aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2024-11-11 16:19:07 +0100
committerToni Uhlig <matzeton@googlemail.com>2024-11-13 17:23:31 +0100
commit9efdecf4efa352a6046c88a945cf9ff8db1b37b9 (patch)
tree43c6ba4a106f47420a4f5dc1ddfe393400c5dbda /test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out
parent8c114e49168eb38a8598b5b342c7144a07323320 (diff)
bump libnDPI to 59ee1fe1156be234fed796972a29a31a0589e25a
* set minimum nDPI version to 4.12.0 (incompatible API changes) * fixed `ndpi_debug_printf()` function signature * JSON schema (flow): added risk `56`: "Obfuscated Traffic" * JSON schema (flow): added "domainame" * fixed OpenWrt build Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out')
-rw-r--r--test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out62
1 files changed, 62 insertions, 0 deletions
diff --git a/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out b/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out
new file mode 100644
index 000000000..8bc342628
--- /dev/null
+++ b/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out
@@ -0,0 +1,62 @@
+ DAEMON-EVENT: init
+ DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
+ DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
+ new: [.....1] [ip4][..tcp] [......127.0.0.1][60654] -> [......127.0.0.1][.1080]
+ detected: [.....1] [ip4][..tcp] [......127.0.0.1][60654] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable]
+ new: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53]
+ detected: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ detection-update: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ RISK: Unidirectional Traffic
+ new: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53]
+ detected: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ new: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53]
+ detected: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ detection-update: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ detection-update: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ detection-update: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ new: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53]
+ detected: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ new: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53]
+ detected: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ new: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53]
+ detected: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ new: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53]
+ detected: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ detection-update: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ RISK: Minor Issues
+ detection-update: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ RISK: Minor Issues
+ detection-update: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ detection-update: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ new: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234]
+ detected: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] [TLS][Unknown][Web][Safe][test.lan]
+ RISK: Known Proto on Non Std Port
+ detection-update: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] [TLS][Unknown][Web][Safe][test.lan]
+ RISK: Known Proto on Non Std Port
+ new: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443]
+ detected: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com]
+ detection-update: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com]
+ analyse: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: < 0.001| 0.070| 0.007| 0.015| 238.385| 3.000]
+ [PKTLEN......: 52.000| 1452.000| 481.500| 599.800| 359742.800| 3.900]
+ [BINS(c->s)..: 14,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [BINS(s->c)..: 5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,0,1,0,1,0,0,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0]
+ [IATS(ms)....: 2.7,2.7,0.3,2.7,17.2,19.6,0.1,0.0,0.0,0.0,0.0,0.0,0.0,0.0,8.4,0.5,11.2,3.0,2.3,5.7,46.1,70.4,31.7,0.1,0.0,0.0,0.0,0.0,0.1,0.1,0.0]
+ [PKTLENS.....: 60,60,52,569,52,1452,52,1452,52,1452,52,1452,52,1053,52,132,245,700,83,83,52,52,1452,52,80,52,1452,52,1452,52,1452,52]
+ [ENTROPIES...: 4.6,5.2,4.9,4.8,4.9,7.8,4.8,7.8,4.9,7.9,4.8,7.9,4.8,7.8,4.8,6.2,7.0,7.7,5.6,5.5,4.9,4.9,7.9,4.9,5.6,4.9,7.9,4.9,7.9,4.9,7.9,4.8]
+ idle: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ idle: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ RISK: Minor Issues
+ idle: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] [TLS][Unknown][Web][Safe]
+ RISK: Known Proto on Non Std Port
+ idle: [.....1] [ip4][..tcp] [......127.0.0.1][60654] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable]
+ idle: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com]
+ idle: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ RISK: Minor Issues
+ idle: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ idle: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan]
+ idle: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ idle: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com]
+ DAEMON-EVENT: shutdown