aboutsummaryrefslogtreecommitdiff
path: root/tests/cfgs
diff options
context:
space:
mode:
authorIvan Nardi <12729895+IvanNardi@users.noreply.github.com>2023-07-03 17:21:32 +0200
committerGitHub <noreply@github.com>2023-07-03 17:21:32 +0200
commitdff1f251939935b43943dea00ef24ef85261b94a (patch)
treec3aa083972d1c9182eb6d2e0b083e5325e3fa9a4 /tests/cfgs
parent86e89b4e230371b2de92e3a3cda6fdea42fff614 (diff)
STUN: fix Skype/MsTeams detection and monitoring logic (#2028)
Diffstat (limited to 'tests/cfgs')
-rw-r--r--tests/cfgs/default/pcap/stun_msteams_unidir.pcapngbin0 -> 6472 bytes
-rw-r--r--tests/cfgs/default/result/stun_msteams_unidir.pcapng.out25
2 files changed, 25 insertions, 0 deletions
diff --git a/tests/cfgs/default/pcap/stun_msteams_unidir.pcapng b/tests/cfgs/default/pcap/stun_msteams_unidir.pcapng
new file mode 100644
index 000000000..c1ea31f4e
--- /dev/null
+++ b/tests/cfgs/default/pcap/stun_msteams_unidir.pcapng
Binary files differ
diff --git a/tests/cfgs/default/result/stun_msteams_unidir.pcapng.out b/tests/cfgs/default/result/stun_msteams_unidir.pcapng.out
new file mode 100644
index 000000000..67ca9b748
--- /dev/null
+++ b/tests/cfgs/default/result/stun_msteams_unidir.pcapng.out
@@ -0,0 +1,25 @@
+Guessed flow protos: 0
+
+DPI Packets (UDP): 7 (7.00 pkts/flow)
+Confidence DPI : 1 (flows)
+Num dissector calls: 190 (190.00 diss/flow)
+LRU cache ookla: 0/0/0 (insert/search/found)
+LRU cache bittorrent: 0/3/0 (insert/search/found)
+LRU cache zoom: 0/0/0 (insert/search/found)
+LRU cache stun: 0/6/0 (insert/search/found)
+LRU cache tls_cert: 0/0/0 (insert/search/found)
+LRU cache mining: 0/0/0 (insert/search/found)
+LRU cache msteams: 1/0/0 (insert/search/found)
+LRU cache stun_zoom: 0/0/0 (insert/search/found)
+Automa host: 0/0 (search/found)
+Automa domain: 0/0 (search/found)
+Automa tls cert: 0/0 (search/found)
+Automa risk mask: 0/0 (search/found)
+Automa common alpns: 0/0 (search/found)
+Patricia risk mask: 2/0 (search/found)
+Patricia risk: 0/0 (search/found)
+Patricia protocols: 2/1 (search/found)
+
+Skype_Teams 12 5944 1
+
+ 1 UDP 52.115.136.55:3479 -> 10.0.0.1:50006 [proto: 78.125/STUN.Skype_Teams][IP: 276/Azure][ClearText][Confidence: DPI][DPI packets: 7][cat: VoIP/10][12 pkts/5944 bytes -> 0 pkts/0 bytes][Goodput ratio: 92/0][4.53 sec][bytes ratio: 1.000 (Upload)][IAT c2s/s2c min/avg/max/stddev: 0/0 453/0 1210/0 379/0][Pkt Len c2s/s2c min/avg/max/stddev: 81/0 495/0 1257/0 539/0][Risk: ** Known Proto on Non Std Port **** Unidirectional Traffic **][Risk Score: 60][Risk Info: No server to client traffic][Plen Bins: 0,16,33,16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,33,0,0,0,0,0,0,0,0,0,0]