aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/no_sni.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2022-09-22 19:07:08 +0200
committerToni Uhlig <matzeton@googlemail.com>2022-09-22 19:07:08 +0200
commit9a28475bba88b711b7075b58473b7e5b5df1f393 (patch)
tree73cdf56320f14b5fe0fbfb2e930cf7ea025f9117 /test/results/flow-info/no_sni.pcap.out
parent28971cd7647a79253000fb33e52b5d2129e5ba62 (diff)
Improved flown analyse event:
* store packet directions * merged direction based IATs * merged direction based PKTLENs Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/no_sni.pcap.out')
-rw-r--r--test/results/flow-info/no_sni.pcap.out30
1 files changed, 18 insertions, 12 deletions
diff --git a/test/results/flow-info/no_sni.pcap.out b/test/results/flow-info/no_sni.pcap.out
index 99ca8be0b..8bdf8757e 100644
--- a/test/results/flow-info/no_sni.pcap.out
+++ b/test/results/flow-info/no_sni.pcap.out
@@ -8,21 +8,25 @@
detection-update: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Network][Fun]
new: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443]
analyse: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Network][Fun]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.180| 0.028| 0.054]
- [IAT(c->s)...: 0.000| 0.178| 0.027| 0.053][IAT(s->c)...: 0.000| 0.180| 0.029| 0.055]
- [PKTLEN(c->s): 54.000| 670.000| 131.600| 144.900][PKTLEN(s->c): 60.000| 736.000| 152.000| 182.300]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.180| 0.028| 0.054| 2913.211| 0.000]
+ [PKTLEN......: 54.000| 736.000| 141.200| 163.800|26828.900| 4.400]
[BINS(c->s)..: 10,1,3,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 11,1,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,0,0,1,1,0,1,1,0,0,1,1,0,0,0,0,0,0,1,1,1,1,1,0,0,1,1,1,0]
+ [IATS........: 137944,138022,4673,280,93,180261,3035,178242,156,4,141,2334,6395,1417,5511,15440,136,687,115,1388,73966,13479,4177,2946,6,76790,62,5422,2521,12,7950,0]
+ [PKTLENS.....: 78,66,54,670,60,224,60,736,54,116,60,54,138,60,85,54,205,140,114,146,85,60,60,60,380,85,54,54,60,307,85,54]
detected: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS.Cloudflare][Web][Acceptable]
detection-update: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS.Cloudflare][Web][Acceptable]
analyse: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS.Cloudflare][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.473| 0.050| 0.107]
- [IAT(c->s)...: 0.000| 0.473| 0.052| 0.119][IAT(s->c)...: 0.000| 0.380| 0.049| 0.095]
- [PKTLEN(c->s): 54.000|1001.000| 185.200| 295.900][PKTLEN(s->c): 60.000|1514.000| 576.800| 561.000]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.473| 0.050| 0.107|11455.737| 0.000]
+ [PKTLEN......: 54.000| 1514.000| 381.000| 489.400|239474.400| 4.000]
[BINS(c->s)..: 12,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,2,0,1,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,0,0,0,0,1,1,0,1,1,0,0,1,1,1,0,1,0,1,0,1,0,1,1,0,1,0]
+ [IATS........: 121173,121273,5431,100429,365,95332,957,4750,120,77068,533,71774,182,427,594,188,76917,15494,380381,472643,2763,2757,2091,2075,1637,1645,1367,284,1629,603,593,0]
+ [PKTLENS.....: 78,66,54,1001,60,286,54,118,224,917,60,566,54,60,85,54,85,60,60,1092,54,844,54,1445,54,1445,54,1514,407,54,1178,54]
new: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443]
new: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443]
new: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443]
@@ -39,12 +43,14 @@
detection-update: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443] [TLS.Cloudflare][Web][Acceptable]
detection-update: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443] [TLS.Cloudflare][Web][Acceptable]
analyse: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS.Cloudflare][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.144| 0.032| 0.043]
- [IAT(c->s)...: 0.000| 0.126| 0.029| 0.037][IAT(s->c)...: 0.000| 0.144| 0.035| 0.049]
- [PKTLEN(c->s): 54.000| 766.000| 136.700| 172.600][PKTLEN(s->c): 60.000|1514.000| 476.300| 529.000]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.144| 0.032| 0.043| 1852.691| 0.000]
+ [PKTLEN......: 54.000| 1514.000| 285.300| 409.400|167573.600| 4.000]
[BINS(c->s)..: 12,0,3,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,1,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,0,0,0,0,1,0,1,1,0,0,1,1,0,1,1,0,0,1,0,1,0,1,0]
+ [IATS........: 81926,82025,5271,129371,1703,673,126443,63976,9103,148,11896,1581,143742,57056,79239,1596,80830,1627,14677,255,13311,11856,23,12136,91,25357,25014,814,775,5252,5500,0]
+ [PKTLENS.....: 78,66,54,766,60,1514,1385,54,118,224,380,129,129,1385,66,60,566,54,85,60,85,54,581,85,54,54,368,54,85,54,368,54]
idle: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS.Cloudflare][Web][Acceptable]
end: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443]
end: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443]