aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/pinterest.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2022-09-22 19:07:08 +0200
committerToni Uhlig <matzeton@googlemail.com>2022-09-22 19:07:08 +0200
commit9a28475bba88b711b7075b58473b7e5b5df1f393 (patch)
tree73cdf56320f14b5fe0fbfb2e930cf7ea025f9117 /test/results/flow-info/pinterest.pcap.out
parent28971cd7647a79253000fb33e52b5d2129e5ba62 (diff)
Improved flown analyse event:
* store packet directions * merged direction based IATs * merged direction based PKTLENs Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/pinterest.pcap.out')
-rw-r--r--test/results/flow-info/pinterest.pcap.out160
1 files changed, 96 insertions, 64 deletions
diff --git a/test/results/flow-info/pinterest.pcap.out b/test/results/flow-info/pinterest.pcap.out
index edea36e82..0289760ca 100644
--- a/test/results/flow-info/pinterest.pcap.out
+++ b/test/results/flow-info/pinterest.pcap.out
@@ -8,12 +8,14 @@
detection-update: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
detection-update: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
analyse: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.172| 0.014| 0.033]
- [IAT(c->s)...: 0.000| 0.041| 0.007| 0.013][IAT(s->c)...: 0.000| 0.172| 0.020| 0.042]
- [PKTLEN(c->s): 86.000| 603.000| 160.700| 149.900][PKTLEN(s->c): 86.000|1134.000| 569.900| 485.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.172| 0.014| 0.033| 1083.758| 0.000]
+ [PKTLEN......: 86.000| 1134.000| 378.100| 421.400|177613.600| 4.200]
[BINS(c->s)..: 10,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,2,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,1,1,1,0,0,0,0,0,0,1,1,1,0,1,1,0,0,1,1,1,1]
+ [IATS........: 17629,17683,505,39969,1745,1,2,41182,41,13,234,2,175,23,26,7012,281,424,41621,1,1,33877,492,1,473,243,41960,172415,2,1,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1134,1134,1134,86,86,86,1134,1134,168,86,86,86,179,185,451,86,86,344,86,152,86,86,124,86,1134,1134,563]
detection-update: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443]
new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38514] -> [.......................2a04:4e42:1d::84][..443]
@@ -43,12 +45,14 @@
new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58726] -> [...............2a00:1450:4007:80b::2002][..443] [MIDSTREAM]
new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][34626] -> [.....................64:ff9b::acd9:13e2][..443] [MIDSTREAM]
analyse: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][SocialNetwork][Fun]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.054| 0.008| 0.015]
- [IAT(c->s)...: 0.000| 0.044| 0.007| 0.013][IAT(s->c)...: 0.000| 0.054| 0.009| 0.017]
- [PKTLEN(c->s): 86.000|1040.000| 244.100| 244.000][PKTLEN(s->c): 86.000|1474.000| 589.000| 631.100]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.054| 0.008| 0.015| 223.156| 0.000]
+ [PKTLEN......: 86.000| 1474.000| 395.000| 486.900|237029.200| 4.100]
[BINS(c->s)..: 9,1,1,1,0,0,0,0,2,2,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,4,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,1,0,0,0,0,0,0,0,0,0,0,0,1,1,1,1,0,1,1,1,0,0,1,0]
+ [IATS........: 29210,29304,461,30605,2146,1,1,1,32223,44,9,7,7205,255,2012,156,139,311,354,53871,1,222,1,43618,1326,1,1343,231,798,527,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1474,1474,1474,1244,86,86,86,86,179,185,377,397,364,1040,342,86,86,86,344,86,152,86,86,86,124,1474,86]
new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443]
detected: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] [TLS][Web][Safe]
new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443]
@@ -58,40 +62,48 @@
detection-update: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] [TLS.Google][Web][Acceptable]
detected: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
analyse: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] [TLS.Google][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.044| 0.009| 0.014]
- [IAT(c->s)...: 0.000| 0.044| 0.008| 0.014][IAT(s->c)...: 0.000| 0.039| 0.011| 0.014]
- [PKTLEN(c->s): 86.000| 603.000| 149.200| 137.000][PKTLEN(s->c): 86.000|1294.000| 396.200| 419.000]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.044| 0.009| 0.014| 199.945| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 265.000| 327.800|107441.100| 4.200]
[BINS(c->s)..: 12,1,2,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,1,0,0,0,0,2,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,1,0,0,0,0,1,1,1,1,0,0,1,0,1,1,1,0,0,0,1,0,0,1]
+ [IATS........: 26021,26034,177,34476,9474,43788,3,51,24,2375,110,130,39176,1,238,310,37117,263,3095,2873,7183,1,7144,49,3,681,625,589,26257,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,86,86,303,86,150,178,409,86,86,86,666,86,117,117,86,507,832,281,86,86,86,125,86,125,86]
detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443]
analyse: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] [TLS][Web][Safe]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.133| 0.017| 0.031]
- [IAT(c->s)...: 0.000| 0.133| 0.014| 0.032][IAT(s->c)...: 0.000| 0.094| 0.021| 0.027]
- [PKTLEN(c->s): 86.000| 603.000| 185.200| 170.400][PKTLEN(s->c): 86.000|1294.000| 501.000| 523.700]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.133| 0.017| 0.031| 941.058| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 323.400| 401.100|160869.700| 4.200]
[BINS(c->s)..: 11,1,2,0,1,0,0,0,0,0,0,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,0,0,0,0]
+ [IATS........: 23500,23520,222,32278,1902,1,33966,35,25,324,242,8,1731,75,102,35078,5741,3731,1,42641,14,135,39228,93613,132689,1225,118,74,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,1294,86,86,86,1294,187,86,86,150,178,465,86,86,666,117,86,86,86,117,86,344,86,125,243,585]
detected: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] [TLS][Web][Safe]
detection-update: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] [TLS][Web][Safe]
detection-update: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] [TLS][Media][Safe]
analyse: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.090| 0.016| 0.023]
- [IAT(c->s)...: 0.000| 0.090| 0.014| 0.025][IAT(s->c)...: 0.000| 0.050| 0.018| 0.020]
- [PKTLEN(c->s): 86.000| 603.000| 151.700| 138.300][PKTLEN(s->c): 86.000|1134.000| 478.000| 456.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.090| 0.016| 0.023| 544.707| 0.000]
+ [PKTLEN......: 86.000| 1134.000| 314.800| 374.800|140490.000| 4.200]
[BINS(c->s)..: 11,1,1,1,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,2,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,1,1,0,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,1,0]
+ [IATS........: 39835,39893,388,39880,1850,1,41296,35,60,18,4,565,563,29,2922,2605,564,39805,119,1086,1924,36819,15,203,49740,40102,89623,0,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1134,1134,86,86,1134,1134,86,86,1134,168,86,86,179,185,382,86,86,86,344,152,86,86,124,86,530,260,86]
detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][SocialNetwork][Fun]
analyse: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.050| 0.009| 0.016]
- [IAT(c->s)...: 0.000| 0.050| 0.008| 0.016][IAT(s->c)...: 0.000| 0.050| 0.011| 0.017]
- [PKTLEN(c->s): 86.000| 603.000| 153.800| 147.400][PKTLEN(s->c): 86.000|1474.000| 871.600| 656.400]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.050| 0.009| 0.016| 268.348| 0.000]
+ [PKTLEN......: 86.000| 1474.000| 512.700| 595.900|355070.700| 4.100]
[BINS(c->s)..: 12,0,1,1,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,8,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,1,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,1,1,1,0,0,0,1]
+ [IATS........: 50290,50337,220,31719,3102,34561,13,675,659,1179,1,1182,11,2643,116,155,32346,1,29460,6,548,1,514,15,6,589,0,0,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1474,1474,86,86,1474,86,1474,1219,86,86,179,185,454,86,86,86,344,152,86,86,1474,1474,1474,86,86,86,1474]
detection-update: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] [TLS][Media][Safe]
new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443]
detected: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] [TLS.Google][Web][Acceptable]
@@ -103,26 +115,32 @@
detection-update: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] [TLS.Google][Web][Acceptable]
detection-update: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51292] -> [.........2a03:2880:f030:13:face:b00c::3][..443] [TLS.Facebook][SocialNetwork][Fun]
analyse: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] [TLS.Google][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.077| 0.017| 0.027]
- [IAT(c->s)...: 0.000| 0.077| 0.013| 0.027][IAT(s->c)...: 0.000| 0.077| 0.022| 0.027]
- [PKTLEN(c->s): 86.000| 603.000| 148.200| 140.700][PKTLEN(s->c): 86.000|1294.000| 694.900| 550.600]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.077| 0.017| 0.027| 751.406| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 421.600| 486.000|236213.000| 4.200]
[BINS(c->s)..: 12,0,2,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0]
+ [IATS........: 76818,76867,1845,47286,29961,75361,6,2,2110,577,1618,47934,88,1,1,1,1,43713,12,4,2,3,3,4,0,0,0,0,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,356,86,86,86,150,178,400,86,86,86,666,117,484,1294,1294,1294,1294,1294,86,86,86,86,86,86,86]
analyse: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] [TLS.Google][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.079| 0.014| 0.022]
- [IAT(c->s)...: 0.000| 0.079| 0.014| 0.024][IAT(s->c)...: 0.000| 0.070| 0.014| 0.021]
- [PKTLEN(c->s): 86.000| 603.000| 146.800| 134.600][PKTLEN(s->c): 86.000|1294.000| 725.400| 553.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.079| 0.014| 0.022| 503.587| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 436.100| 496.100|246097.600| 4.200]
[BINS(c->s)..: 12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,0,0,1,0,1,1,1,1,0,0,0,0,1,1]
+ [IATS........: 51607,51735,639,27991,20462,1,47699,14,8,3349,184,136,69956,1,28,13172,79486,329,8681,8388,16746,3,2,2,16717,40,14,21,164,2,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,326,86,86,86,150,178,347,86,86,86,666,86,117,117,86,1002,1294,1294,1294,86,86,86,86,1294,1294]
analyse: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51292] -> [.........2a03:2880:f030:13:face:b00c::3][..443] [TLS.Facebook][SocialNetwork][Fun]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.093| 0.012| 0.022]
- [IAT(c->s)...: 0.000| 0.065| 0.012| 0.019][IAT(s->c)...: 0.000| 0.093| 0.012| 0.026]
- [PKTLEN(c->s): 86.000| 603.000| 161.300| 135.000][PKTLEN(s->c): 86.000|1466.000| 444.000| 491.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.093| 0.012| 0.022| 484.499| 0.000]
+ [PKTLEN......: 86.000| 1466.000| 285.000| 368.400|135732.300| 4.200]
[BINS(c->s)..: 12,0,2,1,0,0,0,0,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,2,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,1,0,0,0,0,1,1,1,0,0,0,0,0]
+ [IATS........: 26987,27077,236,32338,1,32042,17,3873,399,116,64739,93180,2,1,290,2,3,2,24343,46,12,9,157,3,2,82,23,41,4388,39879,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1466,993,86,86,150,178,344,344,86,86,86,265,166,130,667,86,86,86,86,497,1466,128,86,86,86,117,213]
new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443]
detected: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] [TLS.Facebook][SocialNetwork][Fun]
new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443]
@@ -132,36 +150,44 @@
new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [MIDSTREAM]
detected: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [TLS][Web][Safe]
analyse: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [TLS][Web][Safe]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.029| 0.002| 0.007]
- [IAT(c->s)...: 0.000| 0.029| 0.004| 0.009][IAT(s->c)...: 0.000| 0.023| 0.002| 0.006]
- [PKTLEN(c->s): 86.000| 244.000| 117.200| 59.000][PKTLEN(s->c): 86.000|1294.000|1001.600| 493.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.029| 0.002| 0.007| 49.867| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 752.800| 578.200|334348.700| 4.500]
[BINS(c->s)..: 7,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 2,1,0,1,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,0,1,1,1,1,0,1,1,1,1,0,0,1,1,0,1,1,1,1,0,0,1,1,1,1,1,0,1,1,1,1]
+ [IATS........: 202,23469,160,5107,2,28590,251,1,1,2,214,4,31,19,391,1,1,397,8,1304,1,1316,72,1,1,0,0,0,0,0,0,0]
+ [PKTLENS.....: 244,209,86,86,277,1294,86,1294,1294,1294,1294,86,86,1294,1294,86,1294,1294,1294,1294,86,86,1294,1294,251,125,213,86,1294,1294,1294,1294]
new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443]
detected: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] [TLS.Google][Web][Acceptable]
detection-update: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] [TLS.Google][Web][Acceptable]
analyse: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] [TLS.GoogleServices][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 1.486| 0.068| 0.273]
- [IAT(c->s)...: 0.000| 1.486| 0.105| 0.357][IAT(s->c)...: 0.000| 0.055| 0.019| 0.019]
- [PKTLEN(c->s): 86.000| 603.000| 161.800| 143.600][PKTLEN(s->c): 86.000|1294.000| 354.500| 415.000]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 1.486| 0.068| 0.273|74793.992| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 252.100| 317.700|100919.600| 4.200]
[BINS(c->s)..: 11,1,2,0,0,1,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 8,2,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,1,0,0,0,0,1,1,1,1,0,0,1,0,1,1,0,0,1,1,0,0,1,0]
+ [IATS........: 55481,55557,2604,45080,17803,15,60231,16,286,275,9398,2484,606,42880,228,1,30633,193,14864,14650,23014,23014,8,85,70,1606,29384,1485939,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,86,86,587,86,150,178,458,86,86,86,666,86,117,117,86,476,149,86,86,125,86,86,125,86,251]
analyse: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] [TLS.Google][Web][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.043| 0.009| 0.013]
- [IAT(c->s)...: 0.000| 0.040| 0.009| 0.013][IAT(s->c)...: 0.000| 0.043| 0.010| 0.013]
- [PKTLEN(c->s): 86.000| 603.000| 146.400| 134.000][PKTLEN(s->c): 86.000|1294.000| 719.100| 550.500]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.043| 0.009| 0.013| 174.232| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 432.800| 492.400|242485.900| 4.200]
[BINS(c->s)..: 12,0,2,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,0,0,1,0,1,1,0,0,1,1,1,1,0,0]
+ [IATS........: 23434,23612,605,27825,5261,2,32335,48,7,3191,171,159,42968,880,1,157,40413,894,3393,2534,21369,1,21337,22,7799,1,1,7829,32,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,336,86,86,86,150,178,341,86,86,86,666,86,117,117,86,890,1294,86,86,1294,1294,1294,1294,86,86]
analyse: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] [TLS.Facebook][SocialNetwork][Fun]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 1.522| 0.133| 0.377]
- [IAT(c->s)...: 0.000| 1.490| 0.127| 0.367][IAT(s->c)...: 0.000| 1.522| 0.141| 0.386]
- [PKTLEN(c->s): 86.000| 632.000| 187.800| 185.400][PKTLEN(s->c): 86.000|1466.000| 359.100| 464.100]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 1.522| 0.133| 0.377|141791.068| 0.000]
+ [PKTLEN......: 86.000| 1466.000| 273.400| 363.600|132225.800| 4.100]
[BINS(c->s)..: 11,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 8,2,1,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,0,1,1,0,0,1,1,0,1]
+ [IATS........: 51050,51117,702,184290,1,183671,66,7538,8559,3870,48706,3,10603,1,1,39192,55,6,1700,5826,4025,34675,42375,77042,1489773,1522186,1,32460,71970,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1466,994,86,86,150,178,456,86,86,86,257,166,117,86,86,86,117,121,86,86,506,86,632,86,121,86,1388]
new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56940] -> [......................2a04:4e42:1d::720][..443] [MIDSTREAM]
new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51472] -> [...............2a00:1450:4007:816::2003][..443] [MIDSTREAM]
new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54308] -> [...............2a00:1450:4007:806::200e][..443] [MIDSTREAM]
@@ -181,31 +207,37 @@
detection-update: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][SocialNetwork][Fun]
detection-update: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45126] -> [...............2a00:1450:4007:80a::200e][..443] [TLS.Google][Advertisement][Acceptable]
analyse: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45126] -> [...............2a00:1450:4007:80a::200e][..443] [TLS.Google][Advertisement][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.157| 0.019| 0.038]
- [IAT(c->s)...: 0.000| 0.157| 0.015| 0.039][IAT(s->c)...: 0.000| 0.112| 0.024| 0.035]
- [PKTLEN(c->s): 86.000| 603.000| 143.500| 131.700][PKTLEN(s->c): 86.000|1294.000| 748.300| 539.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.157| 0.019| 0.038| 1426.179| 0.000]
+ [PKTLEN......: 86.000| 1294.000| 427.000| 486.700|236885.800| 4.200]
[BINS(c->s)..: 13,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,1,1,1,0,0,0,0]
+ [IATS........: 46894,46909,201,112030,45428,2,157269,9,5,2935,270,2964,37660,1,1100,1,32562,12,3,631,955,1,308,7,3,3,0,0,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1294,1294,563,86,86,86,150,178,351,86,86,86,666,500,1294,86,86,86,117,1294,1294,1294,1294,86,86,86,86]
analyse: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.136| 0.027| 0.042]
- [IAT(c->s)...: 0.000| 0.111| 0.023| 0.039][IAT(s->c)...: 0.000| 0.136| 0.032| 0.045]
- [PKTLEN(c->s): 86.000| 603.000| 163.300| 138.400][PKTLEN(s->c): 86.000|1474.000| 692.800| 639.800]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.136| 0.027| 0.042| 1750.865| 0.000]
+ [PKTLEN......: 86.000| 1474.000| 444.600| 544.300|296293.800| 4.100]
[BINS(c->s)..: 9,1,1,1,1,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 7,0,1,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,6,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,1,1,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,0,1,1,1,1]
+ [IATS........: 46509,46553,392,49783,3591,52945,10,1267,1,1272,3,2358,266,496,109019,1,1,105909,5,6,6499,35807,111148,135965,1,2,0,0,0,0,0,0]
+ [PKTLENS.....: 94,94,86,603,86,1474,1474,86,86,1474,1244,86,86,179,185,352,86,86,344,152,86,584,86,86,86,124,86,224,86,1474,1474,1474]
detection-update: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][SocialNetwork][Fun]
new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443]
detected: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS][Web][Safe]
detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS][Web][Safe]
detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS][Media][Safe]
analyse: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 0.045| 0.007| 0.012]
- [IAT(c->s)...: 0.000| 0.045| 0.007| 0.013][IAT(s->c)...: 0.000| 0.037| 0.007| 0.012]
- [PKTLEN(c->s): 86.000| 603.000| 150.100| 135.700][PKTLEN(s->c): 86.000|1134.000| 633.300| 504.100]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 0.045| 0.007| 0.012| 147.627| 0.000]
+ [PKTLEN......: 86.000| 1134.000| 391.700| 441.200|194656.500| 4.200]
[BINS(c->s)..: 11,1,1,1,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,1,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,1,1,0,0,1,1,1,1,0,0,0,0,1,0,0,0,0,1,1,1,1,0,0,0,1,1,1]
+ [IATS........: 20965,21014,506,37100,8905,1,45476,39,2004,2,1,1,1959,29,12,7,90,33,7803,454,394,31006,1,387,1,22756,38,359,8296,2575,2,0]
+ [PKTLENS.....: 94,94,86,603,86,1134,1134,86,86,1134,1134,1134,1134,86,86,86,86,127,86,179,185,356,86,86,344,152,86,86,124,86,1134,1134]
detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS][Media][Safe]
guessed: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443] [TLS][Web][Safe]
idle: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443]