diff options
author | Ivan Nardi <12729895+IvanNardi@users.noreply.github.com> | 2024-12-04 16:14:27 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-12-04 16:14:27 +0100 |
commit | 83ce341796197822e2cde8576a8290c8f87a726a (patch) | |
tree | 648aeb98727ddea2f58d95c7ce2091462e995a24 /tests/cfgs/default | |
parent | d31b35d012f239784ffe854a93a46d8d97a6b6c5 (diff) |
signal: improve detection of chats and calls (#2637)
Diffstat (limited to 'tests/cfgs/default')
-rw-r--r-- | tests/cfgs/default/pcap/signal_multiparty.pcapng | bin | 0 -> 11096 bytes | |||
-rw-r--r-- | tests/cfgs/default/result/signal_multiparty.pcapng.out | 27 |
2 files changed, 27 insertions, 0 deletions
diff --git a/tests/cfgs/default/pcap/signal_multiparty.pcapng b/tests/cfgs/default/pcap/signal_multiparty.pcapng Binary files differnew file mode 100644 index 000000000..d88a678f8 --- /dev/null +++ b/tests/cfgs/default/pcap/signal_multiparty.pcapng diff --git a/tests/cfgs/default/result/signal_multiparty.pcapng.out b/tests/cfgs/default/result/signal_multiparty.pcapng.out new file mode 100644 index 000000000..fbbfa87c9 --- /dev/null +++ b/tests/cfgs/default/result/signal_multiparty.pcapng.out @@ -0,0 +1,27 @@ +DPI Packets (UDP): 7 (7.00 pkts/flow) +Confidence DPI : 1 (flows) +Num dissector calls: 7 (7.00 diss/flow) +LRU cache ookla: 0/0/0 (insert/search/found) +LRU cache bittorrent: 0/0/0 (insert/search/found) +LRU cache stun: 4/8/0 (insert/search/found) +LRU cache tls_cert: 0/0/0 (insert/search/found) +LRU cache mining: 0/0/0 (insert/search/found) +LRU cache msteams: 0/0/0 (insert/search/found) +LRU cache fpc_dns: 0/0/0 (insert/search/found) +Automa host: 0/0 (search/found) +Automa domain: 0/0 (search/found) +Automa tls cert: 0/0 (search/found) +Automa risk mask: 0/0 (search/found) +Automa common alpns: 0/0 (search/found) +Patricia risk mask: 2/0 (search/found) +Patricia risk mask IPv6: 0/0 (search/found) +Patricia risk: 0/0 (search/found) +Patricia risk IPv6: 0/0 (search/found) +Patricia protocols: 1/1 (search/found) +Patricia protocols IPv6: 0/0 (search/found) + +SignalVoip 30 9753 1 + +Acceptable 30 9753 1 + + 1 UDP 192.168.12.67:38303 <-> 35.207.138.135:10000 [proto: 338.269/SRTP.SignalVoip][IP: 284/GoogleCloud][Encrypted][Confidence: DPI][FPC: 78/STUN, Confidence: DPI][DPI packets: 7][cat: VoIP/10][24 pkts/9059 bytes <-> 6 pkts/694 bytes][Goodput ratio: 89/64][0.46 sec][bytes ratio: 0.858 (Upload)][IAT c2s/s2c min/avg/max/stddev: 0/0 21/23 213/46 46/22][Pkt Len c2s/s2c min/avg/max/stddev: 87/81 377/116 1036/142 286/27][Risk: ** Known Proto on Non Std Port **][Risk Score: 50][Risk Info: Expected on port 3478][PLAIN TEXT (BCipr/LEZ)][Plen Bins: 0,23,10,20,0,0,3,3,0,3,0,0,0,0,26,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] |