WebApp Sec mailing list archives

[OT] Multi-tier web app client-server response time?!?


From: Stef <stefmit () gmail com>
Date: Wed, 15 Sep 2004 20:04:23 -0500

I apologize in advance, as I know this is not the right mailing list,
but considering the level of expertise here, I would dare to post my
question: I am a network geek, with very few knowledge of application
level (especially Java-based) issues, but I am being challenged by
something that I have not seen resolved anywhere else (yet): in an
environment with Oracle 11i web based applications, with an Oracle 9i
database, I am trying to figure out if there is a way to script a
session from a client, to the first tier (forms/web server), then all
the way back into the database, and back to the client, continuously
(every "n" minutes), for "real life transaction RTT measurements" for
"end user experience" measurements.

So far I have attempted a simple macro recording on the host/client
machines, with some time stamps triggered by the change in pointer or
the hour glass or (hard to control) java-controlled pop-up windows,
but that seem to be very flaky (sometimes it works, sometimes it
doesn't). I have also started looking at OpenSTA, but have note had
the chance to figure it out completely.

Out of consideration for a fellow network and security colleague,
could anyone of you - web gurus - point me in the right direction for
either methodologies for scripting this type of transations, or at
least some links as to where to get this type of information?

As a last resort - with my limited knowledge in the upper layers - I
was going to resort to attempting to replay network captures
(traces/dumps), over the various links I am trying to test this
application, but I really see that as too "artificial" to be the best
choice.

Sorry again for the wasted bandwidth on an off-topic subject (now that
I think about it - perhaps I can force a relationship to websec by
asking how to replay multi-tier web-based applications?!? ;))

TIA,
Stef


Current thread: