diff options
author | Luca <deri@ntop.org> | 2022-02-03 09:17:54 +0100 |
---|---|---|
committer | Luca <deri@ntop.org> | 2022-02-03 09:17:54 +0100 |
commit | 37ff626e78149b4eb877b042672801b58d797100 (patch) | |
tree | 7654aeb95ebd3761a18ab49176d82bad1785f962 /tests/result | |
parent | cd3d720ae36e943a3e9ddd7275b983df6c6652d0 (diff) |
Added new IDN/Punycode risk for spotting internationalized domain names
Diffstat (limited to 'tests/result')
-rw-r--r-- | tests/result/punycode-idn.pcap.out | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/tests/result/punycode-idn.pcap.out b/tests/result/punycode-idn.pcap.out new file mode 100644 index 000000000..769a639f5 --- /dev/null +++ b/tests/result/punycode-idn.pcap.out @@ -0,0 +1,13 @@ +Guessed flow protos: 1 + +DPI Packets (TCP): 8 (8.00 pkts/flow) +DPI Packets (UDP): 4 (2.00 pkts/flow) +Confidence DPI : 3 (flows) + +DNS 2 162 1 +HTTP 12 1597 1 +Spotify 2 197 1 + + 1 TCP 192.168.2.140:56011 <-> 170.33.9.230:80 [proto: 7/HTTP][ClearText][Confidence: DPI][cat: Web/5][7 pkts/568 bytes <-> 5 pkts/1029 bytes][Goodput ratio: 29/69][0.57 sec][Hostname/SNI: www.love.xn--55qx5d][bytes ratio: -0.289 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 77/122 222/352 90/163][Pkt Len c2s/s2c min/avg/max/stddev: 54/60 81/206 137/765 36/280][URL: www.love.xn--55qx5d/][StatusCode: 403][Content-Type: text/html][User-Agent: curl/7.77.0][Risk: ** IDN Domain Name **][Risk Score: 10][PLAIN TEXT (GET / HTTP/1.1)][Plen Bins: 0,0,66,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,33,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + 2 UDP 192.168.2.140:45520 <-> 192.168.2.1:53 [proto: 5.156/DNS.Spotify][ClearText][Confidence: DPI][cat: Music/25][1 pkts/69 bytes <-> 1 pkts/128 bytes][Goodput ratio: 39/67][0.02 sec][Hostname/SNI: i.scdn.co][146.75.62.248][PLAIN TEXT (scdnco)][Plen Bins: 50,0,50,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + 3 UDP 192.168.2.140:60156 <-> 192.168.2.1:53 [proto: 5/DNS][ClearText][Confidence: DPI][cat: Network/14][1 pkts/81 bytes <-> 1 pkts/81 bytes][Goodput ratio: 48/48][0.00 sec][Hostname/SNI: www.xn--mnich-kva.com][::][Risk: ** IDN Domain Name **][Risk Score: 10][Plen Bins: 0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] |