diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2025-01-25 09:14:02 +0100 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2025-01-25 10:07:25 +0100 |
commit | 471ea834933dd089b49777d595cef9f612bdb709 (patch) | |
tree | 85a8600d268ede6bc705a3ba1aec109cc959f5b9 /test/results/flow-info/ndpireader_conf_file | |
parent | 064bd3aefa7a4f98b4c3c079e03df37c1b0b5125 (diff) |
bump libnDPI to e946f49aca13e4447a7d7b2acae6323a4531fb55
* incorporated upstream changes
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/ndpireader_conf_file')
3 files changed, 89 insertions, 0 deletions
diff --git a/test/results/flow-info/ndpireader_conf_file/openvpn_obfuscated.pcapng.out b/test/results/flow-info/ndpireader_conf_file/openvpn_obfuscated.pcapng.out new file mode 100644 index 000000000..d7b5b1307 --- /dev/null +++ b/test/results/flow-info/ndpireader_conf_file/openvpn_obfuscated.pcapng.out @@ -0,0 +1,38 @@ + DAEMON-EVENT: init + DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] + new: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465] + analyse: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 1.020| 0.080| 0.242| 58469.183| 2.300] + [PKTLEN......: 52.000| 1500.000| 308.700| 431.500| 186180.000| 4.000] + [BINS(c->s)..: 7,0,1,3,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 7,0,0,4,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0] + [DIRECTIONS..: 0,1,0,0,1,1,0,0,1,1,1,1,0,0,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,1] + [IATS(ms)....: 20.0,22.1,6.2,28.1,0.0,21.2,1.0,26.3,0.0,0.0,0.0,28.0,0.1,0.2,23.6,57.5,41.8,4.8,15.8,16.4,4.9,7.9,24.7,0.5,24.0,23.3,24.7,66.8,1019.8,977.6,0.7] + [PKTLENS.....: 60,60,52,140,52,152,52,429,148,1500,1500,1500,52,52,152,164,52,52,376,873,52,52,801,52,310,172,395,176,52,199,52,148] + [ENTROPIES...: 4.7,5.2,5.1,6.5,5.1,6.6,5.1,7.3,6.6,7.9,7.9,7.9,5.0,5.1,6.5,6.7,5.1,5.1,7.3,7.8,5.1,5.1,7.7,5.2,7.3,6.7,7.5,6.5,5.1,6.9,5.1,6.5] + guessed: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465] [SMTPS][NordVPN][Email][Safe] + RISK: Fully Encrypted Flow + new: [.....2] [ip4][..udp] [.192.168.12.156][47128] -> [149.102.238.108][.1214] + DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 0] + new: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072] + analyse: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.303| 0.045| 0.076| 5806.697| 3.500] + [PKTLEN......: 52.000| 152.000| 67.300| 23.700| 562.800| 4.900] + [BINS(c->s)..: 9,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 19,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [DIRECTIONS..: 0,1,1,1,1,1,1,1,1,1,1,1,0,1,1,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,0] + [IATS(ms)....: 102.1,4.8,6.5,5.5,5.4,5.3,5.7,5.4,5.2,5.6,5.1,255.6,100.3,15.6,143.0,32.7,143.0,0.0,303.0,27.7,1.3,5.4,5.4,5.7,6.7,5.0,142.9,27.8,1.2,5.5,5.5] + [PKTLENS.....: 60,52,61,61,61,61,61,61,61,61,61,59,64,88,58,80,80,52,152,98,52,59,59,59,59,59,59,52,148,52,52,52] + [ENTROPIES...: 5.3,5.2,5.4,5.5,5.4,5.4,5.5,5.4,5.5,5.4,5.2,5.1,5.2,5.9,5.3,5.2,5.1,5.2,6.3,5.7,5.2,5.3,5.3,5.4,5.3,5.4,5.3,5.2,6.4,5.1,5.2,5.3] + guessed: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072] [TLS][Unknown][Web][Safe] + idle: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072] [TLS][Unknown][Web][Safe] + idle: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465] [SMTPS][NordVPN][Email][Safe] + RISK: Fully Encrypted Flow + guessed: [.....2] [ip4][..udp] [.192.168.12.156][47128] -> [149.102.238.108][.1214] [NordVPN][NordVPN][VPN][Acceptable] + RISK: Susp Entropy + idle: [.....2] [ip4][..udp] [.192.168.12.156][47128] -> [149.102.238.108][.1214] + DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/ndpireader_conf_file/signal_videocall.pcapng.out b/test/results/flow-info/ndpireader_conf_file/signal_videocall.pcapng.out new file mode 100644 index 000000000..626c8440d --- /dev/null +++ b/test/results/flow-info/ndpireader_conf_file/signal_videocall.pcapng.out @@ -0,0 +1,33 @@ + DAEMON-EVENT: init + DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] + new: [.....1] [ip4][..udp] [..192.168.12.67][47926] -> [.35.216.234.234][.3478] + detected: [.....1] [ip4][..udp] [..192.168.12.67][47926] -> [.35.216.234.234][.3478] [STUN][GoogleCloud][Network][Acceptable][] + new: [.....2] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][.3478] + detected: [.....2] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][.3478] [STUN][GoogleCloud][Network][Acceptable][] + detection-update: [.....2] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][.3478] [STUN][GoogleCloud][Network][Acceptable][] + RISK: Unidirectional Traffic + detection-update: [.....2] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][.3478] [STUN][GoogleCloud][Network][Acceptable][] + detection-update: [.....2] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][.3478] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + detection-update: [.....1] [ip4][..udp] [..192.168.12.67][47926] -> [.35.216.234.234][.3478] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][] + RISK: Unidirectional Traffic + detection-update: [.....1] [ip4][..udp] [..192.168.12.67][47926] -> [.35.216.234.234][.3478] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][] + detection-update: [.....1] [ip4][..udp] [..192.168.12.67][47926] -> [.35.216.234.234][.3478] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + new: [.....3] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][56377] + detected: [.....3] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][56377] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][] + RISK: Known Proto on Non Std Port + analyse: [.....3] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][56377] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable] + min| max| avg| stddev| variance| entropy + [IAT.........: 0.008| 2.449| 0.473| 0.711| 505100.075| 3.700] + [PKTLEN......: 56.000| 132.000| 102.600| 22.300| 496.600| 5.000] + [BINS(c->s)..: 1,1,6,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 2,1,7,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [DIRECTIONS..: 0,1,0,0,1,1,1,0,1,0,1,0,0,1,1,0,1,1,0,1,0,0,1,0,0,1,1,0,1,0,1,1] + [IATS(ms)....: 66.0,95.9,49.2,89.8,52.0,7.9,75.8,92.2,90.8,45.8,45.9,841.8,964.7,88.1,209.4,700.4,8.8,797.8,169.0,140.8,10.0,132.1,62.7,2295.1,2449.2,43.9,201.2,880.5,2304.8,1490.8,147.9] + [PKTLENS.....: 124,92,132,132,92,92,124,92,124,92,124,92,124,92,124,92,56,84,124,92,84,56,124,92,124,92,124,92,56,124,92,124] + [ENTROPIES...: 6.0,5.9,5.7,5.9,5.7,5.9,6.0,5.8,6.0,5.7,5.9,5.7,5.9,5.8,5.9,5.8,5.2,5.8,5.9,5.8,5.7,5.1,5.9,5.9,5.8,5.8,5.9,5.7,5.1,5.8,5.8,6.0] + idle: [.....3] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][56377] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable] + RISK: Known Proto on Non Std Port + idle: [.....1] [ip4][..udp] [..192.168.12.67][47926] -> [.35.216.234.234][.3478] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + idle: [.....2] [ip4][..udp] [..192.168.12.67][47926] -> [.35.219.252.146][.3478] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/ndpireader_conf_file/stun_signal_tcp.pcapng.out b/test/results/flow-info/ndpireader_conf_file/stun_signal_tcp.pcapng.out new file mode 100644 index 000000000..1f6d126c4 --- /dev/null +++ b/test/results/flow-info/ndpireader_conf_file/stun_signal_tcp.pcapng.out @@ -0,0 +1,18 @@ + DAEMON-EVENT: init + DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] + new: [.....1] [ip4][..tcp] [..192.168.1.117][51296] -> [.35.219.252.146][...80] + detected: [.....1] [ip4][..tcp] [..192.168.1.117][51296] -> [.35.219.252.146][...80] [STUN][GoogleCloud][Network][Acceptable][] + detection-update: [.....1] [ip4][..tcp] [..192.168.1.117][51296] -> [.35.219.252.146][...80] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + analyse: [.....1] [ip4][..tcp] [..192.168.1.117][51296] -> [.35.219.252.146][...80] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + min| max| avg| stddev| variance| entropy + [IAT.........: 0.000| 0.287| 0.030| 0.068| 4621.743| 3.100] + [PKTLEN......: 40.000| 288.000| 111.600| 62.100| 3852.600| 4.800] + [BINS(c->s)..: 6,0,0,7,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 7,2,2,2,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [DIRECTIONS..: 0,1,0,0,1,1,0,1,0,0,0,0,0,1,1,1,0,0,1,0,1,1,0,1,0,1,0,1,1,1,0,0] + [IATS(ms)....: 5.1,5.2,1.3,6.5,7.4,14.7,7.0,5.3,0.2,0.2,0.2,0.2,5.4,2.6,0.0,6.6,276.6,286.8,49.6,44.8,3.7,9.3,19.8,40.1,25.2,48.6,51.2,0.0,2.7,9.9,0.4] + [PKTLENS.....: 52,52,40,68,46,124,156,124,40,160,160,160,160,92,92,144,40,172,46,172,46,288,140,46,172,46,172,148,46,188,40,140] + [ENTROPIES...: 4.7,4.9,4.8,5.2,4.4,5.8,5.9,5.8,4.6,5.7,5.8,5.9,5.9,5.7,5.8,6.1,4.8,6.1,4.8,6.1,4.7,6.4,5.9,4.8,6.0,4.8,6.1,5.9,4.8,5.9,4.8,5.9] + idle: [.....1] [ip4][..tcp] [..192.168.1.117][51296] -> [.35.219.252.146][...80] [STUN.SignalVoip][GoogleCloud][VoIP][Acceptable][signal.org] + DAEMON-EVENT: shutdown |