summaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/windowsupdate_over_http.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2023-05-23 04:38:07 +0200
committerToni Uhlig <matzeton@googlemail.com>2023-05-24 19:30:19 +0200
commitc9514136b7c4246a57b85474d1a8e376a9009d4a (patch)
treeeb17d83ea16815000a4f723c240e54f21cf0691b /test/results/flow-info/default/windowsupdate_over_http.pcap.out
parenta4e5bab9b2826ae50a48da275b6b441624aab50f (diff)
bump libnDPI to ...
* upstream changed regression test interface, needed to adapt * improved libnDPI helper build script * updated JSON schema Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/default/windowsupdate_over_http.pcap.out')
-rw-r--r--test/results/flow-info/default/windowsupdate_over_http.pcap.out9
1 files changed, 9 insertions, 0 deletions
diff --git a/test/results/flow-info/default/windowsupdate_over_http.pcap.out b/test/results/flow-info/default/windowsupdate_over_http.pcap.out
new file mode 100644
index 000000000..a43f16ba4
--- /dev/null
+++ b/test/results/flow-info/default/windowsupdate_over_http.pcap.out
@@ -0,0 +1,9 @@
+ DAEMON-EVENT: init
+ new: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80]
+ detected: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][SoftwareUpdate][Safe][151.99.72.125]
+ RISK: HTTP/TLS/QUIC Numeric Hostname/SNI
+ detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][Download][Safe][151.99.72.125]
+ RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI
+ idle: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][Download][Safe]
+ RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI
+ DAEMON-EVENT: shutdown