IP Library Granted Patent US 8,015,602
Granted Patent B2
US 8,015,602 · App. 12/551,699 · Granted Sep 6, 2011

Methodology, measurements and analysis of performance and scalability of stateful border gateways

Assignee: Verizon Services Corp.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,602
App. No.
12/551,699
Granted
Sep 6, 2011
Kind
B2
Abstract

Methods and apparatus for testing of Internet-Protocol packet network perimeter protection devices, e.g., Border Gateways such as Session Border Controllers, including 5 dynamic pinhole capable firewalls are discussed. Analysis and testing of these network perimeter protection devices is performed to evaluate the ability of such device to perform at carrier class levels. The efficiency of state look table functions as well as call signaling processing capacity, implemented in a particular perimeter protection device, are determined and evaluated. Proper performance and efficiency of such perimeter protection devices are evaluated as a function of incoming call rate and as a function of total pre-existing active calls. Various different network perimeter protection devices, e.g., of different types and/or from different manufactures, can be benchmarked for suitability to carrier class environments and comparatively evaluated. Test equipment devices, e.g., enhanced Integrated Intelligent End Points (IIEPs), for fault testing, 15 evaluating and stressing the network perimeter protection devices in a system environment are described. Typically these specialized test devices are used in pairs, one on each side of the firewall under test. These test equipment devices include a heavy duty traffic generator module, monitoring and analysis capability including a utilization analysis module, and a graphical output capability.

Claims (76)

1. A method comprising:

establishing a constant session signaling load from a test device through a firewall;

applying a first rate of session signaling change to the firewall while maintaining the constant session signaling load;

monitoring a first processor-utilization rate or a first pinhole-transition delay while applying the first rate of session signaling change to the firewall;

applying a second rate of session signaling change to the firewall while maintaining the constant session signaling load;

monitoring a second processor-utilization rate or a second pinhole-transition delay while applying the second rate of session signaling change to the firewall; and

storing the first and second processor-utilization rates or the first and second pinhole-transition delays in a computer-readable memory.

2. The method of claim 1 ,

wherein establishing the constant session signaling load includes establishing a constant number of sessions through the firewall; and

wherein maintaining the constant session signaling load includes maintaining the constant number of sessions through the firewall.

3. The method of claim 2 ,

wherein applying the first rate of session signaling change includes establishing a first set of new sessions at the first rate; and

wherein applying the second rate of session signaling change includes establishing a second set of new sessions at the second rate.

4. The method of claim 3 ,

wherein monitoring the first processor-utilization rate or the first pinhole-transition delay includes monitoring a first pinhole-transition delay; and

wherein monitoring the second processor-utilization rate or the second pinhole-transition delay includes monitoring a second pinhole-transition delay.

5. The method of claim 2 ,

wherein applying the first rate of session signaling change includes terminating a first set of new sessions at the first rate; and

wherein applying the second rate of session signaling change includes terminating a second set of new sessions at the second rate.

6. The method of claim 5 ,

wherein monitoring the first processor-utilization rate or the first pinhole-transition delay includes monitoring a first pinhole-transition delay; and

wherein monitoring the second processor-utilization rate or the second pinhole-transition delay includes monitoring a second pinhole-transition delay.

7. The method of claim 1 ,

wherein establishing a constant session signaling load includes establishing sessions at a session rate and terminating the sessions at the session rate; and

wherein maintaining the constant session signaling load includes maintaining the establishing of the sessions and the terminating of the sessions at the session rate.

8. The method of claim 7 ,

wherein applying the first rate of session signaling change to the firewall includes establishing additional sessions at the first rate while maintaining the constant session signaling load; and

wherein applying the second rate of session signaling change to the firewall includes establishing additional sessions at the second rate while maintaining the constant session signaling load.

9. The method of claim 8 ,

wherein monitoring the first processor-utilization rate or the first pinhole-transition delay includes monitoring a first pinhole-transition delay; and

wherein monitoring the second processor-utilization rate or the second pinhole-transition delay includes monitoring a second pinhole-transition delay.

10. The method of claim 7 ,

wherein applying the first rate of session signaling change to the firewall includes terminating additional sessions at the first rate while maintaining the constant session signaling load; and

wherein applying the second rate of session signaling change to the firewall includes terminating additional sessions at the second rate while maintaining the constant session signaling load.

11. The method of claim 10 ,

wherein monitoring the first processor-utilization rate or the first pinhole-transition delay includes monitoring a first pinhole-transition delay; and

wherein monitoring the second processor-utilization rate or the second pinhole-transition delay includes monitoring a second pinhole-transition delay.

12. A network device comprising:

an input/output interface to:

send a constant session signaling load from the network device through a firewall;

send, at a first rate, first additional session signaling to the firewall while maintaining the constant session signaling load;

send, at a second rate different than the first rate, second additional session signaling to the firewall while maintaining the constant session signaling load;

a processor configured to:

determine, with respect to the first additional session signaling, a first processor-utilization rate or a first pinhole-transition delay associated with the firewall, and

determine, with respect to the second additional session signaling, a second processor-utilization rate or a second pinhole-transition delay associated with the firewall; and

a memory to store the processor-utilization rates or the pinhole-transition delays.

13. The network device of claim 12 ,

wherein the constant session signaling load includes a constant number of sessions that pass through the firewall.

14. The network device of claim 13 ,

wherein the first additional session signaling includes a first set of new sessions established or terminated at the first rate; and

wherein the second additional session signaling includes a second set of new sessions established or terminated at the second rate.

15. The network device of claim 14 ,

wherein the processor is configured to determine the first pinhole-transition delay and the second pinhole-transition delay.

16. The network device of claim 12 ,

wherein the constant session signaling load includes sessions established and terminated at a session rate.

17. The network device of claim 16 ,

wherein the first additional session signaling includes additional sessions established or terminated at the first rate; and

wherein the second additional session signaling includes additional sessions established or terminated at the second rate while maintaining the constant session signaling load.

18. The network device of claim 17 ,

wherein the processor is configured to determine the first pinhole-transition delay.

19. A method comprising:

establishing a first number of sessions through a packet-switched network perimeter protection device, wherein the first number remains constant;

initiating a first set of new sessions, in addition to the first number of sessions, at a first rate through the perimeter protection device;

determining a first processor-utilization rate or a first pinhole-transition delay associated with initiating the first set of new sessions at the first rate;

initiating a second set of new sessions, in addition to the first number of sessions, at a second rate different than the first rate, through the perimeter protection device; and

determining a second processor-utilization rate or a second pinhole-transition delay associated with initiating the second set of new sessions at the second rate;

wherein the first number of sessions is maintained while initiating the first and second set of new sessions, and wherein initiating the first and second set of new sessions includes initiating new sessions using a session control protocol.

20. The method of claim 19 , wherein determining the second processor-utilization rate or the pinhole-transition delay includes determining a pinhole-opening delay.

21. The method of claim 19 , further comprising:

terminating, at a third rate, the first set of new sessions through the perimeter protection device; and

determining a third processor-utilization rate or a first pinhole-transition delay associated with terminating the first set of new sessions at the third rate,

wherein the first number of sessions are maintained while terminating the first set of new sessions, and wherein terminating the first set of new sessions includes using a session control protocol.

22. The method of claim 21 , further comprising:

terminating, at a fourth rate different than the third rate, the second set of new sessions through the perimeter protection device; and

determining a fourth processor-utilization rate or a second pinhole-transition delay associated with terminating the second set of new sessions at the fourth rate,

wherein the first number of sessions are maintained while terminating the second set of new sessions, and wherein terminating the second set of new sessions includes using a session control protocol.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2015
From: VERIZON PATENT AND LICENSING INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 037094/0111 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2014
From: VERIZON SERVICES CORP.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 033428/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2014
From: ORMAZABAL, GASTON S
To: VERIZON SERVICES CORP.
Reel/Frame 033155/0316 →
Continuity (5)
Continuation 11093699 · Mar 30, 2005
Continuation In Part 10678328 · Oct 3, 2003
Continuation In Part 10679222 · Oct 3, 2003
Continuation In Part 10678779 · Oct 3, 2003
Related Publication 20100058457A1 · Mar 4, 2010