diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2024-11-11 16:19:07 +0100 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2024-11-13 17:23:31 +0100 |
commit | 9efdecf4efa352a6046c88a945cf9ff8db1b37b9 (patch) | |
tree | 43c6ba4a106f47420a4f5dc1ddfe393400c5dbda /test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out | |
parent | 8c114e49168eb38a8598b5b342c7144a07323320 (diff) |
bump libnDPI to 59ee1fe1156be234fed796972a29a31a0589e25a
* set minimum nDPI version to 4.12.0 (incompatible API changes)
* fixed `ndpi_debug_printf()` function signature
* JSON schema (flow): added risk `56`: "Obfuscated Traffic"
* JSON schema (flow): added "domainame"
* fixed OpenWrt build
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out')
-rw-r--r-- | test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out | 62 |
1 files changed, 62 insertions, 0 deletions
diff --git a/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out b/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out new file mode 100644 index 000000000..8bc342628 --- /dev/null +++ b/test/results/flow-info/default/tls_heur__trojan-tcp-tls.pcapng.out @@ -0,0 +1,62 @@ + DAEMON-EVENT: init + DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] + new: [.....1] [ip4][..tcp] [......127.0.0.1][60654] -> [......127.0.0.1][.1080] + detected: [.....1] [ip4][..tcp] [......127.0.0.1][60654] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable] + new: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] + detected: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + detection-update: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + RISK: Unidirectional Traffic + new: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] + detected: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + new: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] + detected: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + detection-update: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + detection-update: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + detection-update: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + new: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] + detected: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan] + new: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] + detected: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan] + new: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] + detected: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan] + new: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] + detected: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan] + detection-update: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan] + RISK: Minor Issues + detection-update: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan] + RISK: Minor Issues + detection-update: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan] + detection-update: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan] + new: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] + detected: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] [TLS][Unknown][Web][Safe][test.lan] + RISK: Known Proto on Non Std Port + detection-update: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] [TLS][Unknown][Web][Safe][test.lan] + RISK: Known Proto on Non Std Port + new: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] + detected: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] + detection-update: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] + analyse: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.070| 0.007| 0.015| 238.385| 3.000] + [PKTLEN......: 52.000| 1452.000| 481.500| 599.800| 359742.800| 3.900] + [BINS(c->s)..: 14,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0] + [DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,0,1,0,1,0,0,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0] + [IATS(ms)....: 2.7,2.7,0.3,2.7,17.2,19.6,0.1,0.0,0.0,0.0,0.0,0.0,0.0,0.0,8.4,0.5,11.2,3.0,2.3,5.7,46.1,70.4,31.7,0.1,0.0,0.0,0.0,0.0,0.1,0.1,0.0] + [PKTLENS.....: 60,60,52,569,52,1452,52,1452,52,1452,52,1452,52,1053,52,132,245,700,83,83,52,52,1452,52,80,52,1452,52,1452,52,1452,52] + [ENTROPIES...: 4.6,5.2,4.9,4.8,4.9,7.8,4.8,7.8,4.9,7.9,4.8,7.9,4.8,7.8,4.8,6.2,7.0,7.7,5.6,5.5,4.9,4.9,7.9,4.9,5.6,4.9,7.9,4.9,7.9,4.9,7.9,4.8] + idle: [.....8] [ip4][..udp] [..192.168.1.183][38613] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan] + idle: [.....5] [ip4][..udp] [......127.0.0.1][53154] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan] + RISK: Minor Issues + idle: [.....9] [ip4][..tcp] [......127.0.0.1][41796] -> [......127.0.0.1][.1234] [TLS][Unknown][Web][Safe] + RISK: Known Proto on Non Std Port + idle: [.....1] [ip4][..tcp] [......127.0.0.1][60654] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable] + idle: [....10] [ip4][..tcp] [..192.168.1.183][58730] -> [142.250.180.142][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] + idle: [.....7] [ip4][..udp] [..192.168.1.183][39434] -> [..192.168.1.253][...53] [DNS][Unknown][Network][Acceptable][test.lan] + RISK: Minor Issues + idle: [.....4] [ip4][..udp] [..192.168.1.183][54260] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + idle: [.....6] [ip4][..udp] [......127.0.0.1][56496] -> [.....127.0.0.53][...53] [DNS][Unknown][Network][Acceptable][test.lan] + idle: [.....3] [ip4][..udp] [..192.168.1.183][46451] -> [..192.168.1.253][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + idle: [.....2] [ip4][..udp] [......127.0.0.1][52786] -> [.....127.0.0.53][...53] [DNS.YouTube][Unknown][Network][Fun][www.youtube.com] + DAEMON-EVENT: shutdown |