summaryrefslogtreecommitdiff
path: root/test/results/dns_ambiguous_names.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2021-10-08 11:12:32 +0200
committerToni Uhlig <matzeton@googlemail.com>2021-10-08 11:31:58 +0200
commit315f90f9828ddfa2e580f45afb1a3d6804bab923 (patch)
tree6433d64724d5988dbc9edca4fe933a35ac05e415 /test/results/dns_ambiguous_names.pcap.out
parentfe77c44e3f6e70e4dfa7c7aa4248f9964518d4f3 (diff)
Fixed invalid "flow_last_seen" timestamp for the first packet.
* After the first packet was processed, "flow_last_seen" was still 0. This behaviour is invalid as the first packet may contain l4 payload data e.g. for UDP and it also breaks nDPId json consistency "flow_first_seen" > 0, but "flow_last_seen" == 0. * JSON schema: set minimum timestamp value for Epoch timestamps to 24710 for flow_*_seen and 1 for pcap packet ts. Those values are dependant on some manipulated pcap's in libnDPI/tests/pcap. Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/dns_ambiguous_names.pcap.out')
-rw-r--r--test/results/dns_ambiguous_names.pcap.out40
1 files changed, 20 insertions, 20 deletions
diff --git a/test/results/dns_ambiguous_names.pcap.out b/test/results/dns_ambiguous_names.pcap.out
index e7780fd43..58548b177 100644
--- a/test/results/dns_ambiguous_names.pcap.out
+++ b/test/results/dns_ambiguous_names.pcap.out
@@ -1,52 +1,52 @@
00487{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","max-flows-per-thread":2048,"max-idle-flows-per-thread":256,"tick-resolution":1000,"reader-thread-count":1,"idle-scan-period":10000,"generic-max-idle-time":600000,"icmp-max-idle-time":10000,"udp-max-idle-time":180000,"tcp-max-idle-time":7440000,"tcp-max-post-end-flow-time":120000,"max-packets-per-flow-to-send":15,"max-packets-per-flow-to-process":255}
-00488{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1625744123717,"flow_last_seen":0,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":48375,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00500{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1625744123717,"flow_last_seen":1625744123717,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":48375,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00474{"flow_id":1,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":717337,"pkt_caplen":96,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":96,"pkt_l4_len":62,"pkt":"ABshv2HAVASmitEsCABFAABS3sIAAEARfvYKyAILCAgICLz3ADUAPh0yZjEBIAABAAAAAAABCjQxLWNvdXJpZXIEcHVzaAVhcHBsZQNjb20AAAEAAQAAKRAAAAAAAAAA"}
-00668{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":1,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1625744123717,"flow_last_seen":0,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":48375,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.ApplePush","breed":"Acceptable","category":"Cloud"},"dns": {"query":"41-courier.push.apple.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00680{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":1,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1625744123717,"flow_last_seen":1625744123717,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":48375,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.ApplePush","breed":"Acceptable","category":"Cloud"},"dns": {"query":"41-courier.push.apple.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00773{"flow_id":1,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":759146,"pkt_caplen":318,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":318,"pkt_l4_len":284,"pkt":"VASmitEsEL9IThY0CABFAAEwD4cAADwRUVQICAgICsgCCwA1vPcBHJeKZjGBgAABAAoAAAABCjQxLWNvdXJpZXIEcHVzaAVhcHBsZQNjb20AAAEAAcAMAAUAAQAAJNcAJgI0MRJjb3VyaWVyLXB1c2gtYXBwbGUDY29tBmFrYWRucwNuZXQAwDcABQABAAAAOwAgEmV1LW5vcnRoLWNvdXJpZXItNApwdXNoLWFwcGxlwE3AaQABAAEAAAARAAQROZKLwGkAAQABAAAAEQAEETmSisBpAAEAAQAAABEABBE5kofAaQABAAEAAAARAAQROZKIwGkAAQABAAAAEQAEETmSicBpAAEAAQAAABEABBE5koTAaQABAAEAAAARAAQROZKGwGkAAQABAAAAEQAEETmShQAAKQIAAAAAAAAA"}
00698{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":2,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":2,"flow_first_seen":1625744123717,"flow_last_seen":1625744123759,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":276,"flow_tot_l4_payload_len":330,"flow_avg_l4_payload_len":165,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":48375,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.ApplePush","breed":"Acceptable","category":"Cloud"},"dns": {"query":"41-courier.push.apple.com","num_queries":1,"num_answers":11,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"17.57.146.139"}}
-00488{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":3,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_first_seen":1625744123764,"flow_last_seen":0,"flow_min_l4_payload_len":44,"flow_max_l4_payload_len":44,"flow_tot_l4_payload_len":44,"flow_avg_l4_payload_len":44,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57290,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00500{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":3,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_first_seen":1625744123764,"flow_last_seen":1625744123764,"flow_min_l4_payload_len":44,"flow_max_l4_payload_len":44,"flow_tot_l4_payload_len":44,"flow_avg_l4_payload_len":44,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57290,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00463{"flow_id":2,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":764039,"pkt_caplen":86,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":86,"pkt_l4_len":52,"pkt":"ABshv2HAVASmitEsCABFAABI3soAAEARfvgKyAILCAgICN\/KADUANB0owxkBIAABAAAAAAABBXRlYW1zBXNreXBlA2NvbQAAAQABAAApEAAAAAAAAAA="}
-00656{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":3,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_first_seen":1625744123764,"flow_last_seen":0,"flow_min_l4_payload_len":44,"flow_max_l4_payload_len":44,"flow_tot_l4_payload_len":44,"flow_avg_l4_payload_len":44,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57290,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"teams.skype.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00668{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":3,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_first_seen":1625744123764,"flow_last_seen":1625744123764,"flow_min_l4_payload_len":44,"flow_max_l4_payload_len":44,"flow_tot_l4_payload_len":44,"flow_avg_l4_payload_len":44,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57290,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"teams.skype.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00529{"flow_id":2,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":4,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":792208,"pkt_caplen":135,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":135,"pkt_l4_len":101,"pkt":"VASmitEsEL9IThY0CABFAAB5Cy0AADwRVmUICAgICsgCCwA138oAZUD8wxmBgAABAAIAAAABBXRlYW1zBXNreXBlA2NvbQAAAQABwAwABQABAAAIAwAVBnMtMDAwMQhzLW1zZWRnZQNuZXQAwC0AAQABAAAAqAAEDWsDgAAAKQIAAAAAAAAA"}
00682{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":4,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":2,"flow_first_seen":1625744123764,"flow_last_seen":1625744123792,"flow_min_l4_payload_len":44,"flow_max_l4_payload_len":93,"flow_tot_l4_payload_len":137,"flow_avg_l4_payload_len":68,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57290,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"teams.skype.com","num_queries":1,"num_answers":3,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"13.107.3.128"}}
-00488{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":5,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_first_seen":1625744123796,"flow_last_seen":0,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57051,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00500{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":5,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_first_seen":1625744123796,"flow_last_seen":1625744123796,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57051,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00466{"flow_id":3,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":5,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":796920,"pkt_caplen":90,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":90,"pkt_l4_len":56,"pkt":"ABshv2HAVASmitEsCABFAABM3uAAAEARft4KyAILCAgICN7bADUAOB0s27sBIAABAAAAAAABA2FwaQV0ZWFtcwVza3lwZQNjb20AAAEAAQAAKRAAAAAAAAAA"}
-00660{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":5,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_first_seen":1625744123796,"flow_last_seen":0,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57051,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"api.teams.skype.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00672{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":5,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_first_seen":1625744123796,"flow_last_seen":1625744123796,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57051,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"api.teams.skype.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00645{"flow_id":3,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":6,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":823325,"pkt_caplen":221,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":221,"pkt_l4_len":187,"pkt":"VASmitEsEL9IThY0CABFAADPnR4AADwRxB0ICAgICsgCCwA13tsAu9ue27uBgAABAAQAAAABA2FwaQV0ZWFtcwVza3lwZQNjb20AAAEAAcAMAAUAAQAADJMAHgl0ZWFtcy1hZmQOdHJhZmZpY21hbmFnZXIDbmV0AMAxAAUAAQAAAOwALxx0ZWFtcy1hZmQtdHJhZmZpY21hbmFnZXItbmV0BnMtMDAwNAhzLW1zZWRnZcBKwFsABQABAAAAjQACwHjAeAABAAEAAACNAAQ0ccKDAAApAgAAAAAAAAA="}
00690{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":6,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":2,"flow_first_seen":1625744123796,"flow_last_seen":1625744123823,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":179,"flow_tot_l4_payload_len":227,"flow_avg_l4_payload_len":113,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57051,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"api.teams.skype.com","num_queries":1,"num_answers":5,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"52.113.194.131"}}
-00488{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":7,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":1,"flow_first_seen":1625744123828,"flow_last_seen":0,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":46134,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00500{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":7,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":1,"flow_first_seen":1625744123828,"flow_last_seen":1625744123828,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":46134,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00470{"flow_id":4,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":7,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":828193,"pkt_caplen":92,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":92,"pkt_l4_len":58,"pkt":"ABshv2HAVASmitEsCABFAABO3ucAAEARftUKyAILCAgICLQ2ADUAOh0u7g0BIAABAAAAAAABCmFsdDItbXRhbGsGZ29vZ2xlA2NvbQAAAQABAAApEAAAAAAAAAA="}
-00667{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":7,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":1,"flow_first_seen":1625744123828,"flow_last_seen":0,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":46134,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.GoogleServices","breed":"Acceptable","category":"Web"},"dns": {"query":"alt2-mtalk.google.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00679{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":7,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":1,"flow_first_seen":1625744123828,"flow_last_seen":1625744123828,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":46134,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.GoogleServices","breed":"Acceptable","category":"Web"},"dns": {"query":"alt2-mtalk.google.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00541{"flow_id":4,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":8,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":853778,"pkt_caplen":143,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":143,"pkt_l4_len":109,"pkt":"VASmitEsEL9IThY0CABFAACB5h8AADwRe2oICAgICsgCCwA1tDYAbSCd7g2BgAABAAIAAAABCmFsdDItbXRhbGsGZ29vZ2xlA2NvbQAAAQABwAwABQABAABUXwAXBGFsdDINbW9iaWxlLWd0YWxrNAFswBfAMwABAAEAAAErAAStwsq8AAApAgAAAAAAAAA="}
00697{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":8,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":2,"flow_first_seen":1625744123828,"flow_last_seen":1625744123853,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":101,"flow_tot_l4_payload_len":151,"flow_avg_l4_payload_len":75,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":46134,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.GoogleServices","breed":"Acceptable","category":"Web"},"dns": {"query":"alt2-mtalk.google.com","num_queries":1,"num_answers":3,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"173.194.202.188"}}
-00488{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":9,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1625744123858,"flow_last_seen":0,"flow_min_l4_payload_len":55,"flow_max_l4_payload_len":55,"flow_tot_l4_payload_len":55,"flow_avg_l4_payload_len":55,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57632,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00500{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":9,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1625744123858,"flow_last_seen":1625744123858,"flow_min_l4_payload_len":55,"flow_max_l4_payload_len":55,"flow_tot_l4_payload_len":55,"flow_avg_l4_payload_len":55,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57632,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00478{"flow_id":5,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":9,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":858437,"pkt_caplen":97,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":97,"pkt_l4_len":63,"pkt":"ABshv2HAVASmitEsCABFAABT3wQAAEARfrMKyAILCAgICOEgADUAPx0zyVMBIAABAAAAAAABB2FuZHJvaWQHY2xpZW50cwZnb29nbGUDY29tAAABAAEAACkQAAAAAAAAAA=="}
-00672{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":9,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1625744123858,"flow_last_seen":0,"flow_min_l4_payload_len":55,"flow_max_l4_payload_len":55,"flow_tot_l4_payload_len":55,"flow_avg_l4_payload_len":55,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57632,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.PlayStore","breed":"Safe","category":"SoftwareUpdate"},"dns": {"query":"android.clients.google.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00684{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":9,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1625744123858,"flow_last_seen":1625744123858,"flow_min_l4_payload_len":55,"flow_max_l4_payload_len":55,"flow_tot_l4_payload_len":55,"flow_avg_l4_payload_len":55,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57632,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.PlayStore","breed":"Safe","category":"SoftwareUpdate"},"dns": {"query":"android.clients.google.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00855{"flow_id":5,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":10,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":885159,"pkt_caplen":377,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":377,"pkt_l4_len":343,"pkt":"VASmitEsEL9IThY0CABFAAFrZGIAADwR\/D0ICAgICsgCCwA14SABV21MyVOBgAABABEAAAABB2FuZHJvaWQHY2xpZW50cwZnb29nbGUDY29tAAABAAHADAAFAAEAAAECAAwHYW5kcm9pZAFswBzAOAABAAEAAAECAARssQ5lwDgAAQABAAABAgAEbLEOccA4AAEAAQAAAQIABEp9g2XAOAABAAEAAAECAARKfYNxwDgAAQABAAABAgAESn2DZsA4AAEAAQAAAQIABEp9g2TAOAABAAEAAAECAARKfYOKwDgAAQABAAABAgAESn2Di8A4AAEAAQAAAQIABEp9zWXAOAABAAEAAAECAARKfc2LwDgAAQABAAABAgAESn3NZMA4AAEAAQAAAQIABEDpoWbAOAABAAEAAAECAARA6aFlwDgAAQABAAABAgAEQOmhisA4AAEAAQAAAQIABEDppIrAOAABAAEAAAECAARA6aRkAAApAgAAAAAAAAA="}
00704{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":10,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":2,"flow_first_seen":1625744123858,"flow_last_seen":1625744123885,"flow_min_l4_payload_len":55,"flow_max_l4_payload_len":335,"flow_tot_l4_payload_len":390,"flow_avg_l4_payload_len":195,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57632,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.PlayStore","breed":"Safe","category":"SoftwareUpdate"},"dns": {"query":"android.clients.google.com","num_queries":1,"num_answers":18,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"108.177.14.101"}}
-00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":11,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":1,"flow_first_seen":1625744123890,"flow_last_seen":0,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":42790,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00501{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":11,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":1,"flow_first_seen":1625744123890,"flow_last_seen":1625744123890,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":42790,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00471{"flow_id":6,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":11,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":890136,"pkt_caplen":92,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":92,"pkt_l4_len":58,"pkt":"ABshv2HAVASmitEsCABFAABO3wwAAEARfrAKyAILCAgICKcmADUAOh0utWIBIAABAAAAAAABASoFdGVhbXMJbWljcm9zb2Z0A2NvbQAAAQABAAApEAAAAAAAAAA="}
-00663{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":11,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":1,"flow_first_seen":1625744123890,"flow_last_seen":0,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":42790,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"_.teams.microsoft.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00675{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":11,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":1,"flow_first_seen":1625744123890,"flow_last_seen":1625744123890,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":50,"flow_tot_l4_payload_len":50,"flow_avg_l4_payload_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":42790,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"_.teams.microsoft.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00574{"flow_id":6,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":12,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":973076,"pkt_caplen":166,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":166,"pkt_l4_len":132,"pkt":"VASmitEsEL9IThY0CABFAACY7gkAADwRc2kICAgICsgCCwA1pyYAhI+OtWKBgwABAAAAAQABASoFdGVhbXMJbWljcm9zb2Z0A2NvbQAAAQABwBQABgABAAABKwA+B25zMS0yMDUJYXp1cmUtZG5zwB4TYXp1cmVkbnMtaG9zdG1hc3RlcsAUAAAAAQAADhAAAAEsACTqAAAAASwAACkCAAAAAAAAAA=="}
00685{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":12,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":2,"flow_first_seen":1625744123890,"flow_last_seen":1625744123973,"flow_min_l4_payload_len":50,"flow_max_l4_payload_len":124,"flow_tot_l4_payload_len":174,"flow_avg_l4_payload_len":87,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":42790,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Teams","breed":"Safe","category":"Collaborative"},"dns": {"query":"_.teams.microsoft.com","num_queries":1,"num_answers":2,"reply_code":3,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
-00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":13,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":1,"flow_first_seen":1625744123977,"flow_last_seen":0,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44198,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00501{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":13,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":1,"flow_first_seen":1625744123977,"flow_last_seen":1625744123977,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44198,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00475{"flow_id":7,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":13,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744123,"pkt_ts_usec":977935,"pkt_caplen":96,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":96,"pkt_l4_len":62,"pkt":"ABshv2HAVASmitEsCABFAABS3y4AAEARfooKyAILCAgICKymADUAPh0yDWEBIAABAAAAAAABDHdpZGUteW91dHViZQFsBmdvb2dsZQNjb20AAAEAAQAAKRAAAAAAAAAA"}
-00666{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":13,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":1,"flow_first_seen":1625744123977,"flow_last_seen":0,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44198,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Google","breed":"Tracker\/Ads","category":"Web"},"dns": {"query":"wide-youtube.l.google.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00678{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":13,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":1,"flow_first_seen":1625744123977,"flow_last_seen":1625744123977,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":54,"flow_tot_l4_payload_len":54,"flow_avg_l4_payload_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44198,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Google","breed":"Tracker\/Ads","category":"Web"},"dns": {"query":"wide-youtube.l.google.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00499{"flow_id":7,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":14,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":6118,"pkt_caplen":112,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":112,"pkt_l4_len":78,"pkt":"VASmitEsEL9IThY0CABFAABiUocAADwRDyIICAgICsgCCwA1rKYATu57DWGBgAABAAEAAAABDHdpZGUteW91dHViZQFsBmdvb2dsZQNjb20AAAEAAcAMAAEAAQAAASsABEDppMYAACkCAAAAAAAAAA=="}
00694{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":14,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":2,"flow_first_seen":1625744123977,"flow_last_seen":1625744124006,"flow_min_l4_payload_len":54,"flow_max_l4_payload_len":70,"flow_tot_l4_payload_len":124,"flow_avg_l4_payload_len":62,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44198,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Google","breed":"Tracker\/Ads","category":"Web"},"dns": {"query":"wide-youtube.l.google.com","num_queries":1,"num_answers":2,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"64.233.164.198"}}
-00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":15,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":1,"flow_first_seen":1625744124010,"flow_last_seen":0,"flow_min_l4_payload_len":46,"flow_max_l4_payload_len":46,"flow_tot_l4_payload_len":46,"flow_avg_l4_payload_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":52541,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00501{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":15,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":1,"flow_first_seen":1625744124010,"flow_last_seen":1625744124010,"flow_min_l4_payload_len":46,"flow_max_l4_payload_len":46,"flow_tot_l4_payload_len":46,"flow_avg_l4_payload_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":52541,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00466{"flow_id":8,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":15,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":10794,"pkt_caplen":88,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":88,"pkt_l4_len":54,"pkt":"ABshv2HAVASmitEsCABFAABK30QAAEARfnwKyAILCAgICM09ADUANh0qX5cBIAABAAAAAAABB2d1enpvbmkFYXBwbGUDY29tAAABAAEAACkQAAAAAAAAAA=="}
-00669{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":15,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":1,"flow_first_seen":1625744124010,"flow_last_seen":0,"flow_min_l4_payload_len":46,"flow_max_l4_payload_len":46,"flow_tot_l4_payload_len":46,"flow_avg_l4_payload_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":52541,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.AppleSiri","breed":"Acceptable","category":"VirtAssistant"},"dns": {"query":"guzzoni.apple.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00681{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":15,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":1,"flow_first_seen":1625744124010,"flow_last_seen":1625744124010,"flow_min_l4_payload_len":46,"flow_max_l4_payload_len":46,"flow_tot_l4_payload_len":46,"flow_avg_l4_payload_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":52541,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.AppleSiri","breed":"Acceptable","category":"VirtAssistant"},"dns": {"query":"guzzoni.apple.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00545{"flow_id":8,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":16,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":69035,"pkt_caplen":146,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":146,"pkt_l4_len":112,"pkt":"VASmitEsEL9IThY0CABFAACEUooAADwRDv0ICAgICsgCCwA1zT0AcK3sX5eBgAABAAIAAAABB2d1enpvbmkFYXBwbGUDY29tAAABAAHADAAFAAEAAAK5AB4RZ3V6em9uaS1hcHBsZS1jb20BdgdhYXBsaW1nwBrALwABAAEAAAErAAQRghUFAAApAgAAAAAAAAA="}
00695{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":16,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":2,"flow_first_seen":1625744124010,"flow_last_seen":1625744124069,"flow_min_l4_payload_len":46,"flow_max_l4_payload_len":104,"flow_tot_l4_payload_len":150,"flow_avg_l4_payload_len":75,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":52541,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.AppleSiri","breed":"Acceptable","category":"VirtAssistant"},"dns": {"query":"guzzoni.apple.com","num_queries":1,"num_answers":3,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"17.130.21.5"}}
-00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":17,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":9,"flow_packet_id":1,"flow_first_seen":1625744124073,"flow_last_seen":0,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":53951,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00501{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":17,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":9,"flow_packet_id":1,"flow_first_seen":1625744124073,"flow_last_seen":1625744124073,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":53951,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00467{"flow_id":9,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":17,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":73647,"pkt_caplen":90,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":90,"pkt_l4_len":56,"pkt":"ABshv2HAVASmitEsCABFAABM31QAAEARfmoKyAILCAgICNK\/ADUAOB0sVeABIAABAAAAAAABBXNob3J0BndlaXhpbgJxcQNjb20AAAEAAQAAKRAAAAAAAAAA"}
-00648{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":17,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":9,"flow_packet_id":1,"flow_first_seen":1625744124073,"flow_last_seen":0,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":53951,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.QQ","breed":"Fun","category":"Chat"},"dns": {"query":"short.weixin.qq.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00660{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":17,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":9,"flow_packet_id":1,"flow_first_seen":1625744124073,"flow_last_seen":1625744124073,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":48,"flow_tot_l4_payload_len":48,"flow_avg_l4_payload_len":48,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":53951,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.QQ","breed":"Fun","category":"Chat"},"dns": {"query":"short.weixin.qq.com","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00514{"flow_id":9,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":18,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":417727,"pkt_caplen":122,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":122,"pkt_l4_len":88,"pkt":"VASmitEsEL9IThY0CABFAABsvHUAADwRpSkICAgICsgCCwA10r8AWILaVeCBgAABAAIAAAABBXNob3J0BndlaXhpbgJxcQNjb20AAAEAAcAMAAEAAQAAAlcABMvN\/k3ADAABAAEAAAJXAATLzf7cAAApAgAAAAAAAAA="}
00676{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":18,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":9,"flow_packet_id":2,"flow_first_seen":1625744124073,"flow_last_seen":1625744124417,"flow_min_l4_payload_len":48,"flow_max_l4_payload_len":80,"flow_tot_l4_payload_len":128,"flow_avg_l4_payload_len":64,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":53951,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.QQ","breed":"Fun","category":"Chat"},"dns": {"query":"short.weixin.qq.com","num_queries":1,"num_answers":3,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"203.205.254.77"}}
-00490{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":19,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":10,"flow_packet_id":1,"flow_first_seen":1625744124422,"flow_last_seen":0,"flow_min_l4_payload_len":60,"flow_max_l4_payload_len":60,"flow_tot_l4_payload_len":60,"flow_avg_l4_payload_len":60,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44883,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00502{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":19,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":10,"flow_packet_id":1,"flow_first_seen":1625744124422,"flow_last_seen":1625744124422,"flow_min_l4_payload_len":60,"flow_max_l4_payload_len":60,"flow_tot_l4_payload_len":60,"flow_avg_l4_payload_len":60,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44883,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00486{"flow_id":10,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":19,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":422852,"pkt_caplen":102,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":102,"pkt_l4_len":68,"pkt":"ABshv2HAVASmitEsCABFAABY4G8AAEARfUMKyAILCAgICK9TADUARB047MoBIAABAAAAAAABCWluc3RhZ3JhbQdmYWFlMS0xA2ZuYQVmYmNkbgNuZXQAAAEAAQAAKRAAAAAAAAAA"}
-00677{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":19,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":10,"flow_packet_id":1,"flow_first_seen":1625744124422,"flow_last_seen":0,"flow_min_l4_payload_len":60,"flow_max_l4_payload_len":60,"flow_tot_l4_payload_len":60,"flow_avg_l4_payload_len":60,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44883,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Instagram","breed":"Fun","category":"SocialNetwork"},"dns": {"query":"instagram.faae1-1.fna.fbcdn.net","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
+00689{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":19,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":10,"flow_packet_id":1,"flow_first_seen":1625744124422,"flow_last_seen":1625744124422,"flow_min_l4_payload_len":60,"flow_max_l4_payload_len":60,"flow_tot_l4_payload_len":60,"flow_avg_l4_payload_len":60,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44883,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Instagram","breed":"Fun","category":"SocialNetwork"},"dns": {"query":"instagram.faae1-1.fna.fbcdn.net","num_queries":0,"num_answers":0,"reply_code":0,"query_type":1,"rsp_type":0,"rsp_addr":"0.0.0.0"}}
00510{"flow_id":10,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":20,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1625744124,"pkt_ts_usec":461060,"pkt_caplen":118,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":118,"pkt_l4_len":84,"pkt":"VASmitEsEL9IThY0CABFAABo+pEAADwRZxEICAgICsgCCwA1r1MAVN6x7MqBgAABAAEAAAABCWluc3RhZ3JhbQdmYWFlMS0xA2ZuYQVmYmNkbgNuZXQAAAEAAcAMAAEAAQAAADsABCncnmAAACkCAAAAAAAAAA=="}
00704{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":20,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":10,"flow_packet_id":2,"flow_first_seen":1625744124422,"flow_last_seen":1625744124461,"flow_min_l4_payload_len":60,"flow_max_l4_payload_len":76,"flow_tot_l4_payload_len":136,"flow_avg_l4_payload_len":68,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":44883,"dst_port":53,"l4_proto":"udp","ndpi": {"proto":"DNS.Instagram","breed":"Fun","category":"SocialNetwork"},"dns": {"query":"instagram.faae1-1.fna.fbcdn.net","num_queries":1,"num_answers":2,"reply_code":0,"query_type":1,"rsp_type":1,"rsp_addr":"41.220.158.96"}}
00503{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":20,"source":"dns_ambiguous_names.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":2,"flow_first_seen":1625744123764,"flow_last_seen":1625744123792,"flow_min_l4_payload_len":44,"flow_max_l4_payload_len":93,"flow_tot_l4_payload_len":137,"flow_avg_l4_payload_len":68,"midstream":0,"l3_proto":"ip4","src_ip":"10.200.2.11","dst_ip":"8.8.8.8","src_port":57290,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}