aboutsummaryrefslogtreecommitdiff
path: root/tests/result
diff options
context:
space:
mode:
authorLuca <deri@ntop.org>2022-02-03 09:17:54 +0100
committerLuca <deri@ntop.org>2022-02-03 09:17:54 +0100
commit37ff626e78149b4eb877b042672801b58d797100 (patch)
tree7654aeb95ebd3761a18ab49176d82bad1785f962 /tests/result
parentcd3d720ae36e943a3e9ddd7275b983df6c6652d0 (diff)
Added new IDN/Punycode risk for spotting internationalized domain names
Diffstat (limited to 'tests/result')
-rw-r--r--tests/result/punycode-idn.pcap.out13
1 files changed, 13 insertions, 0 deletions
diff --git a/tests/result/punycode-idn.pcap.out b/tests/result/punycode-idn.pcap.out
new file mode 100644
index 000000000..769a639f5
--- /dev/null
+++ b/tests/result/punycode-idn.pcap.out
@@ -0,0 +1,13 @@
+Guessed flow protos: 1
+
+DPI Packets (TCP): 8 (8.00 pkts/flow)
+DPI Packets (UDP): 4 (2.00 pkts/flow)
+Confidence DPI : 3 (flows)
+
+DNS 2 162 1
+HTTP 12 1597 1
+Spotify 2 197 1
+
+ 1 TCP 192.168.2.140:56011 <-> 170.33.9.230:80 [proto: 7/HTTP][ClearText][Confidence: DPI][cat: Web/5][7 pkts/568 bytes <-> 5 pkts/1029 bytes][Goodput ratio: 29/69][0.57 sec][Hostname/SNI: www.love.xn--55qx5d][bytes ratio: -0.289 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 77/122 222/352 90/163][Pkt Len c2s/s2c min/avg/max/stddev: 54/60 81/206 137/765 36/280][URL: www.love.xn--55qx5d/][StatusCode: 403][Content-Type: text/html][User-Agent: curl/7.77.0][Risk: ** IDN Domain Name **][Risk Score: 10][PLAIN TEXT (GET / HTTP/1.1)][Plen Bins: 0,0,66,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,33,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ 2 UDP 192.168.2.140:45520 <-> 192.168.2.1:53 [proto: 5.156/DNS.Spotify][ClearText][Confidence: DPI][cat: Music/25][1 pkts/69 bytes <-> 1 pkts/128 bytes][Goodput ratio: 39/67][0.02 sec][Hostname/SNI: i.scdn.co][146.75.62.248][PLAIN TEXT (scdnco)][Plen Bins: 50,0,50,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ 3 UDP 192.168.2.140:60156 <-> 192.168.2.1:53 [proto: 5/DNS][ClearText][Confidence: DPI][cat: Network/14][1 pkts/81 bytes <-> 1 pkts/81 bytes][Goodput ratio: 48/48][0.00 sec][Hostname/SNI: www.xn--mnich-kva.com][::][Risk: ** IDN Domain Name **][Risk Score: 10][Plen Bins: 0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]