From fc4fb4d409c43af8b9bdbd9d0cf8d9b742408f26 Mon Sep 17 00:00:00 2001 From: Luca Deri Date: Wed, 7 Aug 2024 11:35:17 +0200 Subject: Fixed probing attempt risk that was creating false positives --- tests/cfgs/default/result/openwire.pcapng.out | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'tests/cfgs/default/result/openwire.pcapng.out') diff --git a/tests/cfgs/default/result/openwire.pcapng.out b/tests/cfgs/default/result/openwire.pcapng.out index 41b2abf3e..51fb696f8 100644 --- a/tests/cfgs/default/result/openwire.pcapng.out +++ b/tests/cfgs/default/result/openwire.pcapng.out @@ -24,4 +24,4 @@ OpenWire 43 5203 1 Acceptable 43 5203 1 - 1 TCP [::1]:51157 <-> [::1]:61616 [proto: 421/OpenWire][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 4][cat: RPC/16][22 pkts/2807 bytes <-> 21 pkts/2396 bytes][Goodput ratio: 49/43][1.07 sec][bytes ratio: 0.079 (Mixed)][IAT c2s/s2c min/avg/max/stddev: 0/0 63/71 1067/1067 251/266][Pkt Len c2s/s2c min/avg/max/stddev: 64/64 128/114 348/592 83/130][Risk: ** Probing attempt **][Risk Score: 50][Risk Info: TCP connection with unidirectional traffic][PLAIN TEXT (ActiveM)][Plen Bins: 28,0,28,5,5,11,5,0,5,0,5,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + 1 TCP [::1]:51157 <-> [::1]:61616 [proto: 421/OpenWire][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 4][cat: RPC/16][22 pkts/2807 bytes <-> 21 pkts/2396 bytes][Goodput ratio: 49/43][1.07 sec][bytes ratio: 0.079 (Mixed)][IAT c2s/s2c min/avg/max/stddev: 0/0 63/71 1067/1067 251/266][Pkt Len c2s/s2c min/avg/max/stddev: 64/64 128/114 348/592 83/130][PLAIN TEXT (ActiveM)][Plen Bins: 28,0,28,5,5,11,5,0,5,0,5,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] -- cgit v1.2.3