diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2023-11-09 23:18:55 +0100 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2023-11-09 23:44:35 +0100 |
commit | 8ebaccc27d779e981b500e80b69f62396dcaa0ca (patch) | |
tree | 62993474d9ea00d23c579a649ab048fd2a8e76e6 /test/results/flow-info/default/skype.pcap.out | |
parent | dcb595e16153caa1600b64adea6af20009ea8419 (diff) |
py-flow-info: Improved analyse result printing.1.6rc4
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/default/skype.pcap.out')
-rw-r--r-- | test/results/flow-info/default/skype.pcap.out | 48 |
1 files changed, 24 insertions, 24 deletions
diff --git a/test/results/flow-info/default/skype.pcap.out b/test/results/flow-info/default/skype.pcap.out index 5201b8cbc..986aa14d8 100644 --- a/test/results/flow-info/default/skype.pcap.out +++ b/test/results/flow-info/default/skype.pcap.out @@ -65,9 +65,9 @@ detection-update: [....13] [ip4][..udp] [...192.168.1.34][49990] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst6.r.skype.net] RISK: Unidirectional Traffic analyse: [....15] [ip4][..tcp] [...192.168.1.34][50028] -> [.157.56.126.211][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.301| 0.083| 0.084| 7113.901| 4.200] - [PKTLEN......: 52.000| 1492.000| 357.800| 468.900| 219872.600| 4.000] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.301| 0.083| 0.084| 7113.901| 4.200] + [PKTLEN......: 52.000| 1492.000| 357.800| 468.900| 219872.600| 4.000] [BINS(c->s)..: 10,1,1,1,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0] [BINS(s->c)..: 4,1,0,1,0,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0] [DIRECTIONS..: 0,1,0,0,1,1,0,1,1,0,0,1,0,1,0,0,1,0,0,1,0,0,1,1,0,0,0,1,0,1,1,0] @@ -500,9 +500,9 @@ new: [...225] [ip4][..tcp] [...192.168.1.34][50102] -> [...65.55.223.15][..443] new: [...226] [ip4][..tcp] [...192.168.1.34][50103] -> [....64.4.23.166][..443] analyse: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.015| 19.851| 1.938| 5.863| 34377878.733| 1.700] - [PKTLEN......: 313.000| 391.000| 358.000| 29.200| 851.500| 5.000] + min| max| avg| stddev| variance| entropy + [IAT.........: 0.015| 19.851| 1.938| 5.863| 34377878.733| 1.700] + [PKTLEN......: 313.000| 391.000| 358.000| 29.200| 851.500| 5.000] [BINS(c->s)..: 0,0,0,0,0,0,0,0,3,10,6,13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] @@ -576,9 +576,9 @@ detection-update: [...230] [ip4][..udp] [...192.168.1.34][54067] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic analyse: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.965| 0.176| 0.204| 41803.604| 4.200] - [PKTLEN......: 52.000| 1492.000| 164.600| 286.000| 81813.500| 3.900] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.965| 0.176| 0.204| 41803.604| 4.200] + [PKTLEN......: 52.000| 1492.000| 164.600| 286.000| 81813.500| 3.900] [BINS(c->s)..: 10,3,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 11,1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0] [DIRECTIONS..: 0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,1,0,1,0,0,1,0,1,1,0,1,0,1,0,1] @@ -614,9 +614,9 @@ new: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] new: [...252] [ip4][..tcp] [...192.168.1.34][50122] -> [..81.133.19.185][44431] analyse: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.200| 0.063| 0.061| 3703.968| 4.200] - [PKTLEN......: 52.000| 1235.000| 159.800| 252.000| 63524.500| 4.000] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.200| 0.063| 0.061| 3703.968| 4.200] + [PKTLEN......: 52.000| 1235.000| 159.800| 252.000| 63524.500| 4.000] [BINS(c->s)..: 14,2,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 7,1,1,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,0,0,1,0,0,1,0,1,0,1,0,0,1,0,0,0,0,1,1,1,0,0,0,1,1,0,0] @@ -641,9 +641,9 @@ RISK: TLS (probably) Not Carrying HTTPS new: [...261] [ip4][..tcp] [...192.168.1.34][50129] -> [.91.190.218.125][12350] analyse: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] [TLS.AppleiCloud][Apple][Web][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.605| 0.068| 0.136| 18472.737| 3.000] - [PKTLEN......: 40.000| 1480.000| 234.900| 350.900| 123149.100| 3.900] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.605| 0.068| 0.136| 18472.737| 3.000] + [PKTLEN......: 40.000| 1480.000| 234.900| 350.900| 123149.100| 3.900] [BINS(c->s)..: 9,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 9,3,1,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0] [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,0,0,1,1,1,0,0,0,0,1,1,1,1] @@ -691,9 +691,9 @@ new: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] detected: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst5.r.skype.net] analyse: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 1.782| 0.325| 0.510| 259840.393| 3.600] - [PKTLEN......: 52.000| 1176.000| 143.300| 243.100| 59118.200| 3.900] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 1.782| 0.325| 0.510| 259840.393| 3.600] + [PKTLEN......: 52.000| 1176.000| 143.300| 243.100| 59118.200| 3.900] [BINS(c->s)..: 14,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 7,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,0,0,1,0,0,1,0,1,0,1,0,0,1,0,0,1,1,0,0,1,0,0,1,1,0,1,0] @@ -816,9 +816,9 @@ RISK: Unidirectional Traffic update: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] analyse: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 25.524| 1.927| 6.197| 38401982.071| 2.000] - [PKTLEN......: 52.000| 1076.000| 142.500| 232.300| 53983.100| 4.000] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 25.524| 1.927| 6.197| 38401982.071| 2.000] + [PKTLEN......: 52.000| 1076.000| 142.500| 232.300| 53983.100| 4.000] [BINS(c->s)..: 14,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 8,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,0,0,1,0,1,0,0,1,0,1,1,0,1,0,0,1,0,0,1,1,0,0,1,0,1,1,0] @@ -1105,9 +1105,9 @@ update: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] analyse: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 30.126| 1.349| 5.301| 28102044.418| 1.900] - [PKTLEN......: 52.000| 1076.000| 141.400| 232.500| 54056.900| 4.000] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 30.126| 1.349| 5.301| 28102044.418| 1.900] + [PKTLEN......: 52.000| 1076.000| 141.400| 232.500| 54056.900| 4.000] [BINS(c->s)..: 15,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 7,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,0,0,1,0,1,0,0,1,0,1,1,0,1,0,0,1,0,0,1,0,0,1,1,0,1,0,0] |