aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/caches_cfg
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2023-11-09 23:18:55 +0100
committerToni Uhlig <matzeton@googlemail.com>2023-11-09 23:44:35 +0100
commit8ebaccc27d779e981b500e80b69f62396dcaa0ca (patch)
tree62993474d9ea00d23c579a649ab048fd2a8e76e6 /test/results/flow-info/caches_cfg
parentdcb595e16153caa1600b64adea6af20009ea8419 (diff)
py-flow-info: Improved analyse result printing.1.6rc4
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/caches_cfg')
-rw-r--r--test/results/flow-info/caches_cfg/teams.pcap.out96
1 files changed, 48 insertions, 48 deletions
diff --git a/test/results/flow-info/caches_cfg/teams.pcap.out b/test/results/flow-info/caches_cfg/teams.pcap.out
index 5fbd73a71..9ebd658bc 100644
--- a/test/results/flow-info/caches_cfg/teams.pcap.out
+++ b/test/results/flow-info/caches_cfg/teams.pcap.out
@@ -20,9 +20,9 @@
detected: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.030| 0.006| 0.009| 77.930| 3.700]
- [PKTLEN......: 40.000| 1492.000| 393.900| 548.100| 300365.600| 3.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.030| 0.006| 0.009| 77.930| 3.700]
+ [PKTLEN......: 40.000| 1492.000| 393.900| 548.100| 300365.600| 3.900]
[BINS(c->s)..: 10,1,1,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,1,1,0,0,0,1,0,0,0,1,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,0,1,0,1,1,0,0,1,1,0,1,0,0,0,0,1,1,0,1,1,0,1,1,1,0]
@@ -37,9 +37,9 @@
detected: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com]
detection-update: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com]
analyse: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.221| 0.032| 0.054| 2931.592| 3.400]
- [PKTLEN......: 52.000| 1492.000| 907.900| 687.500| 472618.500| 4.400]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.221| 0.032| 0.054| 2931.592| 3.400]
+ [PKTLEN......: 52.000| 1492.000| 907.900| 687.500| 472618.500| 4.400]
[BINS(c->s)..: 5,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0]
[BINS(s->c)..: 5,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,1,0,0,0]
@@ -55,9 +55,9 @@
detected: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com]
detection-update: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com]
analyse: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.050| 0.018| 0.021| 449.200| 3.900]
- [PKTLEN......: 52.000| 1492.000| 680.600| 673.100| 453031.800| 4.200]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.050| 0.018| 0.021| 449.200| 3.900]
+ [PKTLEN......: 52.000| 1492.000| 680.600| 673.100| 453031.800| 4.200]
[BINS(c->s)..: 7,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0,0]
[BINS(s->c)..: 7,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,1,0,0,1,1,1,1,0,0]
@@ -139,9 +139,9 @@
detected: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe][presence.teams.microsoft.com]
detection-update: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe][presence.teams.microsoft.com]
analyse: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.153| 0.028| 0.040| 1626.047| 3.600]
- [PKTLEN......: 52.000| 1492.000| 819.700| 699.200| 488828.900| 4.300]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.153| 0.028| 0.040| 1626.047| 3.600]
+ [PKTLEN......: 52.000| 1492.000| 819.700| 699.200| 488828.900| 4.300]
[BINS(c->s)..: 5,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0,0]
[BINS(s->c)..: 7,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,0,1,0,0,1,1,0,0,0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,1,0]
@@ -156,9 +156,9 @@
detection-update: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org]
RISK: Known Proto on Non Std Port
analyse: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.201| 0.025| 0.047| 2215.159| 3.200]
- [PKTLEN......: 40.000| 1492.000| 340.200| 510.300| 260451.700| 3.800]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.201| 0.025| 0.047| 2215.159| 3.200]
+ [PKTLEN......: 40.000| 1492.000| 340.200| 510.300| 260451.700| 3.800]
[BINS(c->s)..: 11,1,1,1,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0]
[BINS(s->c)..: 3,3,1,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,0,1,0,0,0,0,1,0,1,0,0,1,0,1,0,1,0,0,0,1,1]
@@ -176,9 +176,9 @@
detection-update: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] [TLS.Teams][Azure][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.115| 0.021| 0.031| 968.681| 3.500]
- [PKTLEN......: 52.000| 1492.000| 377.200| 521.700| 272149.200| 3.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.115| 0.021| 0.031| 968.681| 3.500]
+ [PKTLEN......: 52.000| 1492.000| 377.200| 521.700| 272149.200| 3.900]
[BINS(c->s)..: 11,1,1,1,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0]
[BINS(s->c)..: 3,2,1,0,0,1,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,1,0,1,1,0,0,0,0,1,0,1,0,0,1,0,1,0,1,0,0,1,1,0,1]
@@ -192,9 +192,9 @@
detected: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com]
detection-update: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com]
analyse: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 2.010| 0.146| 0.490| 239614.050| 1.700]
- [PKTLEN......: 40.000| 1492.000| 305.200| 468.100| 219152.800| 3.800]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 2.010| 0.146| 0.490| 239614.050| 1.700]
+ [PKTLEN......: 40.000| 1492.000| 305.200| 468.100| 219152.800| 3.800]
[BINS(c->s)..: 9,1,1,0,1,0,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,1,1,0,1,0,0,0,0,1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,0,1,0,1,1,0,0,1,1,1,0,0,0,0,0,1,1,0,1,1,1,0,0,1,1]
@@ -203,9 +203,9 @@
[ENTROPIES...: 4.4,5.0,4.6,5.5,4.5,7.3,7.5,4.6,7.5,4.6,7.7,6.8,4.7,6.5,4.5,7.2,6.0,4.6,4.6,6.2,5.2,7.6,4.4,5.4,4.6,4.5,4.5,7.5,4.7,7.2,4.5,7.3]
detection-update: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com]
analyse: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.540| 0.024| 0.095| 8949.939| 1.900]
- [PKTLEN......: 40.000| 1492.000| 331.500| 473.500| 224192.200| 3.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.540| 0.024| 0.095| 8949.939| 1.900]
+ [PKTLEN......: 40.000| 1492.000| 331.500| 473.500| 224192.200| 3.900]
[BINS(c->s)..: 9,1,1,0,2,0,2,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0]
[BINS(s->c)..: 5,2,1,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,0,1,1,0,0,0,0,0,1,1,1,0,0,0,1,1,0,1,1,0,1,0,0,0,0]
@@ -256,9 +256,9 @@
detection-update: [....40] [ip4][..tcp] [....192.168.1.6][60551] -> [...52.114.15.45][..443] [TLS.Teams][Azure][Collaborative][Safe][trouter2-asse-a.trouter.teams.microsoft.com]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.154| 0.015| 0.036| 1274.324| 2.800]
- [PKTLEN......: 40.000| 1492.000| 585.700| 671.400| 450756.000| 4.000]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.154| 0.015| 0.036| 1274.324| 2.800]
+ [PKTLEN......: 40.000| 1492.000| 585.700| 671.400| 450756.000| 4.000]
[BINS(c->s)..: 10,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,10,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,0,1,0,1,1,0,0,1,0,1,1,0,0,1,1,1,0,1,0,1,1,0,0,1,1]
@@ -278,9 +278,9 @@
detection-update: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.053| 0.020| 0.022| 492.470| 3.900]
- [PKTLEN......: 52.000| 1492.000| 640.900| 667.900| 446080.700| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.053| 0.020| 0.022| 492.470| 3.900]
+ [PKTLEN......: 52.000| 1492.000| 640.900| 667.900| 446080.700| 4.100]
[BINS(c->s)..: 9,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0]
[BINS(s->c)..: 6,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,1,0,1,1,1,0,0,0]
@@ -303,9 +303,9 @@
detection-update: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.126| 0.019| 0.032| 1006.354| 3.400]
- [PKTLEN......: 52.000| 1492.000| 345.200| 499.900| 249913.200| 3.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.126| 0.019| 0.032| 1006.354| 3.400]
+ [PKTLEN......: 52.000| 1492.000| 345.200| 499.900| 249913.200| 3.900]
[BINS(c->s)..: 12,1,3,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0]
[BINS(s->c)..: 2,3,1,0,0,0,0,1,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,0,1,1,0,0,0,0,1,1,0,0,0,1,0,1,0,0,0,1,1,0,1,0]
@@ -317,9 +317,9 @@
detection-update: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][euno-1.api.microsoftstream.com]
new: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443]
analyse: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.162| 0.032| 0.044| 1964.919| 3.600]
- [PKTLEN......: 52.000| 1492.000| 736.700| 694.000| 481656.100| 4.200]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.162| 0.032| 0.044| 1964.919| 3.600]
+ [PKTLEN......: 52.000| 1492.000| 736.700| 694.000| 481656.100| 4.200]
[BINS(c->s)..: 5,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0,0]
[BINS(s->c)..: 8,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0]
[DIRECTIONS..: 0,1,0,0,0,1,1,1,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,0,0,1,0,1,1,1]
@@ -342,9 +342,9 @@
detected: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe][emea.ng.msg.teams.microsoft.com]
detection-update: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe][emea.ng.msg.teams.microsoft.com]
analyse: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.277| 0.019| 0.049| 2449.644| 2.900]
- [PKTLEN......: 52.000| 1492.000| 370.200| 512.100| 262257.700| 3.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.277| 0.019| 0.049| 2449.644| 2.900]
+ [PKTLEN......: 52.000| 1492.000| 370.200| 512.100| 262257.700| 3.900]
[BINS(c->s)..: 11,1,2,1,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 3,3,1,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,1,0,1,1,0,0,0,0,1,1,0,0,0,1,0,1,0,1,0,0,1,1,0,1]
@@ -352,9 +352,9 @@
[PKTLENS.....: 64,60,52,274,1492,1492,64,52,1492,52,1492,471,52,178,145,525,103,121,52,52,90,90,52,511,52,52,1046,134,52,94,52,1335]
[ENTROPIES...: 4.4,5.3,4.9,5.6,7.1,7.3,5.0,5.0,7.5,4.9,7.6,7.5,4.9,6.3,6.3,7.6,5.6,5.9,5.0,4.9,5.4,5.7,5.0,7.5,5.0,5.2,7.8,6.2,5.2,5.6,5.0,7.8]
analyse: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] [TLS.Teams][Azure][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 8.978| 0.329| 1.582| 2503841.415| 0.800]
- [PKTLEN......: 40.000| 1492.000| 339.200| 486.100| 236250.500| 3.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 8.978| 0.329| 1.582| 2503841.415| 0.800]
+ [PKTLEN......: 40.000| 1492.000| 339.200| 486.100| 236250.500| 3.900]
[BINS(c->s)..: 10,1,1,0,1,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 4,3,1,0,0,0,0,0,1,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,1,0,0,0,0,0,1,0,1,0,0,1,1,0,1,0,1,1,1,1,1]
@@ -430,9 +430,9 @@
detected: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][]
RISK: Known Proto on Non Std Port
analyse: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 1.567| 0.072| 0.275| 75449.426| 1.900]
- [PKTLEN......: 40.000| 1492.000| 256.900| 427.000| 182315.300| 3.700]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 1.567| 0.072| 0.275| 75449.426| 1.900]
+ [PKTLEN......: 40.000| 1492.000| 256.900| 427.000| 182315.300| 3.700]
[BINS(c->s)..: 15,1,0,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 4,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0]
[DIRECTIONS..: 0,1,0,0,1,0,1,1,0,0,1,1,0,0,1,1,0,0,0,0,0,0,1,1,0,0,1,0,0,0,1,1]
@@ -445,9 +445,9 @@
new: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6]
detected: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] [ICMP][Unknown][Network][Acceptable]
analyse: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 1.168| 0.160| 0.366| 133702.353| 2.700]
- [PKTLEN......: 66.000| 1242.000| 253.400| 374.400| 140199.200| 4.000]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 1.168| 0.160| 0.366| 133702.353| 2.700]
+ [PKTLEN......: 66.000| 1242.000| 253.400| 374.400| 140199.200| 4.000]
[BINS(c->s)..: 0,2,16,4,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,1,1,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,1,0,1,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]