aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLuca Deri <deri@ntop.org>2020-02-08 10:38:22 +0100
committerLuca Deri <deri@ntop.org>2020-02-08 10:38:22 +0100
commit2bd89be3e2ce52afcf105cdde2b0624f758ad638 (patch)
treec2cc47ce68a09c742d144dea8c28a2308de14d6d
parent5cad39f0e88c03b3cb4f78addf56e217b3d372f2 (diff)
Added new TLS test files
-rw-r--r--tests/pcap/443-chrome.pcapbin0 -> 1546 bytes
-rw-r--r--tests/pcap/443-curl.pcapbin0 -> 75750 bytes
-rw-r--r--tests/pcap/443-firefox.pcapbin0 -> 468763 bytes
-rw-r--r--tests/pcap/443-git.pcapbin0 -> 38333 bytes
-rw-r--r--tests/pcap/443-opvn.pcapbin0 -> 12333 bytes
-rw-r--r--tests/pcap/443-safari.pcapbin0 -> 20609 bytes
-rw-r--r--tests/result/443-chrome.pcap.out3
-rw-r--r--tests/result/443-curl.pcap.out8
-rw-r--r--tests/result/443-firefox.pcap.out8
-rw-r--r--tests/result/443-git.pcap.out8
-rw-r--r--tests/result/443-opvn.pcap.out3
-rw-r--r--tests/result/443-safari.pcap.out8
12 files changed, 38 insertions, 0 deletions
diff --git a/tests/pcap/443-chrome.pcap b/tests/pcap/443-chrome.pcap
new file mode 100644
index 000000000..68f68f415
--- /dev/null
+++ b/tests/pcap/443-chrome.pcap
Binary files differ
diff --git a/tests/pcap/443-curl.pcap b/tests/pcap/443-curl.pcap
new file mode 100644
index 000000000..d6fe47394
--- /dev/null
+++ b/tests/pcap/443-curl.pcap
Binary files differ
diff --git a/tests/pcap/443-firefox.pcap b/tests/pcap/443-firefox.pcap
new file mode 100644
index 000000000..eb4d18317
--- /dev/null
+++ b/tests/pcap/443-firefox.pcap
Binary files differ
diff --git a/tests/pcap/443-git.pcap b/tests/pcap/443-git.pcap
new file mode 100644
index 000000000..9267b1158
--- /dev/null
+++ b/tests/pcap/443-git.pcap
Binary files differ
diff --git a/tests/pcap/443-opvn.pcap b/tests/pcap/443-opvn.pcap
new file mode 100644
index 000000000..492099e0c
--- /dev/null
+++ b/tests/pcap/443-opvn.pcap
Binary files differ
diff --git a/tests/pcap/443-safari.pcap b/tests/pcap/443-safari.pcap
new file mode 100644
index 000000000..6789c1587
--- /dev/null
+++ b/tests/pcap/443-safari.pcap
Binary files differ
diff --git a/tests/result/443-chrome.pcap.out b/tests/result/443-chrome.pcap.out
new file mode 100644
index 000000000..b145b0a02
--- /dev/null
+++ b/tests/result/443-chrome.pcap.out
@@ -0,0 +1,3 @@
+TLS 1 1506 1
+
+ 1 TCP 178.62.197.130:443 -> 192.168.1.13:53059 [proto: 91/TLS][cat: Web/5][1 pkts/1506 bytes -> 0 pkts/0 bytes][Goodput ratio: 95.6/0.0][< 1 sec]
diff --git a/tests/result/443-curl.pcap.out b/tests/result/443-curl.pcap.out
new file mode 100644
index 000000000..c11e95162
--- /dev/null
+++ b/tests/result/443-curl.pcap.out
@@ -0,0 +1,8 @@
+ntop 109 73982 1
+
+JA3 Host Stats:
+ IP Address # JA3C
+ 1 192.168.1.13 1
+
+
+ 1 TCP 192.168.1.13:55523 <-> 178.62.197.130:443 [proto: 91.26/TLS.ntop][cat: Network/14][51 pkts/4260 bytes <-> 58 pkts/69722 bytes][Goodput ratio: 21.8/94.5][1.10 sec][ALPN: h2,http/1.1][bytes ratio: -0.885 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 24.6/19.1 784/784 122.2/114.3][Pkt Len c2s/s2c min/avg/max/stddev: 54/66 83.5/1202.1 583/1506 74.5/562.2][TLSv1.2][Client: www.ntop.org][JA3C: 2a26b1a62e40d25d4de3babc9d532f30][ServerNames: www.ntop.org][JA3S: ae53107a2e47ea20c72ac44821a728bf][Certificate SHA-1: DB:A7:E4:3E:6D:BB:21:AB:68:47:35:E8:0B:8F:15:DF:DB:C7:C9:6F][Validity: 2019-12-17 01:17:28 - 2020-03-16 01:17:28][Cipher: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256]
diff --git a/tests/result/443-firefox.pcap.out b/tests/result/443-firefox.pcap.out
new file mode 100644
index 000000000..5ab2a0e6c
--- /dev/null
+++ b/tests/result/443-firefox.pcap.out
@@ -0,0 +1,8 @@
+ntop 667 458067 1
+
+JA3 Host Stats:
+ IP Address # JA3C
+ 1 192.168.1.13 1
+
+
+ 1 TCP 192.168.1.13:53096 <-> 178.62.197.130:443 [proto: 91.26/TLS.ntop][cat: Network/14][316 pkts/28495 bytes <-> 351 pkts/429572 bytes][Goodput ratio: 26.9/94.6][8.44 sec][ALPN: h2,http/1.1][TLS Supported Versions: TLSv1.3,TLSv1.2,TLSv1.1,TLSv1][bytes ratio: -0.876 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 32.5/20.1 4007/4045 284.5/250.4][Pkt Len c2s/s2c min/avg/max/stddev: 54/66 90.2/1223.9 583/1506 57.9/472.2][TLSv1.2][Client: www.ntop.org][JA3C: f6ce47303dce394049af395fc6d0bc20][ServerNames: www.ntop.org][JA3S: 3653a20186a5b490426131a611e01992][Certificate SHA-1: DB:A7:E4:3E:6D:BB:21:AB:68:47:35:E8:0B:8F:15:DF:DB:C7:C9:6F][Validity: 2019-12-17 01:17:28 - 2020-03-16 01:17:28][Cipher: TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256]
diff --git a/tests/result/443-git.pcap.out b/tests/result/443-git.pcap.out
new file mode 100644
index 000000000..648be8a48
--- /dev/null
+++ b/tests/result/443-git.pcap.out
@@ -0,0 +1,8 @@
+Github 70 37189 1
+
+JA3 Host Stats:
+ IP Address # JA3C
+ 1 192.168.1.13 1
+
+
+ 1 TCP 192.168.1.13:55744 <-> 140.82.114.4:443 [proto: 91.203/TLS.Github][cat: Collaborative/15][35 pkts/3167 bytes <-> 35 pkts/34022 bytes][Goodput ratio: 27.8/93.2][0.82 sec][ALPN: http/1.1][bytes ratio: -0.830 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 24.5/15.3 143/143 48.2/42.5][Pkt Len c2s/s2c min/avg/max/stddev: 54/66 90.5/972.1 583/1490 93.6/615.9][TLSv1.2][Client: github.com][JA3C: 2a26b1a62e40d25d4de3babc9d532f30][ServerNames: github.com,www.github.com][JA3S: ae53107a2e47ea20c72ac44821a728bf][Organization: GitHub, Inc.][Certificate SHA-1: CA:06:F5:6B:25:8B:7A:0D:4F:2B:05:47:09:39:47:86:51:15:19:84][Validity: 2018-05-08 00:00:00 - 2020-06-03 12:00:00][Cipher: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256]
diff --git a/tests/result/443-opvn.pcap.out b/tests/result/443-opvn.pcap.out
new file mode 100644
index 000000000..413f6afda
--- /dev/null
+++ b/tests/result/443-opvn.pcap.out
@@ -0,0 +1,3 @@
+OpenVPN 46 11573 1
+
+ 1 TCP 192.168.1.84:52973 <-> 192.12.192.103:1194 [proto: 159/OpenVPN][cat: VPN/2][25 pkts/5636 bytes <-> 21 pkts/5937 bytes][Goodput ratio: 70.5/76.5][8.96 sec][bytes ratio: -0.026 (Mixed)][IAT c2s/s2c min/avg/max/stddev: 0/0 442.9/427.4 3959/4015 926.5/1024.5][Pkt Len c2s/s2c min/avg/max/stddev: 66/66 225.4/282.7 1506/1506 330.4/399.1][PLAIN TEXT (Registro.it)]
diff --git a/tests/result/443-safari.pcap.out b/tests/result/443-safari.pcap.out
new file mode 100644
index 000000000..ca21b2d06
--- /dev/null
+++ b/tests/result/443-safari.pcap.out
@@ -0,0 +1,8 @@
+ntop 41 19929 1
+
+JA3 Host Stats:
+ IP Address # JA3C
+ 1 192.168.1.13 1
+
+
+ 1 TCP 192.168.1.13:53031 <-> 178.62.197.130:443 [proto: 91.26/TLS.ntop][cat: Network/14][21 pkts/2195 bytes <-> 20 pkts/17734 bytes][Goodput ratio: 36.3/92.5][1.10 sec][ALPN: h2,h2-16,h2-15,h2-14,spdy/3.1,spdy/3,http/1.1][bytes ratio: -0.780 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 50.9/46.7 695/695 167.0/167.7][Pkt Len c2s/s2c min/avg/max/stddev: 66/66 104.5/886.7 394/1506 82.8/661.1][TLSv1.2][Client: www.ntop.org][JA3C: a69708a64f853c3bcc214c2c5faf84f3][ServerNames: www.ntop.org][JA3S: f9fcb52580329fb6a9b61d7542087b90][Certificate SHA-1: DB:A7:E4:3E:6D:BB:21:AB:68:47:35:E8:0B:8F:15:DF:DB:C7:C9:6F][Validity: 2019-12-17 01:17:28 - 2020-03-16 01:17:28][Cipher: TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256]