diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2024-11-11 16:19:07 +0100 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2024-11-13 17:23:31 +0100 |
commit | 9efdecf4efa352a6046c88a945cf9ff8db1b37b9 (patch) | |
tree | 43c6ba4a106f47420a4f5dc1ddfe393400c5dbda /test/results/flow-info/default/tls_heur__shadowsocks-tcp.pcapng.out | |
parent | 8c114e49168eb38a8598b5b342c7144a07323320 (diff) |
bump libnDPI to 59ee1fe1156be234fed796972a29a31a0589e25a
* set minimum nDPI version to 4.12.0 (incompatible API changes)
* fixed `ndpi_debug_printf()` function signature
* JSON schema (flow): added risk `56`: "Obfuscated Traffic"
* JSON schema (flow): added "domainame"
* fixed OpenWrt build
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/default/tls_heur__shadowsocks-tcp.pcapng.out')
-rw-r--r-- | test/results/flow-info/default/tls_heur__shadowsocks-tcp.pcapng.out | 31 |
1 files changed, 31 insertions, 0 deletions
diff --git a/test/results/flow-info/default/tls_heur__shadowsocks-tcp.pcapng.out b/test/results/flow-info/default/tls_heur__shadowsocks-tcp.pcapng.out new file mode 100644 index 000000000..e70a46b38 --- /dev/null +++ b/test/results/flow-info/default/tls_heur__shadowsocks-tcp.pcapng.out @@ -0,0 +1,31 @@ + DAEMON-EVENT: init + DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] + new: [.....1] [ip4][..tcp] [......127.0.0.1][44424] -> [......127.0.0.1][.1080] + detected: [.....1] [ip4][..tcp] [......127.0.0.1][44424] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable] + new: [.....2] [ip4][..udp] [......127.0.0.1][41182] -> [.....127.0.0.53][...53] + detected: [.....2] [ip4][..udp] [......127.0.0.1][41182] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + detection-update: [.....2] [ip4][..udp] [......127.0.0.1][41182] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + RISK: Unidirectional Traffic + detection-update: [.....2] [ip4][..udp] [......127.0.0.1][41182] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + new: [.....3] [ip4][..tcp] [......127.0.0.1][40164] -> [......127.0.0.1][.1234] + new: [.....4] [ip6][..tcp] [..2001:b07:a3d:c112:8628:88aa:8b00:913c][45334] -> [...............2a00:1450:4002:416::200e][..443] + detected: [.....4] [ip6][..tcp] [..2001:b07:a3d:c112:8628:88aa:8b00:913c][45334] -> [...............2a00:1450:4002:416::200e][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] + detection-update: [.....4] [ip6][..tcp] [..2001:b07:a3d:c112:8628:88aa:8b00:913c][45334] -> [...............2a00:1450:4002:416::200e][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] + analyse: [.....4] [ip6][..tcp] [..2001:b07:a3d:c112:8628:88aa:8b00:913c][45334] -> [...............2a00:1450:4002:416::200e][..443] [TLS.YouTube][Google][Media][Fun] + min| max| avg| stddev| variance| entropy + [IAT.........: 0.000| 0.050| 0.008| 0.014| 183.336| 3.300] + [PKTLEN......: 72.000| 4948.000| 786.900| 1186.200| 1407143.500| 3.900] + [BINS(c->s)..: 13,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 3,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0,0,2] + [DIRECTIONS..: 0,1,0,0,1,1,0,1,1,0,0,0,1,0,1,0,1,1,1,0,0,0,1,1,1,1,0,0,1,0,1,1] + [IATS(ms)....: 3.4,3.5,0.3,3.9,24.5,28.1,0.2,0.0,0.2,0.0,3.0,7.5,5.3,6.5,46.4,49.6,0.0,0.0,9.0,0.1,0.0,0.4,0.0,0.0,0.0,0.3,0.0,26.1,26.1,0.4,0.0] + [PKTLENS.....: 80,80,72,589,72,1280,72,4904,631,72,72,345,720,103,103,72,1280,293,1280,72,72,72,1280,1280,1280,4948,72,72,1280,72,1280,1280] + [ENTROPIES...: 4.8,5.3,5.2,4.8,5.2,7.8,5.2,8.0,7.6,5.2,5.2,7.1,7.7,5.8,5.8,5.1,7.8,7.1,7.9,5.2,5.2,5.2,7.8,7.9,7.8,8.0,5.1,5.2,7.9,5.2,7.8,7.8] + idle: [.....2] [ip4][..udp] [......127.0.0.1][41182] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + not-detected: [.....3] [ip4][..tcp] [......127.0.0.1][40164] -> [......127.0.0.1][.1234] [Unknown][Unknown][Unrated] + RISK: Fully Encrypted Flow + idle: [.....3] [ip4][..tcp] [......127.0.0.1][40164] -> [......127.0.0.1][.1234] + idle: [.....1] [ip4][..tcp] [......127.0.0.1][44424] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable] + idle: [.....4] [ip6][..tcp] [..2001:b07:a3d:c112:8628:88aa:8b00:913c][45334] -> [...............2a00:1450:4002:416::200e][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] + DAEMON-EVENT: shutdown |