¬°²z·Qªº¤è¦¡¬°¤W±ªº²Ä¤@ºØ¡A¦]¬°¨ä¥]§t¤F§¹¾ãªº¦¨¥\7¼h¨óij¥æ¤¬¹Lµ{¡C¦ý¬O¹ï©ó¶ÈÃö¤ß4¼hTCP©Ê¯àªº³]³Æ¨Ó»¡¡A²Ä¤GºØ¤è¦¡¤ñ¸û¦X¾A¡C²Ä¤TºØ¤è¦¡±`¥Î©ó±j¨î©î°£TCP³s±µ¤U³Q´ú³]³ÆªºÀ£¤O´ú¸Õ¡C
¸ÓÃþ§Oªº´ú¸Õ¦Ü¤Ö»Ýn¥Î¤áºÝ©M¦øªA¾¹ºÝ¦U¤@Ó°ð¡AHTTP¥Î¤áºÝ¬y¶q³q¹L³Q´ú³]³Æ¨ì¹FHTTP ¦øªA¾¹ºÝ¡A¹Ï1¬O´ú¸Õ³s±µªº¥Ü·N¡C

¹Ï1: À³¥Î¼h³]³Æ´ú¸Õ¥Ü·N¹Ï
ªí1¬O¶i¦æHTTP·s«Ø³s±µ³t²v´ú¸Õ®É³q±`³]¸mªº°Ñ¼Æªí¡A³o¨Ç¨å«¬°Ñ¼Æ³]¸m¥é¯u¤Fºô¸ô¤¤¨å«¬ªºHTTPÀ³¥Î±¡ªp¡A¥i¥H¦b¹êÅç«ÇùرÅçÃÒ³Q´ú³]³Æ¦bºô¸ô¤¤ªºHTTP·s«Ø³s±µ³t²v©Ê¯àªí²{¡C
¥Dn°Ñ¼Æ³]¸m |
´yz |
HTTP ¥Î¤áºÝ |
100 IP addresses or more, use sequential or ¡§use all¡¨ IP addresses |
HTTP ¥Î¤áºÝ¥Dn°Ñ¼Æ³]¸m |
HTTP/1.0,µLKeep-aliveÄÝ©Ê
¨CӥΤá20 ÓTCP ³s±µ
¨CÓTCP³s±µ¤@Ó¥æ©ö¨Æ°È¡] Transaction¡^ |
TCP °Ñ¼Æ |
TCP RX ©M TX ½w¦s³]¸m¬° 4096 ¦ì¤¸²Õ |
HTTP ¥Î¤áºÝ©R¥O¦Cªí |
1 GET ©R¥O ¡V ¶±¤j¤p¬° 1-128 ¦ì¤¸²Õ |
HTTP ¦øªA¾¹ºÝ |
¨CÓIxia´ú¸Õ°ð¥é¯u¤@өΪ̦hÓ¦øªA¾¹ |
HTTP ¦øªA¾¹ºÝ¥Dn°Ñ¼Æ³]¸m |
ÀH¾÷¤ÏÀ³®É©µ 0 ¡V 20 ms
¦^À³¶W®É®Éªø 300 ms |
ªí1: HTTP·s«Ø³s±µ³t²v´ú¸Õ®É«ØÄ³IxLoad °Ñ¼Æ³]¸m
ªí2Á`µ²¤F¤@¨Ç¨å«¬ªºÀ³¥Î³õ´º¡A®Ú¾Ú³Q´ú³]³ÆªºÃþ«¬¥H¤Î¤£¦Pªº¤u§@¼Ò¦¡¡A¥Î¤Wz°Ñ¼Æ¶i¦æ³]¸m¨Ã¶i¦æ´ú¸Õ¡C
³]³ÆÃþ«¬ |
°t¸m³W«h |
´yz |
t¸ü§¡¿Å³]³Æ¡]SLB¡^ |
°t¸m¸ê®Æ«Ê¥]¹LÂo³W«h |
°t¸mSLB¸ê®Æ¥]ÀË´ú¤ÞÀº
³]¸m¬°t¸ü§¡¿Åºtºâªk
¬°¦øªA¾¹ºÝ³]¸m¬°¾ô±µ©ÎªÌ¸ô¥Ñ¼Ò¦¡ |
¨¾¤õÀð |
°t¸m±µ¤J³X°Ý±±¨î³W«h |
°t¸m¬°NAT¼Ò¦¡©ÎªÌ³]¸m¬°¸ô¥Ñ¼Ò¦¡ |
¨¾¤õÀðÃþªº³q¥Î¦w¥þÀË´ú³]³Æ |
°t¸m¬°²`¼h¸ê®Æ«Ê¥]ÀË´ú¡]DPI¡^¥\¯à |
°t¸m¦UºØÀ³¥ÎÀË´ú»PÃѧO¥\¯à
°t¸mIDS ©ÎªÌ´c·N§ðÀ»ÀË´ú¥\¯à |
ªí2: ³Q´ú³]³Æ¨å«¬ªº¤u§@¼Ò¦¡»P«ØÄ³°t¸m
¨ãÅé±Ä¥ÎIxLoad¶i¦æ´ú¸Õ³]¸mªº¨BÆJ¡A¥i¥HÁpµ¸Ixia¤½¥q±o¨ì¾Þ§@«ü¾É®Ñ¡A´ú¸Õªº¥Øªº¬O¯à°÷±o¨ì¹w´Áªºµ²ªG¨Ã¯à°÷¹ï¥X²{ªº¦UºØ²§±`©ÎªÌ°ÝÃD´£¨Ñ¤ÀªR©MÀ°§U¡Aªí3 ¬OHTTP·s«Ø³s±µ¼Æ´ú¸Õ©ÒÃöª`ªºÃöÁä«ü¼Ð¡C
°Ñ¼Æ |
ÃöÁä©Ê¯à«ü¼Ð |
Ixia IxLoad²Îpµ²ªG |
©Ê¯à°Ñ¼Æ |
HTTP ³s±µ³t²v
HTTP³s±µÁ`¼Æ, ¼ÒÀÀªº¥Î¤á¼Æ¡A§]¦R¶q |
HTTP Client ¡V Objectives
HTTP Client ¡V Throughput
|
À³¥Î¼h¨Æ°È¥æ©ö¼Æ
À³¥Î¼h·~°È¥æ©ö¨Æ°È¥¢±ÑºÊ´ú |
Requests µo°eªº¼Æ¶q, ¦¨¥\, ¥¢±Ñ¡A¶W®É¡A©ñ±ó¡A·|¸Ü¶W®É¡A³s±µ®É¶¡¡A 4xx, 5xx ¿ù»~µ¥ |
HTTP Client ¡V Transactions
HTTP Client ¡V HTTP Failures
HTTP Client ¡V Latencies
|
TCP ³s±µ¸ê°T
TCP ¥¢±ÑºÊ´ú |
SYNs ³ø¤åµo°eªº¼Æ¶q¡BSYN/SYN-ACKs ¦¬¨ìªº¼Æ¶q
RESETµo°e©M±µ¦¬ªº¼Æ¶q¡B«¶Ç¡B¶W®É |
HTTP Client ¡V TCP Connections
HTTP Client ¡V TCP Failures
|
¨ä¥LÃöÁä«ü¼Ð |
°ò©ó¨CÓURLªº²Îp«ü¼Ð¡B¦^À³¥N½X |
HTTP Client ¡V Per URL
HTTP Client ¡V xx Codes |
ªí3: HTTP·s«Ø³s±µ¼Æ´ú¸Õ©ÒÃöª`ªºÃöÁä«ü¼Ð
¦b´ú¸Õ¹Lµ{¤¤©ÎªÌ´ú¸Õµ²§ô«á¡A¦pªGÆ[¹î¨ì´ú¸Õµ²ªG©M¹w´Áªº¤£¤@P¡A³o¥i¯à¬O°Ñ¼Æ°t¸mªº°ÝÃD¡A»Ýn¯à°÷³q¹L¤@¨Ç³~®|¶i¦æ¤ÀªR¡Aªí4¬O¸Ó´ú¸Õ¥ô°È¥i¯à¹J¨ìªº°ÝÃD¥H¤Î«ØÄ³¸Ñ¨M¿ìªk¡C
°ÝÃD |
¶EÂ_¥H¤Î«ØÄ³ |
¼W¥[§ó¦h´ú¸Õ°ð¨Ã¨S¦³´£°ª©Ê¯à |
³Q´ú³]³Æ©Ê¯à¥i¯à¹F¨ì¤F³Ì¤jÈ¡A¬d¬Ý¥Î¤áºÝ©ÎªÌ¦øªA¾¹ºÝ¦¬¨ìªºTCP Reset²ÎpÈ¡A¦b³oºØ±¡ªp¤U¥i¯à¬O³Q´ú³]³Æ±q¥Î¤áºÝ²×µ²¤FTCP³s±µ¡A¥t¥~»Ýn¬d¬Ý³Q´ú³]³ÆªºCPU§Q¥Î²v |
¦b´ú¸Õªº¡§Ramp-Up¡¨¶¥¬q¥Î¤áºÝ©ÎªÌ¦øªA¾¹ºÝ¦³¤j¶qªºTCP resets¡A¦b´ú¸Õ¹B¦æªºÃ©w¶¥¬q°ò¥»¨S¦³©ÎªÌ¦³¤Ö¶qªºTCP Timeouts©MRetries |
³oºØ²{¶H¥i¯à¬O³Q´ú³]³Æ¦b´ú¸Õ®ÉÁÙ¨S¦³¡§·Ç³Æ¦n¡¨±µ¦¬©M³B²zTCP½Ð¨D¡F¦pªG¸Ó³]³Æ¨Ï¥Î¦h³B²z¾¹¡A¨º¥i¯à¬O¤j¶q¬ðµoªº¬y¶q¦b¤j¬y¶q¤U¡§¥´¶}¡¨¤F¦h³B²z¾¹ |
±q´ú¸Õ¶}©l¨ìµ²§ô¦b¥Î¤áºÝ©ÎªÌ¦øªA¾¹ºÝ¤@ª½Æ[¹î¨ì¤j¶qªºTCP resets |
¥i¯à¬O³Q´ú³]³Æ¤w¸g¹F¨ì¤F©Ê¯à·¥¡A´î¤Ö´ú¸Õ¥Ø¼ÐȨìTCP¥¢±Ñ¬°¥i±µ¨üªº¼ÆÈ |
¶È¶È¦³¤Ö¶qªºTCP failures (timeout/retry), ³oºØ´ú¸Õµ²ªG¬O§_¥i¥H±µ¨ü? |
³q±`±¡ªp¤U¡A·í³]³Æ¹B¦æ¦b³Ì¤j©Ê¯à·¥®É¡A¤Ö¶qªºTCP Failure¬O¥i¥H±µ¨üªº¡A¦ý¬O¥i¥H®Ú¾Ú¦Û¤v´ú¸Õ¥Ø¼Ðªº»Ýn¡A¥i¥H³]©w¤£¯à¦³TCP Failure |
ªí4: ¥i¯à¹J¨ìªº°ÝÃD»P«ØÄ³ªº¸Ñ¨M¿ìªk
3.2 ³Ì¤jHTTP¦P®É³s±µ¼Æ¶q¡]Maximum Concurrent Connection¡^
¸Ó«ü¼Ð¥Dn¥Î©ó´ú¸Õ³Q´ú³]³Æ¯à°÷ºû«ùªº³Ì¤j±Ò°ÊªºTCP Sessionªº¼Æ¶q¡A¸Ó¹Lµ{¬Oº¥ý³q¹LSYN,SYN-ACK,ACKªºTCP¤T¦¸´¤¤â«Ø¥ßTCP³s±µ¡AµM«á°õ¦æ7¼hªº¸ê®Æ¥æ¤¬¹Lµ{¡A³Ì«á©î°£TCP³s±µ¡C¤@¯ë±¡ªp¤U¡A³]³Æªº³Ì¤j¦P®É³s±µ¼Æ©M³]³Æªº¦sÀxªÅ¶¡¦³Ãö¡A¸ÓȶV¤j¡A¯à°÷ºû«ùªº³s±µ¼Æ´N¶V¦h¡C
´ú¸Õ³s±µ¨£¹Ï1¡Aªí5¬O¦b¶i¦æ¸Ó¶µ¥Ø´ú¸Õ®É±ÀÂ˪º°Ñ¼Æ³]¸mÈ¡C®Ú¾Ú³Q´ú³]³ÆªºÃþ«¬¥H¤Î¤£¦Pªº¤u§@¼Ò¦¡¡Aªí2¤¤¦C¥X¨Óªº°Ñ¼Æ¦P¼Ë¾A¥Î©ó¸Ó´ú¸Õ¡C¦P¼Ë¡Aªí3¤¤¦C¥X¨Óªº¤]¬O¦P®É³s±µ¼Æ´ú¸Õ©Ò»ÝnªºÃöÁä«ü¼Ð¡C
| ¥Dn°Ñ¼Æ³]¸m |
´yz |
HTTP ¥Î¤áºÝ |
³]©w100 ©ÎªÌ§ó¦hIP ¦a§} |
HTTP ¥Î¤áºÝ¥Dn°Ñ¼Æ³]¸m |
HTTP/1.0,µLKeep-aliveÄÝ©Ê
¨CӥΤá20 өΪ̧ó¦hÓTCP ³s±µ
¨CÓTCP³s±µ¤@Ó¥æ©ö¨Æ°È¡] Transaction¡^ |
TCP °Ñ¼Æ³]¸m |
TCP RX ©M TX ½w¦s³]¸m¬° 1024¦ì¤¸²Õ |
HTTP ¥Î¤áºÝ©R¥O¦Cªí |
1 GET ©R¥O ¡V ¶±¤j¤p¬° 1¦ì¤¸²Õ |
HTTP ¦øªA¾¹ºÝ |
¨CÓIxia´ú¸Õ°ð¥é¯u¤@өΪ̦hÓ¦øªA¾¹ |
HTTP ¦øªA¾¹ºÝ¥Dn°Ñ¼Æ³]¸m |
ÀH¾÷¤ÏÀ³®É©µ 0 ¡V 20 ms
¦^À³¶W®É®Éªø 300 ms |
ªí5: ³Ì¤jHTTP¦P®É³s±µ¼Æ¶q«ØÄ³IxLoad°Ñ¼Æ³]¸m
¬°¤FÅçÃÒ³Q´ú³]³Æ¬O§_¹F¨ì³Ì¤jHTTP ·s«Ø³t²vªº¨î¡A¥i¥H¦bIxLoad ®É©µªº²Îpµ²ªG¸Ì±TTFB¡]Time To First Byte¡^°Ñ¼Æ¡A¦b¹Ï2ªº¨Ò¤l¤¤¡ATTFB¦b¡§Ramp Up¡¨¶¥¬q¯à°÷³B²z¤j¶qªº³s±µ½Ð¨D¡AÀH«á³s±µ®É¶¡¡]Connection Time¡^©MTTFBȪº¼W¤j¤ÏÀ³¤F³Q´ú³]³Æ³B²z³t«×ªº´î½w¡Cªí6¬O¸Ó´ú¸Õ¥ô°È¥i¯à¹J¨ìªº°ÝÃD¥H¤Î«ØÄ³¸Ñ¨M¿ìªk¡C

¹Ï2: IxLoad´ú¸Õµ²ªG¤¤TTFB´ú¸Õ¥Ü·N
| °ÝÃD |
¶EÂ_¥H¤Î«ØÄ³ |
¦P®É³s±µ¼Æ¤@ª½¤£¯à¹F¨ìéwª¬ºA¡A¸Ó¼ÆÈÁ`¤W¤U®¶Àú¨Ã¥B®¶Àú½d³ò¬Û·íªº¤j |
¦pªG³Q´ú³]³Æ¤@ª½¤£¯à¹F¨ìéwª¬ºA¡Aº¥ý»ÝnÀˬd³s±µ®É¶¡¡BTCP ¥¢±Ñµ¥«ü¼Ð¡A¦pªGTCP³s±µ®É¶¡«ùÄò¼W¥[¡AªÌ»¡©ú³Q´ú³]³Æ¤£¯àºû«ù¬ÛÀ³¼Æ¶qªº³s±µ¼Æ¡C
¥t¥~»ÝnÀˬdÃþ¤ñ¥Î¤á¼Æ¶q¡A¦pªG¸Óȫܰª¡A³o»¡©ú´ú¸Õ¤u¨ã¹Á¸Õn¹F¨ì¹w¥ý³]©wªº¥Ø¼ÐÈ¡A¨Ã³y¦¨´ú¸Õ°ð¸ê·½¤j¶q®ø¯Ó¡A»ÝnÀˬd´ú¸Õ¤u¨ã°t¸m¥H§PÂ_¥i¯à¦s¦bªº°ÝÃD |
¦pªG§PÂ_¨Ã½T©w³Ì¤j¦P®É³s±µ¼Æªºµ²ªG¤w¸g¹F¨ì? |
³Ì²³æªº¿ìªk¬O¼W¥[§ó¦hªº´ú¸Õ°ð¬Ý¬O§_¦P®É³s±µ¼Æ¶q¦³©Ò¼W¥[¡A¦pªG¨S¦³¼W¥[¡A»¡©ú¤w¸g¹F¨ì¤F³Ì¤jÈ¡C
¦pªG¦³TCP failures ¦s¦b¡A¨Ã¥B·sªºTCP³s±µ¤£¯à«Ø¥ß¡A³o»¡©ú¦P®É³s±µ¼Æ¤w¸g¹F¨ì³Ì¤jÈ¡C
¥t¥~ÁÙnÃöª`TCP³s±µ®É¶¡¡A¥]¬AConnect Time, TTFB and TTLB.
³Ì«á¤@ÂI¡A¦P®É³s±µ¼Æ¤@¯ë©M³Q´ú³]³Æªº¨t²Î°O¾ÐÅ馳Ãö¡A¬d¬Ý°O¾ÐÅéªÅ¶¡ªº¦û¦³±¡ªp¥i¥H¶i¤@¨B½T©w¦P®É³s±µ¼Æ¬O§_¹F¨ì¤F³Ì¤jÈ |
ªí6: ¥i¯à¹J¨ìªº°ÝÃD»P«ØÄ³ªº¸Ñ¨M¿ìªk
3.3 ³Ì¤jHTTP ¨Æ°È¥æ©ö³t²v ¡]Maximum Transactions per Second¡^
¸Ó´ú¸Õ¬OÅçÃÒ³Q´ú³]³Æ¯à°÷¤ä´©ªº³Ì¤j¨Æ°È¥æ©ö³t²v¡A¤@Ó¥æ©ö¬O«ü¤@ӽШD¥H¤Î¬ÛÀ³ªº¦^À³¡C¤ñ¦p³q¹L¬yÄý¾¹³X°Ý¬Yºô¯¸¡Aº¥ý³q¹L¤T¦¸TCP´¤¤â«Ø¥ßTCP³s±µ¡A©Ò½Ð¨Dªº¶±¥]¬A¦hÓª«¥ó¡Gºô¶¡B¹Ï¹³¡BFlash©ÎªÌ?´Oª«¥óµ¥³q¹L¬yÄý¾¹¨Ã¦æ©ÎªÌ¦ê¦C¤U¸ü¡C
¹ï©óHTTP 1.0±Ä¥ÎKeep-alive¯S©Ê©MHTTP1.1¡ATCP¥i¥H¤ä´©¦hÓTransaction¡C¹ï©ó¤j¦h¼Æ§@·~¨t²Î©M¬yÄý¾¹¨Ó»¡¡A¤@ÓTCP¥]¬A¦h¤ÖÓTransaction³£¬O¥i°t¸mªº¡C¦b¶i¦æ¸Ó«ü¼Ð´ú¸Õ®É¡A¤@¯ë±¡ªp¤UºÉ¥i¯à´î¤ÖTCP³s±µªº¼Æ¶q¡A³o¼Ë¥i¥H«OÃҺɥi¯à¦hªºÀ³¥Î¼hTransactionªº¼Æ¶q¡CIxLoad¤ä´©¸Ó¥\¯àªºÆF¬¡³]¸m¡C
¸Ó´ú¸Õ¶µ¥Øªº´ú¸Õ©Ý¼³¨£¹Ï1¡A¬ÛÀ³IxLoadªº°Ñ¼Æ³]¸m¨£ªí7¡A³Q´ú³]³Æ¦³¦hºØ¤u§@¼Ò¦¡¡Aªí2¤¤¦C¥X¨Óªº°Ñ¼Æ¦P¼Ë¾A¥Î©ó¸Ó´ú¸Õ¡C¦P¼Ë¡Aªí3¤¤¦C¥X¨Óªº¤]¬O¦P®É³s±µ¼Æ´ú¸Õ©Ò»ÝnªºÃöÁä«ü¼Ð¡C
| ¥Dn°Ñ¼Æ³]¸m |
´yz |
HTTP ¥Î¤áºÝ |
³]©w100 ©ÎªÌ§ó¦hIP ¦a§} |
HTTP ¥Î¤áºÝ°Ñ¼Æ³]¸m |
HTTP 1.1
¨CӥΤá20 ÓTCP ³s±µ
¨CÓTCP³s±µºÉ¥i¯à¦hªº¥æ©ö¨Æ°È¡] Transaction¡^ |
HTTP ºÝ©Ò½Ð¨Dªº¶±°Ñ¼Æ³]¸m |
1 GET ©R¥O ¡V ¶±¤j¤p¬° 1¦ì¤¸²Õ |
TCP °Ñ¼Æ³]¸m |
TCP RX ©M TX ½w¦s³]¸m¬°4096¦ì¤¸²Õ |
HTTP ¦øªA¾¹ºÝ |
¨CÓIxia´ú¸Õ°ð¥é¯u¤@өΪ̦hÓ¦øªA¾¹ |
HTTP ¦øªA¾¹ºÝ°Ñ¼Æ³]¸m |
ÀH¾÷¤ÏÀ³®É©µ 0 ¡V 20 ms
¦^À³¶W®É®Éªø 300 ms |
ªí7: ³Ì¤j¨Æ°È¥æ©ö³t²v´ú¸Õ«ØÄ³ªºIxLoad°Ñ¼Æ³]¸m
3.4 ³Ì¤j§]¦R¶q¡]Maximum Throughput¡^
º¥ý»Ýn©ú½Tªº¬OÀ³¥Î¼hªº§]¦R¶q©M³q±`²z¸Ñªº2¼h§]¦R¶qpºâ¤èªk¬O¤£¦Pªº¡A¹Ï3¬O¬ÛÃöpºâ¤èªkªº¸ÑÄÀ¡A2¼h§]¦R¶q¬O¹ï¾ãÓ2¼h¸ê®Æ°T®Ø¶i¦æpºâªº¡A¥]¬A¤FÃì¸ô¤W©Ò¦³ªºBits¼Æ¡CÀ³¥Î¼h§]¦R¶q¡]Goodput¡^¥u¹ï¦³®Ä¸ê®Æ¶i¦æpºâ¡A¹ï©ó«¶Çªº¸ê®Æ¥]¤]¤£¦Ò¼{¦b¦³®Ä¸ê®Æ¤¤¡C
¸Ó´ú¸Õ¶µ¥Øªº´ú¸Õ©Ý¼³¨£¹Ï1¡A¬ÛÀ³IxLoadªº°Ñ¼Æ³]¸m¨£ªí8¡A³Q´ú³]³Æ¦³¦hºØ¤u§@¼Ò¦¡¡Aªí2¤¤¦C¥X¨Óªº°Ñ¼Æ¦P¼Ë¾A¥Î©ó¸Ó´ú¸Õ¡C¦P¼Ë¡Aªí3¤¤¦C¥X¨Óªº¤]¬O¦P®É³s±µ¼Æ´ú¸Õ©Ò»ÝnªºÃöÁä«ü¼Ð¡Cªí9¬O¸Ó´ú¸Õ¥ô°È¥i¯à¹J¨ìªº°ÝÃD¥H¤Î«ØÄ³¸Ñ¨M¿ìªk¡C
| ¥Dn°Ñ¼Æ³]¸m |
´yz |
HTTP ¥Î¤áºÝ |
³]©w100 ©ÎªÌ§ó¦hIP ¦a§} |
HTTP ¥Î¤áºÝ°Ñ¼Æ³]¸m |
HTTP 1.1
¨CӥΤá20 ÓTCP ³s±µ
¨CÓTCP³s±µºÉ¥i¯à¦hªº¥æ©ö¨Æ°È¡] Transaction¡^ |
HTTP ºÝ©Ò½Ð¨Dªº¶±°Ñ¼Æ³]¸m |
1 GET ©R¥O ¡V ¶±¤j¤p¬°1MB, 512kB, 1024 bytes, 512 bytes |
TCP °Ñ¼Æ³]¸m |
¥Î¤áºÝ TCP - RX 32768 ¦ì¤¸²Õ, TX 4096¦ì¤¸²Õ
¦øªA¾¹ºÝ TCP ¡V RX 4096¦ì¤¸²Õ, TX 32768¦ì¤¸²Õ |
MSS |
1460, 500, 256, 128 bytes |
HTTP ¦øªA¾¹ºÝ |
¨CÓIxia´ú¸Õ°ð¥é¯u¤@өΪ̦hÓ¦øªA¾¹ |
HTTP ¦øªA¾¹ºÝ°Ñ¼Æ³]¸m |
ÀH¾÷¤ÏÀ³®É©µ 0 ¡V 20 ms
¦^À³¶W®É®Éªø 300 ms |
ªí8: ³Ì¤j¨Æ°È¥æ©ö³t²v´ú¸Õ«ØÄ³ªºIxLoad°Ñ¼Æ³]¸m

¹Ï3: À³¥Î¼h§]¦R¶q©M2¼h§]¦R¶q¸ÑÄÀ
| °ÝÃD |
¶EÂ_¥H¤Î«ØÄ³ |
©Ò³]¸mªº§]¦R¶q¥Ø¼ÐȤ£¯à¹F¨ì¡A¸ÓȤW¤U®¶Àú |
¦pªG³Q´ú³]³Æªº§]¦R¶q¤£¯à¹F¨ìéwª¬ºA¡A¬d¬ÝTCP failures²Îpµ²ªG¡A¤j¶qªºTCP timeout ©M ´_¦ì³ø¤å¥i¥H»¡©ú³Q´ú³]³Æ¤£¯à³B²z¬ÛÀ³ªºÀ£¤O¬y¶q¡C
¥t¥~ÁÙ¥i¥H¼W¥[§ó¦h´ú¸Õ°ð¡A¦pªG´ú¸Õµ²ªG¬Û¦P¡A»¡©ú³Q´ú³]³Æ¤£¯à³B²z§ó¦hªº¸ê®Æ¬yµ{¶q |
¼ÒÀÀ¥Î¤á¼Æ¶q«ùÄò¼W¥[¡A¦ý¬O´ú¸Õ¤u¨ã¤£¯à¹F¨ì©Ò³]¸mªº§]¦R¶q |
³o»¡©ú´ú¸Õ¤u¨ã¹Á¸Õn¹F¨ì¹w¥ý³]©wªº¥Ø¼ÐÈ¡A¨Ã³y¦¨´ú¸Õ°ð¸ê·½¤j¶q®ø¯Ó¡A»ÝnÀˬd´ú¸Õ¤u¨ã°t¸m¥H§PÂ_¥i¯à¦s¦bªº°ÝÃD¡C
¬d¬Ý TCP failures ¸ê°T¥H§PÂ_¥i¯à¦s¦bªººô¸ô°ÝÃD¡C
Àˬd³Q´ú³]³Æ°ðµo°e©M±µ¦¬³ø¤å¬O§_¦³¤j¶q¥á±ó |
ªí9: ¥i¯à¹J¨ìªº°ÝÃD»P«ØÄ³ªº¸Ñ¨M¿ìªk
3.5 ¦b¦³DDoS§ðÀ»¬y¶q¤Uªº©Ê¯à ¡]Application Forwarding Performance under DoS Attacks¡^
¨¾¤õÀð©M¨ã¦³DPI¥\¯àªº³]³Æ³£¨ã¦³«OÅ@·í«e¥¿¦b¹B¦æªº¥Î¤á¤£¨ü§ðÀ»ªº¯à¤O¡A¸Ó¯à¤O¼W¥[¤F¨t²Îªº³B²z¶}¾P¡A·|¹ï¨t²Îªº©Ê¯à³y¦¨¤@©wªº¤U°¡C¸Ó´ú¸Õ±M®×¥DnÅçÃÒ³Q´ú³]³Æ¦b¦³©Úµ´ªA°È¡]DDoS¡^§ðÀ»ªº±¡ªp¤U³Q´ú³]³ÆÂàµo©Ê¯à©Ò¨ü¨ìªº¼vÅT¡C
³q±`¦³¦hºØ¤èªk´ú¸Õ³]³Æ¦b§ðÀ»±¡ªpªº©Ê¯àªí²{¡A¦b³oùØ¥H³]³Æ¨ü¨ìSYN Flood§ðÀ»¬°¨Ò¡A¦P®É¥H¦hºØÀ³¥Î¼h¬y¶qFTP¡BSMTP¡BRTSP¡BSIP°µ¬°I´º¹ïHTTP¬y¶q¥¿±`Âàµo©Ê¯àªº¼vÅT¡Cªí10¬O´ú¸Õ¤u¨ã©Ò»Ýnªº°Ñ¼Æ³]¸m¡C
| ¥Dn°Ñ¼Æ³]¸m |
´yz |
¥Î¤áºÝºô¸ô |
³]©w100 ©ÎªÌ§ó¦hIP ¦a§} |
HTTP ¥Î¤áºÝ¥Dn°Ñ¼Æ³]¸m |
HTTP 1.1
¨CӥΤá3ÓTCP ³s±µ
¨CÓTCP³s±µ1Ó¥æ©ö¨Æ°È¡] Transaction¡^ |
TCP °Ñ¼Æ³]¸m |
TCP RX ©M TX ½w¦s³]¸m¬°4096¦ì¤¸²Õ |
HTTP client command list |
1 GET ©R¥O ¡V ¶±¤j¤p¬°128k-1024k¦ì¤¸²Õ |
HTTP ¦øªA¾¹ºÝ |
¨CÓIxia´ú¸Õ°ð¥é¯u¤@өΪ̦hÓ¦øªA¾¹ |
HTTP ¦øªA¾¹ºÝ°Ñ¼Æ³]¸m |
ÀH¾÷¤ÏÀ³®É©µ 0 ¡V 20 ms
¦^À³¶W®É®Éªø 300 ms |
DoS §ðÀ»Ãþ«¬ |
ARP flood attack, evasive UDP attack, land attack, ping of death attack, ping sweep attack, reset flood attack, smurf attack, SYN flood attack, TCP scan attack, tear-drop attack, UDP flood attack, UDP scan attack, unreachable host attack and Xmas tree attack |
¨ä¥LI´º¬y¶qªº¨óij |
FTP, SMTP, RTSP, SIPµ¥¨óijªº²V¦X |
ªí10: ³Ì¤j¨Æ°È¥æ©ö³t²v´ú¸Õ«ØÄ³ªºIxLoad°Ñ¼Æ³]¸m
¬ÛÀ³ªºµ²ªG¤ÀªR¡B¹ï©óHTTP¨óij¡A¦P¼Ë¥i¥H°Ñ¦Òªí3¡A¹ï©ó¨ä¥LÃþ«¬ªº·~°È¬y¶q©MDoS§ðÀ»¬y¶q¡A¥i¥H¨£ªí11¡C
| DoS §ðÀ» |
©Òµo°eªº¦¨¥\¡B¥¢±Ñªº¸ê®Æ¥] |
DDoS Client ¡V Successful Packets
DDoS Client ¡V Failedl Packets
DDoS Client ¡V Bytes Sent |
¸ê®Æ¥]ºÊ´ú |
¦¬¨ìªº¸ê®Æ¥]¡A®Ú¾Ú¹LÂo³W«h©ÎªÌ¤¹³\¦¬¨ìªº¸ê®Æ¥] |
Packet Monitor Server ¡V Packet Statistics Total |
ªí11: DoS§ðÀ»¬y¶qµ²ªG²Îp¸ê°T
Ixia ¿W¦³ªº¸ê®Æ¥]ºÊ´ú¡]Packet Monitor¡^²Îp¥\¯à¡A¥i¥H§Y®É¤ÀÃþ²Îp¦XªkªºªA°È¬y¶q»P§ðÀ»¬y¶q¡A³o¼Ë´N¥i¥H¦b´ú¸Õ¤u¨ã¤¤§Y®É¬d¬Ý³Q´ú³]³Æ¬O§_¹ï«Dªk¬y¶q¶i¦æ¤F¦³®ÄÄdºI¡A¨Ã½T»{¬O§_¹ï¦Xªk¬y¶q³y¦¨©Ê¯à¤Wªº¼vÅT¡Cªí12¬O¸Ó´ú¸Õ¥ô°È¥i¯à¹J¨ìªº°ÝÃD¥H¤Î«ØÄ³¸Ñ¨M¿ìªk¡C
| °ÝÃD |
¶EÂ_¥H¤Î«ØÄ³ |
±q´ú¸Õ¶}©l¨ìµ²§ô¦b¥Î¤áºÝ©ÎªÌ¦øªA¾¹ºÝ¤@ª½Æ[¹î¨ì¤j¶qªºTCP resets |
¥i¯à¬O³Q´ú³]³Æ¦b¦³DoS§ðÀ»¬y¶q¤U¹F¨ì¤F©Ê¯à·¥¡C³o¦bSYN Flood§ðÀ»¤U«D±`±`¨£ªº²{¶H |
§]¦R¶q¥X²{¤W¤U®¶Àúªº²{¶H |
³]³Æ¤£¯à¹F¨ìéwª¬ºA¡A¬d¬ÝTCP Failures°Ñ¼Æ¡A¤j¶qªºTCP timeout ©M RST ¸ê®Æ¥]»¡©ú³]³Æ¦b¦³DoS§ðÀ»¬y¶q¤U¤£¯à¦A³B²z§ó°ªªº©Ê¯à |
¼ÒÀÀ¥Î¤á¼Æ¶q«ùÄò¼W¥[¡A¦ý¬O´ú¸Õ¤u¨ã¤£¯à¹F¨ì©Ò³]¸mªº§]¦R¶q |
³oºØ²{¶H»¡©ú´ú¸Õ¤u¨ã¥D°Ê·j´M¨Ã¹Á¸Õ¹F¨ì¹w´Á¡A»Ýn¬d¬ÝDoS §ðÀ»¬y¶q¬O§_³y¦¨¤F¤j¶qªºTCP Failure |
ªí12: ¥i¯à¹J¨ìªº°ÝÃD»P«ØÄ³ªº¸Ñ¨M¿ìªk
µ²§ô»y :
®Ú¾ÚFrost & Sullivanªº¤½¶}¬ã¨s³ø§i¡AIxia 4-7¼hIxLoad´ú¸Õ¤è®×¦b2008¦~ªº¥þ²y¥«³õ¦a¦ì³B©ó²Ä¤@¦ì¡A³Ì·s±À¥Xªº°ª©Ê¯àAcceleron ´ú¸Õ¼Ò²Õ¶i¤@¨B½T«O¤FIxLoad¦b®Ö¤ßÀ³¥Î¼h³]³Æªº¦a¦ì¡C