aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/smb_deletefile.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2022-09-22 19:07:08 +0200
committerToni Uhlig <matzeton@googlemail.com>2022-09-22 19:07:08 +0200
commit9a28475bba88b711b7075b58473b7e5b5df1f393 (patch)
tree73cdf56320f14b5fe0fbfb2e930cf7ea025f9117 /test/results/flow-info/smb_deletefile.pcap.out
parent28971cd7647a79253000fb33e52b5d2129e5ba62 (diff)
Improved flown analyse event:
* store packet directions * merged direction based IATs * merged direction based PKTLENs Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info/smb_deletefile.pcap.out')
-rw-r--r--test/results/flow-info/smb_deletefile.pcap.out10
1 files changed, 6 insertions, 4 deletions
diff --git a/test/results/flow-info/smb_deletefile.pcap.out b/test/results/flow-info/smb_deletefile.pcap.out
index c8b3c7c23..70e783b89 100644
--- a/test/results/flow-info/smb_deletefile.pcap.out
+++ b/test/results/flow-info/smb_deletefile.pcap.out
@@ -4,11 +4,13 @@
new: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [MIDSTREAM]
detected: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [NetBIOS.SMBv23][System][Acceptable]
analyse: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [NetBIOS.SMBv23][System][Acceptable]
- [min|max|avg|stddev]
- [IAT(flow)...: 0.000| 2.158| 0.143| 0.529]
- [IAT(c->s)...: 0.000| 2.157| 0.116| 0.481][IAT(s->c)...: 0.000| 2.158| 0.184| 0.595]
- [PKTLEN(c->s): 54.000| 466.000| 202.600| 166.500][PKTLEN(s->c): 60.000| 554.000| 373.300| 180.900]
+ [min|max|avg|stddev|variance|entropy]
+ [IAT.........: 0.000| 2.158| 0.143| 0.529|280112.169| 0.000]
+ [PKTLEN......: 54.000| 554.000| 266.600| 190.900|36432.900| 4.600]
[BINS(c->s)..: 10,0,0,2,0,0,0,1,0,0,4,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 1,0,1,2,0,0,0,0,0,1,0,1,1,0,1,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [DIRECTIONS..: 0,1,0,0,1,0,0,1,0,0,1,0,1,0,0,0,1,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1]
+ [IATS........: 1172,1225,2157281,2158424,1159,87,1253,1160,7461,9355,1883,124,103,75,20,492,151,550,5618,5637,4741,5866,1131,107,1245,1127,130,997,857,25951,26895,0]
+ [PKTLENS.....: 434,554,54,378,522,54,394,538,54,466,180,54,554,54,158,154,60,158,54,130,54,394,538,54,434,410,54,298,370,54,402,466]
idle: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [NetBIOS.SMBv23][System][Acceptable]
DAEMON-EVENT: shutdown