aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/safari.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2022-09-30 18:42:10 +0200
committerToni Uhlig <matzeton@googlemail.com>2022-09-30 19:28:49 +0200
commit14f6b87551c1d03837f25755abbc8eb71d958e3e (patch)
tree6b7f1a3e481f61e726486c8d255b14e0d9e83f12 /test/results/flow-info/safari.pcap.out
parent74f71643da536c6798d077dc1d9b13d56a9afc5d (diff)
Added nDPIsrvd-analysed to generate CSV files from analyse events.
* nDPIsrvd.h: iterate over JSON arrays * nDPId: calculate l3 payload packet entropies for analysis Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/safari.pcap.out')
-rw-r--r--test/results/flow-info/safari.pcap.out54
1 files changed, 30 insertions, 24 deletions
diff --git a/test/results/flow-info/safari.pcap.out b/test/results/flow-info/safari.pcap.out
index 76335848d..9ad62237d 100644
--- a/test/results/flow-info/safari.pcap.out
+++ b/test/results/flow-info/safari.pcap.out
@@ -11,14 +11,15 @@
new: [.....5] [ip4][..tcp] [..192.168.1.178][55268] -> [...146.48.58.18][..443]
new: [.....6] [ip4][..tcp] [..192.168.1.178][55269] -> [...146.48.58.18][..443]
analyse: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.579| 0.077| 0.167|27833.076| 0.000]
- [PKTLEN......: 66.000| 1506.000| 569.500| 644.500|415419.900| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.579| 0.077| 0.167| 27833.076| 2.800]
+ [PKTLEN......: 52.000| 1492.000| 555.500| 644.500| 415419.900| 4.000]
[BINS(c->s)..: 11,0,1,0,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,1,1,0,0,1,1,1,0,1,0,1,0,1,0,1,0,0,1,1,1,0]
[IATS(ms)....: 28.3,28.4,0.6,28.7,7.0,0.1,0.0,35.1,0.0,52.7,82.0,0.0,29.3,0.9,28.1,550.6,1.2,579.0,0.2,0.3,0.1,0.1,0.1,0.1,0.1,0.1,428.1,455.0,4.4,1.2,32.6]
- [PKTLENS.....: 78,74,66,301,66,1506,1506,641,66,66,159,66,117,66,425,66,1506,1506,66,1506,66,1506,66,1506,66,1506,66,445,66,1506,1506,66]
+ [PKTLENS.....: 64,60,52,287,52,1492,1492,627,52,52,145,52,103,52,411,52,1492,1492,52,1492,52,1492,52,1492,52,1492,52,431,52,1492,1492,52]
+ [ENTROPIES...: 4.4,5.3,5.0,5.6,5.0,7.1,7.3,7.6,5.0,4.9,6.1,5.0,5.9,5.0,7.4,5.0,7.9,7.9,4.9,7.9,4.8,7.9,5.0,7.9,4.9,7.9,5.0,7.4,5.1,7.9,7.9,5.1]
detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443] [TLS][Web][Safe]
detected: [.....4] [ip4][..tcp] [..192.168.1.178][55267] -> [...146.48.58.18][..443] [TLS][Web][Safe]
RISK: TLS (probably) Not Carrying HTTPS
@@ -41,50 +42,55 @@
detection-update: [.....6] [ip4][..tcp] [..192.168.1.178][55269] -> [...146.48.58.18][..443] [TLS][Web][Safe]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [.....4] [ip4][..tcp] [..192.168.1.178][55267] -> [...146.48.58.18][..443] [TLS][Web][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.119| 0.018| 0.029| 823.374| 0.000]
- [PKTLEN......: 66.000| 1506.000| 632.000| 660.500|436248.100| 4.200]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.119| 0.018| 0.029| 823.374| 3.500]
+ [PKTLEN......: 52.000| 1492.000| 618.000| 660.500| 436248.100| 4.100]
[BINS(c->s)..: 10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0,0,0,1,1]
[IATS(ms)....: 29.6,29.7,2.4,30.5,0.0,28.2,51.9,8.9,77.9,8.5,0.6,1.2,27.4,0.1,0.1,0.2,0.1,0.1,0.3,0.1,0.1,0.2,0.5,0.1,0.6,24.0,24.0,84.5,7.8,118.9,0.9]
- [PKTLENS.....: 78,74,66,277,66,207,66,117,508,66,66,1506,1506,66,1506,1506,66,1506,1506,66,1506,1506,66,1506,1506,66,1043,66,66,497,66,1506]
+ [PKTLENS.....: 64,60,52,263,52,193,52,103,494,52,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1029,52,52,483,52,1492]
+ [ENTROPIES...: 4.4,5.2,4.9,5.8,5.0,6.4,4.9,5.5,7.5,5.0,4.8,7.9,7.9,5.0,7.9,7.9,5.0,7.9,7.9,4.9,7.9,7.9,5.0,7.9,7.9,4.9,7.8,5.0,4.8,7.5,5.1,7.9]
analyse: [.....2] [ip4][..tcp] [..192.168.1.178][55265] -> [...146.48.58.18][..443] [TLS][Web][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.140| 0.019| 0.033| 1086.908| 0.000]
- [PKTLEN......: 66.000| 1506.000| 616.100| 656.600|431150.100| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.140| 0.019| 0.033| 1086.908| 3.400]
+ [PKTLEN......: 52.000| 1492.000| 602.100| 656.600| 431150.100| 4.100]
[BINS(c->s)..: 10,1,0,0,0,0,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,1,1,0,0,0,0,1,1,1,0,1,1,0,1]
[IATS(ms)....: 30.4,30.4,2.4,30.7,1.7,30.1,50.3,8.6,78.3,9.2,5.0,0.1,33.7,0.1,0.7,0.9,0.1,0.1,0.0,0.3,0.0,104.0,6.6,140.4,1.5,0.5,31.8,0.1,0.1,0.2,0.4]
- [PKTLENS.....: 78,74,66,277,66,207,66,117,472,66,66,1506,1506,66,1506,1506,66,1506,1506,565,66,66,66,500,66,1506,1506,66,1506,1506,66,1506]
+ [PKTLENS.....: 64,60,52,263,52,193,52,103,458,52,52,1492,1492,52,1492,1492,52,1492,1492,551,52,52,52,486,52,1492,1492,52,1492,1492,52,1492]
+ [ENTROPIES...: 4.4,5.2,4.9,5.8,5.1,6.5,4.9,5.5,7.4,5.0,5.0,7.9,7.9,5.0,7.9,7.9,5.0,7.9,7.9,7.5,4.9,5.0,4.9,7.5,5.1,7.9,7.9,4.9,7.9,7.9,4.9,7.9]
analyse: [.....3] [ip4][..tcp] [..192.168.1.178][55266] -> [...146.48.58.18][..443] [TLS][Web][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.144| 0.020| 0.034| 1135.493| 0.000]
- [PKTLEN......: 66.000| 1506.000| 624.000| 657.100|431734.900| 4.200]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.144| 0.020| 0.034| 1135.493| 3.400]
+ [PKTLEN......: 52.000| 1492.000| 610.000| 657.100| 431734.900| 4.100]
[BINS(c->s)..: 10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,0,0,0,1,1,1,0,1,1,0,1,1,0,1]
[IATS(ms)....: 31.3,31.4,1.4,32.4,1.0,32.0,49.5,8.2,77.5,8.4,0.6,1.2,30.1,0.1,0.0,0.1,0.1,0.1,106.8,7.1,144.0,5.8,0.1,35.9,0.1,0.1,0.2,0.1,0.1,0.2,0.1]
- [PKTLENS.....: 78,74,66,277,66,207,66,117,503,66,66,1506,1506,66,1506,1506,66,791,66,66,497,66,1506,1506,66,1506,1506,66,1506,1506,66,1506]
+ [PKTLENS.....: 64,60,52,263,52,193,52,103,489,52,52,1492,1492,52,1492,1492,52,777,52,52,483,52,1492,1492,52,1492,1492,52,1492,1492,52,1492]
+ [ENTROPIES...: 4.3,5.2,4.9,5.8,5.0,6.4,4.8,5.4,7.5,5.0,5.0,7.9,7.9,4.9,7.9,7.9,5.0,7.8,4.9,4.8,7.4,5.1,7.9,7.9,4.8,7.9,7.9,4.9,7.9,7.9,4.9,7.9]
analyse: [.....6] [ip4][..tcp] [..192.168.1.178][55269] -> [...146.48.58.18][..443] [TLS][Web][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.147| 0.020| 0.034| 1161.612| 0.000]
- [PKTLEN......: 66.000| 1506.000| 604.800| 660.800|436665.800| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.147| 0.020| 0.034| 1161.612| 3.300]
+ [PKTLEN......: 52.000| 1492.000| 590.800| 660.800| 436665.800| 4.100]
[BINS(c->s)..: 10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 5,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0]
[IATS(ms)....: 33.6,33.6,1.2,33.6,0.0,32.4,46.9,8.3,78.2,6.3,1.0,0.3,30.4,0.9,0.0,0.9,105.4,6.5,147.0,2.1,0.1,37.3,0.1,0.1,0.2,0.1,0.6,0.8,0.1,0.1,0.2]
- [PKTLENS.....: 78,74,66,277,66,207,66,117,495,66,66,1506,1506,66,1506,181,66,66,500,66,1506,1506,66,1506,1506,66,1506,1506,66,1506,1506,66]
+ [PKTLENS.....: 64,60,52,263,52,193,52,103,481,52,52,1492,1492,52,1492,167,52,52,486,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52]
+ [ENTROPIES...: 4.4,5.3,5.0,5.8,5.0,6.4,4.9,5.7,7.5,5.0,5.1,7.9,7.9,5.1,7.9,6.8,4.9,4.9,7.5,5.0,7.9,7.8,5.1,7.9,7.9,5.0,7.9,7.9,5.0,7.9,7.9,5.1]
analyse: [.....5] [ip4][..tcp] [..192.168.1.178][55268] -> [...146.48.58.18][..443] [TLS][Web][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.146| 0.022| 0.035| 1194.506| 0.000]
- [PKTLEN......: 66.000| 1506.000| 533.000| 616.900|380607.300| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.146| 0.022| 0.035| 1194.506| 3.500]
+ [PKTLEN......: 52.000| 1492.000| 519.000| 616.900| 380607.300| 4.000]
[BINS(c->s)..: 10,1,0,0,0,0,1,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,8,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,0,1,1,1,0,0,1,1,1,0,1,1,0,1,1,1,0,0,0,0,1,1,1,0]
[IATS(ms)....: 30.4,30.5,1.4,31.3,0.1,30.0,50.7,8.3,78.2,9.2,0.2,28.7,116.2,146.0,0.5,0.1,30.4,0.1,0.4,0.5,0.1,0.1,0.0,0.2,0.0,0.9,5.5,36.2,1.5,0.1,31.5]
- [PKTLENS.....: 78,74,66,277,66,207,66,117,494,66,66,1413,66,497,66,1506,1506,66,1506,1506,66,1506,1506,425,66,66,66,503,66,1506,1506,66]
+ [PKTLENS.....: 64,60,52,263,52,193,52,103,480,52,52,1399,52,483,52,1492,1492,52,1492,1492,52,1492,1492,411,52,52,52,489,52,1492,1492,52]
+ [ENTROPIES...: 4.4,5.2,4.9,5.9,4.9,6.5,4.8,5.6,7.5,5.0,5.0,7.9,5.0,7.4,4.9,7.9,7.9,4.8,7.9,7.9,4.9,7.9,7.9,7.5,4.9,4.9,4.8,7.5,5.1,7.9,7.9,5.1]
new: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443]
detected: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] [TLS][Web][Safe]
detection-update: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] [TLS][Web][Safe]