diff options
Diffstat (limited to 'tests')
-rw-r--r-- | tests/cfgs/disable_metadata_and_flowrisks/config.txt (renamed from tests/cfgs/disable_metadata/config.txt) | 2 | ||||
l--------- | tests/cfgs/disable_metadata_and_flowrisks/pcap/sip.pcap (renamed from tests/cfgs/disable_metadata/pcap/sip.pcap) | 0 | ||||
l--------- | tests/cfgs/disable_metadata_and_flowrisks/pcap/tls_verylong_certificate.pcap (renamed from tests/cfgs/disable_metadata/pcap/tls_verylong_certificate.pcap) | 0 | ||||
-rw-r--r-- | tests/cfgs/disable_metadata_and_flowrisks/result/sip.pcap.out (renamed from tests/cfgs/disable_metadata/result/sip.pcap.out) | 4 | ||||
-rw-r--r-- | tests/cfgs/disable_metadata_and_flowrisks/result/tls_verylong_certificate.pcap.out (renamed from tests/cfgs/disable_metadata/result/tls_verylong_certificate.pcap.out) | 0 |
5 files changed, 3 insertions, 3 deletions
diff --git a/tests/cfgs/disable_metadata/config.txt b/tests/cfgs/disable_metadata_and_flowrisks/config.txt index 2be9374b6..7dae53d2f 100644 --- a/tests/cfgs/disable_metadata/config.txt +++ b/tests/cfgs/disable_metadata_and_flowrisks/config.txt @@ -1 +1 @@ ---cfg=tls,metadata.sha1_fingerprint,0 --cfg=tls,metadata.ja3c_fingerprint,0 --cfg=tls,metadata.ja3s_fingerprint,0 --cfg=tls,metadata.ja4c_fingerprint,0 --cfg=metadata.tcp_fingerprint,0 --cfg=sip,metadata.attribute.from,0 --cfg=sip,metadata.attribute.to,0 +--cfg=tls,metadata.sha1_fingerprint,0 --cfg=tls,metadata.ja3c_fingerprint,0 --cfg=tls,metadata.ja3s_fingerprint,0 --cfg=tls,metadata.ja4c_fingerprint,0 --cfg=metadata.tcp_fingerprint,0 --cfg=sip,metadata.attribute.from,0 --cfg=sip,metadata.attribute.to,0 --cfg=flow_risk.all,0 diff --git a/tests/cfgs/disable_metadata/pcap/sip.pcap b/tests/cfgs/disable_metadata_and_flowrisks/pcap/sip.pcap index 471ca4bd0..471ca4bd0 120000 --- a/tests/cfgs/disable_metadata/pcap/sip.pcap +++ b/tests/cfgs/disable_metadata_and_flowrisks/pcap/sip.pcap diff --git a/tests/cfgs/disable_metadata/pcap/tls_verylong_certificate.pcap b/tests/cfgs/disable_metadata_and_flowrisks/pcap/tls_verylong_certificate.pcap index 2f722f28e..2f722f28e 120000 --- a/tests/cfgs/disable_metadata/pcap/tls_verylong_certificate.pcap +++ b/tests/cfgs/disable_metadata_and_flowrisks/pcap/tls_verylong_certificate.pcap diff --git a/tests/cfgs/disable_metadata/result/sip.pcap.out b/tests/cfgs/disable_metadata_and_flowrisks/result/sip.pcap.out index c4812fb6a..4ce3fd591 100644 --- a/tests/cfgs/disable_metadata/result/sip.pcap.out +++ b/tests/cfgs/disable_metadata_and_flowrisks/result/sip.pcap.out @@ -14,7 +14,7 @@ Automa domain: 0/0 (search/found) Automa tls cert: 0/0 (search/found) Automa risk mask: 0/0 (search/found) Automa common alpns: 0/0 (search/found) -Patricia risk mask: 6/0 (search/found) +Patricia risk mask: 0/0 (search/found) Patricia risk mask IPv6: 0/0 (search/found) Patricia risk: 0/0 (search/found) Patricia risk IPv6: 0/0 (search/found) @@ -34,4 +34,4 @@ Unrated 1 146 1 Undetected flows: - 1 UDP 192.168.1.2:30001 -> 212.242.33.36:40393 [proto: 0/Unknown][IP: 0/Unknown][ClearText][Confidence: Unknown][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 1][1 pkts/146 bytes -> 0 pkts/0 bytes][Goodput ratio: 71/0][< 1 sec][Risk: ** Susp Entropy **** Unidirectional Traffic **][Risk Score: 20][Risk Info: No server to client traffic / Entropy: 5.220 (Executable?)][PLAIN TEXT (11894297)][Plen Bins: 0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + 1 UDP 192.168.1.2:30001 -> 212.242.33.36:40393 [proto: 0/Unknown][IP: 0/Unknown][ClearText][Confidence: Unknown][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 1][1 pkts/146 bytes -> 0 pkts/0 bytes][Goodput ratio: 71/0][< 1 sec][PLAIN TEXT (11894297)][Plen Bins: 0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] diff --git a/tests/cfgs/disable_metadata/result/tls_verylong_certificate.pcap.out b/tests/cfgs/disable_metadata_and_flowrisks/result/tls_verylong_certificate.pcap.out index b224f0cd9..b224f0cd9 100644 --- a/tests/cfgs/disable_metadata/result/tls_verylong_certificate.pcap.out +++ b/tests/cfgs/disable_metadata_and_flowrisks/result/tls_verylong_certificate.pcap.out |