diff options
Diffstat (limited to 'test/results/flow-analyse')
-rw-r--r-- | test/results/flow-analyse/chrome.pcap.out | 7 | ||||
-rw-r--r-- | test/results/flow-analyse/default/1kxun.pcap.out (renamed from test/results/flow-analyse/1kxun.pcap.out) | 9 | ||||
-rw-r--r-- | test/results/flow-analyse/default/443-chrome.pcap.out (renamed from test/results/flow-analyse/443-chrome.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/443-curl.pcap.out (renamed from test/results/flow-analyse/443-curl.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/443-firefox.pcap.out (renamed from test/results/flow-analyse/443-firefox.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/443-git.pcap.out (renamed from test/results/flow-analyse/443-git.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/443-opvn.pcap.out (renamed from test/results/flow-analyse/443-opvn.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/443-safari.pcap.out (renamed from test/results/flow-analyse/443-safari.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/4in4tunnel.pcap.out (renamed from test/results/flow-analyse/4in4tunnel.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/4in6tunnel.pcap.out (renamed from test/results/flow-analyse/4in6tunnel.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/6in4tunnel.pcap.out (renamed from test/results/flow-analyse/6in4tunnel.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/6in6tunnel.pcap.out (renamed from test/results/flow-analyse/6in6tunnel.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/BGP_Cisco_hdlc_slarp.pcap.out (renamed from test/results/flow-analyse/BGP_Cisco_hdlc_slarp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/BGP_redist.pcap.out (renamed from test/results/flow-analyse/BGP_redist.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/EAQ.pcap.out (renamed from test/results/flow-analyse/EAQ.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out (renamed from test/results/flow-analyse/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/IEC104.pcap.out (renamed from test/results/flow-analyse/IEC104.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/KakaoTalk_chat.pcap.out (renamed from test/results/flow-analyse/KakaoTalk_chat.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/KakaoTalk_talk.pcap.out (renamed from test/results/flow-analyse/KakaoTalk_talk.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/NTPv2.pcap.out (renamed from test/results/flow-analyse/NTPv2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/NTPv3.pcap.out (renamed from test/results/flow-analyse/NTPv3.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/NTPv4.pcap.out (renamed from test/results/flow-analyse/NTPv4.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/Oscar.pcap.out (renamed from test/results/flow-analyse/Oscar.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/TivoDVR.pcap.out (renamed from test/results/flow-analyse/TivoDVR.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/WebattackRCE.pcap.out (renamed from test/results/flow-analyse/WebattackRCE.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/WebattackSQLinj.pcap.out (renamed from test/results/flow-analyse/WebattackSQLinj.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/WebattackXSS.pcap.out (renamed from test/results/flow-analyse/WebattackXSS.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/activision.pcap.out (renamed from test/results/flow-analyse/activision.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/adult_content.pcap.out (renamed from test/results/flow-analyse/afp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/afp.pcap.out (renamed from test/results/flow-analyse/agora-sd-rtn.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/agora-sd-rtn.pcap.out (renamed from test/results/flow-analyse/ah.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ah.pcapng.out (renamed from test/results/flow-analyse/ajp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ajp.pcap.out (renamed from test/results/flow-analyse/alicloud.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/alexa-app.pcapng.out (renamed from test/results/flow-analyse/alexa-app.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/alicloud.pcap.out (renamed from test/results/flow-analyse/among_us.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/among_us.pcap.out (renamed from test/results/flow-analyse/avast.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/amqp.pcap.out (renamed from test/results/flow-analyse/amqp.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/android.pcap.out (renamed from test/results/flow-analyse/android.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/anyconnect-vpn.pcap.out (renamed from test/results/flow-analyse/anyconnect-vpn.pcap.out) | 3 | ||||
-rw-r--r-- | test/results/flow-analyse/default/anydesk.pcapng.out (renamed from test/results/flow-analyse/anydesk.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/avast.pcap.out (renamed from test/results/flow-analyse/avast_securedns.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/avast_securedns.pcapng.out (renamed from test/results/flow-analyse/badpackets.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bacnet.pcap.out (renamed from test/results/flow-analyse/bjnp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bad-dns-traffic.pcap.out (renamed from test/results/flow-analyse/bad-dns-traffic.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/badpackets.pcap.out (renamed from test/results/flow-analyse/bt_search.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bitcoin.pcap.out (renamed from test/results/flow-analyse/bitcoin.pcap.out) | 8 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bittorrent.pcap.out (renamed from test/results/flow-analyse/bittorrent.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bittorrent_tcp_miss.pcapng.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bittorrent_utp.pcap.out (renamed from test/results/flow-analyse/bittorrent_utp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bjnp.pcap.out (renamed from test/results/flow-analyse/cachefly.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bot.pcap.out (renamed from test/results/flow-analyse/bot.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bt-dns.pcap.out (renamed from test/results/flow-analyse/cloudflare-warp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bt-http.pcapng.out (renamed from test/results/flow-analyse/corba.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/bt_search.pcap.out (renamed from test/results/flow-analyse/cpha.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/cachefly.pcapng.out (renamed from test/results/flow-analyse/crynet.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/capwap.pcap.out (renamed from test/results/flow-analyse/capwap.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/capwap_data.pcapng.out (renamed from test/results/flow-analyse/dazn.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/cassandra.pcap.out (renamed from test/results/flow-analyse/cassandra.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/check_mk_new.pcap.out (renamed from test/results/flow-analyse/check_mk_new.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/chrome.pcap.out (renamed from test/results/flow-analyse/dcerpc.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/citrix.pcap.out (renamed from test/results/flow-analyse/citrix.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/cloudflare-warp.pcap.out (renamed from test/results/flow-analyse/dhcp-fuzz.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/coap_mqtt.pcap.out (renamed from test/results/flow-analyse/coap_mqtt.pcap.out) | 14 | ||||
-rw-r--r-- | test/results/flow-analyse/default/collectd.pcap.out (renamed from test/results/flow-analyse/collectd.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/corba.pcap.out (renamed from test/results/flow-analyse/diameter.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/cpha.pcap.out (renamed from test/results/flow-analyse/discord.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/crawler_false_positive.pcapng.out (renamed from test/results/flow-analyse/dlt_ppp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/crynet.pcap.out (renamed from test/results/flow-analyse/dns-invalid-chars.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/custom_rules_same-ip_multiple_ports.pcapng.out (renamed from test/results/flow-analyse/dns_ambiguous_names.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dazn.pcapng.out (renamed from test/results/flow-analyse/dns_dot.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dcerpc.pcap.out (renamed from test/results/flow-analyse/dns_fragmented.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dhcp-fuzz.pcapng.out (renamed from test/results/flow-analyse/dns_invert_query.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/diameter.pcap.out (renamed from test/results/flow-analyse/dns_long_domainname.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/discord.pcap.out (renamed from test/results/flow-analyse/dnscrypt-v1-and-resolver-pings.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/discord_mid_flow.pcap.out (renamed from test/results/flow-analyse/dnscrypt-v2-doh.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dlt_ppp.pcap.out (renamed from test/results/flow-analyse/dnscrypt-v2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dnp3.pcap.out (renamed from test/results/flow-analyse/dnp3.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns-invalid-chars.pcap.out (renamed from test/results/flow-analyse/dnscrypt_skype_false_positive.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns-tunnel-iodine.pcap.out (renamed from test/results/flow-analyse/dns-tunnel-iodine.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_ambiguous_names.pcap.out (renamed from test/results/flow-analyse/doq.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_doh.pcap.out (renamed from test/results/flow-analyse/dns_doh.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_dot.pcap.out (renamed from test/results/flow-analyse/dtls.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_exfiltration.pcap.out (renamed from test/results/flow-analyse/dns_exfiltration.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_fragmented.pcap.out (renamed from test/results/flow-analyse/dtls2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_invert_query.pcapng.out (renamed from test/results/flow-analyse/dtls_certificate.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dns_long_domainname.pcap.out (renamed from test/results/flow-analyse/dtls_certificate_fragments.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dnscrypt-v1-and-resolver-pings.pcap.out (renamed from test/results/flow-analyse/dtls_mid_sessions.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dnscrypt-v2-doh.pcap.out (renamed from test/results/flow-analyse/dtls_old_version.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dnscrypt-v2.pcap.out (renamed from test/results/flow-analyse/dtls_session_id_and_coockie_both.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dnscrypt_skype_false_positive.pcapng.out (renamed from test/results/flow-analyse/elasticsearch.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/doq.pcapng.out (renamed from test/results/flow-analyse/encrypted_sni.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/doq_adguard.pcapng.out (renamed from test/results/flow-analyse/doq_adguard.pcapng.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dos_win98_smb_netbeui.pcap.out (renamed from test/results/flow-analyse/dos_win98_smb_netbeui.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/drda_db2.pcap.out (renamed from test/results/flow-analyse/drda_db2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dropbox.pcap.out (renamed from test/results/flow-analyse/dropbox.pcap.out) | 8 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls.pcap.out (renamed from test/results/flow-analyse/esp.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls2.pcap.out (renamed from test/results/flow-analyse/ethernetIP.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls_certificate.pcapng.out (renamed from test/results/flow-analyse/ftp_failed.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls_certificate_fragments.pcap.out (renamed from test/results/flow-analyse/fuzz-2006-09-29-28586.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls_mid_sessions.pcapng.out (renamed from test/results/flow-analyse/fuzz-2021-06-07-c6c72a0a56.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls_old_version.pcapng.out (renamed from test/results/flow-analyse/fuzz-2021-10-13.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/dtls_session_id_and_coockie_both.pcap.out (renamed from test/results/flow-analyse/genshin-impact.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/elasticsearch.pcap.out (renamed from test/results/flow-analyse/google_ssl.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/emotet.pcap.out (renamed from test/results/flow-analyse/emotet.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/encrypted_sni.pcap.out (renamed from test/results/flow-analyse/gquic.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/esp.pcapng.out (renamed from test/results/flow-analyse/gre_no_options.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ethereum.pcap.out (renamed from test/results/flow-analyse/ethereum.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ethernetIP.pcap.out (renamed from test/results/flow-analyse/gtp_c.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/exe_download.pcap.out (renamed from test/results/flow-analyse/exe_download.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/exe_download_as_png.pcap.out (renamed from test/results/flow-analyse/exe_download_as_png.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/facebook.pcap.out (renamed from test/results/flow-analyse/facebook.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fastcgi.pcap.out (renamed from test/results/flow-analyse/fastcgi.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/firefox.pcap.out (renamed from test/results/flow-analyse/gtp_false_positive.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fix.pcap.out (renamed from test/results/flow-analyse/fix.pcap.out) | 10 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fix2.pcap.out (renamed from test/results/flow-analyse/fix2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/forticlient.pcap.out (renamed from test/results/flow-analyse/forticlient.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ftp-start-tls.pcap.out (renamed from test/results/flow-analyse/ftp-start-tls.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ftp.pcap.out (renamed from test/results/flow-analyse/ftp.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ftp_failed.pcap.out (renamed from test/results/flow-analyse/gtp_prime.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fuzz-2006-06-26-2594.pcap.out (renamed from test/results/flow-analyse/fuzz-2006-06-26-2594.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fuzz-2006-09-29-28586.pcap.out (renamed from test/results/flow-analyse/h323-overflow.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fuzz-2020-02-16-11740.pcap.out (renamed from test/results/flow-analyse/fuzz-2020-02-16-11740.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fuzz-2021-06-07-c6c72a0a56.pcap.out (renamed from test/results/flow-analyse/h323.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/fuzz-2021-10-13.pcap.out (renamed from test/results/flow-analyse/hangout.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/genshin-impact.pcap.out (renamed from test/results/flow-analyse/hpvirtgrp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/git.pcap.out (renamed from test/results/flow-analyse/git.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/gnutella.pcap.out (renamed from test/results/flow-analyse/gnutella.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/google_ssl.pcap.out (renamed from test/results/flow-analyse/hsrp0.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/googledns_android10.pcap.out (renamed from test/results/flow-analyse/googledns_android10.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/gquic.pcap.out (renamed from test/results/flow-analyse/hsrp2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/gtp_c.pcap.out (renamed from test/results/flow-analyse/hsrp2_ipv6.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/gtp_false_positive.pcapng.out (renamed from test/results/flow-analyse/http-crash-content-disposition.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/gtp_prime.pcapng.out (renamed from test/results/flow-analyse/http-lines-split.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/h323-overflow.pcap.out (renamed from test/results/flow-analyse/http-proxy.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/h323.pcap.out (renamed from test/results/flow-analyse/http_guessed_host_and_guessed.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/hangout.pcap.out (renamed from test/results/flow-analyse/http_on_sip_port.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/heuristic_tcp_ack_payload.pcap.out | 5 | ||||
-rw-r--r-- | test/results/flow-analyse/default/hots.pcapng.out | 3 | ||||
-rw-r--r-- | test/results/flow-analyse/default/hpvirtgrp.pcap.out (renamed from test/results/flow-analyse/i3d.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/hsrp0.pcap.out (renamed from test/results/flow-analyse/imaps.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/hsrp2.pcap.out (renamed from test/results/flow-analyse/ip_fragmented_garbage.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/hsrp2_ipv6.pcapng.out (renamed from test/results/flow-analyse/ipv6_in_gtp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http-crash-content-disposition.pcap.out (renamed from test/results/flow-analyse/irc.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http-lines-split.pcap.out (renamed from test/results/flow-analyse/ja3_lots_of_cipher_suites.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http-manipulated.pcap.out (renamed from test/results/flow-analyse/ja3_lots_of_cipher_suites_2_anon.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http-proxy.pcapng.out (renamed from test/results/flow-analyse/kerberos-error.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_asymmetric.pcapng.out (renamed from test/results/flow-analyse/kerberos-login.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_auth.pcap.out (renamed from test/results/flow-analyse/http_auth.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_connect.pcap.out (renamed from test/results/flow-analyse/http_connect.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_guessed_host_and_guessed.pcapng.out (renamed from test/results/flow-analyse/kerberos.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_ipv6.pcap.out (renamed from test/results/flow-analyse/http_ipv6.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_on_sip_port.pcap.out (renamed from test/results/flow-analyse/kerberos_fuzz.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_origin_different_than_host.pcap.out (renamed from test/results/flow-analyse/lisp_registration.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_starting_with_reply.pcapng.out (renamed from test/results/flow-analyse/lru_ipv6_caches.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/http_ua_splitted_in_two_pkts.pcapng.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/i3d.pcap.out (renamed from test/results/flow-analyse/malformed_dns.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/iax.pcap.out (renamed from test/results/flow-analyse/iax.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/icmp-tunnel.pcap.out (renamed from test/results/flow-analyse/icmp-tunnel.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/iec60780-5-104.pcap.out (renamed from test/results/flow-analyse/iec60780-5-104.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/imap-starttls.pcap.out (renamed from test/results/flow-analyse/imap-starttls.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/imap.pcap.out (renamed from test/results/flow-analyse/imap.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/imaps.pcap.out (renamed from test/results/flow-analyse/malformed_icmp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/imo.pcap.out (renamed from test/results/flow-analyse/imo.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/instagram.pcap.out (renamed from test/results/flow-analyse/instagram.pcap.out) | 5 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ip_fragmented_garbage.pcap.out (renamed from test/results/flow-analyse/malware.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/iphone.pcap.out (renamed from test/results/flow-analyse/iphone.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ipp.pcap.out (renamed from test/results/flow-analyse/ipp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ipsec_isakmp_esp.pcap.out (renamed from test/results/flow-analyse/ipsec_isakmp_esp.pcap.out) | 12 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ipv6_in_gtp.pcap.out (renamed from test/results/flow-analyse/memcached.cap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/irc.pcap.out (renamed from test/results/flow-analyse/mgcp.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ja3_lots_of_cipher_suites.pcap.out (renamed from test/results/flow-analyse/mongo_false_positive.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ja3_lots_of_cipher_suites_2_anon.pcap.out (renamed from test/results/flow-analyse/mongodb.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/jabber.pcap.out (renamed from test/results/flow-analyse/jabber.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/kerberos-error.pcap.out (renamed from test/results/flow-analyse/mpeg-dash.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/kerberos-login.pcap.out (renamed from test/results/flow-analyse/mpeg.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/kerberos.pcap.out (renamed from test/results/flow-analyse/mpegts.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/kerberos_fuzz.pcapng.out (renamed from test/results/flow-analyse/mqtt.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/kismet.pcap.out (renamed from test/results/flow-analyse/kismet.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/kontiki.pcap.out (renamed from test/results/flow-analyse/kontiki.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/line.pcap.out (renamed from test/results/flow-analyse/line.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/linecall_falsepositve.pcap.out (renamed from test/results/flow-analyse/mssql_tds.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/lisp_registration.pcap.out (renamed from test/results/flow-analyse/munin.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/log4j-webapp-exploit.pcap.out (renamed from test/results/flow-analyse/log4j-webapp-exploit.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/long_tls_certificate.pcap.out (renamed from test/results/flow-analyse/long_tls_certificate.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/lru_ipv6_caches.pcapng.out (renamed from test/results/flow-analyse/mysql-8.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/malformed_dns.pcap.out (renamed from test/results/flow-analyse/natpmp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/malformed_icmp.pcap.out (renamed from test/results/flow-analyse/nats.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/malware.pcap.out (renamed from test/results/flow-analyse/ndpi_match_string_subprotocol__error.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/memcached.cap.out (renamed from test/results/flow-analyse/netbios_wildcard_dns_query.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/merakicloud.pcapng.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mgcp.pcapng.out (renamed from test/results/flow-analyse/netflow-fritz.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/modbus.pcap.out (renamed from test/results/flow-analyse/modbus.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/monero.pcap.out (renamed from test/results/flow-analyse/monero.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mongo_false_positive.pcapng.out (renamed from test/results/flow-analyse/netflowv9.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mongodb.pcap.out (renamed from test/results/flow-analyse/oracle12.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mpeg-dash.pcap.out (renamed from test/results/flow-analyse/os_detected.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mpeg.pcap.out (renamed from test/results/flow-analyse/ospfv2_add_new_prefix.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mpegts.pcap.out (renamed from test/results/flow-analyse/pgsql.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mqtt.pcap.out (renamed from test/results/flow-analyse/pim.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mssql_tds.pcap.out (renamed from test/results/flow-analyse/pluralsight.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/munin.pcap.out (renamed from test/results/flow-analyse/pop3.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/mysql-8.pcap.out (renamed from test/results/flow-analyse/pops.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/natpmp.pcap.out (renamed from test/results/flow-analyse/pptp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/nats.pcap.out (renamed from test/results/flow-analyse/punycode-idn.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ndpi_match_string_subprotocol__error.pcapng.out (renamed from test/results/flow-analyse/quic-23.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/nest_log_sink.pcap.out (renamed from test/results/flow-analyse/nest_log_sink.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/netbios.pcap.out (renamed from test/results/flow-analyse/netbios.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/netbios_wildcard_dns_query.pcap.out (renamed from test/results/flow-analyse/quic-24.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/netflix.pcap.out (renamed from test/results/flow-analyse/netflix.pcap.out) | 33 | ||||
-rw-r--r-- | test/results/flow-analyse/default/netflow-fritz.pcap.out (renamed from test/results/flow-analyse/quic-27.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/netflowv9.pcap.out (renamed from test/results/flow-analyse/quic-29.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/nfsv2.pcap.out (renamed from test/results/flow-analyse/nfsv2.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/nfsv3.pcap.out (renamed from test/results/flow-analyse/nfsv3.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/nintendo.pcap.out (renamed from test/results/flow-analyse/nintendo.pcap.out) | 8 | ||||
-rw-r--r-- | test/results/flow-analyse/default/nntp.pcap.out (renamed from test/results/flow-analyse/nntp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/no_sni.pcap.out (renamed from test/results/flow-analyse/no_sni.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ocs.pcap.out (renamed from test/results/flow-analyse/ocs.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ocsp.pcapng.out (renamed from test/results/flow-analyse/ocsp.pcapng.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/oicq.pcap.out (renamed from test/results/flow-analyse/quic-33.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ookla.pcap.out (renamed from test/results/flow-analyse/quic-34.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/openvpn.pcap.out (renamed from test/results/flow-analyse/openvpn.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/oracle12.pcapng.out (renamed from test/results/flow-analyse/quic-fuzz-overflow.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/os_detected.pcapng.out (renamed from test/results/flow-analyse/quic-mvfst-27.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ospfv2_add_new_prefix.pcap.out (renamed from test/results/flow-analyse/quic-mvfst-exp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ossfuzz_seed_fake_traces_1.pcapng.out (renamed from test/results/flow-analyse/quic-v2-01.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ossfuzz_seed_fake_traces_2.pcapng.out (renamed from test/results/flow-analyse/quic_0RTT.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ossfuzz_seed_fake_traces_3.pcapng.out (renamed from test/results/flow-analyse/quic_crypto_aes_auth_size.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ossfuzz_seed_fake_traces_4.pcapng.out (renamed from test/results/flow-analyse/quic_frags_ch_in_multiple_packets.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pgm.pcap.out (renamed from test/results/flow-analyse/pgm.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pgsql.pcap.out (renamed from test/results/flow-analyse/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pim.pcap.out (renamed from test/results/flow-analyse/quic_interop_V.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pinterest.pcap.out (renamed from test/results/flow-analyse/pinterest.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pluralsight.pcap.out (renamed from test/results/flow-analyse/quic_q43.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pop3.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pop3_stls.pcap.out (renamed from test/results/flow-analyse/pop3_stls.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pops.pcapng.out (renamed from test/results/flow-analyse/quic_q46.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pps.pcap.out (renamed from test/results/flow-analyse/pps.pcap.out) | 3 | ||||
-rw-r--r-- | test/results/flow-analyse/default/pptp.pcap.out (renamed from test/results/flow-analyse/quic_q46_b.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/psiphon3.pcap.out (renamed from test/results/flow-analyse/psiphon3.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/punycode-idn.pcap.out (renamed from test/results/flow-analyse/quic_q50.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-23.pcap.out (renamed from test/results/flow-analyse/quic_t50.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-24.pcap.out (renamed from test/results/flow-analyse/quic_t51.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-27.pcap.out (renamed from test/results/flow-analyse/radius_false_positive.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-28.pcap.out (renamed from test/results/flow-analyse/quic-28.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-29.pcap.out (renamed from test/results/flow-analyse/raknet.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-33.pcapng.out (renamed from test/results/flow-analyse/riotgames.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-34.pcap.out (renamed from test/results/flow-analyse/rsh-syslog-false-positive.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-fuzz-overflow.pcapng.out (renamed from test/results/flow-analyse/rsh.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-mvfst-22.pcap.out (renamed from test/results/flow-analyse/quic-mvfst-22.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-mvfst-22_decryption_error.pcap.out (renamed from test/results/flow-analyse/rsync.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-mvfst-27.pcapng.out (renamed from test/results/flow-analyse/rtmp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-mvfst-exp.pcap.out (renamed from test/results/flow-analyse/rtsp_setup_http.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic-v2-01.pcapng.out (renamed from test/results/flow-analyse/salesforce.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic.pcap.out (renamed from test/results/flow-analyse/quic.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic046.pcap.out (renamed from test/results/flow-analyse/quic046.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_0RTT.pcap.out (renamed from test/results/flow-analyse/sccp_hw_conf_register.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_crypto_aes_auth_size.pcap.out (renamed from test/results/flow-analyse/sctp.cap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_frags_ch_in_multiple_packets.pcapng.out (renamed from test/results/flow-analyse/selfsigned.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out (renamed from test/results/flow-analyse/sflow.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_interop_V.pcapng.out (renamed from test/results/flow-analyse/sip_hello.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_q39.pcap.out (renamed from test/results/flow-analyse/quic_q39.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_q43.pcap.out (renamed from test/results/flow-analyse/skype_udp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_q46.pcap.out (renamed from test/results/flow-analyse/smb_frags.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_q46_b.pcap.out (renamed from test/results/flow-analyse/smbv1.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_q50.pcap.out (renamed from test/results/flow-analyse/smpp_in_general.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_t50.pcap.out (renamed from test/results/flow-analyse/smtps.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quic_t51.pcap.out (renamed from test/results/flow-analyse/snapchat.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/quickplay.pcap.out (renamed from test/results/flow-analyse/quickplay.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/radius_false_positive.pcapng.out (renamed from test/results/flow-analyse/snmp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/raknet.pcap.out (renamed from test/results/flow-analyse/soap.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rdp.pcap.out (renamed from test/results/flow-analyse/rdp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/reasm_crash_anon.pcapng.out (renamed from test/results/flow-analyse/reasm_crash_anon.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/reasm_segv_anon.pcapng.out (renamed from test/results/flow-analyse/reasm_segv_anon.pcapng.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/reddit.pcap.out (renamed from test/results/flow-analyse/reddit.pcap.out) | 8 | ||||
-rw-r--r-- | test/results/flow-analyse/default/riot.pcapng.out (renamed from test/results/flow-analyse/socks-http-example.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/riotgames.pcap.out (renamed from test/results/flow-analyse/someip-tp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rsh-syslog-false-positive.pcap.out (renamed from test/results/flow-analyse/someip-udp-method-call.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rsh.pcap.out (renamed from test/results/flow-analyse/someip_sd_sample.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rsync.pcap.out (renamed from test/results/flow-analyse/sql_injection.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rtmp.pcap.out (renamed from test/results/flow-analyse/ssdp-m-search-ua.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rtsp.pcap.out (renamed from test/results/flow-analyse/rtsp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rtsp_setup_http.pcapng.out (renamed from test/results/flow-analyse/ssdp-m-search.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/rx.pcap.out (renamed from test/results/flow-analyse/rx.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/s7comm.pcap.out (renamed from test/results/flow-analyse/s7comm.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/safari.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/salesforce.pcap.out (renamed from test/results/flow-analyse/ssl-cert-name-mismatch.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sccp_hw_conf_register.pcapng.out (renamed from test/results/flow-analyse/steam.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sctp.cap.out (renamed from test/results/flow-analyse/steam_datagram_relay_ping.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/selfsigned.pcap.out (renamed from test/results/flow-analyse/syncthing.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sflow.pcap.out (renamed from test/results/flow-analyse/synscan.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/signal.pcap.out (renamed from test/results/flow-analyse/signal.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/simple-dnscrypt.pcap.out (renamed from test/results/flow-analyse/simple-dnscrypt.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sip.pcap.out (renamed from test/results/flow-analyse/sip.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sip_hello.pcapng.out (renamed from test/results/flow-analyse/syslog.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sites.pcapng.out (renamed from test/results/flow-analyse/sites.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/skinny.pcap.out (renamed from test/results/flow-analyse/skinny.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/skype-conference-call.pcap.out (renamed from test/results/flow-analyse/skype-conference-call.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/skype.pcap.out (renamed from test/results/flow-analyse/skype.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/skype_no_unknown.pcap.out (renamed from test/results/flow-analyse/skype_no_unknown.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/skype_udp.pcap.out (renamed from test/results/flow-analyse/targusdataspeed_false_positives.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smb_deletefile.pcap.out (renamed from test/results/flow-analyse/smb_deletefile.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smb_frags.pcap.out (renamed from test/results/flow-analyse/teredo.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smbv1.pcap.out (renamed from test/results/flow-analyse/threema.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smpp_in_general.pcap.out (renamed from test/results/flow-analyse/tk.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smtp-starttls.pcap.out (renamed from test/results/flow-analyse/smtp-starttls.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smtp.pcap.out (renamed from test/results/flow-analyse/smtp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/smtps.pcapng.out (renamed from test/results/flow-analyse/tls-esni-fuzzed.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/snapchat.pcap.out (renamed from test/results/flow-analyse/tls-rdn-extract.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/snapchat_call.pcapng.out (renamed from test/results/flow-analyse/snapchat_call.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/snapchat_call_v1.pcapng.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/snmp.pcap.out (renamed from test/results/flow-analyse/tls_2_reasms.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/soap.pcap.out (renamed from test/results/flow-analyse/tls_2_reasms_b.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/socks-http-example.pcap.out (renamed from test/results/flow-analyse/tls_alert.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/softether.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/someip-tp.pcap.out (renamed from test/results/flow-analyse/tls_cipher_lens.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/someip-udp-method-call.pcapng.out (renamed from test/results/flow-analyse/tls_client_certificate_with_missing_server_one.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/someip_sd_sample.pcap.out (renamed from test/results/flow-analyse/tls_esni_sni_both.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/source_engine.pcap.out (renamed from test/results/flow-analyse/tls_false_positives.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/sql_injection.pcap.out (renamed from test/results/flow-analyse/tls_invalid_reads.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ssdp-m-search-ua.pcap.out (renamed from test/results/flow-analyse/tls_missing_ch_frag.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ssdp-m-search.pcap.out (renamed from test/results/flow-analyse/tls_multiple_synack_different_seq.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ssh.pcap.out (renamed from test/results/flow-analyse/ssh.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ssl-cert-name-mismatch.pcap.out (renamed from test/results/flow-analyse/tls_port_80.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/starcraft_battle.pcap.out (renamed from test/results/flow-analyse/starcraft_battle.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/steam.pcap.out (renamed from test/results/flow-analyse/tls_torrent.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/steam_datagram_relay_ping.pcapng.out (renamed from test/results/flow-analyse/tls_unidirectional.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/stun.pcap.out (renamed from test/results/flow-analyse/stun.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/stun_signal.pcapng.out (renamed from test/results/flow-analyse/stun_signal.pcapng.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/syncthing.pcap.out (renamed from test/results/flow-analyse/toca-boca.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/synscan.pcap.out (renamed from test/results/flow-analyse/tuya_lp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/syslog.pcap.out (renamed from test/results/flow-analyse/ubntac2.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tailscale.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/targusdataspeed_false_positives.pcap.out (renamed from test/results/flow-analyse/upnp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tcp_scan.pcapng.out (renamed from test/results/flow-analyse/vrrp3.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/teams.pcap.out (renamed from test/results/flow-analyse/teams.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/teamspeak3.pcap.out (renamed from test/results/flow-analyse/teamspeak3.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/teamviewer.pcap.out (renamed from test/results/flow-analyse/teamviewer.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/telegram.pcap.out (renamed from test/results/flow-analyse/telegram.pcap.out) | 6 | ||||
-rw-r--r-- | test/results/flow-analyse/default/telnet.pcap.out (renamed from test/results/flow-analyse/telnet.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/teredo.pcap.out (renamed from test/results/flow-analyse/websocket.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tftp.pcap.out (renamed from test/results/flow-analyse/tftp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/threema.pcap.out (renamed from test/results/flow-analyse/whatsapp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tinc.pcap.out (renamed from test/results/flow-analyse/tinc.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tk.pcap.out (renamed from test/results/flow-analyse/whois.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls-appdata.pcap.out (renamed from test/results/flow-analyse/tls-appdata.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls-esni-fuzzed.pcap.out (renamed from test/results/flow-analyse/windowsupdate_over_http.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls-rdn-extract.pcap.out (renamed from test/results/flow-analyse/wow.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_2_reasms.pcapng.out (renamed from test/results/flow-analyse/xdmcp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_2_reasms_b.pcapng.out (renamed from test/results/flow-analyse/xiaomi.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_alert.pcap.out (renamed from test/results/flow-analyse/xss.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_certificate_too_long.pcap.out (renamed from test/results/flow-analyse/tls_certificate_too_long.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_cipher_lens.pcap.out (renamed from test/results/flow-analyse/z3950.pcapng.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_client_certificate_with_missing_server_one.pcapng.out (renamed from test/results/flow-analyse/zabbix.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_esni_sni_both.pcap.out (renamed from test/results/flow-analyse/zattoo.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_false_positives.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_invalid_reads.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_long_cert.pcap.out (renamed from test/results/flow-analyse/tls_long_cert.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_missing_ch_frag.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_multiple_synack_different_seq.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_port_80.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_torrent.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_unidirectional.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tls_verylong_certificate.pcap.out (renamed from test/results/flow-analyse/tls_verylong_certificate.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/toca-boca.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tor.pcap.out (renamed from test/results/flow-analyse/tor.pcap.out) | 6 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tplink_shp.pcap.out (renamed from test/results/flow-analyse/tplink_shp.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/trickbot.pcap.out (renamed from test/results/flow-analyse/trickbot.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tumblr.pcap.out (renamed from test/results/flow-analyse/tumblr.pcap.out) | 3 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tunnelbear.pcap.out (renamed from test/results/flow-analyse/tunnelbear.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/tuya_lp.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ubntac2.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/ultrasurf.pcap.out (renamed from test/results/flow-analyse/ultrasurf.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/upnp.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/viber.pcap.out (renamed from test/results/flow-analyse/viber.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/vk.pcapng.out | 3 | ||||
-rw-r--r-- | test/results/flow-analyse/default/vnc.pcap.out (renamed from test/results/flow-analyse/vnc.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/vrrp3.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/vxlan.pcap.out (renamed from test/results/flow-analyse/vxlan.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/wa_video.pcap.out (renamed from test/results/flow-analyse/wa_video.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/wa_voice.pcap.out (renamed from test/results/flow-analyse/wa_voice.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/waze.pcap.out (renamed from test/results/flow-analyse/waze.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/webex.pcap.out (renamed from test/results/flow-analyse/webex.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/websocket.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/wechat.pcap.out (renamed from test/results/flow-analyse/wechat.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/weibo.pcap.out (renamed from test/results/flow-analyse/weibo.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/whatsapp.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/whatsapp_login_call.pcap.out (renamed from test/results/flow-analyse/whatsapp_login_call.pcap.out) | 4 | ||||
-rw-r--r-- | test/results/flow-analyse/default/whatsapp_login_chat.pcap.out (renamed from test/results/flow-analyse/whatsapp_login_chat.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/whatsapp_voice_and_message.pcap.out (renamed from test/results/flow-analyse/whatsapp_voice_and_message.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/whatsappfiles.pcap.out (renamed from test/results/flow-analyse/whatsappfiles.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/whois.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/windowsupdate_over_http.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/wireguard.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/wow.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/xdmcp.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/xiaomi.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/xss.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/yandex.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/youtube_quic.pcap.out (renamed from test/results/flow-analyse/youtube_quic.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/youtubeupload.pcap.out (renamed from test/results/flow-analyse/youtubeupload.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/z3950.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/zabbix.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/zattoo.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/default/zcash.pcap.out (renamed from test/results/flow-analyse/zcash.pcap.out) | 0 | ||||
-rw-r--r-- | test/results/flow-analyse/default/zoom.pcap.out (renamed from test/results/flow-analyse/zoom.pcap.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/default/zoom2.pcap.out (renamed from test/results/flow-analyse/zoom2.pcap.out) | 7 | ||||
-rw-r--r-- | test/results/flow-analyse/default/zoom_p2p.pcapng.out (renamed from test/results/flow-analyse/zoom_p2p.pcapng.out) | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/disable_aggressiveness/ookla.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/disable_protocols/dns_long_domainname.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/disable_protocols/pluralsight.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/disable_protocols/quic-mvfst-27.pcapng.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/disable_protocols/soap.pcap.out | 1 | ||||
-rw-r--r-- | test/results/flow-analyse/firefox.pcap.out | 7 | ||||
-rw-r--r-- | test/results/flow-analyse/http-manipulated.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/ookla.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/quic-mvfst-22_decryption_error.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/safari.pcap.out | 7 | ||||
-rw-r--r-- | test/results/flow-analyse/softether.pcap.out | 2 | ||||
-rw-r--r-- | test/results/flow-analyse/wireguard.pcap.out | 2 |
419 files changed, 175 insertions, 186 deletions
diff --git a/test/results/flow-analyse/chrome.pcap.out b/test/results/flow-analyse/chrome.pcap.out deleted file mode 100644 index 08075df97..000000000 --- a/test/results/flow-analyse/chrome.pcap.out +++ /dev/null @@ -1,7 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.178,146.48.58.18,tcp,64393,443,finished,14,18,1620902507870345,1620902508741011,1620902508774460,0,0,750,1440,1998,15691,0,3,57251.0,629043,154280.9,23802585088.0,2.4,"28765,28872,339,29774,6968,212,36564,499,471,13592,322,42282,28,185,11,28620,3,627868,1163,629043,92,171,257,86,255,319,1121,131143,160052,5604,100",52,605.4,1492,632.9,400560.7,4.2,"64,60,52,569,52,1492,1492,52,758,52,132,802,52,52,355,355,52,52,1492,1492,52,1492,1492,52,1492,1471,52,52,703,52,1492,1492","10,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,9,0,0","0,1,0,0,1,1,1,0,1,0,0,0,1,1,1,1,0,0,1,1,0,1,1,0,1,1,0,0,0,1,1,1","4.353732109,5.187538624,4.899450302,4.408748150,5.023146629,7.839999199,7.885083199,4.976373196,7.695921421,5.053296566,6.239557743,7.672363281,5.100070000,5.100070477,7.407363892,7.424428940,5.014835358,5.053296566,7.878479958,7.865577221,5.014835358,7.868523121,7.861433029,4.976373672,7.872521877,7.876061916,5.014835358,4.969671726,7.674196243,5.138531685,7.867238522,7.866298676",TLS,91,1,Safe,Web,6,DPI,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,64394,443,info,15,17,1620902508740717,1620902509329896,1620902509327995,0,0,717,1440,2136,15926,0,111,37950.2,468764,110334.2,12173627392.0,2.3,"28488,28560,612,28383,2758,30530,2041,28373,116,26422,441785,468764,1748,1393,30158,119,111,182,125,120,237,134,128,266,240,251,495,806,26027,25276,1809",52,617.1,1492,638.0,407026.8,4.2,"64,60,52,687,52,312,52,132,52,355,52,769,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,52,1015,52,756","11,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,1,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,0,1,0,0","4.416232109,5.300120831,4.923394680,7.069493294,5.100070000,6.936732292,5.014835358,6.319468975,5.176993370,7.399957657,5.053297043,7.734244347,5.100070477,7.871783733,7.865388870,5.000318050,7.853028297,7.882699490,5.000318050,7.860120296,7.865950584,4.923395157,7.858026981,7.861842632,4.961856365,7.886532307,7.875236988,5.038779736,4.863714218,7.794827461,4.961856365,7.699286461",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,64411,443,info,16,16,1620902509276446,1620902509372872,1620902509370350,0,0,754,1440,2057,13178,0,0,6139.7,34983,11118.4,123618440.0,3.1,"26769,26817,1326,28249,6762,1293,14,34983,12,374,291,27566,2,0,26902,1379,1360,1118,15,1124,130,231,245,356,130,118,13,252,11,746,1742",52,528.7,1492,598.4,358096.1,4.1,"64,60,52,569,52,1492,1492,758,52,52,132,758,52,355,52,52,355,52,1492,1492,52,52,1492,1492,52,1492,1492,398,52,52,52,806","12,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,0,2,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0","0,1,0,0,1,1,1,1,0,0,0,0,1,1,1,0,1,0,1,1,0,0,1,1,0,1,1,1,0,0,0,0","4.372218132,5.300120354,4.976373672,4.428920269,5.061608315,7.850123882,7.875483036,7.741683960,5.014835358,4.983880520,6.165837288,7.733215809,5.025067329,7.436167240,5.061608315,5.014835358,7.285673618,5.014835358,7.868979931,7.867131233,4.961856842,4.892748356,7.867380619,7.881838322,5.014835358,7.868318081,7.878070354,7.538454533,4.945418835,4.976373672,4.892748356,7.771022320",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,64409,443,info,13,19,1620902509273191,1620902509394114,1620902509395716,0,0,706,1440,1421,19283,0,114,7853.2,30653,12089.6,146159520.0,3.4,"29278,29334,864,29011,2497,30653,580,334,26242,1058,2318,28687,1760,236,1984,377,499,883,126,124,243,136,114,251,129,941,26868,117,26169,1503,132",52,699.6,1492,675.5,456346.8,4.2,"64,60,52,687,52,312,52,132,758,52,52,355,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,52,1492,1492,52,1492,1492","10,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,13,0,0","0,1,0,0,1,1,0,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0,1,1,0,1,1","4.459277153,5.300120831,5.053297043,7.112785339,5.138531685,6.956218719,5.014835358,6.314823151,7.726174831,5.100070477,5.138531685,7.359657288,5.053297043,7.866115093,7.869250298,5.053296566,7.869906902,7.896156788,5.091758251,7.882206440,7.875400543,5.091758251,7.869582176,7.850453377,5.091758251,7.881830215,4.931210041,7.872938633,7.859384537,5.014835358,7.875035286,7.879170895",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,64410,443,info,14,18,1620902509274034,1620902509374250,1620902509399481,0,0,706,1440,1303,17152,0,3,7279.5,38324,12250.6,150076944.0,3.2,"28686,28726,1295,29880,9620,122,15,38324,11,451,233,27995,116,117,14,27547,3,1242,1253,2514,126,125,241,123,122,245,249,230,376,396,25266",52,629.3,1492,651.9,424923.8,4.2,"64,60,52,569,52,1492,1492,758,52,52,132,758,52,52,355,355,52,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,52,1492,52,1492","11,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,1,1,0,0,0,0,1,1,1,1,0,0,1,1,0,1,1,0,1,1,0,1,0,1,0,1","4.459277153,5.227644920,5.053297043,4.381318092,5.061608315,7.847862244,7.882750034,7.710128307,4.976373672,5.014834881,6.203536034,7.715669155,5.047091484,5.061608315,7.379821777,7.371205807,5.038779736,5.014835358,7.886833668,7.871653080,5.053297043,7.876582146,7.890680313,5.053297043,7.866287708,7.867833614,5.053297043,7.851022720,4.931210041,7.851374149,5.053297043,7.874514103",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,64408,443,info,15,17,1620902509272814,1620902509401477,1620902509396846,0,0,709,1440,2130,15696,0,1,8151.5,32013,12799.0,163814464.0,3.3,"29778,29819,1050,30027,2482,31460,377,194,32013,8,1,31458,983,109,1078,130,153,122,98,131,118,249,502,124,630,126,1459,27278,100,26052,4586",52,609.7,1492,634.7,402848.7,4.2,"64,60,52,687,52,312,52,132,758,52,355,52,52,1492,1492,52,1492,52,1492,52,1492,1492,52,1492,1492,52,1492,52,1492,785,52,761","11,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,0,1,1,1,0,1,1,0,1,0,1,0,1,1,0,1,1,0,1,0,1,1,0,0","4.428027153,5.266787052,5.000318050,7.051597595,5.100070000,6.943971634,5.000318050,6.181417465,7.706695080,5.023147106,7.387262821,5.061608315,4.923395157,7.884211063,7.888196468,4.961856365,7.848547459,4.916692734,7.861028194,5.038779736,7.884697914,7.888879299,5.038779736,7.874349594,7.889142036,5.000318050,7.871818066,4.916692734,7.869739056,7.732701302,5.038779736,7.671216488",,,,,,,,"" diff --git a/test/results/flow-analyse/1kxun.pcap.out b/test/results/flow-analyse/default/1kxun.pcap.out index 4981fc333..36e43fe6b 100644 --- a/test/results/flow-analyse/1kxun.pcap.out +++ b/test/results/flow-analyse/default/1kxun.pcap.out @@ -6,18 +6,9 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,192.168.115.8,106.187.35.246,tcp,49600,80,finished,10,22,1470104379117772,1470104379360886,1470104379361184,0,0,362,1260,724,24259,0,23,15694.4,142000,32346.1,1046270720.0,2.8,"54,51945,52076,32,5225,53,60454,877,31,40,63,40,400,73,48,50,170,85115,142000,23,40785,2483,129,70,65,43573,78,404,66,55,49",40,822.0,1300,585.2,342449.5,4.5,"52,52,52,40,40,402,402,46,359,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300","8,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0,0,0,0,0,0,0","0,0,1,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,0,0,1,1,1,1,1,0,0,1,1,1,1","4.540471077,4.540471077,4.993616104,4.784183979,4.784183979,5.806403637,5.806403637,4.330940247,5.620885849,6.705548286,7.731300354,7.779007435,7.737928867,7.737201214,7.704045296,7.681565285,7.569606781,4.071334362,6.314223289,4.784183979,4.784183979,7.705962181,7.781871796,7.735430241,7.740441799,7.698603153,4.834183693,4.834183693,7.712049484,7.719846249,5.648873806,3.023065329",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" 1,ip4,192.168.115.8,106.185.35.110,tcp,49606,80,finished,14,18,1470104379916887,1470104380141237,1470104380142241,0,0,357,1260,714,20160,0,26,14506.6,146838,33179.1,1100853504.0,2.6,"56,37783,37994,70,1795,58,38952,109751,153,146838,45,329,66,113,56,463,29,236,62,115,388,44,244,36267,36544,26,410,130,482,92,113",40,693.6,1300,612.0,374554.6,4.3,"52,52,52,40,40,397,397,46,1300,1300,40,40,1300,1300,1300,1300,40,40,1300,1300,1300,40,40,1300,1300,40,40,1300,1300,1300,1300,1300","12,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0,0,0,0","0,0,1,0,0,0,0,1,1,1,0,0,1,1,1,1,0,0,1,1,1,0,0,1,1,0,0,1,1,1,1,1","4.540471077,4.540471077,4.955154896,4.784183979,4.784183979,5.758289814,5.758289814,4.303872585,5.568258762,4.972586632,4.784183979,4.784183979,4.816908836,5.305360317,5.245053291,5.141684532,4.684184074,4.684184074,5.953328609,5.139973164,5.197480202,4.784183979,4.784183979,5.838756561,5.133826733,4.734184265,4.734184265,4.452571869,4.709616661,4.691545486,5.564413548,5.160192013",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"11" 1,ip4,192.168.115.8,42.120.51.152,tcp,49609,8080,finished,19,13,1470104380890420,1470104382084858,1470104381881083,0,0,445,1260,3612,6271,0,25,70487.1,398999,104302.2,10878943232.0,3.6,"50,76520,76599,25,1136,41,62341,85,61755,47,298859,73,398999,66467,177,166123,34,60273,507,89,60822,34,117112,46,178142,469,61984,45,102335,44259,349653",40,350.6,1300,410.3,168364.1,4.1,"52,52,48,40,40,292,292,46,65,485,485,485,485,46,1300,1300,40,40,1300,1300,528,40,40,267,267,46,65,477,477,46,733,40","9,0,0,0,0,0,0,4,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0","0,0,1,0,0,0,0,1,1,0,0,0,0,1,1,1,0,0,1,1,1,0,0,0,0,1,1,0,0,1,1,0","4.633441925,4.633441925,4.967222691,4.981687069,4.981687069,5.768459320,5.768459320,4.652828693,5.358993053,6.064707279,6.064707279,6.054220200,6.054220200,4.609350204,5.268521309,4.718248367,4.931687355,4.931687355,4.699154854,5.227048397,4.912804604,4.931686878,4.931686878,5.830219269,5.830219269,4.609350204,5.397304058,6.051352978,6.051352978,4.696306705,5.685911179,4.912815094",HTTP,7,0,Acceptable,Web,6,DPI,"5,12" -1,ip4,192.168.115.8,183.131.48.144,tcp,49613,80,finished,20,12,1470104382053678,1470104384990940,1470104384790982,0,0,503,1024,1006,9497,0,26,183050.5,862765,252834.9,63925489664.0,3.6,"31,69271,69368,26,1928,34,67940,1399,6083,291,73959,37,665858,862765,47,408647,411020,37,251400,251827,47,336785,335976,58,329935,190,130781,55,599505,799208,58",40,369.3,1064,452.5,204736.5,3.9,"52,52,46,40,40,543,543,46,321,1064,1064,40,40,1064,40,40,1064,40,40,1064,40,40,1064,40,40,1064,1064,40,40,1064,40,40","18,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,0,0,0,1,1,1,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,1,0,0,1,0,0","4.463547707,4.463547707,4.611080170,4.784183979,4.784183979,5.504161358,5.504161358,4.457919598,5.616157532,3.396698952,2.285910130,4.834183693,4.834183693,2.224251509,4.834183693,4.834183693,2.277304173,4.834183693,4.834183693,2.234616041,4.834183693,4.834183693,2.318356037,4.834183693,4.834183693,2.277927399,2.247195482,4.834183693,4.834183693,2.248827934,4.834183693,4.834183693",HTTP,7,0,Acceptable,Media,6,DPI,"11,12" 1,ip4,192.168.115.8,106.187.35.246,tcp,49603,80,finished,11,21,1470104379118972,1470104424311883,1470104379310452,0,0,361,1260,723,22966,0,19,1464012.6,45001141,7948794.0,63183326806016.0,0.1,"34,54477,54551,26,4891,45,65495,70,68,364,89,71,208,46,29,27,25,61484,19,69006,62,56,48,731,52,51,51,454,70696,24,45001141",40,781.6,1300,593.2,351838.7,4.4,"52,52,52,40,40,401,401,46,359,1300,1300,1300,1300,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300,1300,1300,1300,1300,1267,40,40,41","9,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,17,0,0,0,0,0,0,0,0","0,0,1,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,0,0,1,1,1,1,1,1,1,1,1,0,0,0","4.578932762,4.578932762,5.032077789,4.884183884,4.884183884,5.794129372,5.794129372,4.434307098,5.652597904,7.484868050,7.818575859,7.782110691,7.797027111,7.823266506,7.845933437,7.821538448,7.845500469,7.838393688,4.834183693,4.834183693,7.836544514,7.832671165,7.837013721,7.831301689,7.829290867,7.832065582,7.849477768,7.838781357,7.842006683,4.884183884,4.884183884,4.829466343",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" 1,ip4,192.168.2.126,172.105.121.82,tcp,46170,80,finished,2,30,1654385136207603,1654385137102946,1654385137455380,208,0,212,21600,420,143010,1,0,69132.9,895343,184366.4,33990969344.0,2.2,"356191,54,308075,59,2442,3212,112,200163,0,56,36,29,26,27,25,1594,86,63,42,33,23,24,35,23,895343,371980,1,1344,81,1941,0",260,4534.2,21652,5608.1,31450232.0,4.2,"264,373,13012,14452,2932,2932,1492,7252,2932,1492,2932,2932,1492,1492,1492,1492,1492,4372,6324,2932,2932,1492,1492,1492,788,260,373,17332,21652,1492,4372,17332","0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,16","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1","5.893450737,5.720896244,7.959624290,7.965476036,7.917325974,7.914794445,7.850610256,7.954618454,7.905844212,7.834187031,7.916584969,7.918063164,7.852417469,7.840590954,7.847774029,7.850798130,7.845216751,7.939498901,7.947888374,7.909615040,7.916443348,7.857475281,7.837258339,7.835073948,7.714247704,5.815073967,5.763088703,7.974996090,7.979550838,7.864511967,7.949629784,7.970819473",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,172.105.121.82,tcp,60148,80,finished,5,27,1654385131029337,1654385137110902,1654385137463937,202,0,212,21600,1039,156844,1,0,403747.2,4660887,1126862.6,1269819375616.0,2.4,"306055,4848,325793,248766,0,4660887,4604216,364,552,841,1047,367664,0,134,94,2523,0,311381,0,119,1695,102,878348,204467,0,1564,1050,216537,375544,43,1531",254,4985.8,21652,6236.2,38890032.0,4.1,"254,370,6284,254,370,5668,264,372,1492,1492,7252,2932,5812,2932,10132,2932,1492,5812,2932,1492,8692,1492,5754,263,372,20212,21652,15349,264,373,2932,21652","0,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,2,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,17","0,1,1,0,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,0,1,1,1","5.855428219,5.722984791,7.936409950,5.839015007,5.749445915,7.913037300,5.895416737,5.774818897,7.526371002,7.860151768,7.955783844,7.904475212,7.946855068,7.922424793,7.958326817,7.918138504,7.851068020,7.947721004,7.924707413,7.854940414,7.955513000,7.859978199,7.947089672,5.929639816,5.726084709,7.965382099,7.968444347,7.959605694,5.904361725,5.721296787,7.762065887,7.963563442",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,172.105.121.82,tcp,46200,80,finished,2,30,1654385136215384,1654385137106944,1654385137800355,212,0,212,21600,424,219741,1,0,79888.1,891560,189010.9,35725131776.0,2.5,"348410,61,2586,311307,74,1916,87,90,200152,34,703,82,0,83,0,49,891560,375934,1624,82,2179,0,1527,332757,94,46,1896,46,1564,0,1588",264,6932.2,21652,6776.1,45915728.0,4.3,"264,372,1492,11572,1492,4372,2932,13012,7252,1492,1492,1492,1492,2932,2932,1492,4591,264,374,21652,2932,10132,11572,17332,7252,18772,5812,20212,1492,10132,11572,21652","0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,20","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.907779694,5.727939606,7.439003944,7.956123352,7.841159344,7.930701256,7.923262119,7.962357998,7.944649220,7.845450401,7.840456009,7.848997116,7.852864742,7.909528732,7.921172619,7.844360828,7.935763836,5.871500015,5.737739563,7.220952511,7.767323017,7.970802784,7.950772762,7.960227966,7.942826271,7.962452412,7.924762726,7.957526207,7.815425396,7.959965229,7.959893227,7.962502480",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" 1,ip4,192.168.2.126,161.117.13.29,tcp,45380,80,finished,3,29,1654385140171515,1654385140959776,1654385142015753,424,0,765,8640,1625,79973,1,331,84919.3,408625,132393.4,17528006656.0,3.3,"380392,4573,408625,215737,457,986,1014,178521,331,482,379636,185383,1426,654,331743,5741,174159,6079,334,924,170502,413,6008,1070,341,710,169481,463,585,5307,422",476,2601.9,8692,2200.3,4841425.0,4.6,"817,1492,1253,488,1492,1492,7252,4372,1492,1492,2504,476,2932,8692,1492,2932,8692,2932,1492,1492,7252,1492,1492,2932,1492,1492,2932,1492,1492,2932,1492,1492","0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,16,0,12","0,1,1,0,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.859029770,7.746788025,7.815745831,5.897830009,7.640064240,7.862792492,7.967751980,7.950705051,7.860798836,7.868959904,7.893837929,5.886357784,7.845828056,7.976538658,7.857397079,7.933415890,7.973951340,7.934168339,7.877964020,7.860165596,7.967057228,7.876602173,7.849090099,7.929278374,7.849063396,7.848120213,7.928964138,7.852302074,7.863938808,7.928197861,7.863379478,7.881860733",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,14.136.136.108,tcp,49354,80,finished,2,30,1654385145219802,1654385146051643,1654385146466639,526,0,526,10080,1052,96620,1,0,67054.1,831841,169464.5,28718202880.0,2.4,"207030,367,1074,749,203546,401,538,843,360,1168,0,622,204026,463,1910,0,0,808,831841,413644,0,1524,1634,381,916,201620,415,562,974,897,365",337,3104.2,10132,2492.5,6212617.0,4.6,"578,337,1492,8692,2932,1492,1492,2932,1492,1492,5812,4372,1492,1492,1492,5812,2932,2932,3942,578,337,1492,8692,10132,5812,2932,1492,1492,2932,4372,4372,1492","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,16","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1","5.836778641,5.800940037,7.833999634,7.976774216,7.942587852,7.846837997,7.855956078,7.933282375,7.886686802,7.866371155,7.968765736,7.957736492,7.885743618,7.873675346,7.876061440,7.966520309,7.932492733,7.934986115,7.950095177,5.861396790,5.841276169,7.808639050,7.978169918,7.980235577,7.968087673,7.920913696,7.863669872,7.851905346,7.935641766,7.952698708,7.959656239,7.886331558",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,14.136.136.108,tcp,49370,80,finished,2,30,1654385146263001,1654385147139518,1654385147568107,514,0,526,15840,1040,85228,1,0,70374.9,876517,169534.6,28741967872.0,2.6,"216812,0,1301,0,1174,217584,379,838,0,730,814,206371,3184,729,0,1431,202135,477,2906,412,436,624,0,742,876517,236517,1,2089,899,206105,416",337,2747.9,15892,3042.0,9253907.0,4.4,"566,337,1492,4372,1492,5812,1492,1492,1492,1492,1492,2932,1492,4372,2932,2932,8692,1492,1492,1492,1492,1492,1492,1492,1190,578,337,7252,15892,4372,1492,1492","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,17,0,10","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1","5.857450962,5.836749077,7.826755047,7.934190273,7.674187660,7.939618587,7.839453220,7.840780735,7.846045494,7.830045223,7.801501751,7.909759045,7.855455875,7.935122013,7.917196274,7.838707447,7.965010166,7.842932224,7.847500801,7.848862648,7.845387459,7.829781055,7.842148304,7.830836773,7.812441826,5.880833626,5.847996712,7.975015640,7.987394810,7.957153320,7.871502399,7.839539528",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" 1,ip4,192.168.2.126,14.136.136.108,tcp,49380,80,finished,2,30,1654385146276743,1654385147163604,1654385147585918,514,0,526,18720,1040,97896,1,0,70839.9,886861,171207.7,29312067584.0,2.6,"223740,209594,1687,0,207155,354,1309,724,462,462,1177,203967,420,1398,676,628,3543,0,0,886861,237591,464,978,2452,823,206716,876,409,919,0,651",337,3143.8,18772,3724.0,13867894.0,4.3,"566,2932,1492,1492,11572,1492,1492,2932,1492,1492,1492,7252,1492,1492,1492,1492,4372,1492,2932,4239,578,337,1492,8692,18772,1492,2932,1492,1492,5812,1492,1316","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,17,0,11","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1","5.862786770,7.902865887,7.781876564,7.771229267,7.963672161,7.848064899,7.850860119,7.915616512,7.853264332,7.865233421,7.839958668,7.951301098,7.843721867,7.832941532,7.839491367,7.869894028,7.948531628,7.838067055,7.923059940,7.938112259,5.870801449,5.836921215,7.830684185,7.978819847,7.990375519,7.851813316,7.925859928,7.854060650,7.888266563,7.969222546,7.854313850,7.852722645",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" 1,ip4,192.168.2.126,14.136.136.108,tcp,49372,80,finished,3,29,1654385146253018,1654385147560064,1654385147928387,514,0,526,18720,1554,113644,1,0,96206.9,899707,188732.5,35619966976.0,3.0,"205636,2121,0,0,1,224803,394,328,1444,0,193718,403,372,1728,1281,1888,225980,899707,237971,1,2439,199154,468,952,1305,0,0,407339,371504,0,1478",337,3651.9,18772,4182.9,17496908.0,4.3,"566,337,1492,4372,2932,4372,1492,1492,1492,1492,5812,1492,1492,1492,2932,4372,5812,3718,578,337,7252,15892,1492,1492,7252,1492,5812,640,566,337,7787,18772","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,14","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,0,1,1,1","5.863167286,5.867280483,7.343351841,7.933300972,7.883011341,7.923881531,7.831630230,7.793837070,7.811074257,7.877987385,7.956270695,7.807632446,7.787700176,7.808306217,7.895200729,7.941674709,7.934331417,7.911615372,5.884228706,5.838101864,7.975082397,7.990115643,7.874265194,7.866392612,7.972415924,7.851024628,7.967773914,7.664193153,5.866144657,5.879995346,7.941644669,7.977370262",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" 1,ip4,192.168.2.126,161.117.13.29,tcp,45416,80,finished,8,24,1654385140835391,1654385156967826,1654385157149701,434,0,1114,14400,6674,81693,1,0,1046669.2,6045020,1981650.1,3926937042944.0,3.0,"188503,1,1404,179436,1430,692,418,2433,676,270050,61,0,644,0,3892849,3428911,186128,186289,192621,208977,367165,352334,5253796,5339015,3643,6045020,5959115,408,493,194856,189377",486,2813.5,14452,2993.9,8963654.0,4.4,"486,2932,2932,8692,2932,7252,1492,1492,14452,1492,2932,2932,7252,7252,4078,803,695,805,1511,807,1401,803,1516,1065,2932,1130,1155,1492,1492,1575,1166,1083","0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,1,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,1,0,0,7,0,13","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,0,1,0,1,0,1,0,1,1,0,1,1,1,0,1","5.943944454,7.829628944,7.931543350,7.979783535,7.931476593,7.968062401,7.861111164,7.864268780,7.984925747,7.877884388,7.929042339,7.930032253,7.967924595,7.974642754,7.952368736,5.943904400,6.386446476,5.942170143,7.482911110,5.931495190,6.238120556,5.934639931,6.488353729,5.849187374,6.477306366,6.757167339,5.825885773,6.421376705,7.814886093,7.859082222,5.823412418,6.869374752",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,172.105.121.82,tcp,46184,80,finished,4,28,1654385136206220,1654385176599830,1654385177114485,207,0,212,23040,838,163493,1,0,2622641.0,39119714,9528466.0,90791657603072.0,1.3,"353699,0,3771,104,303718,4300,92,205833,106,0,880957,368900,1,5053,392939,352227,0,1591,70,2344,55,1451,285655,0,2146,39119714,38675191,1,2923,335353,3681",259,5187.3,23092,6479.7,41986280.0,4.1,"264,372,1492,1492,10132,2932,2932,23092,1492,1492,1158,259,372,18772,7743,264,373,1492,21652,4372,17332,4372,10132,5812,1492,5145,259,374,1492,11572,2932,2932","0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,7,0,16","0,1,1,1,1,1,1,1,1,1,1,0,1,1,1,0,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1","5.840793610,5.758453846,7.221220016,7.581106663,7.944396973,7.912007809,7.918235779,7.968857765,7.829185963,7.833258629,7.814552307,5.918824673,5.722350121,7.963245392,7.958693981,5.886214256,5.716395378,7.016712666,7.971186638,7.917016029,7.966053009,7.937659740,7.962855339,7.935114861,7.850684166,7.933465481,5.848567009,5.760809898,7.509957790,7.938345909,7.890325069,7.878456116",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,172.105.121.82,tcp,38314,80,finished,2,30,1654385176794172,1654385178155648,1654385178652815,207,0,207,15840,414,190898,1,0,103874.8,1361476,260786.7,68009684992.0,2.5,"326102,0,0,0,180,328843,179,2720,0,177591,469,1313,2855,118,155,777,2306,401346,1361476,293524,1,1093,2137,2758,88,201,2770,309632,0,0,1485",259,6030.5,15892,5319.9,28301380.0,4.4,"259,374,1492,1492,2932,7252,1492,8692,2932,15892,1492,1492,4372,13012,8692,2932,1492,15892,13186,259,374,1492,5812,15892,11572,10132,4372,14452,2932,2932,13012,4372","0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,21","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1","5.862609386,5.739748001,7.483025551,7.871859074,7.907062054,7.948117256,7.824954033,7.955245495,7.912051678,7.957016468,7.844995975,7.818977833,7.915155411,7.942556381,7.931100368,7.889071465,7.843290806,7.954283714,7.957226276,5.824898720,5.733853340,7.490488529,7.941090584,7.961003304,7.942962170,7.945000648,7.908642769,7.925697327,7.901566505,7.900532722,7.942762852,7.917910576",HTTP.1kxun,7.295,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.2.126,18.66.2.90,tcp,35664,80,finished,1,31,1654385184927393,1654385184927393,1654385184996498,183,0,183,7140,183,129251,1,0,2229.2,14880,3186.7,10155003.0,3.8,"14880,612,571,2499,0,0,3579,106,930,0,2545,9210,1,87,6481,115,1571,2984,1607,79,1540,90,67,2792,6531,3088,0,2380,1844,2843,73",235,4096.8,7192,1776.8,3156934.0,4.8,"235,783,1480,2908,4336,4336,4336,4336,2908,1480,4336,4336,2908,4336,4336,2908,4336,5764,5764,5764,5764,4336,5764,1480,5764,4336,2908,7192,4336,7192,7192,2908","0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,27","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.996097565,5.777042866,7.226827621,7.290063858,7.169473648,7.549562454,7.741216660,7.886993408,7.805087090,7.871054173,7.816677570,7.889826775,7.874413013,7.855673790,7.883734226,7.880590916,7.907371998,7.911734104,7.904975414,7.920679092,7.923110485,7.898054600,7.889371872,7.836673737,7.848505497,7.876494408,7.870183945,7.916009903,7.791001797,7.856836319,7.815247536,7.823584557",HTTP,7,0,Acceptable,Web,6,DPI,"" -1,ip4,192.168.2.126,18.64.103.30,tcp,36640,80,finished,1,31,1654385184944474,1654385184944474,1654385185026289,497,0,497,5712,497,108528,1,0,2639.2,21003,4638.3,21513396.0,3.6,"21003,154,0,129,0,3134,0,1686,3067,15801,2210,0,2030,2737,73,1485,603,2873,1573,1531,81,0,114,3525,1587,2816,10499,1437,55,0,1612",549,3459.0,5764,1697.9,2882863.0,4.8,"549,1480,1480,2908,1480,2908,1480,4336,4336,4336,2908,1480,4336,1480,4336,4336,4336,5764,5764,4336,1480,1480,1480,4336,5764,5764,3200,4188,5576,1524,5764,5764","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,1,21","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.799116135,7.840260029,7.837001801,7.939268112,7.819420338,7.933657646,7.851344109,7.947911739,7.957500458,7.951948166,7.927341938,7.869306087,7.937100410,7.834094048,7.880655766,7.952060223,7.945407391,7.962455273,7.963794708,7.945417404,7.845272064,7.833052158,7.834871292,7.945909023,7.953672886,7.962710381,7.899997234,7.937138081,7.962800980,7.869377136,7.964761734,7.964723110",HTTP,7,0,Acceptable,Web,6,DPI,"" diff --git a/test/results/flow-analyse/443-chrome.pcap.out b/test/results/flow-analyse/default/443-chrome.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/443-chrome.pcap.out +++ b/test/results/flow-analyse/default/443-chrome.pcap.out diff --git a/test/results/flow-analyse/443-curl.pcap.out b/test/results/flow-analyse/default/443-curl.pcap.out index cc4123c8a..cc4123c8a 100644 --- a/test/results/flow-analyse/443-curl.pcap.out +++ b/test/results/flow-analyse/default/443-curl.pcap.out diff --git a/test/results/flow-analyse/443-firefox.pcap.out b/test/results/flow-analyse/default/443-firefox.pcap.out index 2a8ca3e83..2a8ca3e83 100644 --- a/test/results/flow-analyse/443-firefox.pcap.out +++ b/test/results/flow-analyse/default/443-firefox.pcap.out diff --git a/test/results/flow-analyse/443-git.pcap.out b/test/results/flow-analyse/default/443-git.pcap.out index cc849e387..cc849e387 100644 --- a/test/results/flow-analyse/443-git.pcap.out +++ b/test/results/flow-analyse/default/443-git.pcap.out diff --git a/test/results/flow-analyse/443-opvn.pcap.out b/test/results/flow-analyse/default/443-opvn.pcap.out index dd639e558..dd639e558 100644 --- a/test/results/flow-analyse/443-opvn.pcap.out +++ b/test/results/flow-analyse/default/443-opvn.pcap.out diff --git a/test/results/flow-analyse/443-safari.pcap.out b/test/results/flow-analyse/default/443-safari.pcap.out index 592c26e2f..592c26e2f 100644 --- a/test/results/flow-analyse/443-safari.pcap.out +++ b/test/results/flow-analyse/default/443-safari.pcap.out diff --git a/test/results/flow-analyse/4in4tunnel.pcap.out b/test/results/flow-analyse/default/4in4tunnel.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/4in4tunnel.pcap.out +++ b/test/results/flow-analyse/default/4in4tunnel.pcap.out diff --git a/test/results/flow-analyse/4in6tunnel.pcap.out b/test/results/flow-analyse/default/4in6tunnel.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/4in6tunnel.pcap.out +++ b/test/results/flow-analyse/default/4in6tunnel.pcap.out diff --git a/test/results/flow-analyse/6in4tunnel.pcap.out b/test/results/flow-analyse/default/6in4tunnel.pcap.out index e72f56dd5..e72f56dd5 100644 --- a/test/results/flow-analyse/6in4tunnel.pcap.out +++ b/test/results/flow-analyse/default/6in4tunnel.pcap.out diff --git a/test/results/flow-analyse/6in6tunnel.pcap.out b/test/results/flow-analyse/default/6in6tunnel.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/6in6tunnel.pcap.out +++ b/test/results/flow-analyse/default/6in6tunnel.pcap.out diff --git a/test/results/flow-analyse/BGP_Cisco_hdlc_slarp.pcap.out b/test/results/flow-analyse/default/BGP_Cisco_hdlc_slarp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/BGP_Cisco_hdlc_slarp.pcap.out +++ b/test/results/flow-analyse/default/BGP_Cisco_hdlc_slarp.pcap.out diff --git a/test/results/flow-analyse/BGP_redist.pcap.out b/test/results/flow-analyse/default/BGP_redist.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/BGP_redist.pcap.out +++ b/test/results/flow-analyse/default/BGP_redist.pcap.out diff --git a/test/results/flow-analyse/EAQ.pcap.out b/test/results/flow-analyse/default/EAQ.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/EAQ.pcap.out +++ b/test/results/flow-analyse/default/EAQ.pcap.out diff --git a/test/results/flow-analyse/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out b/test/results/flow-analyse/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out index 6d789bb7a..fe3e0b58a 100644 --- a/test/results/flow-analyse/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out +++ b/test/results/flow-analyse/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out @@ -1,4 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.35.40.22,10.23.1.42,udp,2944,2944,finished,16,16,1228468937630923,1228468963851351,1228468963854227,45,0,334,372,1020,3039,0,15,1691733.2,4370196,2031243.2,4125948903424.0,3.7,"147,2580,146,4369720,177,4369379,142,4370170,85,4370186,150,4369866,79,4370149,291,4370036,88,4369436,150,3508424,3524296,204367,192966,657514,15,652477,151,4369658,82,4370196,609",73,154.8,400,98.9,9786.3,4.7,"73,73,278,150,73,73,278,150,73,73,278,150,73,73,278,150,73,73,278,150,362,400,80,87,74,74,279,151,74,74,279,151","0,15,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,7,0,0,0,7,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,0,1,0,0,1,1,0,0,1,1","5.184563637,5.058271885,5.379110336,5.406789303,5.184563637,5.179216385,5.374631405,5.446616650,5.168875217,5.151818752,5.378158569,5.424983501,5.206613541,5.151818752,5.376394272,5.444680214,5.168875217,5.134762764,5.362365723,5.408768177,5.778869152,5.247618675,5.299749374,5.105933189,5.158446312,5.175271988,5.367991447,5.455423832,5.202299118,5.175271988,5.384085178,5.429594994",Megaco,181,0,Acceptable,VoIP,6,DPI,"" +1,ip4,10.35.40.22,10.23.1.42,udp,2944,2944,finished,16,16,1228468937630923,1228468963851351,1228468963854227,45,0,334,372,1020,3039,0,15,1691733.2,4370196,2031243.2,4125948903424.0,3.7,"147,2580,146,4369720,177,4369379,142,4370170,85,4370186,150,4369866,79,4370149,291,4370036,88,4369436,150,3508424,3524296,204367,192966,657514,15,652477,151,4369658,82,4370196,609",73,154.8,400,98.9,9786.3,4.7,"73,73,278,150,73,73,278,150,73,73,278,150,73,73,278,150,73,73,278,150,362,400,80,87,74,74,279,151,74,74,279,151","0,15,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,7,0,0,0,7,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,0,1,0,0,1,1,0,0,1,1","5.184563637,5.058271885,5.379110336,5.406789303,5.184563637,5.179216385,5.374631405,5.446616650,5.168875217,5.151818752,5.378158569,5.424983501,5.206613541,5.151818752,5.376394272,5.444680214,5.168875217,5.134762764,5.362365723,5.408768177,5.778869152,5.247618675,5.299749374,5.105933189,5.158446312,5.175271988,5.367991447,5.455423832,5.202299118,5.175271988,5.384085178,5.429594994",Megaco,181,0,Acceptable,VoIP,6,DPI,"46" 1,ip4,10.35.60.100,10.23.1.52,udp,15580,16756,finished,32,0,1228468965434208,1228468966054624,1228468965434208,172,0,172,0,5504,0,0,1438,20013.4,39530,4863.7,23655656.0,4.9,"20823,19142,39530,1438,19970,20000,19294,20526,19616,19873,20995,20283,18519,20415,19722,19948,20367,20228,19700,20355,19296,20527,20111,20020,19630,19979,19869,20276,20190,19810,19964",200,200.0,200,0.0,0.0,5.0,"200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200","0,0,0,0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1.668765187,1.658265829,1.688265920,1.668265820,1.688265920,1.664491415,1.674491525,1.654990792,1.678265929,1.688265920,1.674491405,2.400679350,2.428031683,2.447857141,2.461457968,2.439298868,2.470501661,2.457857370,2.473841906,2.452007294,2.451812983,2.430955410,2.434056997,2.410386086,2.416019678,2.457857370,2.467857122,2.455026150,2.458799601,2.438038588,2.441251755,2.457820177",RTP,87,0,Acceptable,Media,6,DPI,"" -1,ip4,10.35.40.25,10.35.40.200,udp,5060,5060,finished,16,16,1228468958651923,1228469002203721,1228469002181512,383,0,881,852,9868,8158,0,263,2809077.0,27628387,6895590.0,47549159309312.0,2.5,"1429,5975,263,162733,421,6673080,696,6843298,378,2041486,761,2040704,344,12449,653,131771,424,27628387,388,27585469,481,6913792,703,6841323,326,83992,388,88136,409,19767,961",290,591.3,909,211.9,44888.2,4.9,"905,905,290,290,474,474,811,811,438,438,880,880,411,411,779,779,479,479,446,446,558,558,832,832,350,350,461,461,438,438,909,909","0,0,0,0,0,0,0,0,0,0,0,2,4,2,0,0,0,0,0,0,0,0,0,2,0,2,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,2,0,2,0,0,4,2,0,2,0,0,0,0,0,0,0,2,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,1,1,1,1,0,0,1,1,0,0,0,0,1,1,0,0,1,1,0,0,1,1,1,1,0,0,0,0","5.687162399,5.687162399,5.626669884,5.626669884,5.571601391,5.571601391,5.667925358,5.667925358,5.573338985,5.573338985,5.690092564,5.690092564,5.617296219,5.617296219,5.771171570,5.771171570,5.591165543,5.591165543,5.621240139,5.621240139,5.739367962,5.739367962,5.722489834,5.722489834,5.587724209,5.587724209,5.563357353,5.563357353,5.591295242,5.591295242,5.709114552,5.709114552",SIP,100,0,Acceptable,VoIP,6,DPI,"" +1,ip4,10.35.40.25,10.35.40.200,udp,5060,5060,finished,16,16,1228468958651923,1228469002203721,1228469002181512,383,0,881,852,9868,8158,0,263,2809077.0,27628387,6895590.0,47549159309312.0,2.5,"1429,5975,263,162733,421,6673080,696,6843298,378,2041486,761,2040704,344,12449,653,131771,424,27628387,388,27585469,481,6913792,703,6841323,326,83992,388,88136,409,19767,961",290,591.3,909,211.9,44888.2,4.9,"905,905,290,290,474,474,811,811,438,438,880,880,411,411,779,779,479,479,446,446,558,558,832,832,350,350,461,461,438,438,909,909","0,0,0,0,0,0,0,0,0,0,0,2,4,2,0,0,0,0,0,0,0,0,0,2,0,2,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,2,0,2,0,0,4,2,0,2,0,0,0,0,0,0,0,2,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,1,1,1,1,0,0,1,1,0,0,0,0,1,1,0,0,1,1,0,0,1,1,1,1,0,0,0,0","5.687162399,5.687162399,5.626669884,5.626669884,5.571601391,5.571601391,5.667925358,5.667925358,5.573338985,5.573338985,5.690092564,5.690092564,5.617296219,5.617296219,5.771171570,5.771171570,5.591165543,5.591165543,5.621240139,5.621240139,5.739367962,5.739367962,5.722489834,5.722489834,5.587724209,5.587724209,5.563357353,5.563357353,5.591295242,5.591295242,5.709114552,5.709114552",SIP,100,0,Acceptable,VoIP,6,DPI,"46" diff --git a/test/results/flow-analyse/IEC104.pcap.out b/test/results/flow-analyse/default/IEC104.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/IEC104.pcap.out +++ b/test/results/flow-analyse/default/IEC104.pcap.out diff --git a/test/results/flow-analyse/KakaoTalk_chat.pcap.out b/test/results/flow-analyse/default/KakaoTalk_chat.pcap.out index eccf1a37a..eccf1a37a 100644 --- a/test/results/flow-analyse/KakaoTalk_chat.pcap.out +++ b/test/results/flow-analyse/default/KakaoTalk_chat.pcap.out diff --git a/test/results/flow-analyse/KakaoTalk_talk.pcap.out b/test/results/flow-analyse/default/KakaoTalk_talk.pcap.out index 75c635c22..75c635c22 100644 --- a/test/results/flow-analyse/KakaoTalk_talk.pcap.out +++ b/test/results/flow-analyse/default/KakaoTalk_talk.pcap.out diff --git a/test/results/flow-analyse/NTPv2.pcap.out b/test/results/flow-analyse/default/NTPv2.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/NTPv2.pcap.out +++ b/test/results/flow-analyse/default/NTPv2.pcap.out diff --git a/test/results/flow-analyse/NTPv3.pcap.out b/test/results/flow-analyse/default/NTPv3.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/NTPv3.pcap.out +++ b/test/results/flow-analyse/default/NTPv3.pcap.out diff --git a/test/results/flow-analyse/NTPv4.pcap.out b/test/results/flow-analyse/default/NTPv4.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/NTPv4.pcap.out +++ b/test/results/flow-analyse/default/NTPv4.pcap.out diff --git a/test/results/flow-analyse/Oscar.pcap.out b/test/results/flow-analyse/default/Oscar.pcap.out index ade9f6ffb..ade9f6ffb 100644 --- a/test/results/flow-analyse/Oscar.pcap.out +++ b/test/results/flow-analyse/default/Oscar.pcap.out diff --git a/test/results/flow-analyse/TivoDVR.pcap.out b/test/results/flow-analyse/default/TivoDVR.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/TivoDVR.pcap.out +++ b/test/results/flow-analyse/default/TivoDVR.pcap.out diff --git a/test/results/flow-analyse/WebattackRCE.pcap.out b/test/results/flow-analyse/default/WebattackRCE.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/WebattackRCE.pcap.out +++ b/test/results/flow-analyse/default/WebattackRCE.pcap.out diff --git a/test/results/flow-analyse/WebattackSQLinj.pcap.out b/test/results/flow-analyse/default/WebattackSQLinj.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/WebattackSQLinj.pcap.out +++ b/test/results/flow-analyse/default/WebattackSQLinj.pcap.out diff --git a/test/results/flow-analyse/WebattackXSS.pcap.out b/test/results/flow-analyse/default/WebattackXSS.pcap.out index 3237ca8bd..3237ca8bd 100644 --- a/test/results/flow-analyse/WebattackXSS.pcap.out +++ b/test/results/flow-analyse/default/WebattackXSS.pcap.out diff --git a/test/results/flow-analyse/activision.pcap.out b/test/results/flow-analyse/default/activision.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/activision.pcap.out +++ b/test/results/flow-analyse/default/activision.pcap.out diff --git a/test/results/flow-analyse/afp.pcap.out b/test/results/flow-analyse/default/adult_content.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/afp.pcap.out +++ b/test/results/flow-analyse/default/adult_content.pcap.out diff --git a/test/results/flow-analyse/agora-sd-rtn.pcap.out b/test/results/flow-analyse/default/afp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/agora-sd-rtn.pcap.out +++ b/test/results/flow-analyse/default/afp.pcap.out diff --git a/test/results/flow-analyse/ah.pcapng.out b/test/results/flow-analyse/default/agora-sd-rtn.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ah.pcapng.out +++ b/test/results/flow-analyse/default/agora-sd-rtn.pcap.out diff --git a/test/results/flow-analyse/ajp.pcap.out b/test/results/flow-analyse/default/ah.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ajp.pcap.out +++ b/test/results/flow-analyse/default/ah.pcapng.out diff --git a/test/results/flow-analyse/alicloud.pcap.out b/test/results/flow-analyse/default/ajp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/alicloud.pcap.out +++ b/test/results/flow-analyse/default/ajp.pcap.out diff --git a/test/results/flow-analyse/alexa-app.pcapng.out b/test/results/flow-analyse/default/alexa-app.pcapng.out index 1371472ba..1371472ba 100644 --- a/test/results/flow-analyse/alexa-app.pcapng.out +++ b/test/results/flow-analyse/default/alexa-app.pcapng.out diff --git a/test/results/flow-analyse/among_us.pcap.out b/test/results/flow-analyse/default/alicloud.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/among_us.pcap.out +++ b/test/results/flow-analyse/default/alicloud.pcap.out diff --git a/test/results/flow-analyse/avast.pcap.out b/test/results/flow-analyse/default/among_us.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/avast.pcap.out +++ b/test/results/flow-analyse/default/among_us.pcap.out diff --git a/test/results/flow-analyse/amqp.pcap.out b/test/results/flow-analyse/default/amqp.pcap.out index 733684bd4..3d0f20efb 100644 --- a/test/results/flow-analyse/amqp.pcap.out +++ b/test/results/flow-analyse/default/amqp.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,127.0.0.1,127.0.1.1,tcp,44205,5672,finished,16,16,1490904166118902,1490904169595775,1490904169595788,37,0,329,0,2113,0,1,31,224314.8,2001684,536643.9,287986745344.0,2.4,"31,198,177,103,103,2001663,2001684,188,167,98,97,1032593,1032598,113,109,94,93,11037,11041,111,108,94,93,17674,17676,105,104,99,99,412703,412706",52,118.0,381,99.5,9895.7,4.6,"93,52,148,52,355,52,93,52,148,52,355,52,90,52,148,52,381,52,89,52,148,52,257,52,91,52,148,52,311,52,90,52","0,6,0,5,0,0,1,0,1,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.892737865,4.569115162,5.131951332,4.569115162,5.420554638,4.569115162,4.937272072,4.569115162,5.150565624,4.569115162,5.432780266,4.569115162,4.933847904,4.569115162,5.110024929,4.516136646,5.444756508,4.569115162,4.894715786,4.569115162,5.123056412,4.569115162,5.521058559,4.530653477,4.818450451,4.530653477,5.131469727,4.569115162,5.487017632,4.569115162,4.933847904,4.569115162",AMQP,192,0,Acceptable,RPC,6,DPI,"" +1,ip4,127.0.0.1,127.0.1.1,tcp,44205,5672,finished,16,16,1490904166118902,1490904169595775,1490904169595788,37,0,329,0,2113,0,1,31,224314.8,2001684,536643.9,287986745344.0,2.4,"31,198,177,103,103,2001663,2001684,188,167,98,97,1032593,1032598,113,109,94,93,11037,11041,111,108,94,93,17674,17676,105,104,99,99,412703,412706",52,118.0,381,99.5,9895.7,4.6,"93,52,148,52,355,52,93,52,148,52,355,52,90,52,148,52,381,52,89,52,148,52,257,52,91,52,148,52,311,52,90,52","0,6,0,5,0,0,1,0,1,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.892737865,4.569115162,5.131951332,4.569115162,5.420554638,4.569115162,4.937272072,4.569115162,5.150565624,4.569115162,5.432780266,4.569115162,4.933847904,4.569115162,5.110024929,4.516136646,5.444756508,4.569115162,4.894715786,4.569115162,5.123056412,4.569115162,5.521058559,4.530653477,4.818450451,4.530653477,5.131469727,4.569115162,5.487017632,4.569115162,4.933847904,4.569115162",AMQP,192,0,Acceptable,RPC,6,DPI,"46" diff --git a/test/results/flow-analyse/android.pcap.out b/test/results/flow-analyse/default/android.pcap.out index 0f2cf621e..0f2cf621e 100644 --- a/test/results/flow-analyse/android.pcap.out +++ b/test/results/flow-analyse/default/android.pcap.out diff --git a/test/results/flow-analyse/anyconnect-vpn.pcap.out b/test/results/flow-analyse/default/anyconnect-vpn.pcap.out index 461b29aa6..b360890dd 100644 --- a/test/results/flow-analyse/anyconnect-vpn.pcap.out +++ b/test/results/flow-analyse/default/anyconnect-vpn.pcap.out @@ -1,5 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,10.0.0.227,8.37.102.91,tcp,56919,443,info,17,15,1569687245688240,1569687246009851,1569687246009730,0,0,1448,1448,6050,7973,0,0,20745.2,71520,21568.3,465190496.0,4.0,"39490,39550,431,43733,1217,44517,40926,4,40928,1,38216,8,38254,1,33217,1,0,71520,5,38273,6102,35094,41225,217,42300,2869,5,1,44938,0,58",52,490.7,1500,597.2,356597.6,4.0,"64,56,52,219,52,1500,52,1500,1500,52,52,1500,1167,52,52,1500,1500,1319,52,52,663,52,127,52,1161,52,345,697,105,52,52,52","11,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,2,0,0","6,1,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,1,1,0,0,1,1,0,0,0,0,0,1,1,0,1,1,0,0,1,1,1,1,0,0,0","4.277806282,5.056655407,4.776611805,5.499976635,4.815073490,7.340889931,4.829590321,7.117477894,7.208638191,4.868052006,4.829590321,7.407335281,5.918903828,4.829590321,4.829590321,6.806384563,7.188310623,7.472460270,4.685171604,4.791129112,7.602285385,4.714205265,6.163617611,4.752666950,7.823616028,4.868052006,7.252848148,7.725178242,5.773176193,4.906513691,4.829590321,4.829590321",,,,,,,,"" -1,ip4,10.0.0.227,8.37.96.194,tcp,56921,4287,finished,16,16,1569687260591875,1569687261807505,1569687261836138,0,0,1195,1368,2943,4489,0,272,79351.4,384774,121592.3,14784686080.0,3.7,"28537,28596,272,35158,11581,46466,4231,33144,2963,31899,1468,30539,1730,30777,254948,281121,5133,31326,314965,342213,26303,53543,25788,25778,4801,30501,2712,28408,358152,384774,2066",52,285.0,1420,416.2,173206.9,3.9,"64,64,52,200,52,1360,52,1247,52,103,52,496,52,463,52,363,52,167,52,777,52,1420,52,1160,52,114,52,122,52,110,52,110","9,2,0,0,1,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0","8,2,1,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,1,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,0,0,1,1,0,0,1,1","4.328511238,5.005488396,4.776612282,5.402243614,5.091758728,7.442438602,4.882569313,7.578964233,4.916693211,5.863890648,4.829590321,7.531296730,4.969671726,7.509452820,4.882569313,7.315038681,4.993616581,6.548084259,4.959492683,7.706759453,5.014835358,7.870440960,4.921030998,7.786418438,4.882569313,6.148206234,5.014835358,6.198904037,4.921030998,6.028552055,5.091758728,6.119950771",TLS,91,1,Safe,Web,6,DPI,"5,6,15,24" +1,ip4,10.0.0.227,8.37.96.194,tcp,56921,4287,finished,16,16,1569687260591875,1569687261807505,1569687261836138,0,0,1195,1368,2943,4489,0,272,79351.4,384774,121592.3,14784686080.0,3.7,"28537,28596,272,35158,11581,46466,4231,33144,2963,31899,1468,30539,1730,30777,254948,281121,5133,31326,314965,342213,26303,53543,25788,25778,4801,30501,2712,28408,358152,384774,2066",52,285.0,1420,416.2,173206.9,3.9,"64,64,52,200,52,1360,52,1247,52,103,52,496,52,463,52,363,52,167,52,777,52,1420,52,1160,52,114,52,122,52,110,52,110","9,2,0,0,1,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0","8,2,1,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,1,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,0,0,1,1,0,0,1,1","4.328511238,5.005488396,4.776612282,5.402243614,5.091758728,7.442438602,4.882569313,7.578964233,4.916693211,5.863890648,4.829590321,7.531296730,4.969671726,7.509452820,4.882569313,7.315038681,4.993616581,6.548084259,4.959492683,7.706759453,5.014835358,7.870440960,4.921030998,7.786418438,4.882569313,6.148206234,5.014835358,6.198904037,4.921030998,6.028552055,5.091758728,6.119950771",TLS,91,1,Safe,Web,6,DPI,"5,6,15,24,41" 1,ip4,10.0.0.227,8.37.102.91,tcp,56929,443,info,15,17,1569687267035097,1569687267393587,1569687267393508,0,0,965,1448,1471,13402,0,0,23125.8,138032,32185.7,1035917504.0,3.6,"42362,42438,1999,46916,1210,46124,40336,4,40344,1,37231,6,37243,1,97159,138032,40854,1159,43270,9027,4,1,1,0,9,1,1,51168,0,0,0",52,517.3,1500,619.3,383541.0,4.0,"64,56,52,204,52,1500,52,1500,1500,52,52,1500,1167,52,52,406,127,52,1017,52,1500,209,1500,209,1500,209,1500,209,52,52,52,52","12,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,1,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,8,0,0","0,1,0,0,1,1,0,1,1,0,0,1,1,0,0,0,1,0,0,1,1,1,1,1,1,1,1,1,0,0,0,0","4.215306282,4.950672150,4.700937271,5.452831745,4.700937271,7.337546349,4.738150120,7.112461567,7.211231709,4.791128635,4.791128635,7.407482147,5.922111034,4.791128635,4.829590321,7.350569248,6.160544395,4.791128635,7.794639587,4.868052006,7.862796307,6.916011810,7.871273518,6.899218082,7.872875214,6.733156681,7.846444607,6.809710979,4.829590321,4.767184258,4.829590321,4.829590321",,,,,,,,"" -1,ip4,10.0.0.227,8.37.102.91,udp,54107,443,finished,16,16,1569687268746220,1569687268990048,1569687268992240,93,0,157,365,2016,3458,0,1,15801.5,47070,18787.6,352972736.0,3.9,"43486,43887,46602,46963,13778,22397,136,45366,3,1,180,3,8893,184,3220,4,34551,3,41128,530,5716,3654,11825,10035,4233,4600,46982,47070,168,405,3845",76,199.1,393,70.7,5001.8,4.9,"127,76,147,216,121,153,153,153,249,201,201,201,185,137,153,345,297,169,217,153,153,297,153,265,185,393,185,265,153,169,169,329","0,0,1,11,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,2,5,1,2,2,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,0,0,1,1,1,1,1,0,0,1,1,1,1,0,0,1,0,1,0,1,0,1,0,0,0,1","5.462343693,4.390864372,5.914839268,6.005654812,5.535966873,6.360437393,6.343824863,6.387973785,6.973914146,6.706965446,6.711217403,6.676970959,6.521679401,6.215778828,6.357885838,7.282065392,7.113596439,6.506012440,6.831180573,6.432122707,6.290798664,7.059806824,6.370957851,7.132057190,6.624488354,7.326114655,6.671812534,7.077751637,6.532753944,6.585647583,6.474001408,7.264476776",DTLS,30,1,Safe,Web,6,DPI,"7" diff --git a/test/results/flow-analyse/anydesk.pcapng.out b/test/results/flow-analyse/default/anydesk.pcapng.out index bdda144d0..bdda144d0 100644 --- a/test/results/flow-analyse/anydesk.pcapng.out +++ b/test/results/flow-analyse/default/anydesk.pcapng.out diff --git a/test/results/flow-analyse/avast_securedns.pcapng.out b/test/results/flow-analyse/default/avast.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/avast_securedns.pcapng.out +++ b/test/results/flow-analyse/default/avast.pcap.out diff --git a/test/results/flow-analyse/badpackets.pcap.out b/test/results/flow-analyse/default/avast_securedns.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/badpackets.pcap.out +++ b/test/results/flow-analyse/default/avast_securedns.pcapng.out diff --git a/test/results/flow-analyse/bjnp.pcap.out b/test/results/flow-analyse/default/bacnet.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/bjnp.pcap.out +++ b/test/results/flow-analyse/default/bacnet.pcap.out diff --git a/test/results/flow-analyse/bad-dns-traffic.pcap.out b/test/results/flow-analyse/default/bad-dns-traffic.pcap.out index 774561d8b..774561d8b 100644 --- a/test/results/flow-analyse/bad-dns-traffic.pcap.out +++ b/test/results/flow-analyse/default/bad-dns-traffic.pcap.out diff --git a/test/results/flow-analyse/bt_search.pcap.out b/test/results/flow-analyse/default/badpackets.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/bt_search.pcap.out +++ b/test/results/flow-analyse/default/badpackets.pcap.out diff --git a/test/results/flow-analyse/bitcoin.pcap.out b/test/results/flow-analyse/default/bitcoin.pcap.out index 317089271..957e5eeb8 100644 --- a/test/results/flow-analyse/bitcoin.pcap.out +++ b/test/results/flow-analyse/default/bitcoin.pcap.out @@ -1,5 +1,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.142,69.118.54.122,tcp,55328,8333,finished,2,30,1301328089970465,1301328231627793,1301328234475638,44,0,105,1448,149,36033,1,1,9231048.0,141657328,28184708.0,794377756606464.0,1.9,"52705,59165,36072737,6972560,71059721,141657328,28238337,91,32968,6,2,1933055,1,2,1,2,4527,16790,273,4103,461,12118,1136,339,10616,15667,2671,6,3102,4098,7913",72,1182.7,1500,570.2,325114.2,4.8,"157,157,72,113,107,113,96,1500,1500,1500,1500,1031,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,3,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,24,0,0","0,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.331577301,4.391512871,4.909439087,5.158895969,4.722836494,5.592147827,4.927504063,7.410189629,7.472129822,7.510345459,7.516362667,7.410877228,3.553941965,3.447642088,3.529692411,3.496179581,3.466899872,3.442958832,3.518888474,3.453003168,3.457215071,3.471271992,3.497405529,3.477877617,3.477765560,3.484272242,3.466756582,3.504224300,3.495511293,3.509394407,3.499261856,3.458781719",Mining,42,0,Unsafe,Mining,6,DPI,"22" -1,ip4,192.168.1.142,74.89.181.229,tcp,55348,8333,finished,3,29,1301328319392147,1301328419814379,1301328420325069,44,0,105,1448,204,35103,1,5,6495327.5,100110670,19444800.0,378100231700480.0,2.0,"59193,103209,9823152,39766075,21773202,100110670,311562,29237037,27,63547,5,128,1815,36336,73,10069,11,2188,6,22497,6,36,5434,1881,16669,98,3307,3200,88,2587,1046",72,1155.3,1500,597.2,356626.8,4.7,"157,157,72,168,107,107,96,107,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,2,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,24,0,0","0,1,1,1,1,1,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.470258713,4.521859646,5.133765697,5.303792000,4.884179592,4.884179592,5.089661121,4.793436050,3.556293964,3.471724272,3.563110828,3.507483721,3.465379477,3.476032257,3.517805815,3.485985279,3.486981392,3.481694460,3.513358593,3.496114254,3.507799149,3.471463203,3.516937494,3.517798901,3.501855373,3.464563370,3.465409040,3.545469761,3.513061523,3.455718517,3.526946545,3.479244232",Mining,42,0,Unsafe,Mining,6,DPI,"22" -1,ip4,192.168.1.142,66.68.83.22,tcp,55383,8333,finished,9,23,1301328472925065,1301328607711436,1301328616076718,44,0,1448,1448,9102,23653,1,11,8965742.0,134322478,25481870.0,649325705166848.0,2.2,"62318,90510,14042384,39643167,11451980,9238604,22700384,134322478,190526,216456,52,56784,49,15,11,45582876,5468,2949,79677,2390,56420,14875,38291,1106,29429,10233,41403,43,29590,11803,15753",72,1075.6,1500,630.5,397582.1,4.7,"157,157,72,113,113,113,168,113,96,1500,1500,1500,1500,1500,1500,317,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,1,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0","1,4,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0","0,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.314049721,4.516415119,5.159438610,5.621953964,5.629888535,5.436272144,5.232412338,5.492824554,5.047397614,6.620144367,6.645269394,6.641551971,6.624248028,6.652445793,6.650110245,6.173855782,3.519509792,3.418695927,3.522331953,3.473526716,3.458976030,3.461488724,3.521340132,3.498308420,3.439558506,3.445366859,3.488321781,3.470211506,3.484444618,3.500530481,3.521874428,3.458418369",Mining,42,0,Unsafe,Mining,6,DPI,"22" -1,ip4,192.168.1.142,195.218.16.178,tcp,55400,8333,finished,6,26,1301328699728375,1301328741904043,1301328743741542,44,0,1448,1448,5826,27918,1,34,2780285.0,41186439,7975567.0,63609669419008.0,2.2,"128208,113258,17195103,11450771,3438749,6775,2755264,41186439,319900,321845,34,347450,8283500,31885,35035,52689,19022,36630,49289,41130,63903,2317,29070,27748,37436,32734,49198,24571,33724,41084,34074",72,1106.5,1500,621.5,386298.0,4.7,"157,157,72,107,107,107,107,113,96,1500,1500,1500,1385,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,3,0,0","1,5,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0","0,1,1,1,1,1,1,1,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.383668423,4.444240093,4.982605934,4.668665886,4.713104248,4.762123585,4.780815601,5.560832977,4.996669769,6.587570190,6.648486137,6.600738525,6.599431038,3.406774759,3.373550653,3.345058441,3.338595867,3.355129480,3.392081499,3.337737560,3.285459280,3.329736471,3.341146708,3.315114975,3.270951748,3.318075180,3.308751106,3.279112339,3.298598528,3.384484768,3.426392555,3.339625120",Mining,42,0,Unsafe,Mining,6,DPI,"22" +1,ip4,192.168.1.142,69.118.54.122,tcp,55328,8333,finished,2,30,1301328089970465,1301328231627793,1301328234475638,44,0,105,1448,149,36033,1,1,9231048.0,141657328,28184708.0,794377756606464.0,1.9,"52705,59165,36072737,6972560,71059721,141657328,28238337,91,32968,6,2,1933055,1,2,1,2,4527,16790,273,4103,461,12118,1136,339,10616,15667,2671,6,3102,4098,7913",72,1182.7,1500,570.2,325114.2,4.8,"157,157,72,113,107,113,96,1500,1500,1500,1500,1031,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,3,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,24,0,0","0,1,1,1,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.331577301,4.391512871,4.909439087,5.158895969,4.722836494,5.592147827,4.927504063,7.410189629,7.472129822,7.510345459,7.516362667,7.410877228,3.553941965,3.447642088,3.529692411,3.496179581,3.466899872,3.442958832,3.518888474,3.453003168,3.457215071,3.471271992,3.497405529,3.477877617,3.477765560,3.484272242,3.466756582,3.504224300,3.495511293,3.509394407,3.499261856,3.458781719",Mining,42,0,Unsafe,Mining,6,DPI,"22,46" +1,ip4,192.168.1.142,74.89.181.229,tcp,55348,8333,finished,3,29,1301328319392147,1301328419814379,1301328420325069,44,0,105,1448,204,35103,1,5,6495327.5,100110670,19444800.0,378100231700480.0,2.0,"59193,103209,9823152,39766075,21773202,100110670,311562,29237037,27,63547,5,128,1815,36336,73,10069,11,2188,6,22497,6,36,5434,1881,16669,98,3307,3200,88,2587,1046",72,1155.3,1500,597.2,356626.8,4.7,"157,157,72,168,107,107,96,107,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,2,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,24,0,0","0,1,1,1,1,1,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.470258713,4.521859646,5.133765697,5.303792000,4.884179592,4.884179592,5.089661121,4.793436050,3.556293964,3.471724272,3.563110828,3.507483721,3.465379477,3.476032257,3.517805815,3.485985279,3.486981392,3.481694460,3.513358593,3.496114254,3.507799149,3.471463203,3.516937494,3.517798901,3.501855373,3.464563370,3.465409040,3.545469761,3.513061523,3.455718517,3.526946545,3.479244232",Mining,42,0,Unsafe,Mining,6,DPI,"22,46" +1,ip4,192.168.1.142,66.68.83.22,tcp,55383,8333,finished,9,23,1301328472925065,1301328607711436,1301328616076718,44,0,1448,1448,9102,23653,1,11,8965742.0,134322478,25481870.0,649325705166848.0,2.2,"62318,90510,14042384,39643167,11451980,9238604,22700384,134322478,190526,216456,52,56784,49,15,11,45582876,5468,2949,79677,2390,56420,14875,38291,1106,29429,10233,41403,43,29590,11803,15753",72,1075.6,1500,630.5,397582.1,4.7,"157,157,72,113,113,113,168,113,96,1500,1500,1500,1500,1500,1500,317,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,1,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0","1,4,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0","0,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.314049721,4.516415119,5.159438610,5.621953964,5.629888535,5.436272144,5.232412338,5.492824554,5.047397614,6.620144367,6.645269394,6.641551971,6.624248028,6.652445793,6.650110245,6.173855782,3.519509792,3.418695927,3.522331953,3.473526716,3.458976030,3.461488724,3.521340132,3.498308420,3.439558506,3.445366859,3.488321781,3.470211506,3.484444618,3.500530481,3.521874428,3.458418369",Mining,42,0,Unsafe,Mining,6,DPI,"22,46" +1,ip4,192.168.1.142,195.218.16.178,tcp,55400,8333,finished,6,26,1301328699728375,1301328741904043,1301328743741542,44,0,1448,1448,5826,27918,1,34,2780285.0,41186439,7975567.0,63609669419008.0,2.2,"128208,113258,17195103,11450771,3438749,6775,2755264,41186439,319900,321845,34,347450,8283500,31885,35035,52689,19022,36630,49289,41130,63903,2317,29070,27748,37436,32734,49198,24571,33724,41084,34074",72,1106.5,1500,621.5,386298.0,4.7,"157,157,72,107,107,107,107,113,96,1500,1500,1500,1385,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,3,0,0","1,5,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0","0,1,1,1,1,1,1,1,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.383668423,4.444240093,4.982605934,4.668665886,4.713104248,4.762123585,4.780815601,5.560832977,4.996669769,6.587570190,6.648486137,6.600738525,6.599431038,3.406774759,3.373550653,3.345058441,3.338595867,3.355129480,3.392081499,3.337737560,3.285459280,3.329736471,3.341146708,3.315114975,3.270951748,3.318075180,3.308751106,3.279112339,3.298598528,3.384484768,3.426392555,3.339625120",Mining,42,0,Unsafe,Mining,6,DPI,"22,46" diff --git a/test/results/flow-analyse/bittorrent.pcap.out b/test/results/flow-analyse/default/bittorrent.pcap.out index 6a2783568..9f2eb6160 100644 --- a/test/results/flow-analyse/bittorrent.pcap.out +++ b/test/results/flow-analyse/default/bittorrent.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.3,198.100.146.9,tcp,52915,60163,finished,12,20,1455469976336620,1455469980135637,1455469980194523,17,0,176,1440,904,20536,1,12043,246997.4,919975,228791.8,52345696256.0,4.4,"176832,184047,360999,337345,477634,919975,779765,619481,619422,156869,158080,151021,161242,12043,185627,163549,148908,165750,153542,19235,148725,12813,146117,495893,130312,32142,133808,27318,421482,129521,27423",66,722.4,1492,635.2,403438.9,4.4,"120,132,611,228,66,176,90,86,1492,69,1166,69,609,81,69,389,69,188,609,1492,1492,1492,1492,1492,188,1492,1492,1492,1492,197,1492,1492","5,1,1,1,3,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,12,0,0","0,1,1,0,1,0,1,0,1,0,1,0,1,0,0,1,0,0,1,1,1,1,1,1,0,1,1,1,1,0,1,1","6.014183998,6.126387119,4.946569443,5.524954319,4.794059277,3.940484047,5.368589878,4.276479721,7.786795139,4.471814156,7.741641998,4.592490196,7.566695690,4.716621876,4.551665783,7.390619278,4.569711208,2.883123636,7.557919025,4.866727352,7.736888409,7.724407196,7.768088341,7.796109200,3.117206812,7.722576141,7.763302326,7.809885979,7.808127880,3.077500105,7.837090492,7.871365547",BitTorrent,37,0,Acceptable,Download,6,DPI,"5" +1,ip4,192.168.1.3,198.100.146.9,tcp,52915,60163,finished,12,20,1455469976336620,1455469980135637,1455469980194523,17,0,176,1440,904,20536,1,12043,246997.4,919975,228791.8,52345696256.0,4.4,"176832,184047,360999,337345,477634,919975,779765,619481,619422,156869,158080,151021,161242,12043,185627,163549,148908,165750,153542,19235,148725,12813,146117,495893,130312,32142,133808,27318,421482,129521,27423",66,722.4,1492,635.2,403438.9,4.4,"120,132,611,228,66,176,90,86,1492,69,1166,69,609,81,69,389,69,188,609,1492,1492,1492,1492,1492,188,1492,1492,1492,1492,197,1492,1492","5,1,1,1,3,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,12,0,0","0,1,1,0,1,0,1,0,1,0,1,0,1,0,0,1,0,0,1,1,1,1,1,1,0,1,1,1,1,0,1,1","6.014183998,6.126387119,4.946569443,5.524954319,4.794059277,3.940484047,5.368589878,4.276479721,7.786795139,4.471814156,7.741641998,4.592490196,7.566695690,4.716621876,4.551665783,7.390619278,4.569711208,2.883123636,7.557919025,4.866727352,7.736888409,7.724407196,7.768088341,7.796109200,3.117206812,7.722576141,7.763302326,7.809885979,7.808127880,3.077500105,7.837090492,7.871365547",BitTorrent,37,0,Acceptable,Download,6,DPI,"5,46" diff --git a/test/results/flow-analyse/default/bittorrent_tcp_miss.pcapng.out b/test/results/flow-analyse/default/bittorrent_tcp_miss.pcapng.out new file mode 100644 index 000000000..8bf88bfc8 --- /dev/null +++ b/test/results/flow-analyse/default/bittorrent_tcp_miss.pcapng.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.122.34,178.71.206.1,tcp,48987,6881,finished,12,20,1673446123917965,1673446124132868,1673446124132335,0,0,471,1440,1025,22693,0,8,13847.5,64959,17166.0,294672928.0,3.8,"18673,26924,29858,64959,29324,33873,54911,20576,19623,21996,21047,6908,279,229,213,159,199,287,569,92,484,33856,18,24514,384,131,356,353,18454,16,8",40,782.2,1480,666.4,444053.7,4.4,"60,52,40,238,464,40,511,280,108,419,328,90,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,40,40,1480,1480,1480,1480,1480,40,40,40","8,0,1,0,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,1,0,0,0,0,0,1,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,15,0,0","0,1,0,0,1,0,0,1,0,1,0,1,1,1,1,1,1,1,1,1,1,1,0,0,1,1,1,1,1,0,0,0","4.679967880,5.131024837,4.765311718,7.106909752,7.520512581,4.903055668,7.548049450,7.183899879,6.238460064,5.624160767,5.095487118,4.067485332,7.834874630,7.871198177,7.882282257,7.884436607,7.876652241,7.857866764,7.878300190,7.864074230,7.855942726,7.876870155,4.853056431,4.803055763,7.863341808,7.865004539,7.869568825,7.874233246,7.854714394,4.853055954,4.903056145,4.853055954",BitTorrent,37,0,Acceptable,Download,6,DPI,"5" diff --git a/test/results/flow-analyse/bittorrent_utp.pcap.out b/test/results/flow-analyse/default/bittorrent_utp.pcap.out index fe0055be8..fe0055be8 100644 --- a/test/results/flow-analyse/bittorrent_utp.pcap.out +++ b/test/results/flow-analyse/default/bittorrent_utp.pcap.out diff --git a/test/results/flow-analyse/cachefly.pcapng.out b/test/results/flow-analyse/default/bjnp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/cachefly.pcapng.out +++ b/test/results/flow-analyse/default/bjnp.pcap.out diff --git a/test/results/flow-analyse/bot.pcap.out b/test/results/flow-analyse/default/bot.pcap.out index 13d568dd1..0e20b1e7f 100644 --- a/test/results/flow-analyse/bot.pcap.out +++ b/test/results/flow-analyse/default/bot.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,40.77.167.36,89.31.72.220,tcp,64768,80,finished,7,25,1645108240233170,1645108240455112,1645108240455337,0,0,316,1440,316,33120,0,4,14326.1,114244,36180.2,1309009792.0,2.2,"409,106526,4,106682,7609,64,117,61,7,4,842,8,6,4,114244,282,105363,69,4,6,123,5,6,4,232,8,61,8,763,123,465",46,1086.5,1480,631.2,398369.0,4.6,"48,48,46,356,46,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,46,46,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,46,46,1480","6,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,23,0,0","0,1,0,0,1,1,1,1,1,1,1,1,1,1,1,0,0,1,1,1,1,1,1,1,1,1,1,1,1,0,0,1","4.668832779,4.823934078,4.705051422,5.553816795,4.685968399,6.426275253,7.497505188,7.820932388,7.830261230,7.797591209,7.805040359,7.821845531,7.816341877,7.795114517,7.064133644,4.748529911,4.585274220,7.814039707,7.815784454,7.820162296,7.814042091,7.827082157,7.799123287,7.792435646,7.357606411,5.923022270,7.867007732,5.467782974,4.930641174,4.661573410,4.661573410,5.117170334",HTTP,7,0,Acceptable,Web,6,DPI,"" +1,ip4,40.77.167.36,89.31.72.220,tcp,64768,80,finished,7,25,1645108240233170,1645108240455112,1645108240455337,0,0,316,1440,316,33120,0,4,14326.1,114244,36180.2,1309009792.0,2.2,"409,106526,4,106682,7609,64,117,61,7,4,842,8,6,4,114244,282,105363,69,4,6,123,5,6,4,232,8,61,8,763,123,465",46,1086.5,1480,631.2,398369.0,4.6,"48,48,46,356,46,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,46,46,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,46,46,1480","6,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,23,0,0","0,1,0,0,1,1,1,1,1,1,1,1,1,1,1,0,0,1,1,1,1,1,1,1,1,1,1,1,1,0,0,1","4.668832779,4.823934078,4.705051422,5.553816795,4.685968399,6.426275253,7.497505188,7.820932388,7.830261230,7.797591209,7.805040359,7.821845531,7.816341877,7.795114517,7.064133644,4.748529911,4.585274220,7.814039707,7.815784454,7.820162296,7.814042091,7.827082157,7.799123287,7.792435646,7.357606411,5.923022270,7.867007732,5.467782974,4.930641174,4.661573410,4.661573410,5.117170334",HTTP,7,0,Acceptable,Web,6,DPI,"44" diff --git a/test/results/flow-analyse/cloudflare-warp.pcap.out b/test/results/flow-analyse/default/bt-dns.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/cloudflare-warp.pcap.out +++ b/test/results/flow-analyse/default/bt-dns.pcap.out diff --git a/test/results/flow-analyse/corba.pcap.out b/test/results/flow-analyse/default/bt-http.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/corba.pcap.out +++ b/test/results/flow-analyse/default/bt-http.pcapng.out diff --git a/test/results/flow-analyse/cpha.pcap.out b/test/results/flow-analyse/default/bt_search.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/cpha.pcap.out +++ b/test/results/flow-analyse/default/bt_search.pcap.out diff --git a/test/results/flow-analyse/crynet.pcap.out b/test/results/flow-analyse/default/cachefly.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/crynet.pcap.out +++ b/test/results/flow-analyse/default/cachefly.pcapng.out diff --git a/test/results/flow-analyse/capwap.pcap.out b/test/results/flow-analyse/default/capwap.pcap.out index bc268879d..abb2c5e44 100644 --- a/test/results/flow-analyse/capwap.pcap.out +++ b/test/results/flow-analyse/default/capwap.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.10.9,192.168.10.10,udp,5246,12380,finished,17,15,1422329005767224,1422329016659899,1422329016659404,64,0,1457,1457,8579,6468,0,0,702737.3,10093423,2455548.8,6029719371776.0,1.6,"760,9998434,10093423,96372,2625,2,127,182379,1,0,0,94,314122,135275,2746,249,111759,1,157255,1,325739,280124,1,39490,1,39481,264,2133,995,502,500",92,498.2,1485,485.4,235625.0,4.4,"142,142,101,92,133,576,576,346,576,576,165,315,406,123,1485,1485,1485,1437,1021,1437,461,141,109,125,141,125,109,877,141,109,125,861","0,0,5,3,0,0,0,0,0,1,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,2,0,0","0,0,1,6,1,0,0,0,1,0,0,1,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0","0,0,1,0,1,0,0,0,1,1,1,1,1,0,1,0,0,1,1,0,0,1,0,0,1,1,0,0,1,0,1,0","3.893290997,3.893290997,4.830492973,4.615938187,5.436969757,6.642759323,6.913249969,6.397701263,6.902666569,6.846169949,6.368118286,7.090667248,7.118800163,5.456940651,7.874491215,7.866423607,7.870229721,7.867388248,7.782578468,7.843720436,7.507147312,6.314983845,5.763504982,6.039584160,6.280849457,6.035200119,5.804700375,7.759332657,6.342943668,5.774928570,6.117315292,7.735942364",CAPWAP,247,0,Acceptable,Network,6,DPI,"" -1,ip4,192.168.10.10,192.168.10.9,udp,12380,5247,finished,32,0,1422329017533285,1422329049032294,1422329017533285,80,0,283,0,4909,0,0,499857,1016097.1,3999845,875106.2,765810835456.0,4.6,"499983,500014,499872,2999961,499995,500031,499980,499982,499890,499986,499975,499998,499999,999998,999993,500014,2999827,1000005,999991,500032,1999814,500016,499990,999989,500017,1499983,499857,1999983,999996,999993,3999845",108,181.4,311,58.4,3415.7,4.9,"108,195,282,137,224,137,108,195,311,137,108,108,137,282,137,195,195,282,137,195,108,253,166,195,195,195,253,137,108,195,224,166","0,0,6,7,2,9,2,5,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.322847843,4.775271893,5.243394375,4.682712078,4.886671543,4.761803627,4.409015179,4.971165657,5.125069618,4.609245777,4.380640507,4.355712414,4.823248386,4.982461452,4.627756596,4.929459095,4.873090267,5.032708645,4.636066914,4.873720646,4.399159431,4.936395168,4.818520069,5.070401192,4.945625305,4.792158127,4.963052750,4.698768139,4.306179047,4.887980938,4.937054634,4.651456833",CAPWAP,247,0,Acceptable,Network,6,DPI,"" +1,ip4,192.168.10.9,192.168.10.10,udp,5246,12380,finished,17,15,1422329005767224,1422329016659899,1422329016659404,64,0,1457,1457,8579,6468,0,0,702737.3,10093423,2455548.8,6029719371776.0,1.6,"760,9998434,10093423,96372,2625,2,127,182379,1,0,0,94,314122,135275,2746,249,111759,1,157255,1,325739,280124,1,39490,1,39481,264,2133,995,502,500",92,498.2,1485,485.4,235625.0,4.4,"142,142,101,92,133,576,576,346,576,576,165,315,406,123,1485,1485,1485,1437,1021,1437,461,141,109,125,141,125,109,877,141,109,125,861","0,0,5,3,0,0,0,0,0,1,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,2,0,0","0,0,1,6,1,0,0,0,1,0,0,1,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0","0,0,1,0,1,0,0,0,1,1,1,1,1,0,1,0,0,1,1,0,0,1,0,0,1,1,0,0,1,0,1,0","3.893290997,3.893290997,4.830492973,4.615938187,5.436969757,6.642759323,6.913249969,6.397701263,6.902666569,6.846169949,6.368118286,7.090667248,7.118800163,5.456940651,7.874491215,7.866423607,7.870229721,7.867388248,7.782578468,7.843720436,7.507147312,6.314983845,5.763504982,6.039584160,6.280849457,6.035200119,5.804700375,7.759332657,6.342943668,5.774928570,6.117315292,7.735942364",CAPWAP,247,0,Acceptable,Network,6,DPI,"46" +1,ip4,192.168.10.10,192.168.10.9,udp,12380,5247,finished,32,0,1422329017533285,1422329049032294,1422329017533285,80,0,283,0,4909,0,0,499857,1016097.1,3999845,875106.2,765810835456.0,4.6,"499983,500014,499872,2999961,499995,500031,499980,499982,499890,499986,499975,499998,499999,999998,999993,500014,2999827,1000005,999991,500032,1999814,500016,499990,999989,500017,1499983,499857,1999983,999996,999993,3999845",108,181.4,311,58.4,3415.7,4.9,"108,195,282,137,224,137,108,195,311,137,108,108,137,282,137,195,195,282,137,195,108,253,166,195,195,195,253,137,108,195,224,166","0,0,6,7,2,9,2,5,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.322847843,4.775271893,5.243394375,4.682712078,4.886671543,4.761803627,4.409015179,4.971165657,5.125069618,4.609245777,4.380640507,4.355712414,4.823248386,4.982461452,4.627756596,4.929459095,4.873090267,5.032708645,4.636066914,4.873720646,4.399159431,4.936395168,4.818520069,5.070401192,4.945625305,4.792158127,4.963052750,4.698768139,4.306179047,4.887980938,4.937054634,4.651456833",CAPWAP,247,0,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/dazn.pcapng.out b/test/results/flow-analyse/default/capwap_data.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dazn.pcapng.out +++ b/test/results/flow-analyse/default/capwap_data.pcapng.out diff --git a/test/results/flow-analyse/cassandra.pcap.out b/test/results/flow-analyse/default/cassandra.pcap.out index 197071446..197071446 100644 --- a/test/results/flow-analyse/cassandra.pcap.out +++ b/test/results/flow-analyse/default/cassandra.pcap.out diff --git a/test/results/flow-analyse/check_mk_new.pcap.out b/test/results/flow-analyse/default/check_mk_new.pcap.out index 2f63b633b..2f63b633b 100644 --- a/test/results/flow-analyse/check_mk_new.pcap.out +++ b/test/results/flow-analyse/default/check_mk_new.pcap.out diff --git a/test/results/flow-analyse/dcerpc.pcap.out b/test/results/flow-analyse/default/chrome.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dcerpc.pcap.out +++ b/test/results/flow-analyse/default/chrome.pcap.out diff --git a/test/results/flow-analyse/citrix.pcap.out b/test/results/flow-analyse/default/citrix.pcap.out index 3e3cf8a69..3e3cf8a69 100644 --- a/test/results/flow-analyse/citrix.pcap.out +++ b/test/results/flow-analyse/default/citrix.pcap.out diff --git a/test/results/flow-analyse/dhcp-fuzz.pcapng.out b/test/results/flow-analyse/default/cloudflare-warp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dhcp-fuzz.pcapng.out +++ b/test/results/flow-analyse/default/cloudflare-warp.pcap.out diff --git a/test/results/flow-analyse/coap_mqtt.pcap.out b/test/results/flow-analyse/default/coap_mqtt.pcap.out index 8a9d09899..1853d3109 100644 --- a/test/results/flow-analyse/coap_mqtt.pcap.out +++ b/test/results/flow-analyse/default/coap_mqtt.pcap.out @@ -1,9 +1,9 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.56.1,192.168.56.101,tcp,53528,17501,finished,15,17,1455907267002212,1455907271697274,1455907271735420,0,0,60,86,286,367,0,72,304137.8,4438876,1061040.8,1125807423488.0,1.6,"72,248,4635,4859,1038,9311,9054,2795,3496,481,2352,21820,23421,198700,4438876,4242440,38504,37941,469,2294,62501,64983,1232,38696,37823,527,2778,66747,69695,1087,39395",40,62.3,126,30.1,907.0,4.9,"52,52,46,59,40,44,100,44,55,45,124,46,100,44,46,126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40","11,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1","4.523146629,4.808010101,4.370963573,5.094007969,4.634184361,4.533184528,5.525953770,4.586559772,4.953907967,4.699598312,5.658671856,4.370963097,5.525953770,4.632013798,4.267595291,5.562683582,4.539122581,4.634183884,5.525953293,4.684184074,4.677468300,5.578556538,4.370963573,4.582601070,4.634183884,5.473502159,4.634183884,4.632013321,5.594429493,4.294663429,4.555532932,4.684184074",MQTT,222,0,Acceptable,RPC,6,DPI,"5" -1,ip4,192.168.56.1,192.168.56.101,tcp,53522,17501,finished,14,18,1455907243976582,1455907271915318,1455907271915135,0,0,60,86,258,448,1,130,1802493.1,27505948,6724537.0,45219399598080.0,1.2,"709,199149,27505948,27310358,42735,39960,130,529,60417,61165,1588,38934,37729,553,2947,66282,69491,1247,39646,39140,1019,2437,62744,65305,1790,40465,38726,170,6175,66713,73088",40,63.4,126,32.8,1072.6,4.8,"46,42,46,126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46","10,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0","4.462504387,4.630411148,4.327484608,5.610302448,4.685968399,4.634184361,5.482468128,4.634184361,4.722923279,5.610302448,4.370963097,4.729446411,4.534184456,5.565953732,4.634184361,4.768377304,5.610302448,4.370963097,4.729446888,4.634184361,5.525953293,4.634184361,4.722922802,5.626175404,4.370963573,4.729446411,4.634184361,5.522468567,4.684184551,4.768377781,5.610302448,4.414441586",MQTT,222,0,Acceptable,RPC,6,DPI,"5" -1,ip4,192.168.56.1,192.168.56.101,tcp,53523,17501,finished,14,18,1455907258332152,1455907271915337,1455907271915223,0,0,60,86,258,448,1,237,876330.8,13150790,3197714.5,10225378656256.0,1.4,"404,199934,13150790,12952309,38608,37989,477,2148,62571,64954,1016,38807,38093,501,2594,66803,69615,1179,39541,39110,979,2406,62938,65497,773,40198,39480,237,5592,67477,73236",40,63.4,126,32.8,1072.6,4.8,"46,42,46,126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46","10,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0","4.419025898,4.733946800,4.327484608,5.558483124,4.685968399,4.584184170,5.505953312,4.634183884,4.677468777,5.588438511,4.370963573,4.685968399,4.634183884,5.505952835,4.684184074,4.768377304,5.572565556,4.414441586,4.729446411,4.684184074,5.525953770,4.684184074,4.722923279,5.559791088,4.414441586,4.685968399,4.684184074,5.545953751,4.684184074,4.768377304,5.558483124,4.370963097",MQTT,222,0,Acceptable,RPC,6,DPI,"5" -1,ip4,192.168.56.101,192.168.56.1,tcp,17501,53524,finished,18,14,1455907271483430,1455907271957948,1455907271958031,0,0,86,60,446,320,1,156,30616.7,73508,26730.8,714536192.0,4.3,"1998,38598,37069,480,2447,62266,64859,841,38683,38127,461,2290,67273,69748,665,39428,39498,931,2251,63248,65640,1623,40275,38699,156,6124,67250,73508,2463,42357,39863",40,65.0,126,33.2,1105.2,4.8,"126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100","13,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1","5.604311466,4.599011421,4.615311623,5.545953751,4.615311623,4.705766201,5.566574574,4.311074257,4.626079559,4.615311623,5.484536648,4.511769295,4.624093056,5.568364620,4.303872585,4.627490997,4.684184074,5.518404961,4.615311623,4.649170399,5.582447052,4.370963097,4.669558048,4.634183884,5.525953770,4.684184074,4.768377304,5.588438511,4.370963097,4.555533409,4.684184074,5.520660400",MQTT,222,0,Acceptable,RPC,6,DPI,"5" -1,ip4,192.168.56.1,192.168.56.101,udp,50311,17500,finished,16,16,1455907271481938,1455907273126173,1455907273127913,94,0,101,24,1538,306,0,1824,106135.8,117757,19323.7,373406144.0,4.9,"1824,103882,104036,108951,108450,105413,105949,113800,113717,106838,107131,109410,109028,108906,115953,117757,112312,110612,110806,109887,107946,108022,108009,113116,114023,110812,110429,107359,111248,109470,105114",45,85.6,129,38.6,1486.7,4.8,"124,47,123,46,122,45,129,52,125,48,122,45,124,47,124,47,126,49,123,46,124,47,123,46,123,46,123,46,129,52,122,45","0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.543972015,5.027887821,5.510700703,5.088779926,5.530181885,5.047409534,5.667361259,5.185924053,5.578914642,5.069235325,5.512969971,5.047409534,5.559295654,5.027887344,5.530185699,4.958842754,5.597733021,5.084096432,5.503751278,5.045301914,5.504820824,5.027887821,5.497614384,5.045301437,5.497614384,5.088779926,5.490664959,5.088779926,5.682090759,5.315825462,5.555962563,5.047409534",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" -1,ip4,192.168.56.1,192.168.56.101,udp,50318,17500,finished,16,16,1455907272856457,1455907274582746,1455907274587363,95,0,100,23,1552,320,0,2441,111522.4,127663,20842.5,434411712.0,4.9,"2441,112948,114313,107773,108080,108005,107995,109511,111427,119112,118338,116979,117004,127663,125063,114041,112993,120228,120931,111475,111310,105608,107791,113820,112048,122618,125498,112978,109966,123530,125708",46,86.5,128,38.5,1485.6,4.9,"123,46,127,50,126,49,128,51,123,46,125,48,126,49,125,48,123,46,124,47,128,51,126,49,123,46,123,46,123,46,127,50","0,0,6,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.503751755,5.045301437,5.557007790,5.123855114,5.607614994,5.043280125,5.664313793,5.241052628,5.514686108,4.950420856,5.534836769,5.027568340,5.639360428,5.084096432,5.610115051,5.084961891,5.505375385,5.088779926,5.607682705,5.070440769,5.642791271,5.133018017,5.545912743,4.930835724,5.488303185,5.088779926,5.491476536,5.045301437,5.523996830,5.088779926,5.658226490,5.203855038",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" -1,ip4,192.168.56.1,192.168.56.101,udp,50312,17500,finished,16,16,1455907274088318,1455907275896569,1455907275902611,95,0,101,24,1564,332,0,1319,116856.3,131359,22365.2,500202464.0,4.9,"1319,105009,107122,122637,124565,114853,120385,119749,111541,123867,122956,105381,109394,122887,120099,118036,119438,130107,131359,131277,128951,120148,121275,112275,114829,128910,125477,127969,127046,125146,128537",46,87.2,129,38.5,1485.3,4.9,"125,48,129,52,125,48,126,49,126,49,123,46,123,46,123,46,128,51,126,49,127,50,125,48,125,48,128,51,127,50,126,49","0,0,3,13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.540076256,5.126628399,5.646005154,5.238902569,5.556076050,5.011841774,5.645351887,5.124912739,5.661224842,5.124912739,5.536271572,5.045301914,5.526149273,5.010309696,5.552532196,5.088779926,5.645638943,5.155473709,5.623487949,5.027874470,5.658226013,5.203855038,5.594115257,5.084961414,5.581238747,5.084961414,5.642791271,5.201836586,5.575829029,5.148757458,5.623488426,5.043280125",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" -1,ip4,192.168.56.1,192.168.56.101,udp,50319,17500,finished,16,16,1455907275690777,1455907277661201,1455907277663998,94,0,101,24,1561,329,0,5091,127214.4,172321,26264.3,689812928.0,4.9,"5091,140506,139383,127325,129287,138036,134456,137698,141222,137865,138593,132603,133311,132101,136834,172321,164608,137809,136671,122327,121648,117128,118696,128848,133217,115516,110107,123592,124533,106749,105564",45,87.1,129,38.6,1487.1,4.9,"127,50,128,51,123,46,123,46,126,49,123,46,122,45,127,50,125,48,129,52,126,49,124,47,125,48,129,52,124,47,128,51","0,0,4,12,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.584132195,5.148756981,5.612321377,5.123405457,5.484527588,5.088779926,5.497614384,5.088779926,5.597732544,5.084096432,5.526148796,5.088780403,5.523175716,5.047409534,5.616926193,5.163855076,5.550037384,5.084961891,5.666587353,5.277364254,5.567777157,5.068690777,5.565383434,5.070440769,5.542193413,5.084961414,5.626701832,5.238902569,5.490826130,4.985334873,5.638961315,5.241052151",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" +1,ip4,192.168.56.1,192.168.56.101,tcp,53522,17501,finished,14,18,1455907243976582,1455907271915318,1455907271915135,0,0,60,86,258,448,1,130,1802493.1,27505948,6724537.0,45219399598080.0,1.2,"709,199149,27505948,27310358,42735,39960,130,529,60417,61165,1588,38934,37729,553,2947,66282,69491,1247,39646,39140,1019,2437,62744,65305,1790,40465,38726,170,6175,66713,73088",40,63.4,126,32.8,1072.6,4.8,"46,42,46,126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46","10,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0","4.462504387,4.630411148,4.327484608,5.610302448,4.685968399,4.634184361,5.482468128,4.634184361,4.722923279,5.610302448,4.370963097,4.729446411,4.534184456,5.565953732,4.634184361,4.768377304,5.610302448,4.370963097,4.729446888,4.634184361,5.525953293,4.634184361,4.722922802,5.626175404,4.370963573,4.729446411,4.634184361,5.522468567,4.684184551,4.768377781,5.610302448,4.414441586",MQTT,222,0,Acceptable,RPC,6,DPI,"5,46" +1,ip4,192.168.56.1,192.168.56.101,tcp,53523,17501,finished,14,18,1455907258332152,1455907271915337,1455907271915223,0,0,60,86,258,448,1,237,876330.8,13150790,3197714.5,10225378656256.0,1.4,"404,199934,13150790,12952309,38608,37989,477,2148,62571,64954,1016,38807,38093,501,2594,66803,69615,1179,39541,39110,979,2406,62938,65497,773,40198,39480,237,5592,67477,73236",40,63.4,126,32.8,1072.6,4.8,"46,42,46,126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46","10,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0,0,1,0,1,1,1,0","4.419025898,4.733946800,4.327484608,5.558483124,4.685968399,4.584184170,5.505953312,4.634183884,4.677468777,5.588438511,4.370963573,4.685968399,4.634183884,5.505952835,4.684184074,4.768377304,5.572565556,4.414441586,4.729446411,4.684184074,5.525953770,4.684184074,4.722923279,5.559791088,4.414441586,4.685968399,4.684184074,5.545953751,4.684184074,4.768377304,5.558483124,4.370963097",MQTT,222,0,Acceptable,RPC,6,DPI,"5,46" +1,ip4,192.168.56.101,192.168.56.1,tcp,17501,53524,finished,18,14,1455907271483430,1455907271957948,1455907271958031,0,0,86,60,446,320,1,156,30616.7,73508,26730.8,714536192.0,4.3,"1998,38598,37069,480,2447,62266,64859,841,38683,38127,461,2290,67273,69748,665,39428,39498,931,2251,63248,65640,1623,40275,38699,156,6124,67250,73508,2463,42357,39863",40,65.0,126,33.2,1105.2,4.8,"126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100","13,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1","5.604311466,4.599011421,4.615311623,5.545953751,4.615311623,4.705766201,5.566574574,4.311074257,4.626079559,4.615311623,5.484536648,4.511769295,4.624093056,5.568364620,4.303872585,4.627490997,4.684184074,5.518404961,4.615311623,4.649170399,5.582447052,4.370963097,4.669558048,4.634183884,5.525953770,4.684184074,4.768377304,5.588438511,4.370963097,4.555533409,4.684184074,5.520660400",MQTT,222,0,Acceptable,RPC,6,DPI,"5,46" +1,ip4,192.168.56.1,192.168.56.101,udp,50311,17500,finished,16,16,1455907271481938,1455907273126173,1455907273127913,94,0,101,24,1538,306,0,1824,106135.8,117757,19323.7,373406144.0,4.9,"1824,103882,104036,108951,108450,105413,105949,113800,113717,106838,107131,109410,109028,108906,115953,117757,112312,110612,110806,109887,107946,108022,108009,113116,114023,110812,110429,107359,111248,109470,105114",45,85.6,129,38.6,1486.7,4.8,"124,47,123,46,122,45,129,52,125,48,122,45,124,47,124,47,126,49,123,46,124,47,123,46,123,46,123,46,129,52,122,45","0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.543972015,5.027887821,5.510700703,5.088779926,5.530181885,5.047409534,5.667361259,5.185924053,5.578914642,5.069235325,5.512969971,5.047409534,5.559295654,5.027887344,5.530185699,4.958842754,5.597733021,5.084096432,5.503751278,5.045301914,5.504820824,5.027887821,5.497614384,5.045301437,5.497614384,5.088779926,5.490664959,5.088779926,5.682090759,5.315825462,5.555962563,5.047409534",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" +1,ip4,192.168.56.1,192.168.56.101,udp,50318,17500,finished,16,16,1455907272856457,1455907274582746,1455907274587363,95,0,100,23,1552,320,0,2441,111522.4,127663,20842.5,434411712.0,4.9,"2441,112948,114313,107773,108080,108005,107995,109511,111427,119112,118338,116979,117004,127663,125063,114041,112993,120228,120931,111475,111310,105608,107791,113820,112048,122618,125498,112978,109966,123530,125708",46,86.5,128,38.5,1485.6,4.9,"123,46,127,50,126,49,128,51,123,46,125,48,126,49,125,48,123,46,124,47,128,51,126,49,123,46,123,46,123,46,127,50","0,0,6,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.503751755,5.045301437,5.557007790,5.123855114,5.607614994,5.043280125,5.664313793,5.241052628,5.514686108,4.950420856,5.534836769,5.027568340,5.639360428,5.084096432,5.610115051,5.084961891,5.505375385,5.088779926,5.607682705,5.070440769,5.642791271,5.133018017,5.545912743,4.930835724,5.488303185,5.088779926,5.491476536,5.045301437,5.523996830,5.088779926,5.658226490,5.203855038",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" +1,ip4,192.168.56.1,192.168.56.101,udp,50312,17500,finished,16,16,1455907274088318,1455907275896569,1455907275902611,95,0,101,24,1564,332,0,1319,116856.3,131359,22365.2,500202464.0,4.9,"1319,105009,107122,122637,124565,114853,120385,119749,111541,123867,122956,105381,109394,122887,120099,118036,119438,130107,131359,131277,128951,120148,121275,112275,114829,128910,125477,127969,127046,125146,128537",46,87.2,129,38.5,1485.3,4.9,"125,48,129,52,125,48,126,49,126,49,123,46,123,46,123,46,128,51,126,49,127,50,125,48,125,48,128,51,127,50,126,49","0,0,3,13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.540076256,5.126628399,5.646005154,5.238902569,5.556076050,5.011841774,5.645351887,5.124912739,5.661224842,5.124912739,5.536271572,5.045301914,5.526149273,5.010309696,5.552532196,5.088779926,5.645638943,5.155473709,5.623487949,5.027874470,5.658226013,5.203855038,5.594115257,5.084961414,5.581238747,5.084961414,5.642791271,5.201836586,5.575829029,5.148757458,5.623488426,5.043280125",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" +1,ip4,192.168.56.1,192.168.56.101,udp,50319,17500,finished,16,16,1455907275690777,1455907277661201,1455907277663998,94,0,101,24,1561,329,0,5091,127214.4,172321,26264.3,689812928.0,4.9,"5091,140506,139383,127325,129287,138036,134456,137698,141222,137865,138593,132603,133311,132101,136834,172321,164608,137809,136671,122327,121648,117128,118696,128848,133217,115516,110107,123592,124533,106749,105564",45,87.1,129,38.6,1487.1,4.9,"127,50,128,51,123,46,123,46,126,49,123,46,122,45,127,50,125,48,129,52,126,49,124,47,125,48,129,52,124,47,128,51","0,0,4,12,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.584132195,5.148756981,5.612321377,5.123405457,5.484527588,5.088779926,5.497614384,5.088779926,5.597732544,5.084096432,5.526148796,5.088780403,5.523175716,5.047409534,5.616926193,5.163855076,5.550037384,5.084961891,5.666587353,5.277364254,5.567777157,5.068690777,5.565383434,5.070440769,5.542193413,5.084961414,5.626701832,5.238902569,5.490826130,4.985334873,5.638961315,5.241052151",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" diff --git a/test/results/flow-analyse/collectd.pcap.out b/test/results/flow-analyse/default/collectd.pcap.out index 6d576cb72..6d576cb72 100644 --- a/test/results/flow-analyse/collectd.pcap.out +++ b/test/results/flow-analyse/default/collectd.pcap.out diff --git a/test/results/flow-analyse/diameter.pcap.out b/test/results/flow-analyse/default/corba.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/diameter.pcap.out +++ b/test/results/flow-analyse/default/corba.pcap.out diff --git a/test/results/flow-analyse/discord.pcap.out b/test/results/flow-analyse/default/cpha.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/discord.pcap.out +++ b/test/results/flow-analyse/default/cpha.pcap.out diff --git a/test/results/flow-analyse/dlt_ppp.pcap.out b/test/results/flow-analyse/default/crawler_false_positive.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dlt_ppp.pcap.out +++ b/test/results/flow-analyse/default/crawler_false_positive.pcapng.out diff --git a/test/results/flow-analyse/dns-invalid-chars.pcap.out b/test/results/flow-analyse/default/crynet.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dns-invalid-chars.pcap.out +++ b/test/results/flow-analyse/default/crynet.pcap.out diff --git a/test/results/flow-analyse/dns_ambiguous_names.pcap.out b/test/results/flow-analyse/default/custom_rules_same-ip_multiple_ports.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dns_ambiguous_names.pcap.out +++ b/test/results/flow-analyse/default/custom_rules_same-ip_multiple_ports.pcapng.out diff --git a/test/results/flow-analyse/dns_dot.pcap.out b/test/results/flow-analyse/default/dazn.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dns_dot.pcap.out +++ b/test/results/flow-analyse/default/dazn.pcapng.out diff --git a/test/results/flow-analyse/dns_fragmented.pcap.out b/test/results/flow-analyse/default/dcerpc.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dns_fragmented.pcap.out +++ b/test/results/flow-analyse/default/dcerpc.pcap.out diff --git a/test/results/flow-analyse/dns_invert_query.pcapng.out b/test/results/flow-analyse/default/dhcp-fuzz.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dns_invert_query.pcapng.out +++ b/test/results/flow-analyse/default/dhcp-fuzz.pcapng.out diff --git a/test/results/flow-analyse/dns_long_domainname.pcap.out b/test/results/flow-analyse/default/diameter.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dns_long_domainname.pcap.out +++ b/test/results/flow-analyse/default/diameter.pcap.out diff --git a/test/results/flow-analyse/dnscrypt-v1-and-resolver-pings.pcap.out b/test/results/flow-analyse/default/discord.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dnscrypt-v1-and-resolver-pings.pcap.out +++ b/test/results/flow-analyse/default/discord.pcap.out diff --git a/test/results/flow-analyse/dnscrypt-v2-doh.pcap.out b/test/results/flow-analyse/default/discord_mid_flow.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dnscrypt-v2-doh.pcap.out +++ b/test/results/flow-analyse/default/discord_mid_flow.pcap.out diff --git a/test/results/flow-analyse/dnscrypt-v2.pcap.out b/test/results/flow-analyse/default/dlt_ppp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dnscrypt-v2.pcap.out +++ b/test/results/flow-analyse/default/dlt_ppp.pcap.out diff --git a/test/results/flow-analyse/dnp3.pcap.out b/test/results/flow-analyse/default/dnp3.pcap.out index 8989b172e..8989b172e 100644 --- a/test/results/flow-analyse/dnp3.pcap.out +++ b/test/results/flow-analyse/default/dnp3.pcap.out diff --git a/test/results/flow-analyse/dnscrypt_skype_false_positive.pcapng.out b/test/results/flow-analyse/default/dns-invalid-chars.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dnscrypt_skype_false_positive.pcapng.out +++ b/test/results/flow-analyse/default/dns-invalid-chars.pcap.out diff --git a/test/results/flow-analyse/dns-tunnel-iodine.pcap.out b/test/results/flow-analyse/default/dns-tunnel-iodine.pcap.out index 58e0aaf88..342a15f90 100644 --- a/test/results/flow-analyse/dns-tunnel-iodine.pcap.out +++ b/test/results/flow-analyse/default/dns-tunnel-iodine.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.0.2.30,10.0.2.20,udp,44639,53,finished,19,13,1282356640051082,1282356645071860,1282356640060900,40,0,281,1434,2968,3580,0,93,162277.3,1002966,368318.9,135658823680.0,2.4,"93,897,1083,5795,5715,411,342,245,227,219,217,216,215,213,212,209,230,282,586,445,177,314,494,447,227,245,1001664,1002291,1001465,1002966,1002454",68,232.6,1462,286.6,82112.7,4.4,"68,89,89,130,74,123,109,152,118,170,124,182,104,142,120,174,74,82,74,81,74,79,309,1078,309,1462,309,309,309,309,309,309","0,6,4,1,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,4,1,3,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,0,0,0,0","4.192683220,4.481659889,4.827383041,4.928776741,4.048753262,5.135797501,4.621113777,4.797404289,4.689741611,4.823459148,5.501323700,5.868503571,5.093356609,5.373332500,5.574461937,5.911468983,4.085981369,4.376136780,4.058953762,4.299961090,4.038551807,4.297753811,4.143254280,7.508830547,3.346999884,7.575299263,4.126974583,4.140811443,4.147284031,4.120341778,4.126974583,4.140811920",DNS,5,0,Acceptable,Network,6,DPI,"23" +1,ip4,10.0.2.30,10.0.2.20,udp,44639,53,finished,19,13,1282356640051082,1282356645071860,1282356640060900,40,0,281,1434,2968,3580,0,93,162277.3,1002966,368318.9,135658823680.0,2.4,"93,897,1083,5795,5715,411,342,245,227,219,217,216,215,213,212,209,230,282,586,445,177,314,494,447,227,245,1001664,1002291,1001465,1002966,1002454",68,232.6,1462,286.6,82112.7,4.4,"68,89,89,130,74,123,109,152,118,170,124,182,104,142,120,174,74,82,74,81,74,79,309,1078,309,1462,309,309,309,309,309,309","0,6,4,1,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,4,1,3,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,0,0,0,0","4.192683220,4.481659889,4.827383041,4.928776741,4.048753262,5.135797501,4.621113777,4.797404289,4.689741611,4.823459148,5.501323700,5.868503571,5.093356609,5.373332500,5.574461937,5.911468983,4.085981369,4.376136780,4.058953762,4.299961090,4.038551807,4.297753811,4.143254280,7.508830547,3.346999884,7.575299263,4.126974583,4.140811443,4.147284031,4.120341778,4.126974583,4.140811920",DNS,5,0,Acceptable,Network,6,DPI,"23,49" diff --git a/test/results/flow-analyse/doq.pcapng.out b/test/results/flow-analyse/default/dns_ambiguous_names.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/doq.pcapng.out +++ b/test/results/flow-analyse/default/dns_ambiguous_names.pcap.out diff --git a/test/results/flow-analyse/dns_doh.pcap.out b/test/results/flow-analyse/default/dns_doh.pcap.out index 63ca14564..63ca14564 100644 --- a/test/results/flow-analyse/dns_doh.pcap.out +++ b/test/results/flow-analyse/default/dns_doh.pcap.out diff --git a/test/results/flow-analyse/dtls.pcap.out b/test/results/flow-analyse/default/dns_dot.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls.pcap.out +++ b/test/results/flow-analyse/default/dns_dot.pcap.out diff --git a/test/results/flow-analyse/dns_exfiltration.pcap.out b/test/results/flow-analyse/default/dns_exfiltration.pcap.out index a0382f7b2..a0382f7b2 100644 --- a/test/results/flow-analyse/dns_exfiltration.pcap.out +++ b/test/results/flow-analyse/default/dns_exfiltration.pcap.out diff --git a/test/results/flow-analyse/dtls2.pcap.out b/test/results/flow-analyse/default/dns_fragmented.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls2.pcap.out +++ b/test/results/flow-analyse/default/dns_fragmented.pcap.out diff --git a/test/results/flow-analyse/dtls_certificate.pcapng.out b/test/results/flow-analyse/default/dns_invert_query.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls_certificate.pcapng.out +++ b/test/results/flow-analyse/default/dns_invert_query.pcapng.out diff --git a/test/results/flow-analyse/dtls_certificate_fragments.pcap.out b/test/results/flow-analyse/default/dns_long_domainname.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls_certificate_fragments.pcap.out +++ b/test/results/flow-analyse/default/dns_long_domainname.pcap.out diff --git a/test/results/flow-analyse/dtls_mid_sessions.pcapng.out b/test/results/flow-analyse/default/dnscrypt-v1-and-resolver-pings.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls_mid_sessions.pcapng.out +++ b/test/results/flow-analyse/default/dnscrypt-v1-and-resolver-pings.pcap.out diff --git a/test/results/flow-analyse/dtls_old_version.pcapng.out b/test/results/flow-analyse/default/dnscrypt-v2-doh.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls_old_version.pcapng.out +++ b/test/results/flow-analyse/default/dnscrypt-v2-doh.pcap.out diff --git a/test/results/flow-analyse/dtls_session_id_and_coockie_both.pcap.out b/test/results/flow-analyse/default/dnscrypt-v2.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/dtls_session_id_and_coockie_both.pcap.out +++ b/test/results/flow-analyse/default/dnscrypt-v2.pcap.out diff --git a/test/results/flow-analyse/elasticsearch.pcap.out b/test/results/flow-analyse/default/dnscrypt_skype_false_positive.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/elasticsearch.pcap.out +++ b/test/results/flow-analyse/default/dnscrypt_skype_false_positive.pcapng.out diff --git a/test/results/flow-analyse/encrypted_sni.pcap.out b/test/results/flow-analyse/default/doq.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/encrypted_sni.pcap.out +++ b/test/results/flow-analyse/default/doq.pcapng.out diff --git a/test/results/flow-analyse/doq_adguard.pcapng.out b/test/results/flow-analyse/default/doq_adguard.pcapng.out index 1c0e790cb..15f1c1338 100644 --- a/test/results/flow-analyse/doq_adguard.pcapng.out +++ b/test/results/flow-analyse/default/doq_adguard.pcapng.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.12.169,94.140.14.14,udp,41070,784,finished,16,16,1608278425043144,1608278427520204,1608278427556259,31,0,1232,1252,3388,9887,0,12,160973.4,1885270,453072.4,205274628096.0,2.4,"36477,41681,43201,66,19,41861,6662,38406,6603,58707,16,206479,12,419140,55,727,29151,153173,67,8229,73,10468,39556,83,37026,44980,51489,1830423,63,12,1885270",59,442.8,1280,522.9,273444.5,4.1,"1260,168,1260,1280,1280,1270,83,84,184,81,1270,1270,1270,1270,255,59,83,84,69,292,140,86,59,69,423,59,70,59,87,89,89,69","4,8,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0","0,5,0,0,2,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,2,0,0,0,0,0,0,0,0","0,1,0,1,1,1,0,0,1,1,1,1,1,1,0,0,0,0,1,1,0,0,0,1,1,0,1,0,0,0,0,1","7.847249508,6.664321423,7.854867935,7.829421520,7.845530033,7.828608036,5.784439087,5.698686600,6.822151661,5.751563549,7.848925114,7.841618061,7.849283695,7.840007782,7.166291237,5.550272942,5.778533459,5.825033665,5.698887825,7.230185032,6.684528351,6.026679039,5.577555180,5.650410652,7.431746960,5.496964455,5.706285954,5.435783863,6.043458462,6.076747894,6.093711376,5.553960800",QUIC.DoH_DoT,188.196,1,Acceptable,Network,6,DPI,"" +1,ip4,192.168.12.169,94.140.14.14,udp,41070,784,finished,16,16,1608278425043144,1608278427520204,1608278427556259,31,0,1232,1252,3388,9887,0,12,160973.4,1885270,453072.4,205274628096.0,2.4,"36477,41681,43201,66,19,41861,6662,38406,6603,58707,16,206479,12,419140,55,727,29151,153173,67,8229,73,10468,39556,83,37026,44980,51489,1830423,63,12,1885270",59,442.8,1280,522.9,273444.5,4.1,"1260,168,1260,1280,1280,1270,83,84,184,81,1270,1270,1270,1270,255,59,83,84,69,292,140,86,59,69,423,59,70,59,87,89,89,69","4,8,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0","0,5,0,0,2,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,2,0,0,0,0,0,0,0,0","0,1,0,1,1,1,0,0,1,1,1,1,1,1,0,0,0,0,1,1,0,0,0,1,1,0,1,0,0,0,0,1","7.847249508,6.664321423,7.854867935,7.829421520,7.845530033,7.828608036,5.784439087,5.698686600,6.822151661,5.751563549,7.848925114,7.841618061,7.849283695,7.840007782,7.166291237,5.550272942,5.778533459,5.825033665,5.698887825,7.230185032,6.684528351,6.026679039,5.577555180,5.650410652,7.431746960,5.496964455,5.706285954,5.435783863,6.043458462,6.076747894,6.093711376,5.553960800",QUIC.DoH_DoT,188.196,1,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/dos_win98_smb_netbeui.pcap.out b/test/results/flow-analyse/default/dos_win98_smb_netbeui.pcap.out index 389bbaddf..389bbaddf 100644 --- a/test/results/flow-analyse/dos_win98_smb_netbeui.pcap.out +++ b/test/results/flow-analyse/default/dos_win98_smb_netbeui.pcap.out diff --git a/test/results/flow-analyse/drda_db2.pcap.out b/test/results/flow-analyse/default/drda_db2.pcap.out index 3a6778052..3a6778052 100644 --- a/test/results/flow-analyse/drda_db2.pcap.out +++ b/test/results/flow-analyse/default/drda_db2.pcap.out diff --git a/test/results/flow-analyse/dropbox.pcap.out b/test/results/flow-analyse/default/dropbox.pcap.out index 9d96b6416..fd9ed0868 100644 --- a/test/results/flow-analyse/dropbox.pcap.out +++ b/test/results/flow-analyse/default/dropbox.pcap.out @@ -1,5 +1,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.56.1,192.168.56.101,udp,50311,17500,finished,16,16,1455907271481938,1455907273126173,1455907273127913,94,0,101,24,1538,306,0,1824,106135.8,117757,19323.7,373406144.0,4.9,"1824,103882,104036,108951,108450,105413,105949,113800,113717,106838,107131,109410,109028,108906,115953,117757,112312,110612,110806,109887,107946,108022,108009,113116,114023,110812,110429,107359,111248,109470,105114",45,85.6,129,38.6,1486.7,4.8,"124,47,123,46,122,45,129,52,125,48,122,45,124,47,124,47,126,49,123,46,124,47,123,46,123,46,123,46,129,52,122,45","0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.543972015,5.027887821,5.510700703,5.088779926,5.530181885,5.047409534,5.667361259,5.185924053,5.578914642,5.069235325,5.512969971,5.047409534,5.559295654,5.027887344,5.530185699,4.958842754,5.597733021,5.084096432,5.503751278,5.045301914,5.504820824,5.027887821,5.497614384,5.045301437,5.497614384,5.088779926,5.490664959,5.088779926,5.682090759,5.315825462,5.555962563,5.047409534",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" -1,ip4,192.168.56.1,192.168.56.101,udp,50318,17500,finished,16,16,1455907272856457,1455907274582746,1455907274587363,95,0,100,23,1552,320,0,2441,111522.4,127663,20842.5,434411712.0,4.9,"2441,112948,114313,107773,108080,108005,107995,109511,111427,119112,118338,116979,117004,127663,125063,114041,112993,120228,120931,111475,111310,105608,107791,113820,112048,122618,125498,112978,109966,123530,125708",46,86.5,128,38.5,1485.6,4.9,"123,46,127,50,126,49,128,51,123,46,125,48,126,49,125,48,123,46,124,47,128,51,126,49,123,46,123,46,123,46,127,50","0,0,6,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.503751755,5.045301437,5.557007790,5.123855114,5.607614994,5.043280125,5.664313793,5.241052628,5.514686108,4.950420856,5.534836769,5.027568340,5.639360428,5.084096432,5.610115051,5.084961891,5.505375385,5.088779926,5.607682705,5.070440769,5.642791271,5.133018017,5.545912743,4.930835724,5.488303185,5.088779926,5.491476536,5.045301437,5.523996830,5.088779926,5.658226490,5.203855038",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" -1,ip4,192.168.56.1,192.168.56.101,udp,50312,17500,finished,16,16,1455907274088318,1455907275896569,1455907275902611,95,0,101,24,1564,332,0,1319,116856.3,131359,22365.2,500202464.0,4.9,"1319,105009,107122,122637,124565,114853,120385,119749,111541,123867,122956,105381,109394,122887,120099,118036,119438,130107,131359,131277,128951,120148,121275,112275,114829,128910,125477,127969,127046,125146,128537",46,87.2,129,38.5,1485.3,4.9,"125,48,129,52,125,48,126,49,126,49,123,46,123,46,123,46,128,51,126,49,127,50,125,48,125,48,128,51,127,50,126,49","0,0,3,13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.540076256,5.126628399,5.646005154,5.238902569,5.556076050,5.011841774,5.645351887,5.124912739,5.661224842,5.124912739,5.536271572,5.045301914,5.526149273,5.010309696,5.552532196,5.088779926,5.645638943,5.155473709,5.623487949,5.027874470,5.658226013,5.203855038,5.594115257,5.084961414,5.581238747,5.084961414,5.642791271,5.201836586,5.575829029,5.148757458,5.623488426,5.043280125",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" -1,ip4,192.168.56.1,192.168.56.101,udp,50319,17500,finished,16,16,1455907275690777,1455907277661201,1455907277663998,94,0,101,24,1561,329,0,5091,127214.4,172321,26264.3,689812928.0,4.9,"5091,140506,139383,127325,129287,138036,134456,137698,141222,137865,138593,132603,133311,132101,136834,172321,164608,137809,136671,122327,121648,117128,118696,128848,133217,115516,110107,123592,124533,106749,105564",45,87.1,129,38.6,1487.1,4.9,"127,50,128,51,123,46,123,46,126,49,123,46,122,45,127,50,125,48,129,52,126,49,124,47,125,48,129,52,124,47,128,51","0,0,4,12,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.584132195,5.148756981,5.612321377,5.123405457,5.484527588,5.088779926,5.497614384,5.088779926,5.597732544,5.084096432,5.526148796,5.088780403,5.523175716,5.047409534,5.616926193,5.163855076,5.550037384,5.084961891,5.666587353,5.277364254,5.567777157,5.068690777,5.565383434,5.070440769,5.542193413,5.084961414,5.626701832,5.238902569,5.490826130,4.985334873,5.638961315,5.241052151",Dropbox,121,0,Acceptable,Cloud,6,DPI,"" +1,ip4,192.168.56.1,192.168.56.101,udp,50311,17500,finished,16,16,1455907271481938,1455907273126173,1455907273127913,94,0,101,24,1538,306,0,1824,106135.8,117757,19323.7,373406144.0,4.9,"1824,103882,104036,108951,108450,105413,105949,113800,113717,106838,107131,109410,109028,108906,115953,117757,112312,110612,110806,109887,107946,108022,108009,113116,114023,110812,110429,107359,111248,109470,105114",45,85.6,129,38.6,1486.7,4.8,"124,47,123,46,122,45,129,52,125,48,122,45,124,47,124,47,126,49,123,46,124,47,123,46,123,46,123,46,129,52,122,45","0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.543972015,5.027887821,5.510700703,5.088779926,5.530181885,5.047409534,5.667361259,5.185924053,5.578914642,5.069235325,5.512969971,5.047409534,5.559295654,5.027887344,5.530185699,4.958842754,5.597733021,5.084096432,5.503751278,5.045301914,5.504820824,5.027887821,5.497614384,5.045301437,5.497614384,5.088779926,5.490664959,5.088779926,5.682090759,5.315825462,5.555962563,5.047409534",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" +1,ip4,192.168.56.1,192.168.56.101,udp,50318,17500,finished,16,16,1455907272856457,1455907274582746,1455907274587363,95,0,100,23,1552,320,0,2441,111522.4,127663,20842.5,434411712.0,4.9,"2441,112948,114313,107773,108080,108005,107995,109511,111427,119112,118338,116979,117004,127663,125063,114041,112993,120228,120931,111475,111310,105608,107791,113820,112048,122618,125498,112978,109966,123530,125708",46,86.5,128,38.5,1485.6,4.9,"123,46,127,50,126,49,128,51,123,46,125,48,126,49,125,48,123,46,124,47,128,51,126,49,123,46,123,46,123,46,127,50","0,0,6,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.503751755,5.045301437,5.557007790,5.123855114,5.607614994,5.043280125,5.664313793,5.241052628,5.514686108,4.950420856,5.534836769,5.027568340,5.639360428,5.084096432,5.610115051,5.084961891,5.505375385,5.088779926,5.607682705,5.070440769,5.642791271,5.133018017,5.545912743,4.930835724,5.488303185,5.088779926,5.491476536,5.045301437,5.523996830,5.088779926,5.658226490,5.203855038",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" +1,ip4,192.168.56.1,192.168.56.101,udp,50312,17500,finished,16,16,1455907274088318,1455907275896569,1455907275902611,95,0,101,24,1564,332,0,1319,116856.3,131359,22365.2,500202464.0,4.9,"1319,105009,107122,122637,124565,114853,120385,119749,111541,123867,122956,105381,109394,122887,120099,118036,119438,130107,131359,131277,128951,120148,121275,112275,114829,128910,125477,127969,127046,125146,128537",46,87.2,129,38.5,1485.3,4.9,"125,48,129,52,125,48,126,49,126,49,123,46,123,46,123,46,128,51,126,49,127,50,125,48,125,48,128,51,127,50,126,49","0,0,3,13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.540076256,5.126628399,5.646005154,5.238902569,5.556076050,5.011841774,5.645351887,5.124912739,5.661224842,5.124912739,5.536271572,5.045301914,5.526149273,5.010309696,5.552532196,5.088779926,5.645638943,5.155473709,5.623487949,5.027874470,5.658226013,5.203855038,5.594115257,5.084961414,5.581238747,5.084961414,5.642791271,5.201836586,5.575829029,5.148757458,5.623488426,5.043280125",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" +1,ip4,192.168.56.1,192.168.56.101,udp,50319,17500,finished,16,16,1455907275690777,1455907277661201,1455907277663998,94,0,101,24,1561,329,0,5091,127214.4,172321,26264.3,689812928.0,4.9,"5091,140506,139383,127325,129287,138036,134456,137698,141222,137865,138593,132603,133311,132101,136834,172321,164608,137809,136671,122327,121648,117128,118696,128848,133217,115516,110107,123592,124533,106749,105564",45,87.1,129,38.6,1487.1,4.9,"127,50,128,51,123,46,123,46,126,49,123,46,122,45,127,50,125,48,129,52,126,49,124,47,125,48,129,52,124,47,128,51","0,0,4,12,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.584132195,5.148756981,5.612321377,5.123405457,5.484527588,5.088779926,5.497614384,5.088779926,5.597732544,5.084096432,5.526148796,5.088780403,5.523175716,5.047409534,5.616926193,5.163855076,5.550037384,5.084961891,5.666587353,5.277364254,5.567777157,5.068690777,5.565383434,5.070440769,5.542193413,5.084961414,5.626701832,5.238902569,5.490826130,4.985334873,5.638961315,5.241052151",Dropbox,121,0,Acceptable,Cloud,6,DPI,"46" diff --git a/test/results/flow-analyse/esp.pcapng.out b/test/results/flow-analyse/default/dtls.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/esp.pcapng.out +++ b/test/results/flow-analyse/default/dtls.pcap.out diff --git a/test/results/flow-analyse/ethernetIP.pcap.out b/test/results/flow-analyse/default/dtls2.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ethernetIP.pcap.out +++ b/test/results/flow-analyse/default/dtls2.pcap.out diff --git a/test/results/flow-analyse/ftp_failed.pcap.out b/test/results/flow-analyse/default/dtls_certificate.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ftp_failed.pcap.out +++ b/test/results/flow-analyse/default/dtls_certificate.pcapng.out diff --git a/test/results/flow-analyse/fuzz-2006-09-29-28586.pcap.out b/test/results/flow-analyse/default/dtls_certificate_fragments.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/fuzz-2006-09-29-28586.pcap.out +++ b/test/results/flow-analyse/default/dtls_certificate_fragments.pcap.out diff --git a/test/results/flow-analyse/fuzz-2021-06-07-c6c72a0a56.pcap.out b/test/results/flow-analyse/default/dtls_mid_sessions.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/fuzz-2021-06-07-c6c72a0a56.pcap.out +++ b/test/results/flow-analyse/default/dtls_mid_sessions.pcapng.out diff --git a/test/results/flow-analyse/fuzz-2021-10-13.pcap.out b/test/results/flow-analyse/default/dtls_old_version.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/fuzz-2021-10-13.pcap.out +++ b/test/results/flow-analyse/default/dtls_old_version.pcapng.out diff --git a/test/results/flow-analyse/genshin-impact.pcap.out b/test/results/flow-analyse/default/dtls_session_id_and_coockie_both.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/genshin-impact.pcap.out +++ b/test/results/flow-analyse/default/dtls_session_id_and_coockie_both.pcap.out diff --git a/test/results/flow-analyse/google_ssl.pcap.out b/test/results/flow-analyse/default/elasticsearch.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/google_ssl.pcap.out +++ b/test/results/flow-analyse/default/elasticsearch.pcap.out diff --git a/test/results/flow-analyse/emotet.pcap.out b/test/results/flow-analyse/default/emotet.pcap.out index 355e19230..d66be3cbb 100644 --- a/test/results/flow-analyse/emotet.pcap.out +++ b/test/results/flow-analyse/default/emotet.pcap.out @@ -1,6 +1,6 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,10.2.25.102,193.252.22.84,tcp,57309,587,finished,13,19,1645830066121611,1645830074471734,1645830074471604,0,0,698,160,898,391,0,254,538713.4,3056402,774055.0,599161176064.0,3.7,"749523,749719,1106307,1106777,773,369838,370621,895,325625,326244,506,323,737,841210,842439,907,363,438,3054676,3056402,1628,247201,247778,521,1205120,1205575,420,442964,443628,704,254",40,80.8,738,121.9,14849.5,4.3,"52,44,40,94,61,40,200,52,40,58,72,40,42,40,58,56,40,42,40,80,77,40,86,73,40,87,46,40,48,79,40,738","8,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","14,4,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,1,0,1,1,0,1,0,1,1,0,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0","4.644789696,4.953416348,4.981687069,5.477373600,5.387795925,4.784183979,5.738989830,5.361793995,4.834184170,5.487123966,5.654376030,4.784183979,4.955064297,4.734184265,5.288679600,5.421465874,4.784183979,4.859826565,4.784183979,5.343945503,5.557319641,4.765312195,5.392617702,5.626545429,4.834184170,5.525993347,5.097266674,4.834184170,5.095175266,5.329178810,4.784184456,5.639209747",SMTP,3,0,Acceptable,Email,6,DPI,"" 1,ip4,10.3.29.101,104.161.127.22,tcp,56309,80,finished,12,20,1648563468993352,1648563469442201,1648563469442152,0,0,446,1361,446,24498,0,77,28956.4,204389,59845.4,3581476608.0,2.7,"115764,115896,335,518,204207,77,204389,352,224,565,217,228,441,212,496,705,246,220,470,115050,221,115302,340,251,573,9235,226,9483,474,242,690",40,820.0,1401,663.1,439751.8,4.4,"52,44,40,486,40,1401,1401,40,1401,1401,40,1401,1401,40,1401,1401,40,1401,1401,40,1401,1401,40,1401,1401,40,1401,1401,40,1401,1401,40","11,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,18,0,0,0,0,0","0,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0","4.710365295,4.913976669,4.680641174,5.777981758,4.621928692,7.446667671,7.722211838,4.711769104,7.820096016,7.819649696,4.730641365,7.834948540,7.865209579,4.730641365,7.838735580,7.852061272,4.780641079,7.835340023,7.853207111,4.711769104,7.851351738,7.847233772,4.780641079,7.872184753,7.855648994,4.780641079,7.879763126,7.844507217,4.680641174,7.843948364,7.837398529,4.780641079",HTTP,7,0,Acceptable,Web,6,DPI,"" -1,ip4,10.4.20.102,107.161.178.210,tcp,54319,80,finished,17,15,1650490398530577,1650490399009658,1650490399009514,0,0,225,1388,225,19432,0,40,30903.8,260940,65726.9,4320020480.0,3.0,"97254,97549,387,260940,260431,3204,3158,9543,9466,6236,69,6255,124,124,128,201,123,50,174,174,40,2646,2680,60630,60713,9884,9822,15114,15099,12868,12932",46,657.7,1428,680.4,462891.9,4.1,"52,48,46,265,1428,46,1428,46,1428,46,1428,1428,46,1428,46,1428,46,1428,46,1428,46,46,1428,46,1428,46,1428,46,1428,46,1428,46","16,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0,0,0","0,1,0,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,0,1,0,0,1,0,1,0,1,0,1,0,1,0","4.633441925,5.001628399,4.330939770,5.702507019,4.791214466,4.390829086,5.521807671,4.303872585,6.000949860,4.347350597,5.983242989,6.243623734,4.347351074,5.943493843,4.390829086,4.384503365,4.390829086,4.537651062,4.347351074,4.500005245,4.390829086,4.390829086,4.575252056,4.390829086,4.522280216,4.390829086,4.470242500,4.347350597,4.561497688,4.347350597,4.580824375,4.390829086",HTTP,7,0,Acceptable,Web,6,DPI,"4" +1,ip4,10.4.20.102,107.161.178.210,tcp,54319,80,finished,17,15,1650490398530577,1650490399009658,1650490399009514,0,0,225,1388,225,19432,0,40,30903.8,260940,65726.9,4320020480.0,3.0,"97254,97549,387,260940,260431,3204,3158,9543,9466,6236,69,6255,124,124,128,201,123,50,174,174,40,2646,2680,60630,60713,9884,9822,15114,15099,12868,12932",46,657.7,1428,680.4,462891.9,4.1,"52,48,46,265,1428,46,1428,46,1428,46,1428,1428,46,1428,46,1428,46,1428,46,1428,46,46,1428,46,1428,46,1428,46,1428,46,1428,46","16,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0,0,0","0,1,0,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,0,1,0,0,1,0,1,0,1,0,1,0,1,0","4.633441925,5.001628399,4.330939770,5.702507019,4.791214466,4.390829086,5.521807671,4.303872585,6.000949860,4.347350597,5.983242989,6.243623734,4.347351074,5.943493843,4.390829086,4.384503365,4.390829086,4.537651062,4.347351074,4.500005245,4.390829086,4.390829086,4.575252056,4.390829086,4.522280216,4.390829086,4.470242500,4.347350597,4.561497688,4.347350597,4.580824375,4.390829086",HTTP,7,0,Acceptable,Download,6,DPI,"4" 1,ip4,10.4.25.101,77.105.36.156,tcp,49797,80,finished,10,22,1650905413858492,1650905414512477,1650905414512421,0,0,152,1388,152,26616,0,56,42190.8,292217,79641.8,6342810624.0,2.9,"184236,184528,232,171817,120639,81,116,292217,2662,111,117,90,2892,2739,117,70,3040,164670,68,120,164820,2817,118,71,3042,2918,68,119,165,3158,56",46,878.9,1428,652.6,425943.0,4.5,"52,52,46,192,46,612,1428,1428,46,1428,1428,1428,1100,46,1428,1428,1428,46,1428,1428,1428,46,1428,1428,1428,46,1428,1428,1428,1428,46,46","9,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,18,0,0,0,0","0,1,0,0,1,1,1,1,0,1,1,1,1,0,1,1,1,0,1,1,1,0,1,1,1,0,1,1,1,1,0,0","4.671903610,4.849197388,4.501398563,5.653024197,4.390829563,5.577536106,4.013392448,5.117209911,4.501398563,5.103430748,5.009723663,5.324585438,5.512314796,4.457919598,5.070570469,5.174447536,5.467666149,4.457920074,5.218022346,5.067547321,5.343363285,4.501398087,5.389601707,5.123095036,5.071803093,4.354552746,5.203499794,5.430387497,5.394243717,4.889959335,4.501398563,4.390829086",HTTP,7,0,Acceptable,Download,6,DPI,"4,11" 1,ip4,10.4.25.101,138.197.147.101,tcp,49803,443,info,14,18,1650905467542773,1650905469294827,1650905469297748,0,0,480,1388,722,19664,0,0,113130.0,1262510,287859.5,82863079424.0,2.7,"109372,109625,14139,123772,13228,122858,52674,132935,80275,6518,151937,1117119,71,165,1262510,58,2900,71,3072,96890,117,96947,3054,71,165,71,3262,0,116,2919,118",46,682.0,1428,663.2,439900.2,4.2,"52,52,46,189,46,1418,46,133,282,46,520,46,1428,1428,1428,46,46,1428,1428,52,1428,1428,60,1428,1428,1428,1428,60,60,60,1428,1428","11,0,1,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0,0,0","0,1,0,0,1,1,0,0,1,0,0,1,1,1,1,0,0,1,1,0,1,1,0,1,1,1,1,0,0,0,1,1","4.661227226,4.908878326,4.501398087,5.357971191,4.609350681,7.499943256,4.609350204,5.862740993,7.080684185,4.501398087,7.521671295,4.522393703,7.860427856,7.879212856,7.876828194,4.501398087,4.501398087,7.862761021,7.872880459,4.974009037,7.863744259,7.867939472,5.142321110,7.869549751,7.874364853,7.859346390,7.876013756,5.142321110,5.142321110,5.142320633,7.842814445,7.873933792",,,,,,,,"" diff --git a/test/results/flow-analyse/gquic.pcap.out b/test/results/flow-analyse/default/encrypted_sni.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/gquic.pcap.out +++ b/test/results/flow-analyse/default/encrypted_sni.pcap.out diff --git a/test/results/flow-analyse/gre_no_options.pcapng.out b/test/results/flow-analyse/default/esp.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/gre_no_options.pcapng.out +++ b/test/results/flow-analyse/default/esp.pcapng.out diff --git a/test/results/flow-analyse/ethereum.pcap.out b/test/results/flow-analyse/default/ethereum.pcap.out index 76b8a2c8c..76b8a2c8c 100644 --- a/test/results/flow-analyse/ethereum.pcap.out +++ b/test/results/flow-analyse/default/ethereum.pcap.out diff --git a/test/results/flow-analyse/gtp_c.pcap.out b/test/results/flow-analyse/default/ethernetIP.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/gtp_c.pcap.out +++ b/test/results/flow-analyse/default/ethernetIP.pcap.out diff --git a/test/results/flow-analyse/exe_download.pcap.out b/test/results/flow-analyse/default/exe_download.pcap.out index aa98fa3a4..e0e51cfd1 100644 --- a/test/results/flow-analyse/exe_download.pcap.out +++ b/test/results/flow-analyse/default/exe_download.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.9.25.101,144.91.69.195,tcp,49165,80,finished,11,21,1569434051004796,1569434051966172,1569434051966041,0,0,153,1460,153,25896,0,7,62020.0,319527,115050.4,13236601856.0,3.0,"319320,319527,656,1120,298136,10,298579,1555,147,1842,2428,2695,9,4969,246,28639,114,28917,100748,305805,34,11,94,205204,207,207,651,10,7,7,727",40,854.5,1500,668.4,446708.3,4.4,"52,44,40,193,40,1500,1308,40,1404,1404,40,1404,1500,1288,40,1404,1404,1404,40,40,1500,1500,1212,1404,40,1404,40,1500,1500,1500,1116,40","10,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,2,0,0,8,0,0,7,0,0","0,1,0,0,1,1,1,0,1,1,0,1,1,1,0,1,1,1,0,0,1,1,1,1,0,1,0,1,1,1,1,0","4.385625362,4.876442909,4.621928215,5.761415958,4.730640888,3.668365002,0.301540941,4.621928692,0.282004327,4.382377148,4.571928501,5.688343048,5.482964993,5.437496185,4.521928310,5.899663925,5.776542664,5.685672760,4.571928501,4.571928501,5.409879208,5.378962994,5.436534882,5.744604588,4.571928978,5.603744507,4.521928787,5.738482952,5.793150902,5.592350006,5.696241856,4.571928978",HTTP,7,0,Acceptable,Download,6,DPI,"4,11,12" +1,ip4,10.9.25.101,144.91.69.195,tcp,49165,80,finished,11,21,1569434051004796,1569434051966172,1569434051966041,0,0,153,1460,153,25896,0,7,62020.0,319527,115050.4,13236601856.0,3.0,"319320,319527,656,1120,298136,10,298579,1555,147,1842,2428,2695,9,4969,246,28639,114,28917,100748,305805,34,11,94,205204,207,207,651,10,7,7,727",40,854.5,1500,668.4,446708.3,4.4,"52,44,40,193,40,1500,1308,40,1404,1404,40,1404,1500,1288,40,1404,1404,1404,40,40,1500,1500,1212,1404,40,1404,40,1500,1500,1500,1116,40","10,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,2,0,0,8,0,0,7,0,0","0,1,0,0,1,1,1,0,1,1,0,1,1,1,0,1,1,1,0,0,1,1,1,1,0,1,0,1,1,1,1,0","4.385625362,4.876442909,4.621928215,5.761415958,4.730640888,3.668365002,0.301540941,4.621928692,0.282004327,4.382377148,4.571928501,5.688343048,5.482964993,5.437496185,4.521928310,5.899663925,5.776542664,5.685672760,4.571928501,4.571928501,5.409879208,5.378962994,5.436534882,5.744604588,4.571928978,5.603744507,4.521928787,5.738482952,5.793150902,5.592350006,5.696241856,4.571928978",HTTP,7,0,Acceptable,Download,6,DPI,"4,11,12,47" diff --git a/test/results/flow-analyse/exe_download_as_png.pcap.out b/test/results/flow-analyse/default/exe_download_as_png.pcap.out index 7131beddf..31dee1e14 100644 --- a/test/results/flow-analyse/exe_download_as_png.pcap.out +++ b/test/results/flow-analyse/default/exe_download_as_png.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.9.25.101,185.98.87.185,tcp,49197,80,finished,11,21,1569434903040298,1569434904481632,1569434904508320,0,0,149,1460,149,25916,0,12,93850.2,613012,192589.9,37090865152.0,2.7,"400153,400486,228,717,612677,12,613012,424,482,834,426,507,936,1134,423,1552,361,732,1082,417726,1390,103,419479,654,405,941,2596,154,2784,26602,344",40,855.0,1500,664.6,441668.3,4.4,"52,44,40,189,40,1500,1308,40,1404,1404,40,1404,1404,40,1404,1404,40,1404,1404,40,1404,1404,1404,40,1404,1404,40,1404,1404,40,1404,1404","10,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,17,0,0,1,0,0","0,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,1,0,1,1,0,1,1,0,1,1","4.593450069,4.921897411,4.734183788,5.453228951,4.630641460,3.420540333,0.300011843,4.784183979,0.284853339,4.608477116,4.784183979,4.479417324,3.353007078,4.684184074,3.253508806,3.476947546,4.734183788,4.057516575,5.282192707,4.734183788,5.523138046,4.632616997,4.955163479,4.715311527,4.361701965,2.729017735,4.734184265,6.268059254,4.366500378,4.734183788,4.014078617,2.777677774",HTTP,7,0,Acceptable,Web,6,DPI,"4,12" +1,ip4,10.9.25.101,185.98.87.185,tcp,49197,80,finished,11,21,1569434903040298,1569434904481632,1569434904508320,0,0,149,1460,149,25916,0,12,93850.2,613012,192589.9,37090865152.0,2.7,"400153,400486,228,717,612677,12,613012,424,482,834,426,507,936,1134,423,1552,361,732,1082,417726,1390,103,419479,654,405,941,2596,154,2784,26602,344",40,855.0,1500,664.6,441668.3,4.4,"52,44,40,189,40,1500,1308,40,1404,1404,40,1404,1404,40,1404,1404,40,1404,1404,40,1404,1404,1404,40,1404,1404,40,1404,1404,40,1404,1404","10,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,17,0,0,1,0,0","0,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,1,0,1,1,0,1,1,0,1,1","4.593450069,4.921897411,4.734183788,5.453228951,4.630641460,3.420540333,0.300011843,4.784183979,0.284853339,4.608477116,4.784183979,4.479417324,3.353007078,4.684184074,3.253508806,3.476947546,4.734183788,4.057516575,5.282192707,4.734183788,5.523138046,4.632616997,4.955163479,4.715311527,4.361701965,2.729017735,4.734184265,6.268059254,4.366500378,4.734183788,4.014078617,2.777677774",HTTP,7,0,Acceptable,Web,6,DPI,"4,12,47" diff --git a/test/results/flow-analyse/facebook.pcap.out b/test/results/flow-analyse/default/facebook.pcap.out index 75e0d09fc..75e0d09fc 100644 --- a/test/results/flow-analyse/facebook.pcap.out +++ b/test/results/flow-analyse/default/facebook.pcap.out diff --git a/test/results/flow-analyse/fastcgi.pcap.out b/test/results/flow-analyse/default/fastcgi.pcap.out index 3f718f6b1..3f718f6b1 100644 --- a/test/results/flow-analyse/fastcgi.pcap.out +++ b/test/results/flow-analyse/default/fastcgi.pcap.out diff --git a/test/results/flow-analyse/gtp_false_positive.pcapng.out b/test/results/flow-analyse/default/firefox.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/gtp_false_positive.pcapng.out +++ b/test/results/flow-analyse/default/firefox.pcap.out diff --git a/test/results/flow-analyse/fix.pcap.out b/test/results/flow-analyse/default/fix.pcap.out index 80e1de139..9a1149dd0 100644 --- a/test/results/flow-analyse/fix.pcap.out +++ b/test/results/flow-analyse/default/fix.pcap.out @@ -1,6 +1,6 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,208.245.107.3,192.168.0.20,tcp,4000,45578,finished,16,16,1493755109301176,1493755110311293,1493755110311459,0,0,457,86,1522,86,1,170,65174.2,314954,68088.5,4636038656.0,4.4,"170,209,52428,3585,93980,87569,49399,50741,50707,52796,52875,49653,49630,49737,49707,49456,49402,49750,49791,49981,50005,49926,49930,49589,49596,49797,49760,50218,50168,314891,314954",40,93.1,497,87.5,7658.2,4.6,"79,46,126,155,40,46,497,46,216,46,219,46,129,46,96,46,171,46,98,46,67,46,92,46,67,46,75,46,94,46,67,46","4,6,1,1,1,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.154581547,4.414441109,6.395655632,5.091774940,4.780641556,4.457919598,5.201892376,4.414441109,4.962749958,4.457919598,5.236365318,4.414441109,5.106607437,4.457919598,5.098806381,4.457919598,5.104629040,4.398030281,5.136437416,4.347350597,5.144082069,4.457919598,4.962267876,4.414441109,5.073113441,4.370962620,5.166584492,4.457919598,4.922869682,4.457919598,5.102964401,4.370963097",FIX,230,0,Safe,RPC,6,DPI,"" -1,ip4,8.17.22.31,192.168.0.20,tcp,4000,47968,finished,16,16,1493755109264927,1493755110667807,1493755110668000,0,0,69,87,553,87,1,25,90514.6,300186,84141.6,7079807488.0,4.2,"147,100141,123,100163,124,100018,123,100053,25,99913,99995,100225,100166,100788,100836,300170,29,300186,26,222,17881,82390,142005,200503,158539,99966,99944,398,386,200212,200256",52,72.0,139,23.6,558.3,4.9,"82,52,87,78,52,52,87,86,52,52,78,52,121,52,77,52,91,121,52,52,139,52,91,52,87,52,87,52,76,52,84,52","6,8,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,0,1,0,1,0,1,0,0,1,1,1,0,0,1,0,1,0,1,0,1,0,1","5.351819992,5.248330116,5.436416626,5.363250256,5.103910923,5.156889915,5.413428307,5.384781837,5.115703106,5.168681622,5.321646214,5.132944584,5.563299656,5.209868431,5.466999531,5.248330116,5.438351631,5.219768047,5.118427753,5.132945061,6.504659653,5.091758728,5.478478432,5.209868431,5.454665184,5.171406746,5.204155445,5.209868431,5.232492447,5.209868431,5.401538372,5.132945061",FIX,230,0,Safe,RPC,6,DPI,"" -1,ip4,8.17.22.31,192.168.0.20,tcp,4000,43594,finished,16,16,1493755109242949,1493755111999185,1493755111999341,0,0,188,85,1313,85,1,24,177826.7,291268,112931.7,12753577984.0,4.5,"209,293,265,250589,114,250615,24,223,18233,232135,291268,250073,208970,250691,250733,250586,250560,250658,250654,250671,250658,250632,30,250660,26,251471,251453,249735,249759,250325,250315",52,95.7,240,52.0,2700.5,4.8,"138,52,77,52,91,138,52,52,137,52,155,52,155,52,172,52,155,52,155,52,104,52,240,99,52,52,121,52,189,52,104,52","2,4,3,5,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1,1,0,1,0,1,0,1","5.494600296,5.156889439,5.286477566,5.118427753,5.354906082,5.367415428,5.156889915,5.118428230,6.408948421,5.130219936,5.439220428,5.209867954,5.526780605,5.248329639,5.560081959,5.171406746,5.428024292,5.209867954,5.492540359,5.209868431,5.433600426,5.171406746,5.581422329,5.564811230,5.171406746,5.209867954,5.463109970,5.209867954,5.382565022,5.209867954,5.537013054,5.209868431",FIX,230,0,Safe,RPC,6,DPI,"" -1,ip4,208.245.107.3,192.168.0.20,tcp,4000,45584,finished,16,16,1493755109440420,1493755120254899,1493755120295550,0,0,39,87,498,173,1,168,699019.6,5507323,1280900.8,1640706605056.0,3.7,"168,500717,500699,200419,200471,184,89723,210661,340264,500679,460548,5507291,5507323,600979,600971,400442,400455,700964,700990,400404,400386,600557,600559,400806,400807,600830,600822,215,54314,45693,140268",40,63.6,127,21.9,481.2,4.9,"75,46,75,46,79,46,127,40,75,46,75,46,75,46,75,46,75,46,75,46,75,46,75,46,75,46,79,46,126,40,75,46","2,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","14,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1","4.945594788,4.398030758,5.188046455,4.398030758,5.199008465,4.457919598,6.476713657,4.730641365,4.962196827,4.457919598,5.241379738,4.501398087,5.161379337,4.501398087,5.025595188,4.457919598,5.052261829,4.457919598,5.214713573,4.457919598,5.224778175,4.501398087,5.241379738,4.457919598,5.025595188,4.501398087,5.249641418,4.501398087,6.379781723,4.730641365,4.998929024,4.457919598",FIX,230,0,Safe,RPC,6,DPI,"" -1,ip4,8.17.22.31,192.168.0.20,tcp,4000,40918,finished,16,16,1493755110328857,1493755130974521,1493755130974683,0,0,81,85,651,170,1,110,1331983.5,4175061,1132458.4,1282462056448.0,4.4,"110,1093319,1093395,599016,598995,1546128,1546141,239,22763,2072709,2137804,913298,870712,442005,442027,3366066,3366054,1195438,1195405,437653,437695,1550229,1550211,211,22417,1711389,1774342,1498173,1457475,4175061,4175010",52,77.7,137,28.5,811.2,4.9,"91,52,112,52,91,52,91,52,137,52,91,52,91,52,112,52,91,52,112,52,91,52,91,52,137,52,91,52,133,52,91,52","2,13,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","14,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,1","5.567693233,5.103910923,5.539355278,5.053297043,5.492160797,5.118427753,5.446647644,5.118427753,6.341468334,5.115703106,5.351537228,5.171406269,5.539231300,5.171406746,5.445882797,5.171406746,5.442563534,5.118428230,5.588550091,5.209868431,5.417931080,5.209867954,5.425766945,5.132945061,6.498472691,5.168681622,5.496372223,5.094483376,5.470992565,5.171406269,5.501759529,5.171406746",FIX,230,0,Safe,RPC,6,DPI,"" +1,ip4,208.245.107.3,192.168.0.20,tcp,4000,45578,finished,16,16,1493755109301176,1493755110311293,1493755110311459,0,0,457,86,1522,86,1,170,65174.2,314954,68088.5,4636038656.0,4.4,"170,209,52428,3585,93980,87569,49399,50741,50707,52796,52875,49653,49630,49737,49707,49456,49402,49750,49791,49981,50005,49926,49930,49589,49596,49797,49760,50218,50168,314891,314954",40,93.1,497,87.5,7658.2,4.6,"79,46,126,155,40,46,497,46,216,46,219,46,129,46,96,46,171,46,98,46,67,46,92,46,67,46,75,46,94,46,67,46","4,6,1,1,1,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.154581547,4.414441109,6.395655632,5.091774940,4.780641556,4.457919598,5.201892376,4.414441109,4.962749958,4.457919598,5.236365318,4.414441109,5.106607437,4.457919598,5.098806381,4.457919598,5.104629040,4.398030281,5.136437416,4.347350597,5.144082069,4.457919598,4.962267876,4.414441109,5.073113441,4.370962620,5.166584492,4.457919598,4.922869682,4.457919598,5.102964401,4.370963097",FIX,230,0,Safe,RPC,6,DPI,"46" +1,ip4,8.17.22.31,192.168.0.20,tcp,4000,47968,finished,16,16,1493755109264927,1493755110667807,1493755110668000,0,0,69,87,553,87,1,25,90514.6,300186,84141.6,7079807488.0,4.2,"147,100141,123,100163,124,100018,123,100053,25,99913,99995,100225,100166,100788,100836,300170,29,300186,26,222,17881,82390,142005,200503,158539,99966,99944,398,386,200212,200256",52,72.0,139,23.6,558.3,4.9,"82,52,87,78,52,52,87,86,52,52,78,52,121,52,77,52,91,121,52,52,139,52,91,52,87,52,87,52,76,52,84,52","6,8,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,0,1,0,1,0,1,0,0,1,1,1,0,0,1,0,1,0,1,0,1,0,1","5.351819992,5.248330116,5.436416626,5.363250256,5.103910923,5.156889915,5.413428307,5.384781837,5.115703106,5.168681622,5.321646214,5.132944584,5.563299656,5.209868431,5.466999531,5.248330116,5.438351631,5.219768047,5.118427753,5.132945061,6.504659653,5.091758728,5.478478432,5.209868431,5.454665184,5.171406746,5.204155445,5.209868431,5.232492447,5.209868431,5.401538372,5.132945061",FIX,230,0,Safe,RPC,6,DPI,"46" +1,ip4,8.17.22.31,192.168.0.20,tcp,4000,43594,finished,16,16,1493755109242949,1493755111999185,1493755111999341,0,0,188,85,1313,85,1,24,177826.7,291268,112931.7,12753577984.0,4.5,"209,293,265,250589,114,250615,24,223,18233,232135,291268,250073,208970,250691,250733,250586,250560,250658,250654,250671,250658,250632,30,250660,26,251471,251453,249735,249759,250325,250315",52,95.7,240,52.0,2700.5,4.8,"138,52,77,52,91,138,52,52,137,52,155,52,155,52,172,52,155,52,155,52,104,52,240,99,52,52,121,52,189,52,104,52","2,4,3,5,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1,1,0,1,0,1,0,1","5.494600296,5.156889439,5.286477566,5.118427753,5.354906082,5.367415428,5.156889915,5.118428230,6.408948421,5.130219936,5.439220428,5.209867954,5.526780605,5.248329639,5.560081959,5.171406746,5.428024292,5.209867954,5.492540359,5.209868431,5.433600426,5.171406746,5.581422329,5.564811230,5.171406746,5.209867954,5.463109970,5.209867954,5.382565022,5.209867954,5.537013054,5.209868431",FIX,230,0,Safe,RPC,6,DPI,"46" +1,ip4,208.245.107.3,192.168.0.20,tcp,4000,45584,finished,16,16,1493755109440420,1493755120254899,1493755120295550,0,0,39,87,498,173,1,168,699019.6,5507323,1280900.8,1640706605056.0,3.7,"168,500717,500699,200419,200471,184,89723,210661,340264,500679,460548,5507291,5507323,600979,600971,400442,400455,700964,700990,400404,400386,600557,600559,400806,400807,600830,600822,215,54314,45693,140268",40,63.6,127,21.9,481.2,4.9,"75,46,75,46,79,46,127,40,75,46,75,46,75,46,75,46,75,46,75,46,75,46,75,46,75,46,79,46,126,40,75,46","2,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","14,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1","4.945594788,4.398030758,5.188046455,4.398030758,5.199008465,4.457919598,6.476713657,4.730641365,4.962196827,4.457919598,5.241379738,4.501398087,5.161379337,4.501398087,5.025595188,4.457919598,5.052261829,4.457919598,5.214713573,4.457919598,5.224778175,4.501398087,5.241379738,4.457919598,5.025595188,4.501398087,5.249641418,4.501398087,6.379781723,4.730641365,4.998929024,4.457919598",FIX,230,0,Safe,RPC,6,DPI,"46" +1,ip4,8.17.22.31,192.168.0.20,tcp,4000,40918,finished,16,16,1493755110328857,1493755130974521,1493755130974683,0,0,81,85,651,170,1,110,1331983.5,4175061,1132458.4,1282462056448.0,4.4,"110,1093319,1093395,599016,598995,1546128,1546141,239,22763,2072709,2137804,913298,870712,442005,442027,3366066,3366054,1195438,1195405,437653,437695,1550229,1550211,211,22417,1711389,1774342,1498173,1457475,4175061,4175010",52,77.7,137,28.5,811.2,4.9,"91,52,112,52,91,52,91,52,137,52,91,52,91,52,112,52,91,52,112,52,91,52,91,52,137,52,91,52,133,52,91,52","2,13,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","14,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,1","5.567693233,5.103910923,5.539355278,5.053297043,5.492160797,5.118427753,5.446647644,5.118427753,6.341468334,5.115703106,5.351537228,5.171406269,5.539231300,5.171406746,5.445882797,5.171406746,5.442563534,5.118428230,5.588550091,5.209868431,5.417931080,5.209867954,5.425766945,5.132945061,6.498472691,5.168681622,5.496372223,5.094483376,5.470992565,5.171406269,5.501759529,5.171406746",FIX,230,0,Safe,RPC,6,DPI,"46" diff --git a/test/results/flow-analyse/fix2.pcap.out b/test/results/flow-analyse/default/fix2.pcap.out index bde7533ad..bde7533ad 100644 --- a/test/results/flow-analyse/fix2.pcap.out +++ b/test/results/flow-analyse/default/fix2.pcap.out diff --git a/test/results/flow-analyse/forticlient.pcap.out b/test/results/flow-analyse/default/forticlient.pcap.out index 99ab4ddb6..99ab4ddb6 100644 --- a/test/results/flow-analyse/forticlient.pcap.out +++ b/test/results/flow-analyse/default/forticlient.pcap.out diff --git a/test/results/flow-analyse/ftp-start-tls.pcap.out b/test/results/flow-analyse/default/ftp-start-tls.pcap.out index 2e194d592..2e194d592 100644 --- a/test/results/flow-analyse/ftp-start-tls.pcap.out +++ b/test/results/flow-analyse/default/ftp-start-tls.pcap.out diff --git a/test/results/flow-analyse/ftp.pcap.out b/test/results/flow-analyse/default/ftp.pcap.out index 7fa5ffb12..12cd6afe4 100644 --- a/test/results/flow-analyse/ftp.pcap.out +++ b/test/results/flow-analyse/default/ftp.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.212,90.130.70.73,tcp,50694,21,finished,18,14,1552590234892296,1552590235175924,1552590235202548,0,0,30,241,86,532,0,6,19157.4,90047,20644.4,426190272.0,4.1,"27412,27520,29008,29012,526,27660,315,27401,217,69061,21193,90047,306,27070,21,26780,133,26972,64,26857,6,275,27478,27261,90,29,651,27147,26517,90,26761",52,71.9,293,42.7,1824.0,4.8,"64,60,52,72,52,68,52,86,52,65,52,75,52,57,52,86,52,58,67,117,52,52,63,96,52,293,52,82,74,52,57,86","18,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,4,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,0,1,0,1,0,0,1,0,0,1","4.219557285,5.306893826,4.854784012,5.580945969,4.891996861,5.392103672,5.192626476,5.723867416,4.853535175,5.160228252,5.115703106,5.653334618,4.853535175,5.038432598,5.038779736,5.595732212,4.829590797,5.029721737,5.522709370,5.304079056,4.891996861,4.891996861,5.214752197,5.731670380,4.891996861,5.029207230,4.891996861,5.558178902,5.555310249,4.891996861,5.073520184,5.687595367",FTP_CONTROL,1,0,Unsafe,Download,6,DPI,"22" +1,ip4,192.168.1.212,90.130.70.73,tcp,50694,21,finished,18,14,1552590234892296,1552590235175924,1552590235202548,0,0,30,241,86,532,0,6,19157.4,90047,20644.4,426190272.0,4.1,"27412,27520,29008,29012,526,27660,315,27401,217,69061,21193,90047,306,27070,21,26780,133,26972,64,26857,6,275,27478,27261,90,29,651,27147,26517,90,26761",52,71.9,293,42.7,1824.0,4.8,"64,60,52,72,52,68,52,86,52,65,52,75,52,57,52,86,52,58,67,117,52,52,63,96,52,293,52,82,74,52,57,86","18,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,4,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,0,1,0,1,0,0,1,0,0,1","4.219557285,5.306893826,4.854784012,5.580945969,4.891996861,5.392103672,5.192626476,5.723867416,4.853535175,5.160228252,5.115703106,5.653334618,4.853535175,5.038432598,5.038779736,5.595732212,4.829590797,5.029721737,5.522709370,5.304079056,4.891996861,4.891996861,5.214752197,5.731670380,4.891996861,5.029207230,4.891996861,5.558178902,5.555310249,4.891996861,5.073520184,5.687595367",FTP_CONTROL,1,0,Unsafe,Download,6,DPI,"22,36" 1,ip4,192.168.1.212,90.130.70.73,tcp,50696,24523,info,13,19,1552590241545143,1552590241637688,1552590241639633,0,0,0,1440,0,24480,0,2,6033.4,29579,11108.9,123407192.0,3.1,"28770,28814,29579,29566,281,284,597,608,340,458,790,363,375,64,327,2,379,43,300,27513,27767,195,211,1702,115,4,1805,1866,1903,218,1796",52,818.0,1492,717.5,514855.0,4.3,"64,60,52,1492,64,1492,52,1492,52,1492,1492,52,1492,52,1492,1492,1492,52,52,1492,1492,52,1492,52,1492,1492,52,52,1492,52,1492,1492","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0","0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,1,1,0,0,1,1,0,1,0,1,1,1,0,1,0,1,1","4.309056282,5.300120831,4.882569313,0.368800014,5.022979736,0.368800014,4.955154896,0.368800014,4.829590797,0.368800014,0.368800014,4.916693211,0.368800014,4.829590797,0.368800014,0.368800014,0.367459536,4.916693211,4.829590797,0.367459506,0.360797286,4.878231525,0.368800014,4.829590797,0.367459536,0.367459536,5.171406746,4.955154896,0.367459536,4.829590797,0.367459536,0.368800014",,,,,,,,"" diff --git a/test/results/flow-analyse/gtp_prime.pcapng.out b/test/results/flow-analyse/default/ftp_failed.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/gtp_prime.pcapng.out +++ b/test/results/flow-analyse/default/ftp_failed.pcap.out diff --git a/test/results/flow-analyse/fuzz-2006-06-26-2594.pcap.out b/test/results/flow-analyse/default/fuzz-2006-06-26-2594.pcap.out index 72e07973f..2fd3a7582 100644 --- a/test/results/flow-analyse/fuzz-2006-06-26-2594.pcap.out +++ b/test/results/flow-analyse/default/fuzz-2006-06-26-2594.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.1.2,192.168.1.255,udp,137,137,finished,32,0,1120469540839312,1120470161396896,1120469540839312,42,0,50,0,1592,0,0,741823,20017986.0,47494748,22627942.0,512023754440704.0,3.9,"746308,47494748,744583,751092,46512252,745680,46548540,1500555,45837567,749435,751083,46756478,741823,751085,45987992,749213,47479804,47268139,749384,47257959,751080,46297871,749788,46627979,750158,751078,45907667,749430,751084,46347688,750041",78,78.0,78,0.0,0.0,5.0,"78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78","0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.275660515,4.184385777,4.229382992,4.337641239,4.229382992,4.245346546,4.229382992,4.275660515,4.299727440,4.275660515,4.292109013,4.275660515,4.337901115,4.229382992,4.229382992,4.203742027,4.250019550,4.178100586,4.229382992,4.255024433,4.194064140,4.238767147,4.229382992,4.325850487,4.194064140,4.194064140,4.264408588,4.321938515,4.255024433,4.256044388,4.229382992,3.185813189",NetBIOS,10,0,Acceptable,System,6,DPI,"" -1,ip4,212.242.33.35,192.168.1.2,udp,5060,5060,finished,10,22,1120469572981006,1120470268128176,1120470473529233,306,0,593,1076,4595,6254,0,25935,51474044.0,279041814,59389388.0,3527099352612864.0,4.2,"17474795,107207461,89874891,17280679,167478647,167525220,17335822,73902652,91241081,17333170,25935,17724998,29031776,29092737,68237242,29272359,29031830,29031631,29031476,18604480,279041814,227102,15287489,17115049,32679444,257340,76383084,29031077,58063525,24495477,17375114",33,367.0,1104,296.2,87757.2,4.4,"514,374,495,514,708,514,708,519,514,708,334,498,33,33,33,33,33,33,33,33,853,621,368,33,1104,473,363,33,33,33,466,701","0,0,0,0,0,0,0,0,0,1,1,0,0,1,1,5,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","12,0,0,0,0,0,0,0,0,0,2,0,0,1,1,0,0,0,0,0,0,4,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,1,0,1,0,0,1,0,0,1,1,1,1,1,1,1,1,1,0,1,1,1,0,1,1,1,1,1,1","5.828991890,5.782027245,5.782989502,5.772095203,5.761000156,1.504078388,3.362369776,2.947608709,5.765282631,4.114200115,5.769235611,3.191431999,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,5.808829308,5.790666103,5.744666100,4.098355293,1.549071550,5.804477692,4.601107121,4.098355293,4.037749290,4.098355293,3.348246098,2.334293365",SIP,100,0,Acceptable,VoIP,6,DPI,"" +1,ip4,212.242.33.35,192.168.1.2,udp,5060,5060,finished,10,22,1120469572981006,1120470268128176,1120470473529233,306,0,593,1076,4595,6254,0,25935,51474044.0,279041814,59389388.0,3527099352612864.0,4.2,"17474795,107207461,89874891,17280679,167478647,167525220,17335822,73902652,91241081,17333170,25935,17724998,29031776,29092737,68237242,29272359,29031830,29031631,29031476,18604480,279041814,227102,15287489,17115049,32679444,257340,76383084,29031077,58063525,24495477,17375114",33,367.0,1104,296.2,87757.2,4.4,"514,374,495,514,708,514,708,519,514,708,334,498,33,33,33,33,33,33,33,33,853,621,368,33,1104,473,363,33,33,33,466,701","0,0,0,0,0,0,0,0,0,1,1,0,0,1,1,5,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","12,0,0,0,0,0,0,0,0,0,2,0,0,1,1,0,0,0,0,0,0,4,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,1,0,1,0,0,1,0,0,1,1,1,1,1,1,1,1,1,0,1,1,1,0,1,1,1,1,1,1","5.828991890,5.782027245,5.782989502,5.772095203,5.761000156,1.504078388,3.362369776,2.947608709,5.765282631,4.114200115,5.769235611,3.191431999,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,5.808829308,5.790666103,5.744666100,4.098355293,1.549071550,5.804477692,4.601107121,4.098355293,4.037749290,4.098355293,3.348246098,2.334293365",SIP,100,0,Acceptable,VoIP,6,DPI,"46" diff --git a/test/results/flow-analyse/h323-overflow.pcap.out b/test/results/flow-analyse/default/fuzz-2006-09-29-28586.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/h323-overflow.pcap.out +++ b/test/results/flow-analyse/default/fuzz-2006-09-29-28586.pcap.out diff --git a/test/results/flow-analyse/fuzz-2020-02-16-11740.pcap.out b/test/results/flow-analyse/default/fuzz-2020-02-16-11740.pcap.out index f5598e1b2..352bc7900 100644 --- a/test/results/flow-analyse/fuzz-2020-02-16-11740.pcap.out +++ b/test/results/flow-analyse/default/fuzz-2020-02-16-11740.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.12.64.30,198.226.25.53,udp,29200,1812,finished,18,14,1528996068129675,1528997019398709,1528997011828903,655,0,703,276,12258,2595,0,155168,61128012.0,612411195,140850256.0,19838793242640384.0,2.7,"155168,452627740,595449,114837328,612411195,44261470,205164,4046522,4037802,201918,4553249,187053,43562433,202627,48502104,3244519,3442366,3335821,3536360,209147,201397,255983176,256164296,599645,6262990,492548,7309633,8000538,8015324,522347,7260933",165,492.2,731,248.2,61618.1,4.8,"683,243,225,304,225,731,165,683,165,683,192,731,683,731,683,192,165,683,731,165,683,192,731,225,711,731,711,304,731,225,711,731","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,4,3,5,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,1,1,0,1,0,1,0,1,0,0,0,0,1,1,0,0,1,0,1,0,1,0,0,0,1,0,1,0,0","6.047428131,2.762376308,6.336006641,6.922207832,6.356189251,5.597228050,5.971614838,6.076896191,5.962701321,0.885235786,6.148619175,6.046576977,6.067515373,2.928206921,4.093657970,6.062733173,5.981721401,6.049886227,6.077444077,5.974218369,5.025151253,6.080809116,6.063514709,6.407587528,5.992080212,6.077442646,5.517450333,6.840845585,6.115455151,6.520883560,5.811926842,4.154052258",Radius,146,0,Acceptable,Network,6,DPI,"" +1,ip4,10.12.64.30,198.226.25.53,udp,29200,1812,finished,18,14,1528996068129675,1528997019398709,1528997011828903,655,0,703,276,12258,2595,0,155168,61128012.0,612411195,140850256.0,19838793242640384.0,2.7,"155168,452627740,595449,114837328,612411195,44261470,205164,4046522,4037802,201918,4553249,187053,43562433,202627,48502104,3244519,3442366,3335821,3536360,209147,201397,255983176,256164296,599645,6262990,492548,7309633,8000538,8015324,522347,7260933",165,492.2,731,248.2,61618.1,4.8,"683,243,225,304,225,731,165,683,165,683,192,731,683,731,683,192,165,683,731,165,683,192,731,225,711,731,711,304,731,225,711,731","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,4,3,5,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,1,1,0,1,0,1,0,1,0,0,0,0,1,1,0,0,1,0,1,0,1,0,0,0,1,0,1,0,0","6.047428131,2.762376308,6.336006641,6.922207832,6.356189251,5.597228050,5.971614838,6.076896191,5.962701321,0.885235786,6.148619175,6.046576977,6.067515373,2.928206921,4.093657970,6.062733173,5.981721401,6.049886227,6.077444077,5.974218369,5.025151253,6.080809116,6.063514709,6.407587528,5.992080212,6.077442646,5.517450333,6.840845585,6.115455151,6.520883560,5.811926842,4.154052258",Radius,146,0,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/h323.pcap.out b/test/results/flow-analyse/default/fuzz-2021-06-07-c6c72a0a56.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/h323.pcap.out +++ b/test/results/flow-analyse/default/fuzz-2021-06-07-c6c72a0a56.pcap.out diff --git a/test/results/flow-analyse/hangout.pcap.out b/test/results/flow-analyse/default/fuzz-2021-10-13.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/hangout.pcap.out +++ b/test/results/flow-analyse/default/fuzz-2021-10-13.pcap.out diff --git a/test/results/flow-analyse/hpvirtgrp.pcap.out b/test/results/flow-analyse/default/genshin-impact.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/hpvirtgrp.pcap.out +++ b/test/results/flow-analyse/default/genshin-impact.pcap.out diff --git a/test/results/flow-analyse/git.pcap.out b/test/results/flow-analyse/default/git.pcap.out index 59318415a..59318415a 100644 --- a/test/results/flow-analyse/git.pcap.out +++ b/test/results/flow-analyse/default/git.pcap.out diff --git a/test/results/flow-analyse/gnutella.pcap.out b/test/results/flow-analyse/default/gnutella.pcap.out index 90e367ca7..a17deab0a 100644 --- a/test/results/flow-analyse/gnutella.pcap.out +++ b/test/results/flow-analyse/default/gnutella.pcap.out @@ -2,8 +2,6 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,10.0.2.15,75.133.101.93,tcp,50285,52367,finished,13,19,88704875,100541304,100658601,0,0,599,1460,1036,10762,0,68,767424.4,8796467,2113226.8,4465727373312.0,2.6,"111774,112031,223,580,122233,123811,1735,510239,510348,125373,7027,133055,508500,509079,643423,701863,8737919,8796467,643884,78,644721,118605,2969,121592,121581,84,121516,120907,68,120959,117511",40,409.2,1500,491.7,241767.6,4.1,"52,44,40,639,40,652,90,40,353,40,182,423,40,68,40,449,40,86,40,1500,1052,40,640,1488,40,1500,628,40,1500,628,40,640","9,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,1,0,0,0,0,0,0,1,1,0,0,0,0,0,4,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,1,0,1,1,1,0,0,1,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1","4.585552692,4.823068142,4.680641651,5.822128773,4.621928692,5.725380421,5.587119579,4.671928883,7.096185207,4.621928692,6.667861462,7.368043423,4.680641651,5.340273857,4.621928692,7.401152134,4.780641556,5.582901478,4.621928692,7.849462032,7.784356117,4.730641365,7.643722534,7.861162663,4.730641365,7.864004135,7.644542217,4.680641174,7.856564045,7.631118298,4.680641174,7.673601151",Gnutella,35,0,Potentially Dangerous,Download,6,DPI,"22" 1,ip4,10.0.2.15,104.156.226.72,tcp,50284,53258,finished,16,16,88704150,101062565,101062734,0,0,600,1024,1062,6684,0,1,797322.6,8218469,1970792.9,3884024594432.0,2.9,"128313,128710,372,938,178629,178799,1,501219,501471,98390,140683,469376,511641,1190983,1233531,8175797,8218469,772334,828075,95677,89547,96875,110099,405396,409608,95445,89124,2830,63380,645,642",40,282.6,1064,381.8,145784.6,3.9,"52,44,40,640,40,668,90,40,353,40,574,40,68,40,442,40,86,40,1064,40,1064,40,1064,40,1064,40,1064,40,55,40,50,40","12,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,1,0,0,1,1,0,1,0,1,0,1,0,1,0,0,1,0,1","4.662476063,4.732159138,4.630641460,5.806861401,4.521928787,5.724582195,5.627513409,4.621928692,7.193869114,4.621928692,7.467946053,4.730641842,5.399097443,4.571928978,7.330091953,4.730641365,5.719189644,4.621928692,7.801183701,4.730641365,7.783223152,4.680641174,7.789729118,4.730641365,7.787688255,4.730641365,7.814134598,4.680641651,4.944017887,4.621928692,4.859469414,4.621928692",Gnutella,35,0,Potentially Dangerous,Download,6,DPI,"22" 1,ip4,10.0.2.15,104.238.172.250,tcp,50312,23548,finished,16,16,90745963,101065402,101065057,0,0,601,628,1115,1487,0,346,665759.1,8692014,2110974.0,4456211546112.0,1.9,"30928,31210,439,818,29157,31647,2471,501745,502012,17074,17362,35097,479690,480352,544167,592641,8643736,8692014,619,570,563,598,427,387,461,428,346,360,379,396,439",40,121.8,668,170.0,28912.7,4.1,"52,44,40,641,40,668,90,40,353,40,182,370,40,67,40,427,40,94,40,50,40,50,40,50,40,50,40,50,40,50,40,50","12,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","12,0,0,0,1,0,0,0,0,0,1,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,1,1,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0","4.492582321,4.720129013,4.521928787,5.809185505,4.508695602,5.773917675,5.619303703,4.558695793,7.143177032,4.389823914,6.687948704,7.327623844,4.671928406,5.289166927,4.558695793,7.411965370,4.621928692,5.812307358,4.489823818,4.722780704,4.489823818,4.682780743,4.489823818,4.722780704,4.489823818,4.722780704,4.439823627,4.722780704,4.489823818,4.722780704,4.489823818,4.642780781",Gnutella,35,0,Potentially Dangerous,Download,6,DPI,"22" -1,ip4,10.0.2.15,69.118.162.229,tcp,50327,46906,finished,10,22,114930255,119175893,120208521,0,0,533,1460,533,25332,0,19,307222.7,1138736,463516.9,214847930368.0,3.3,"108990,109470,822,1560,1123233,14904,1138736,509,4088,37,4418,993404,175,19,291,993807,142,988894,159,41,989074,4759,4845,1004141,96,26,62,1004324,1027632,5162,84",40,848.8,1500,665.4,442787.6,4.4,"52,44,40,573,40,834,1500,40,1500,1500,104,40,1500,1500,1500,898,40,40,1500,1500,1500,40,898,40,1500,1500,1500,898,40,1500,1500,1500","9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,15,0,0","0,1,0,0,1,1,1,0,1,1,1,0,1,1,1,1,0,0,1,1,1,0,1,0,1,1,1,1,0,1,1,1","4.609497547,4.578639030,4.630641460,5.871806145,4.521928787,5.952865124,0.550871491,4.780641079,0.258170635,0.344010741,2.390491486,4.730641365,0.581234336,0.509969771,0.584714293,5.567255974,4.730641365,4.780641079,7.829332829,7.753004074,7.739068508,4.630640984,7.696638107,4.680641174,7.725103855,7.755664349,7.761345387,7.697982311,4.780641079,7.769303799,7.739727497,7.769325733",HTTP.Gnutella,7.35,0,Potentially Dangerous,Media,6,DPI,"5,12,22" 1,ip4,10.0.2.15,188.61.52.183,tcp,50300,11852,finished,16,16,90742816,121143186,117002254,0,0,599,1460,1696,3374,0,49,1827735.8,13801588,3934254.5,15478358540288.0,2.8,"17190,17418,3506,3946,14197,14999,687,2797,2855,25798,49,26144,8990,9323,15893,71757,495574,483536,221196,265159,15579,77266,487598,467678,9468962,9510672,13760964,13801588,1593559,1633954,4140974",40,198.9,1500,294.0,86413.1,4.0,"52,44,40,639,40,699,111,40,304,40,1500,180,40,166,40,91,40,219,40,404,40,387,40,507,40,115,40,111,40,176,40,101","8,1,2,1,1,0,0,0,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,1,1,0,1,1,0,0,0,0,1,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,1,0,0,1,1,0,1,0,0,1,1,0,1,0,0,1,1,0,0,1,0","4.624014378,4.823068142,4.780641079,5.806199551,4.621928692,5.719610691,5.576837540,4.671928883,5.283092022,4.671928883,7.655467510,6.721651554,4.721928596,6.328861237,4.558695793,5.166602612,4.830641270,6.855683327,4.780641556,7.482919216,4.671928883,7.395811558,4.730640888,7.500388622,4.830641270,5.985765934,4.621928692,5.830484867,4.830641270,6.691635132,4.621928692,5.872485161",Gnutella,35,0,Potentially Dangerous,Download,6,DPI,"22" -1,ip4,10.0.2.15,189.147.72.83,tcp,50328,26108,finished,11,21,114930776,123432179,124445371,0,0,538,1460,538,22968,0,42,581161.2,1214808,505873.5,255907954688.0,4.2,"193649,195345,1788,3675,1208824,5559,69,1214808,993314,122,993548,1040345,116,1040488,1001310,128,1001514,998194,120,998177,1008259,218,1008532,1046807,141,1046873,1000209,118,1000330,1013376,42",40,775.1,1500,623.9,389219.0,4.4,"52,44,40,578,40,846,1500,326,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132","10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1","4.624014378,4.777613640,4.730640888,5.858736038,4.571928978,5.938837528,7.826196671,7.250766277,4.730641365,7.843273640,7.780950546,4.780641079,7.843047142,7.798923969,4.780641079,7.867131710,7.830142498,4.671928406,7.858473778,7.796208858,4.780641079,7.826694965,7.757758141,4.730641365,7.853250504,7.817744732,4.780641079,7.872528076,7.809401989,4.780641079,7.820863247,7.791663170",HTTP.Gnutella,7.35,0,Potentially Dangerous,Media,6,DPI,"5,12,22" 1,ip4,10.0.2.15,109.214.154.216,tcp,50248,6346,finished,14,18,71205274,117002547,132821508,0,0,304,1024,705,2420,0,1091,3464951.8,22684647,6255594.5,39132462055424.0,3.3,"399865,400165,2576,3065,879170,880284,1091,343284,15848,359592,3003,2180,5087,145122,145627,10048654,10048652,469496,2676,472723,3557750,3604090,6175326,6222212,413766,464528,22633783,22684647,605343,604983,15818919",40,138.2,1064,217.4,47264.8,4.0,"52,44,40,344,40,323,143,40,118,762,40,53,58,40,149,40,104,40,1064,45,40,122,40,70,40,213,40,52,40,123,40,62","9,0,2,2,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","12,0,2,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,1,1,0,1,1,0,0,1,0,1,1,1,0,1,0,0,1,1,0,0,1,0,1,1","4.638531685,4.760457039,4.611769199,5.768550396,4.503056526,5.575543404,5.615631580,4.553056717,5.640929699,7.709812641,4.680641174,4.708038807,4.874885082,4.592897415,6.317804813,4.453056812,5.923436165,4.453056812,7.776337624,4.335103989,4.830641270,6.163827896,4.780641556,5.454720020,4.621928692,6.573338509,4.730640888,4.776329994,4.621928692,6.159438610,4.571928978,4.925578117",Gnutella,35,0,Potentially Dangerous,Download,6,DPI,"22" 1,ip4,10.0.2.15,86.208.180.181,tcp,50249,45883,finished,16,16,71205609,187576304,187064352,0,0,303,1065,713,3012,0,276,7491272.5,55455380,14262251.0,203411798622208.0,3.2,"106993,107336,276,805,178388,179820,1439,41004,98031,375723,432936,10046845,10046768,42293,94463,6595038,6594815,3591919,3643921,39217,93460,24009088,24063297,605105,604823,14641110,23768,14665256,55396943,55455380,453178",40,156.9,1105,244.6,59812.5,4.0,"52,44,40,343,40,323,143,40,912,40,149,40,104,40,1105,40,200,40,70,40,189,40,52,40,123,40,64,489,40,50,40,49","11,0,2,2,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","10,0,0,0,1,1,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,1,0,0,1,0,1,1,0,1,0,0,1,1,0,0,1,0,1,1,1,0,1,0,0","4.624014378,4.624093533,4.730641365,5.758390427,4.553056717,5.558244705,5.696007252,4.621928692,7.730160713,4.830641270,6.349717140,4.521929264,5.981128693,4.571928978,7.767892838,4.780641556,6.727245331,4.730641365,5.454720020,4.603056908,6.642654419,4.780641079,4.853253365,4.671928883,6.256999493,4.671928883,5.061660290,7.508594036,4.830641270,4.642780781,4.780641556,4.618614674",Gnutella,35,0,Potentially Dangerous,Download,6,DPI,"22" diff --git a/test/results/flow-analyse/hsrp0.pcap.out b/test/results/flow-analyse/default/google_ssl.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/hsrp0.pcap.out +++ b/test/results/flow-analyse/default/google_ssl.pcap.out diff --git a/test/results/flow-analyse/googledns_android10.pcap.out b/test/results/flow-analyse/default/googledns_android10.pcap.out index dc1eb4a21..dc1eb4a21 100644 --- a/test/results/flow-analyse/googledns_android10.pcap.out +++ b/test/results/flow-analyse/default/googledns_android10.pcap.out diff --git a/test/results/flow-analyse/hsrp2.pcap.out b/test/results/flow-analyse/default/gquic.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/hsrp2.pcap.out +++ b/test/results/flow-analyse/default/gquic.pcap.out diff --git a/test/results/flow-analyse/hsrp2_ipv6.pcapng.out b/test/results/flow-analyse/default/gtp_c.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/hsrp2_ipv6.pcapng.out +++ b/test/results/flow-analyse/default/gtp_c.pcap.out diff --git a/test/results/flow-analyse/http-crash-content-disposition.pcap.out b/test/results/flow-analyse/default/gtp_false_positive.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/http-crash-content-disposition.pcap.out +++ b/test/results/flow-analyse/default/gtp_false_positive.pcapng.out diff --git a/test/results/flow-analyse/http-lines-split.pcap.out b/test/results/flow-analyse/default/gtp_prime.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/http-lines-split.pcap.out +++ b/test/results/flow-analyse/default/gtp_prime.pcapng.out diff --git a/test/results/flow-analyse/http-proxy.pcapng.out b/test/results/flow-analyse/default/h323-overflow.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/http-proxy.pcapng.out +++ b/test/results/flow-analyse/default/h323-overflow.pcap.out diff --git a/test/results/flow-analyse/http_guessed_host_and_guessed.pcapng.out b/test/results/flow-analyse/default/h323.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/http_guessed_host_and_guessed.pcapng.out +++ b/test/results/flow-analyse/default/h323.pcap.out diff --git a/test/results/flow-analyse/http_on_sip_port.pcap.out b/test/results/flow-analyse/default/hangout.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/http_on_sip_port.pcap.out +++ b/test/results/flow-analyse/default/hangout.pcap.out diff --git a/test/results/flow-analyse/default/heuristic_tcp_ack_payload.pcap.out b/test/results/flow-analyse/default/heuristic_tcp_ack_payload.pcap.out new file mode 100644 index 000000000..aed199fc9 --- /dev/null +++ b/test/results/flow-analyse/default/heuristic_tcp_ack_payload.pcap.out @@ -0,0 +1,5 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,194.226.199.21,52.18.127.189,tcp,58155,443,info,15,17,1681478090730262,1681478119542351,1681478119592875,0,0,1085,2920,2972,5602,0,0,1860474.4,28647677,7030273.0,49424738811904.0,1.1,"50259,51105,553,51728,128,0,97,51293,1354,0,1851,500,202,193,0,51721,0,48,140,50129,407,8135,0,8098,85064,28647677,19,62,28613926,13,0",42,308.7,2960,576.0,331721.9,3.6,"52,52,42,557,46,153,1500,2960,42,378,49,42,166,145,502,550,160,91,118,46,42,78,439,78,42,46,113,86,1125,46,46,86","6,2,1,2,0,0,0,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,3,1,2,0,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1","0,1,0,0,1,1,1,1,0,1,1,0,0,0,0,0,1,1,1,1,0,0,1,1,0,1,0,0,0,1,1,1","4.700937748,4.839770317,4.678030014,5.790879726,4.390829086,5.801830769,7.220153809,7.298819065,4.678030014,7.385129929,4.797285557,4.725648880,6.228291035,6.284518242,7.567343235,7.646277905,6.609186172,5.432500839,6.074527264,4.434307575,4.678030014,5.448187351,7.460664272,5.370555878,4.678030014,4.477785587,5.985470772,5.565127373,7.818080425,4.434307575,4.477785587,5.465760708",,,,,,,,"" +1,ip4,194.226.199.61,35.241.9.150,tcp,27453,443,info,16,16,1681887518918488,1681887519032454,1681887519031452,0,0,321,2824,867,19359,0,0,7320.3,29949,11049.8,122098208.0,3.5,"24068,24393,353,24974,2405,0,38,27411,305,4695,29949,0,24556,1245,0,54,26487,9,288,44,25578,893,503,1582,287,1013,999,1290,1231,1003,1277",42,672.8,2864,1000.3,1000640.1,3.7,"52,52,42,258,46,2088,2088,462,42,42,133,318,109,42,217,361,78,46,78,364,1452,42,1452,2864,42,42,2864,42,2864,42,2864,42","11,1,1,0,0,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,1,1,0,0,0,0,0,1,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,6","0,1,0,0,1,1,1,1,0,0,0,1,1,0,0,0,0,1,1,1,1,0,1,1,0,0,1,0,1,0,1,0","4.585552692,5.017560482,4.686327934,5.680439472,4.505982876,7.413378239,7.563780785,7.408977032,4.733946800,4.686327934,5.833590031,7.044709682,5.829442978,4.715973377,6.852140903,7.372029781,5.280656338,4.505982876,5.229373932,7.303534985,7.876083851,4.582791805,7.885684490,7.924335957,4.733946800,4.781565666,7.928474426,4.781565666,7.931355953,4.781565666,7.921189308,4.638709068",,,,,,,,"" +1,ip4,194.226.199.103,217.69.139.59,tcp,62580,443,info,18,14,1682070088015038,1682070095281485,1682070089825216,0,0,569,2843,1472,9558,0,0,292794.3,5455602,1016505.8,1033283960832.0,1.7,"0,10465,0,1548808,0,1559948,0,2544,0,14096,0,4417,0,92,0,17069,0,11,0,4686,0,18454,0,216157,0,213846,0,10430,0,5455602,0",42,385.9,2883,734.4,539373.9,3.4,"52,52,46,46,46,46,42,42,609,609,46,46,1450,1450,2883,2883,42,42,42,42,166,166,298,298,42,42,298,298,42,42,71,71","14,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,2","0,0,1,1,1,1,0,0,0,0,1,1,1,1,1,1,0,0,0,0,0,0,1,1,0,0,1,1,0,0,0,0","4.540081024,4.540081024,4.772925377,4.772925377,4.772925377,4.772925377,4.829184532,4.829184532,7.086583614,7.086583614,4.565871716,4.565871716,7.215152740,7.215152740,7.539601803,7.539601803,4.715973377,4.715973377,4.733946800,4.733946800,6.348270416,6.348270416,7.138381004,7.138381004,4.781565666,4.781565666,7.126602650,7.126602650,4.733946800,4.733946800,5.169243813,5.169243813",,,,,,,,"" +1,ip4,194.226.199.61,2.22.40.186,tcp,6946,443,info,14,18,1682070122465460,1682070127475501,1682070127468714,0,0,1460,2920,3416,10610,0,1,323009.5,2634777,687597.7,472790597632.0,2.8,"9842,15325,2065171,1798,114,2048180,1988,1777,823,1,2161,39414,217233,215957,433218,854700,2634777,793,114791,2391,133538,311,1201538,215,30,1,210,55,15686,389,868",42,481.7,2960,697.2,486142.7,3.8,"52,52,52,52,42,561,52,52,46,2960,1216,1500,52,46,1500,1500,1500,52,52,42,42,120,138,46,311,327,46,101,71,1500,658,673","8,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","9,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,4,0,1","0,1,1,0,0,0,1,1,1,1,1,1,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,0,0,0","4.767184734,4.961856842,4.961856842,4.767184734,4.617807865,6.804517746,4.961856842,4.961856842,4.565872192,7.936507702,7.812016487,7.865312576,4.834680557,5.055958748,7.863229275,7.863562107,7.864302158,4.873142242,4.834680557,4.725648880,4.773267746,6.283937454,6.596406460,4.609350204,7.253105640,7.293287277,4.609350204,6.180341721,5.790450096,7.859360218,7.630677700,7.711422920",,,,,,,,"" diff --git a/test/results/flow-analyse/default/hots.pcapng.out b/test/results/flow-analyse/default/hots.pcapng.out new file mode 100644 index 000000000..70370e2df --- /dev/null +++ b/test/results/flow-analyse/default/hots.pcapng.out @@ -0,0 +1,3 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.0.73,24.105.56.13,udp,54598,3724,finished,14,18,1654637718943449,1654637719490075,1654637811243833,20,0,24,32,320,540,0,3612,2995064.8,91418317,16143814.0,260622725939200.0,0.2,"39885,24383,63734,66162,61944,34445,30828,61113,3612,33342,62853,57422,6903,91418317,63443,62525,36602,26359,63168,62882,63116,62919,63469,62673,63217,32441,30200,63038,62887,26082,37046",48,54.9,60,5.0,25.2,5.0,"52,48,52,52,52,52,48,52,48,52,52,52,48,52,60,60,60,48,60,60,60,60,60,60,60,60,48,60,60,60,48,60","14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.946224213,4.767892838,4.792377472,4.869300842,4.946224213,4.946224213,4.809559822,4.869300842,4.767892838,4.907762527,4.946224213,4.907762527,4.752166748,4.946224213,4.432916641,4.366249561,4.366250038,3.700824261,4.366250038,4.432916641,4.332916737,4.399583340,4.199582577,4.302914619,4.287001610,4.366250038,3.742490768,4.353668213,4.366249561,4.399583340,3.742490768,4.366249561",Heroes_of_the_Storm,336,0,Fun,Game,6,DPI,"46" +1,ip4,24.105.57.16,192.168.0.73,udp,3724,50609,finished,32,0,1654785317878340,1654785318886180,1654785317878340,20,0,122,0,2479,0,0,1113,32511.0,62822,18812.4,353907232.0,4.7,"31758,14744,16286,4737,58380,5040,58167,42440,20509,62822,16348,46993,45239,18003,62811,27060,19191,16374,50151,13098,1113,62335,31570,31017,31934,30736,13221,50259,34089,29278,62137",48,105.5,150,33.5,1124.4,4.9,"111,111,48,132,132,103,103,121,121,103,109,109,103,48,150,109,109,48,109,48,150,150,146,48,129,48,138,138,121,48,123,109","7,0,16,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.727404118,5.736169815,3.659157991,5.974259377,6.029637337,5.373315811,5.410210133,5.896153450,5.877972126,5.645791054,5.660812855,5.713362217,5.521955967,3.700824261,6.180423737,5.754983425,5.770836353,3.742490768,5.748058796,3.700824261,6.267391682,6.252244949,6.277539730,3.742491007,6.034878731,3.742490768,6.026935577,6.097950459,5.911030293,3.700824499,5.963339806,5.665075302",Heroes_of_the_Storm,336,0,Fun,Game,6,DPI,"46" diff --git a/test/results/flow-analyse/i3d.pcap.out b/test/results/flow-analyse/default/hpvirtgrp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/i3d.pcap.out +++ b/test/results/flow-analyse/default/hpvirtgrp.pcap.out diff --git a/test/results/flow-analyse/imaps.pcap.out b/test/results/flow-analyse/default/hsrp0.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/imaps.pcap.out +++ b/test/results/flow-analyse/default/hsrp0.pcap.out diff --git a/test/results/flow-analyse/ip_fragmented_garbage.pcap.out b/test/results/flow-analyse/default/hsrp2.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ip_fragmented_garbage.pcap.out +++ b/test/results/flow-analyse/default/hsrp2.pcap.out diff --git a/test/results/flow-analyse/ipv6_in_gtp.pcap.out b/test/results/flow-analyse/default/hsrp2_ipv6.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ipv6_in_gtp.pcap.out +++ b/test/results/flow-analyse/default/hsrp2_ipv6.pcapng.out diff --git a/test/results/flow-analyse/irc.pcap.out b/test/results/flow-analyse/default/http-crash-content-disposition.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/irc.pcap.out +++ b/test/results/flow-analyse/default/http-crash-content-disposition.pcap.out diff --git a/test/results/flow-analyse/ja3_lots_of_cipher_suites.pcap.out b/test/results/flow-analyse/default/http-lines-split.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ja3_lots_of_cipher_suites.pcap.out +++ b/test/results/flow-analyse/default/http-lines-split.pcap.out diff --git a/test/results/flow-analyse/ja3_lots_of_cipher_suites_2_anon.pcap.out b/test/results/flow-analyse/default/http-manipulated.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ja3_lots_of_cipher_suites_2_anon.pcap.out +++ b/test/results/flow-analyse/default/http-manipulated.pcap.out diff --git a/test/results/flow-analyse/kerberos-error.pcap.out b/test/results/flow-analyse/default/http-proxy.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/kerberos-error.pcap.out +++ b/test/results/flow-analyse/default/http-proxy.pcapng.out diff --git a/test/results/flow-analyse/kerberos-login.pcap.out b/test/results/flow-analyse/default/http_asymmetric.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/kerberos-login.pcap.out +++ b/test/results/flow-analyse/default/http_asymmetric.pcapng.out diff --git a/test/results/flow-analyse/http_auth.pcap.out b/test/results/flow-analyse/default/http_auth.pcap.out index 272fa8914..9004ceda5 100644 --- a/test/results/flow-analyse/http_auth.pcap.out +++ b/test/results/flow-analyse/default/http_auth.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.0.4,192.254.189.169,tcp,54337,80,finished,14,18,1381844050222515,1381844057134728,1381844055865656,0,0,739,1448,739,17637,0,139,405011.4,4861829,1193509.9,1424465723392.0,2.2,"180032,180140,139,193993,206403,1322,401505,596,594,735,724,4027,4555,8666,4603,3019,7560,3303,5323,8621,158972,3971,162953,3627,4243,7859,2612,2607,4861805,4861829,1269016",52,626.9,1500,665.6,443042.2,4.1,"64,60,52,791,52,1500,537,52,131,52,274,52,1500,1500,52,1500,1500,52,1500,1500,52,1500,1500,52,1500,1500,52,975,52,52,52,52","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,1,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,1,0,1,0,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0,1,0,0","4.441382408,5.118823051,5.130219936,5.854406357,5.046594620,5.442737579,5.621041775,5.077241421,5.402398586,5.024262905,5.623777390,5.077241421,5.441255569,5.120078564,4.955154419,5.048518181,5.069016457,5.130219936,5.089414597,5.056834221,5.053296566,5.097548008,5.174168587,5.115702629,5.356103420,5.382487297,5.046594620,5.653643131,5.038779736,5.046595097,5.130219936,5.085056305",HTTP,7,0,Acceptable,Web,6,DPI,"" +1,ip4,192.168.0.4,192.254.189.169,tcp,54337,80,finished,14,18,1381844050222515,1381844057134728,1381844055865656,0,0,739,1448,739,17637,0,139,405011.4,4861829,1193509.9,1424465723392.0,2.2,"180032,180140,139,193993,206403,1322,401505,596,594,735,724,4027,4555,8666,4603,3019,7560,3303,5323,8621,158972,3971,162953,3627,4243,7859,2612,2607,4861805,4861829,1269016",52,626.9,1500,665.6,443042.2,4.1,"64,60,52,791,52,1500,537,52,131,52,274,52,1500,1500,52,1500,1500,52,1500,1500,52,1500,1500,52,1500,1500,52,975,52,52,52,52","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,1,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,1,0,1,0,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0,1,0,0","4.441382408,5.118823051,5.130219936,5.854406357,5.046594620,5.442737579,5.621041775,5.077241421,5.402398586,5.024262905,5.623777390,5.077241421,5.441255569,5.120078564,4.955154419,5.048518181,5.069016457,5.130219936,5.089414597,5.056834221,5.053296566,5.097548008,5.174168587,5.115702629,5.356103420,5.382487297,5.046594620,5.653643131,5.038779736,5.046595097,5.130219936,5.085056305",HTTP,7,0,Acceptable,Web,6,DPI,"36,43" diff --git a/test/results/flow-analyse/http_connect.pcap.out b/test/results/flow-analyse/default/http_connect.pcap.out index 3544d53ab..3544d53ab 100644 --- a/test/results/flow-analyse/http_connect.pcap.out +++ b/test/results/flow-analyse/default/http_connect.pcap.out diff --git a/test/results/flow-analyse/kerberos.pcap.out b/test/results/flow-analyse/default/http_guessed_host_and_guessed.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/kerberos.pcap.out +++ b/test/results/flow-analyse/default/http_guessed_host_and_guessed.pcapng.out diff --git a/test/results/flow-analyse/http_ipv6.pcap.out b/test/results/flow-analyse/default/http_ipv6.pcap.out index 8479c67b1..1217452b5 100644 --- a/test/results/flow-analyse/http_ipv6.pcap.out +++ b/test/results/flow-analyse/default/http_ipv6.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip6,2a00:d40:1:3:7aac:c0ff:fea7:d4c,2a00:1450:4001:803::1017,udp,45931,443,finished,17,15,1448269127400446,1448269137275811,1448269136257808,37,0,1350,1350,4058,4856,0,1512,604281.6,6008829,1486148.8,2208638173184.0,2.8,"25363,26190,172445,219452,15689,87208,38758,110203,47003,1512,26672,45844,1752482,1778725,6798,78256,246614,318052,6008829,6008710,4760,76866,102599,174483,2367,73860,70885,142482,2922,74310,992388",77,326.6,1398,376.2,141514.9,4.3,"1398,1398,85,1202,80,660,88,238,80,88,567,88,77,243,80,623,91,88,80,248,77,575,91,249,80,572,88,250,80,547,88,251","0,9,0,0,0,1,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0","2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,1,3,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,1,0,0,1,0,1,1,0,0,1,1,0,0,1,1,0,0","4.737460136,7.856492996,5.340356827,7.783504963,5.237494946,7.640817642,5.426836967,6.897242546,5.228057861,5.435415268,7.531185150,5.426837444,4.923079967,6.917997837,5.187493324,7.660722733,5.627426147,5.458142281,5.212494373,6.952660084,4.934730053,7.572426796,5.495558739,6.882013798,5.262493610,7.594254971,5.480869293,6.910377979,5.237494469,7.573482990,5.374089718,6.950065613",QUIC.Google,188.126,1,Acceptable,Web,6,DPI,"" +1,ip6,2a00:d40:1:3:7aac:c0ff:fea7:d4c,2a00:1450:4001:803::1017,udp,45931,443,finished,17,15,1448269127400446,1448269137275811,1448269136257808,37,0,1350,1350,4058,4856,0,1512,604281.6,6008829,1486148.8,2208638173184.0,2.8,"25363,26190,172445,219452,15689,87208,38758,110203,47003,1512,26672,45844,1752482,1778725,6798,78256,246614,318052,6008829,6008710,4760,76866,102599,174483,2367,73860,70885,142482,2922,74310,992388",77,326.6,1398,376.2,141514.9,4.3,"1398,1398,85,1202,80,660,88,238,80,88,567,88,77,243,80,623,91,88,80,248,77,575,91,249,80,572,88,250,80,547,88,251","0,9,0,0,0,1,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0","2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,1,3,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,1,0,0,1,0,1,1,0,0,1,1,0,0,1,1,0,0","4.737460136,7.856492996,5.340356827,7.783504963,5.237494946,7.640817642,5.426836967,6.897242546,5.228057861,5.435415268,7.531185150,5.426837444,4.923079967,6.917997837,5.187493324,7.660722733,5.627426147,5.458142281,5.212494373,6.952660084,4.934730053,7.572426796,5.495558739,6.882013798,5.262493610,7.594254971,5.480869293,6.910377979,5.237494469,7.573482990,5.374089718,6.950065613",QUIC.Google,188.126,1,Acceptable,Web,6,DPI,"46" diff --git a/test/results/flow-analyse/kerberos_fuzz.pcapng.out b/test/results/flow-analyse/default/http_on_sip_port.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/kerberos_fuzz.pcapng.out +++ b/test/results/flow-analyse/default/http_on_sip_port.pcap.out diff --git a/test/results/flow-analyse/lisp_registration.pcap.out b/test/results/flow-analyse/default/http_origin_different_than_host.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/lisp_registration.pcap.out +++ b/test/results/flow-analyse/default/http_origin_different_than_host.pcap.out diff --git a/test/results/flow-analyse/lru_ipv6_caches.pcapng.out b/test/results/flow-analyse/default/http_starting_with_reply.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/lru_ipv6_caches.pcapng.out +++ b/test/results/flow-analyse/default/http_starting_with_reply.pcapng.out diff --git a/test/results/flow-analyse/default/http_ua_splitted_in_two_pkts.pcapng.out b/test/results/flow-analyse/default/http_ua_splitted_in_two_pkts.pcapng.out new file mode 100644 index 000000000..0289a0c76 --- /dev/null +++ b/test/results/flow-analyse/default/http_ua_splitted_in_two_pkts.pcapng.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,254.125.135.128,66.152.103.45,tcp,21359,80,finished,21,11,1506664814072079,1506664884688466,1506664884891709,0,0,1388,358,16613,1748,0,2278,4562452.0,23451757,7140164.0,50981941280768.0,3.5,"200188,228774,3208,234021,1087486,3262,1090830,5345683,5834,5351689,23448878,3179,23451757,8290030,3196,8292329,1123787,3421,1127523,8802271,4342,8806776,19530296,2278,19532387,1784873,3657,1788814,938512,3420,943316",60,626.3,1440,557.2,310424.4,4.5,"60,60,1440,327,181,1440,259,181,1440,535,410,1440,257,181,1440,327,181,1440,257,181,1440,461,410,1440,258,181,1440,313,181,1440,259,181","1,0,0,0,0,0,5,0,3,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0,0,0","1,0,0,0,8,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1","4.739262104,5.106893539,5.867009163,5.823337078,5.714051723,5.877876282,5.739666462,5.708738327,5.861988068,5.999320984,5.770567417,5.882071018,5.723089695,5.732763290,5.864256382,5.841103554,5.697688103,5.890019894,5.735716343,5.730837822,5.881994724,5.957257271,5.801627636,5.887722969,5.723830700,5.705350399,5.852463722,5.804970741,5.650331974,5.849934578,5.692368984,5.757890701",HTTP,7,0,Acceptable,Web,6,DPI,"" diff --git a/test/results/flow-analyse/malformed_dns.pcap.out b/test/results/flow-analyse/default/i3d.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/malformed_dns.pcap.out +++ b/test/results/flow-analyse/default/i3d.pcap.out diff --git a/test/results/flow-analyse/iax.pcap.out b/test/results/flow-analyse/default/iax.pcap.out index 7604afaee..a961be6dc 100644 --- a/test/results/flow-analyse/iax.pcap.out +++ b/test/results/flow-analyse/default/iax.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,82.110.36.84,192.168.2.120,udp,4569,4566,finished,27,5,1123840005963862,1123840006456930,1123840006059195,12,0,172,172,3882,372,0,948,18980.7,51403,10969.1,120322248.0,4.7,"2173,5097,7653,24399,24352,24724,16912,51403,9638,12261,14097,6869,22758,16765,31325,17887,20048,11489,43190,21320,13940,17067,22553,948,20517,34133,6854,21003,19904,17982,29140",40,161.5,200,59.5,3538.2,4.9,"94,40,40,46,40,46,192,200,200,46,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192","3,0,1,0,0,23,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.666565895,4.339823723,4.439823151,4.354552269,4.384184837,4.354552269,1.312757373,1.546443224,1.322564363,4.327484608,1.142194629,1.312757373,1.944322586,1.302340746,1.312757373,1.312757373,1.312757373,1.302340746,1.312757373,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.321057439,1.335405827,1.335405827,1.335405827,1.335405827",IAX,95,0,Acceptable,VoIP,6,DPI,"" +1,ip4,82.110.36.84,192.168.2.120,udp,4569,4566,finished,27,5,1123840005963862,1123840006456930,1123840006059195,12,0,172,172,3882,372,0,948,18980.7,51403,10969.1,120322248.0,4.7,"2173,5097,7653,24399,24352,24724,16912,51403,9638,12261,14097,6869,22758,16765,31325,17887,20048,11489,43190,21320,13940,17067,22553,948,20517,34133,6854,21003,19904,17982,29140",40,161.5,200,59.5,3538.2,4.9,"94,40,40,46,40,46,192,200,200,46,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192,192","3,0,1,0,0,23,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.666565895,4.339823723,4.439823151,4.354552269,4.384184837,4.354552269,1.312757373,1.546443224,1.322564363,4.327484608,1.142194629,1.312757373,1.944322586,1.302340746,1.312757373,1.312757373,1.312757373,1.302340746,1.312757373,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.335405827,1.321057439,1.335405827,1.335405827,1.335405827,1.335405827",IAX,95,0,Acceptable,VoIP,6,DPI,"46" diff --git a/test/results/flow-analyse/icmp-tunnel.pcap.out b/test/results/flow-analyse/default/icmp-tunnel.pcap.out index 7a37d7ad8..6e6e28fdc 100644 --- a/test/results/flow-analyse/icmp-tunnel.pcap.out +++ b/test/results/flow-analyse/default/icmp-tunnel.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.154.131,192.168.154.132,icmp,,,finished,23,9,1360227866459330,1360227888466859,1360227888466987,92,0,92,92,2116,828,0,998770,1419844.6,13999352,2296693.5,5274800750592.0,4.2,"998770,1000036,1000056,999983,1000051,1000074,1000009,1000032,1000047,1000127,999991,999982,1000043,999922,13999352,1001250,1001214,1000977,1001002,1001107,1001081,1000973,1000923,1000944,1000921,1001115,1001144,1001036,1001015,1001004,1001005",112,112.0,112,0.0,0.0,5.0,"112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112","0,0,23,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.610230446,5.622818947,5.669650555,5.651793003,5.651793003,5.604961395,5.645053387,5.630681515,5.633935928,5.622818947,5.633935928,5.669650555,5.651793480,5.645053387,5.669650555,5.683875084,5.669650555,5.701732159,5.633935928,5.666017056,5.633935928,5.666017056,5.645053387,5.677134514,5.637421608,5.672758102,5.602598667,5.623562336,5.651793003,5.683875084,5.669650555,5.701732159",ICMP,81,0,Acceptable,Network,6,DPI,"17" +1,ip4,192.168.154.131,192.168.154.132,icmp,,,finished,23,9,1360227866459330,1360227888466859,1360227888466987,92,0,92,92,2116,828,0,998770,1419844.6,13999352,2296693.5,5274800750592.0,4.2,"998770,1000036,1000056,999983,1000051,1000074,1000009,1000032,1000047,1000127,999991,999982,1000043,999922,13999352,1001250,1001214,1000977,1001002,1001107,1001081,1000973,1000923,1000944,1000921,1001115,1001144,1001036,1001015,1001004,1001005",112,112.0,112,0.0,0.0,5.0,"112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112","0,0,23,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","5.610230446,5.622818947,5.669650555,5.651793003,5.651793003,5.604961395,5.645053387,5.630681515,5.633935928,5.622818947,5.633935928,5.669650555,5.651793480,5.645053387,5.669650555,5.683875084,5.669650555,5.701732159,5.633935928,5.666017056,5.633935928,5.666017056,5.645053387,5.677134514,5.637421608,5.672758102,5.602598667,5.623562336,5.651793003,5.683875084,5.669650555,5.701732159",ICMP,81,0,Acceptable,Network,6,DPI,"17,46" diff --git a/test/results/flow-analyse/iec60780-5-104.pcap.out b/test/results/flow-analyse/default/iec60780-5-104.pcap.out index 370a8cd02..370a8cd02 100644 --- a/test/results/flow-analyse/iec60780-5-104.pcap.out +++ b/test/results/flow-analyse/default/iec60780-5-104.pcap.out diff --git a/test/results/flow-analyse/imap-starttls.pcap.out b/test/results/flow-analyse/default/imap-starttls.pcap.out index 4cdc35999..4cdc35999 100644 --- a/test/results/flow-analyse/imap-starttls.pcap.out +++ b/test/results/flow-analyse/default/imap-starttls.pcap.out diff --git a/test/results/flow-analyse/imap.pcap.out b/test/results/flow-analyse/default/imap.pcap.out index 71ff89547..65cb76557 100644 --- a/test/results/flow-analyse/imap.pcap.out +++ b/test/results/flow-analyse/default/imap.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.40.4.2,10.40.3.2,tcp,46045,143,finished,19,13,1213095262213846,1213095266780228,1213095266780369,0,0,73,696,179,1401,0,88,294609.8,4331408,1060070.4,1123749068800.0,1.4,"126,150,12887,12906,231,444,36852,36794,135,4330018,4331408,1394,16846,17272,39867,39540,93,199,596,39710,39393,88,905,1344,39009,38693,107,104,10836,47768,37190",52,101.9,748,125.9,15857.5,4.4,"60,60,52,94,52,71,117,52,84,52,78,79,52,72,73,52,109,52,72,73,52,109,52,73,64,52,311,52,125,164,52,748","18,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,4,1,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,1,0,0,1,0,0,1,0,1,0,0,1,0,1,0,0,1,0,1,0,0,1,0,1","4.466519356,4.994044781,4.884933472,5.545080185,4.923395157,5.188045025,5.565508366,4.846471786,5.532327652,4.923395157,5.445330620,5.491897583,4.961857319,5.242550373,5.321550369,4.892440796,5.645212650,4.899451256,5.225256920,5.331891060,4.961856842,5.594664574,4.961857319,5.357347012,5.240169048,4.961857319,5.602889538,4.923395157,5.631970406,5.824433327,4.923395157,5.541430473",IMAP,4,0,Unsafe,Email,6,DPI,"22" +1,ip4,10.40.4.2,10.40.3.2,tcp,46045,143,finished,19,13,1213095262213846,1213095266780228,1213095266780369,0,0,73,696,179,1401,0,88,294609.8,4331408,1060070.4,1123749068800.0,1.4,"126,150,12887,12906,231,444,36852,36794,135,4330018,4331408,1394,16846,17272,39867,39540,93,199,596,39710,39393,88,905,1344,39009,38693,107,104,10836,47768,37190",52,101.9,748,125.9,15857.5,4.4,"60,60,52,94,52,71,117,52,84,52,78,79,52,72,73,52,109,52,72,73,52,109,52,73,64,52,311,52,125,164,52,748","18,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,4,1,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,1,0,0,1,0,0,1,0,1,0,0,1,0,1,0,0,1,0,1,0,0,1,0,1","4.466519356,4.994044781,4.884933472,5.545080185,4.923395157,5.188045025,5.565508366,4.846471786,5.532327652,4.923395157,5.445330620,5.491897583,4.961857319,5.242550373,5.321550369,4.892440796,5.645212650,4.899451256,5.225256920,5.331891060,4.961856842,5.594664574,4.961857319,5.357347012,5.240169048,4.961857319,5.602889538,4.923395157,5.631970406,5.824433327,4.923395157,5.541430473",IMAP,4,0,Unsafe,Email,6,DPI,"22,36" diff --git a/test/results/flow-analyse/malformed_icmp.pcap.out b/test/results/flow-analyse/default/imaps.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/malformed_icmp.pcap.out +++ b/test/results/flow-analyse/default/imaps.pcap.out diff --git a/test/results/flow-analyse/imo.pcap.out b/test/results/flow-analyse/default/imo.pcap.out index a937108b1..a937108b1 100644 --- a/test/results/flow-analyse/imo.pcap.out +++ b/test/results/flow-analyse/default/imo.pcap.out diff --git a/test/results/flow-analyse/instagram.pcap.out b/test/results/flow-analyse/default/instagram.pcap.out index 26e147b5a..c0babb1ca 100644 --- a/test/results/flow-analyse/instagram.pcap.out +++ b/test/results/flow-analyse/default/instagram.pcap.out @@ -7,9 +7,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,192.168.0.103,82.85.26.162,tcp,58052,80,finished,15,17,1436720942530885,1436720942601472,1436720942602785,0,0,260,1418,260,23009,1,30,4596.4,62164,15022.2,225667616.0,2.0,"61310,214,427,62164,336,336,1434,671,916,885,1556,61,61,1618,61,61,1312,92,30,1312,61,92,31,61,519,549,2411,2441,1373,61,31",52,779.2,1470,693.8,481326.3,4.3,"312,1470,1470,1461,52,52,52,1470,52,1470,52,1470,1470,1470,52,52,52,1470,1470,1470,52,52,1470,52,52,1470,52,1470,52,382,1470,1470","14,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0","0,1,1,1,0,0,0,1,0,1,0,1,1,1,0,0,0,1,1,1,0,0,1,0,0,1,0,1,0,1,1,1","5.872007370,7.407559395,7.844656944,7.852430344,4.993615627,5.046594620,5.008132935,7.842045307,5.046594620,7.880799770,5.008132935,7.822133541,7.825195312,7.841379166,5.046594620,5.008132935,4.969671249,7.828572273,7.860865593,7.842309952,5.046594620,5.008132935,7.841728687,5.046594620,4.969671249,7.704082012,5.046594620,7.760354519,5.046594620,7.391226292,7.738003731,7.744394302",HTTP.Instagram,7.211,0,Fun,SocialNetwork,6,DPI,"" 1,ip4,31.13.86.52,192.168.0.103,tcp,80,58216,info,21,11,1436720950909974,1436720950923433,1436720950922975,1398,0,1398,0,29358,0,1,30,853.5,2198,594.0,352792.4,4.6,"367,1465,1587,519,458,824,1465,61,30,1648,2198,2075,366,213,641,367,1312,1678,488,214,610,641,1037,1679,336,488,915,794,335,977,672",52,969.4,1450,664.0,440886.1,4.5,"1450,52,1450,52,1450,1450,52,1450,1450,1450,52,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,21,0,0,0,0","11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,0,0,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0","7.845948219,5.046595097,7.540397644,4.969671726,7.871668816,7.850661755,5.008133411,7.849848747,7.439690590,7.543411732,5.008133411,7.855735302,5.008133411,7.820466042,7.850073814,4.969671726,7.838098049,7.834076881,5.046594620,7.213315964,7.751162052,5.046594620,7.844347477,7.850857258,5.008132935,7.825020313,7.824017048,5.046594620,7.437387466,7.851827145,5.046594620,7.850535870",,,,,,,,"" 1,ip4,2.22.236.51,192.168.0.103,tcp,80,44151,info,17,15,1436720952553865,1436720952574830,1436720952572908,1418,0,1418,0,24106,0,1,31,1290.6,3846,1167.1,1362190.6,4.3,"122,2106,427,3387,31,3174,2289,427,946,1892,213,2563,1831,3785,61,3846,183,1342,1312,367,183,213,275,519,519,885,854,2075,2106,2014,61",52,805.3,1470,707.6,500717.4,4.3,"1470,52,1470,1470,52,52,1470,52,1470,1470,52,52,1470,52,1470,1470,52,52,1470,52,1470,52,1470,52,1470,52,1470,52,1470,52,1470,1470","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0,0","15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,0,1,1,0,1,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0","7.838996410,5.123517990,7.796014309,7.834145069,5.123517990,5.085056305,7.799090385,5.085056305,7.778009892,7.746161938,5.046594620,5.085056305,7.694964409,5.085056305,7.722822666,7.781306744,5.161979675,5.109000683,7.744096756,5.161979675,7.786537647,5.161979675,7.830977440,5.161979675,7.801307678,5.123517990,7.796917439,5.123517990,7.805510998,5.123517990,7.825653553,7.826405048",,,,,,,,"" -1,ip4,192.168.2.17,31.13.86.52,tcp,49355,443,finished,14,18,1568796253770116,1568796253821857,1568796253819210,0,0,498,1388,784,17805,0,7,3252.7,16760,5626.7,31659210.0,3.3,"12399,14597,58,14624,1725,26,7,16760,58,2044,498,16542,723,227,12497,604,464,936,285,275,177,245,128,170,272,201,2390,75,1564,117,147",52,633.5,1440,640.4,410152.9,4.2,"64,60,52,274,52,1440,1440,355,52,52,116,550,245,682,75,52,1440,1440,52,1440,1440,1440,1440,1440,1440,1440,1440,52,52,52,52,52","11,0,1,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,1,1,1,0,1,1,0,1,1,1,1,1,1,1,1,0,0,0,0,0","4.303027153,5.094311714,4.831954956,6.418707371,4.961856842,7.850357056,7.872403145,7.366671085,4.947339535,4.947339535,5.857741833,7.586094856,7.121934414,7.678453922,5.461499214,5.000318050,7.859985828,7.855003357,4.955154419,7.881975174,7.852957726,7.858335018,7.869473934,7.875190735,7.849181652,7.858565331,7.871207237,5.000318050,4.916692734,5.038779736,4.916692734,4.947339058",TLS.Instagram,91.211,1,Fun,SocialNetwork,6,DPI,"" -1,ip4,192.168.2.17,31.13.86.52,tcp,49359,443,finished,15,17,1568796254524506,1568796254710630,1568796254725634,0,0,571,1388,1587,13458,0,5,12492.0,158859,36696.7,1346645888.0,2.3,"12015,14119,556,167,14869,68,308,601,354,271,107,13997,388,138,112,165,226,1385,108,1160,122,114,5,489,10627,8948,1625,2191,142763,158859,395",52,522.8,1440,570.2,325102.6,4.1,"64,60,52,471,565,52,52,274,685,1440,1440,1440,52,1440,1440,1440,706,1440,136,52,52,52,52,52,52,86,52,230,52,623,685,1440","11,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0","0,1,0,0,0,1,1,1,1,1,1,1,0,1,1,1,1,1,0,0,0,0,0,0,0,1,0,1,0,0,1,1","4.346072197,5.035815716,4.870416641,6.991298199,7.577324390,5.038779736,5.038779736,6.829315662,7.680058956,7.881175995,7.859010696,7.855990410,4.831954956,7.860237122,7.871424198,7.861568928,7.676653862,7.867210865,6.338829517,5.000318527,4.878231525,4.923395157,4.825253010,4.961856365,4.839769840,5.854624271,4.961856842,7.028743744,4.961856842,7.587353230,7.689682484,7.874731064",TLS.Instagram,91.211,1,Fun,SocialNetwork,6,DPI,"" -1,ip4,192.168.2.17,31.13.86.52,tcp,49358,443,finished,14,18,1568796254515573,1568796254765378,1568796254925955,0,0,588,1388,2208,12690,0,7,21296.4,156515,45250.9,2047640320.0,2.9,"11078,12229,3431,138,15990,219,497,12957,479,11770,12042,155644,475,129,254,92,123,275,7,156515,111,123,122,255,2699,48704,55896,8249,149165,503,16",52,518.2,1440,557.6,310915.1,4.2,"64,60,52,471,581,52,52,274,52,136,230,52,826,1440,1440,1440,1440,1043,1440,86,52,52,52,52,52,640,640,52,52,827,1440,1440","9,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0","0,1,0,0,0,1,1,1,0,0,1,0,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,1,1,1,1,1","4.346072197,5.127645016,4.961856365,6.968073845,7.557704926,5.014835358,5.000318050,6.747485161,4.894361019,6.339305878,6.972853184,4.923395157,7.735570908,7.861948490,7.862287998,7.850868702,7.873754501,7.803619862,7.845140934,5.812837601,5.000318050,5.038779736,5.000318050,5.000318050,5.000318050,7.587841034,7.587659836,5.038779736,4.985801220,7.746087074,7.844884872,7.864926338",TLS.Instagram,91.211,1,Fun,SocialNetwork,6,DPI,"" -1,ip4,192.168.2.17,31.13.86.52,tcp,49360,443,finished,12,20,1568796265146962,1568796265180861,1568796265192260,0,0,526,1388,1014,20310,0,13,2554.7,16353,4723.5,22311642.0,3.2,"11840,12942,2760,70,16353,27,401,1108,14120,264,633,553,236,305,380,53,1148,300,94,1743,117,248,13,105,10046,132,1375,75,1411,144,201",52,719.0,1440,652.7,426025.8,4.3,"64,60,52,456,578,52,52,274,685,52,75,136,1440,1440,1440,1440,1440,52,1440,1440,52,52,52,52,52,1440,1440,1440,1440,1440,1440,1440","9,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0,0,0","0,1,0,0,0,1,1,1,1,0,1,0,1,1,1,1,1,0,1,1,0,0,0,0,0,1,1,1,1,1,1,1","4.314822197,5.127645493,4.839769840,6.925364971,7.610651493,4.993616104,4.955154419,6.841492653,7.701351166,4.870416641,5.685419083,6.370187283,7.864970684,7.852431297,7.854520321,7.870986938,7.857660770,4.961856842,7.885574341,7.873176098,4.961856842,4.839769840,4.961856365,5.000318527,4.878231049,7.857898235,7.858515739,7.865076542,7.865763187,7.848808289,7.881348610,7.866808891",TLS.Instagram,91.211,1,Fun,SocialNetwork,6,DPI,"" 1,ip4,192.168.2.17,31.13.86.52,tcp,49357,443,finished,15,17,1568796254514906,1568796265194500,1568796265280665,0,0,597,1388,2170,10887,0,6,691785.6,10469815,2560795.0,6557671096320.0,1.2,"11096,12433,1241,548,13252,614,103,14204,568,14367,12466,169576,258,200,98,307,55,169,229,6,169709,106,1819,218,113,542,10413415,52212,10469815,9752,75862",52,460.7,1440,528.6,279392.3,4.1,"64,60,52,471,649,52,52,274,52,136,230,52,825,1440,1440,1440,1440,1440,628,1440,86,52,52,52,52,52,52,587,587,52,52,828","10,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0","0,1,0,0,0,1,1,1,0,0,1,0,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1","4.215376377,5.115063667,4.860988617,7.062851906,7.630533695,5.014835358,4.976373672,6.836615562,4.884933949,6.378606796,7.007258415,4.822527409,7.742178440,7.852344990,7.873802185,7.849394321,7.865141869,7.857724190,7.720446110,7.850056171,5.757548332,4.976373672,4.976373672,4.937912464,4.937911987,4.899450779,4.976373672,7.590856075,7.594714642,5.053297043,5.053297043,7.784784317",TLS.Instagram,91.211,1,Fun,SocialNetwork,6,DPI,"" -1,ip4,192.168.2.17,31.13.86.52,tcp,49361,443,finished,15,17,1568796265147078,1568796265327859,1568796265324773,0,0,526,1388,1014,15077,0,6,11563.7,131670,31792.0,1010731712.0,2.4,"12123,13295,2535,457,15987,6,842,13996,1396,14470,16133,131670,10,876,193,264,9,116,291,177,158,249,254,129919,113,139,2594,71,83,9,41",52,555.5,1440,619.5,383805.7,4.1,"64,60,52,456,578,52,52,274,52,136,230,52,826,75,1440,1440,1440,1440,1440,1440,1440,1440,1440,1440,52,52,52,52,52,52,52,52","12,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0,0,0","0,1,0,0,0,1,1,1,0,0,1,0,1,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0","4.346072197,5.127645016,4.923394680,7.025774479,7.548739910,4.961856365,4.961856842,6.762446880,4.908877850,6.376214027,6.979849815,4.884933472,7.738527298,5.578752518,7.854865074,7.854829311,7.858168602,7.848493099,7.843452930,7.870431900,7.877417564,7.866308212,7.865350246,7.841341019,4.961856365,4.961856365,4.908877850,4.923394680,4.801308155,4.860988617,4.738902092,4.923395157",TLS.Instagram,91.211,1,Fun,SocialNetwork,6,DPI,"" diff --git a/test/results/flow-analyse/malware.pcap.out b/test/results/flow-analyse/default/ip_fragmented_garbage.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/malware.pcap.out +++ b/test/results/flow-analyse/default/ip_fragmented_garbage.pcap.out diff --git a/test/results/flow-analyse/iphone.pcap.out b/test/results/flow-analyse/default/iphone.pcap.out index 0679df6cd..0679df6cd 100644 --- a/test/results/flow-analyse/iphone.pcap.out +++ b/test/results/flow-analyse/default/iphone.pcap.out diff --git a/test/results/flow-analyse/ipp.pcap.out b/test/results/flow-analyse/default/ipp.pcap.out index 0f0ece312..0f0ece312 100644 --- a/test/results/flow-analyse/ipp.pcap.out +++ b/test/results/flow-analyse/default/ipp.pcap.out diff --git a/test/results/flow-analyse/ipsec_isakmp_esp.pcap.out b/test/results/flow-analyse/default/ipsec_isakmp_esp.pcap.out index 9cf821ebc..54c0f9d79 100644 --- a/test/results/flow-analyse/ipsec_isakmp_esp.pcap.out +++ b/test/results/flow-analyse/default/ipsec_isakmp_esp.pcap.out @@ -1,7 +1,7 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.2.100,109.237.187.193,udp,14500,4500,finished,16,16,946744635161000,946745723299000,946745723443000,96,0,1332,1028,12356,3648,0,0,70207096.0,662067000,185660096.0,34469670203424768.0,2.0,"122000,677000,771000,222000,34000,2372000,0,1000,23000,2387000,0,0,22000,24000,661960000,662067000,681000,743000,195000,34000,407000,0,0,421000,0,4000,138000,188000,12771000,421390000,408766000",108,528.1,1360,468.7,219671.5,4.5,"844,236,140,108,124,444,1360,1360,928,1360,160,160,160,928,160,844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236","0,0,0,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0","0,0,3,0,7,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,0,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.741627216,6.965078831,6.116603374,5.779674053,6.059063911,7.410885334,7.860165119,7.863566875,7.772638798,7.854592800,6.636003017,6.657938480,6.612657070,7.764769077,6.596687317,7.754736900,6.881987095,6.222157478,5.801217556,6.004589081,7.442288876,7.852550507,7.852631569,7.794322968,6.638905048,6.506283283,6.772091866,7.817639828,6.695438385,5.748310089,7.756398201,6.820323944",IPSec,79,1,Safe,VPN,6,DPI,"" -1,ip4,192.168.2.100,109.237.187.227,udp,14500,4500,finished,15,17,946763527783000,946763527783000,946763527783000,96,0,1332,1028,10256,4624,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,493.0,1360,453.9,206039.0,4.4,"844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0","0,0,4,0,6,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.693149090,6.908532143,6.289921284,5.907789707,6.064967155,7.449052334,7.871124744,7.858648777,7.794081688,6.655786514,6.611001968,6.493160248,7.792814732,6.670437813,5.759838581,7.685832500,6.882148743,6.265015125,5.724118233,6.052976131,7.485020638,7.879636765,7.861135006,7.787482738,6.603220463,6.625156879,6.573005676,7.827785015,6.468286991,5.669764996,7.726345062,6.805452824",IPSec,79,1,Safe,VPN,6,DPI,"" -1,ip4,192.168.2.100,109.237.187.227,udp,10500,500,finished,16,16,946763527783000,946763527783000,946763527783000,776,0,800,288,12608,2720,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",80,507.0,828,320.2,102515.0,4.7,"804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,8,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.943627357,4.600413322,5.035194874,6.560711384,4.957199574,4.634849548,5.032216549,6.619104385,4.913105965,4.609849930,4.993678570,6.435603142,4.935446262,4.594285965,5.011265278,6.551633835,4.906664848,4.582717896,4.951835632,6.504704952,4.882042408,4.594286442,4.970667839,6.575375080,4.923563004,4.694285870,5.003669262,6.614925861,4.935611725,4.644286156,5.001285553,6.506689072",IPSec,79,1,Safe,VPN,6,DPI,"" -1,ip4,192.168.2.100,109.237.187.130,udp,14500,4500,finished,13,19,946763527783000,946763527783000,946763527783000,96,0,1332,1332,7848,12096,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,651.2,1360,511.6,261688.4,4.5,"844,236,140,108,124,444,1360,1056,160,160,1056,160,1360,1360,1312,844,236,140,108,124,444,1360,1056,160,160,1056,160,1360,1360,1312,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0","0,0,2,0,4,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,2,4,0,0,0,0,0,0","0,1,0,1,0,1,0,0,1,1,1,0,1,1,1,0,1,0,1,0,1,0,0,1,1,1,0,1,1,1,0,1","7.731180668,6.807529449,6.307871342,5.782698631,6.032709122,7.449109077,7.850845337,7.804824352,6.606283665,6.623502254,7.788777351,6.573501587,7.833298206,7.853844643,7.853167534,7.760776520,6.845402241,6.255957603,5.919319153,6.125529766,7.423834324,7.868905544,7.797307491,6.606283665,6.670437813,7.803458691,6.729874611,7.870663643,7.821934700,7.841155052,7.723438740,6.936455250",IPSec,79,1,Safe,VPN,6,DPI,"" -1,ip4,192.168.2.100,109.237.187.195,udp,14500,4500,finished,15,17,946763527783000,946763527783000,946763527783000,96,0,1332,1332,10224,7128,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,570.2,1360,486.8,236933.9,4.5,"844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0","0,0,2,0,6,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.744743347,6.853363991,6.347064018,5.738097668,6.151700020,7.473697186,7.876097679,7.831090450,7.765502453,6.747092724,6.687656403,6.679874420,7.827803612,6.462619305,7.846179008,7.744938850,6.903948784,6.261349678,5.757190228,6.099359512,7.429207802,7.852733135,7.863712311,7.793406487,6.532532215,6.538568020,6.619940281,7.820692539,6.667374134,7.838056564,7.740211487,6.937667370",IPSec,79,1,Safe,VPN,6,DPI,"" -1,ip4,192.168.2.100,109.237.187.225,udp,14500,4500,finished,15,17,946763527783000,946763527783000,946763527783000,96,0,1332,1332,10240,5876,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,531.6,1360,472.2,222978.4,4.4,"844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0","0,0,3,0,6,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.735000610,6.885608673,6.313099861,5.849783897,6.173916817,7.464264393,7.831699848,7.833400249,7.798014164,6.661001682,6.578844547,6.648502350,7.808434486,6.640223026,5.685765266,7.751714706,6.969136238,6.248125076,5.863762856,6.151700020,7.458979130,7.869451523,7.855331421,7.760697842,6.747092247,6.645437717,6.637656689,7.804164410,6.573502064,7.848899364,7.732619762,6.921160221",IPSec,79,1,Safe,VPN,6,DPI,"" +1,ip4,192.168.2.100,109.237.187.193,udp,14500,4500,finished,16,16,946744635161000,946745723299000,946745723443000,96,0,1332,1028,12356,3648,0,0,70207096.0,662067000,185660096.0,34469670203424768.0,2.0,"122000,677000,771000,222000,34000,2372000,0,1000,23000,2387000,0,0,22000,24000,661960000,662067000,681000,743000,195000,34000,407000,0,0,421000,0,4000,138000,188000,12771000,421390000,408766000",108,528.1,1360,468.7,219671.5,4.5,"844,236,140,108,124,444,1360,1360,928,1360,160,160,160,928,160,844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236","0,0,0,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0","0,0,3,0,7,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,0,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.741627216,6.965078831,6.116603374,5.779674053,6.059063911,7.410885334,7.860165119,7.863566875,7.772638798,7.854592800,6.636003017,6.657938480,6.612657070,7.764769077,6.596687317,7.754736900,6.881987095,6.222157478,5.801217556,6.004589081,7.442288876,7.852550507,7.852631569,7.794322968,6.638905048,6.506283283,6.772091866,7.817639828,6.695438385,5.748310089,7.756398201,6.820323944",IPSec,79,1,Safe,VPN,6,DPI,"46" +1,ip4,192.168.2.100,109.237.187.227,udp,14500,4500,finished,15,17,946763527783000,946763527783000,946763527783000,96,0,1332,1028,10256,4624,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,493.0,1360,453.9,206039.0,4.4,"844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0","0,0,4,0,6,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.693149090,6.908532143,6.289921284,5.907789707,6.064967155,7.449052334,7.871124744,7.858648777,7.794081688,6.655786514,6.611001968,6.493160248,7.792814732,6.670437813,5.759838581,7.685832500,6.882148743,6.265015125,5.724118233,6.052976131,7.485020638,7.879636765,7.861135006,7.787482738,6.603220463,6.625156879,6.573005676,7.827785015,6.468286991,5.669764996,7.726345062,6.805452824",IPSec,79,1,Safe,VPN,6,DPI,"46" +1,ip4,192.168.2.100,109.237.187.227,udp,10500,500,finished,16,16,946763527783000,946763527783000,946763527783000,776,0,800,288,12608,2720,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",80,507.0,828,320.2,102515.0,4.7,"804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,8,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.943627357,4.600413322,5.035194874,6.560711384,4.957199574,4.634849548,5.032216549,6.619104385,4.913105965,4.609849930,4.993678570,6.435603142,4.935446262,4.594285965,5.011265278,6.551633835,4.906664848,4.582717896,4.951835632,6.504704952,4.882042408,4.594286442,4.970667839,6.575375080,4.923563004,4.694285870,5.003669262,6.614925861,4.935611725,4.644286156,5.001285553,6.506689072",IPSec,79,1,Safe,VPN,6,DPI,"46" +1,ip4,192.168.2.100,109.237.187.130,udp,14500,4500,finished,13,19,946763527783000,946763527783000,946763527783000,96,0,1332,1332,7848,12096,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,651.2,1360,511.6,261688.4,4.5,"844,236,140,108,124,444,1360,1056,160,160,1056,160,1360,1360,1312,844,236,140,108,124,444,1360,1056,160,160,1056,160,1360,1360,1312,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0","0,0,2,0,4,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,2,4,0,0,0,0,0,0","0,1,0,1,0,1,0,0,1,1,1,0,1,1,1,0,1,0,1,0,1,0,0,1,1,1,0,1,1,1,0,1","7.731180668,6.807529449,6.307871342,5.782698631,6.032709122,7.449109077,7.850845337,7.804824352,6.606283665,6.623502254,7.788777351,6.573501587,7.833298206,7.853844643,7.853167534,7.760776520,6.845402241,6.255957603,5.919319153,6.125529766,7.423834324,7.868905544,7.797307491,6.606283665,6.670437813,7.803458691,6.729874611,7.870663643,7.821934700,7.841155052,7.723438740,6.936455250",IPSec,79,1,Safe,VPN,6,DPI,"46" +1,ip4,192.168.2.100,109.237.187.195,udp,14500,4500,finished,15,17,946763527783000,946763527783000,946763527783000,96,0,1332,1332,10224,7128,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,570.2,1360,486.8,236933.9,4.5,"844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0","0,0,2,0,6,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.744743347,6.853363991,6.347064018,5.738097668,6.151700020,7.473697186,7.876097679,7.831090450,7.765502453,6.747092724,6.687656403,6.679874420,7.827803612,6.462619305,7.846179008,7.744938850,6.903948784,6.261349678,5.757190228,6.099359512,7.429207802,7.852733135,7.863712311,7.793406487,6.532532215,6.538568020,6.619940281,7.820692539,6.667374134,7.838056564,7.740211487,6.937667370",IPSec,79,1,Safe,VPN,6,DPI,"46" +1,ip4,192.168.2.100,109.237.187.225,udp,14500,4500,finished,15,17,946763527783000,946763527783000,946763527783000,96,0,1332,1332,10240,5876,0,0,0.0,0,0.0,0.0,0.0,"0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",108,531.6,1360,472.2,222978.4,4.4,"844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236","0,0,0,4,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0","0,0,3,0,6,0,3,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0","0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,1,0,0,0,1,1,1,1,0,1,0,1","7.735000610,6.885608673,6.313099861,5.849783897,6.173916817,7.464264393,7.831699848,7.833400249,7.798014164,6.661001682,6.578844547,6.648502350,7.808434486,6.640223026,5.685765266,7.751714706,6.969136238,6.248125076,5.863762856,6.151700020,7.458979130,7.869451523,7.855331421,7.760697842,6.747092247,6.645437717,6.637656689,7.804164410,6.573502064,7.848899364,7.732619762,6.921160221",IPSec,79,1,Safe,VPN,6,DPI,"46" diff --git a/test/results/flow-analyse/memcached.cap.out b/test/results/flow-analyse/default/ipv6_in_gtp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/memcached.cap.out +++ b/test/results/flow-analyse/default/ipv6_in_gtp.pcap.out diff --git a/test/results/flow-analyse/mgcp.pcapng.out b/test/results/flow-analyse/default/irc.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mgcp.pcapng.out +++ b/test/results/flow-analyse/default/irc.pcap.out diff --git a/test/results/flow-analyse/mongo_false_positive.pcapng.out b/test/results/flow-analyse/default/ja3_lots_of_cipher_suites.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mongo_false_positive.pcapng.out +++ b/test/results/flow-analyse/default/ja3_lots_of_cipher_suites.pcap.out diff --git a/test/results/flow-analyse/mongodb.pcap.out b/test/results/flow-analyse/default/ja3_lots_of_cipher_suites_2_anon.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mongodb.pcap.out +++ b/test/results/flow-analyse/default/ja3_lots_of_cipher_suites_2_anon.pcap.out diff --git a/test/results/flow-analyse/jabber.pcap.out b/test/results/flow-analyse/default/jabber.pcap.out index 299373ec3..30febf252 100644 --- a/test/results/flow-analyse/jabber.pcap.out +++ b/test/results/flow-analyse/default/jabber.pcap.out @@ -1,4 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,172.16.0.62,172.16.1.138,tcp,57094,5222,finished,17,15,1502379723841804,1502379724444209,1502379724444121,0,0,338,379,929,1485,0,218,38862.0,337747,84176.8,7085729792.0,3.0,"444,511,417,828,400,374,12411,12818,2412,2410,348,1979,1627,218,40781,36965,77519,220,613,337303,337747,374,834,51093,51498,6383,6386,306,844,109053,109606",52,128.1,431,104.5,10930.1,4.6,"64,60,52,74,52,168,52,231,52,337,52,214,212,52,390,52,172,52,104,52,103,52,168,52,231,52,431,52,175,52,184,52","11,1,0,3,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,0,1,1,3,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,1,1,0,1,0,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,0,0,1,1,0","4.198073387,4.993659973,4.853535175,5.479191780,4.902175903,5.439201832,4.902175903,5.621643066,4.738150120,5.383924484,4.723633289,5.581990719,6.107189655,4.670654774,6.120055676,4.902175903,5.874162197,4.853535175,5.356550694,4.849197388,5.481268406,4.776612282,5.385900497,4.786790848,5.631215096,4.630272865,5.375878334,4.800556660,5.531776905,4.762094975,5.626255989,4.762094975",Jabber,67,0,Acceptable,Web,6,DPI,"" 1,ip4,172.16.0.62,172.16.1.138,tcp,57122,5222,finished,17,15,1502380175298881,1502380175888009,1502380175887945,0,0,338,379,929,1483,0,72,38006.2,336798,84915.4,7210629120.0,2.8,"690,749,72,451,362,328,190,509,138,134,177,1433,1288,169,39805,40983,80676,197,580,336438,336798,280,830,51170,51717,134,126,305,762,115132,115569",52,128.0,431,104.5,10917.3,4.6,"64,60,52,74,52,168,52,229,52,337,52,214,212,52,390,52,172,52,104,52,103,52,168,52,231,52,431,52,175,52,184,52","11,1,0,3,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,0,1,1,3,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,1,1,0,1,0,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,0,0,1,1,0","4.266673088,5.131404400,4.776611805,5.441964149,4.902175903,5.444538593,4.825252533,5.585448742,4.738150120,5.405127525,4.776611805,5.600682259,6.105852604,4.815073490,6.126323223,4.863714218,5.952934742,4.675744057,5.351836681,4.801308155,5.387970448,4.584303856,5.442506313,4.863714218,5.598178864,4.776611805,5.389763355,4.671903133,5.446438789,4.762094498,5.526237488,4.685171604",Jabber,67,0,Acceptable,Web,6,DPI,"" -1,ip4,172.16.0.62,172.16.1.138,tcp,57149,5222,finished,18,14,1502380915481182,1502381566576939,1502381566616902,0,0,239,463,1086,2076,1,2,42007464.0,600487770,147104800.0,21639823353708544.0,1.4,"5033,2,5089,3,217021,217977,974,3684463,3688323,3876,600484177,600487770,3,3561,6,1107,1119,7791,47498,39730,447,62982,63440,253,504,186,80,2,90,46583978,46623992",52,150.8,515,117.9,13893.8,4.6,"291,460,172,52,52,234,515,52,234,179,52,202,256,158,106,52,272,52,100,52,100,52,274,52,100,153,52,52,157,52,187,52","9,4,0,0,2,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,5,0,0,3,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,0,1,0,0,1,0,0,1,1,0,0,1,0,0,1,0,1,1,0,0,1,0,1,1,0,0,1","5.572191238,5.460877895,5.502878189,4.891996861,4.853535175,5.455323696,5.262341499,4.891996861,5.508277893,5.549472332,4.853535175,5.489766598,5.608968258,5.516506672,5.456765175,4.747577667,5.601363182,4.800556183,5.462725163,4.870416641,5.430274010,4.908877850,5.580210686,4.647958755,5.434380531,5.509377956,4.699688911,4.762538910,5.683691025,4.646709919,5.424290180,4.908878326",Jabber,67,0,Acceptable,Web,6,DPI,"" +1,ip4,172.16.0.62,172.16.1.138,tcp,57149,5222,finished,18,14,1502380915481182,1502381566576939,1502381566616902,0,0,239,463,1086,2076,1,2,42007464.0,600487770,147104800.0,21639823353708544.0,1.4,"5033,2,5089,3,217021,217977,974,3684463,3688323,3876,600484177,600487770,3,3561,6,1107,1119,7791,47498,39730,447,62982,63440,253,504,186,80,2,90,46583978,46623992",52,150.8,515,117.9,13893.8,4.6,"291,460,172,52,52,234,515,52,234,179,52,202,256,158,106,52,272,52,100,52,100,52,274,52,100,153,52,52,157,52,187,52","9,4,0,0,2,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,5,0,0,3,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,0,1,0,0,1,0,0,1,1,0,0,1,0,0,1,0,1,1,0,0,1,0,1,1,0,0,1","5.572191238,5.460877895,5.502878189,4.891996861,4.853535175,5.455323696,5.262341499,4.891996861,5.508277893,5.549472332,4.853535175,5.489766598,5.608968258,5.516506672,5.456765175,4.747577667,5.601363182,4.800556183,5.462725163,4.870416641,5.430274010,4.908877850,5.580210686,4.647958755,5.434380531,5.509377956,4.699688911,4.762538910,5.683691025,4.646709919,5.424290180,4.908878326",Jabber,67,0,Acceptable,Web,6,DPI,"46" diff --git a/test/results/flow-analyse/mpeg-dash.pcap.out b/test/results/flow-analyse/default/kerberos-error.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mpeg-dash.pcap.out +++ b/test/results/flow-analyse/default/kerberos-error.pcap.out diff --git a/test/results/flow-analyse/mpeg.pcap.out b/test/results/flow-analyse/default/kerberos-login.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mpeg.pcap.out +++ b/test/results/flow-analyse/default/kerberos-login.pcap.out diff --git a/test/results/flow-analyse/mpegts.pcap.out b/test/results/flow-analyse/default/kerberos.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mpegts.pcap.out +++ b/test/results/flow-analyse/default/kerberos.pcap.out diff --git a/test/results/flow-analyse/mqtt.pcap.out b/test/results/flow-analyse/default/kerberos_fuzz.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mqtt.pcap.out +++ b/test/results/flow-analyse/default/kerberos_fuzz.pcapng.out diff --git a/test/results/flow-analyse/kismet.pcap.out b/test/results/flow-analyse/default/kismet.pcap.out index b3f236d55..b3f236d55 100644 --- a/test/results/flow-analyse/kismet.pcap.out +++ b/test/results/flow-analyse/default/kismet.pcap.out diff --git a/test/results/flow-analyse/kontiki.pcap.out b/test/results/flow-analyse/default/kontiki.pcap.out index f8e100fae..0dae0ff11 100644 --- a/test/results/flow-analyse/kontiki.pcap.out +++ b/test/results/flow-analyse/default/kontiki.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.25.32.59,64.200.148.86,udp,19948,8888,finished,10,22,1213662198289578,1213662198988100,1213662198992190,4,0,217,1241,591,24254,0,13,45197.9,607738,118031.4,13931400192.0,2.6,"198615,212422,193796,607738,3074,5780,31191,29960,8831,9093,72,244,17,19380,18261,96,127,127,114,15289,14893,16,235,114,13,97,15924,15357,18,115,125",32,804.4,1269,568.0,322604.6,4.5,"32,32,32,48,56,245,499,232,204,118,1269,1269,1269,1269,44,1269,1269,1269,1269,1269,44,1269,1269,1269,1269,1269,1269,44,1269,1269,1269,1269","7,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0,0,0,0,0,0,0,0","0,0,0,0,1,0,1,0,1,0,1,1,1,1,0,1,1,1,1,1,0,1,1,1,1,1,1,0,1,1,1,1","4.327819824,4.390319824,4.390319824,4.808207035,5.107008457,6.254767418,7.256530285,7.013645172,6.874151707,6.231850147,7.871051788,7.843012333,7.837141991,7.838663578,4.925117970,7.837912083,7.840578079,7.843400478,7.848168850,7.821814060,4.879663467,7.851324558,7.825254917,7.844458103,7.841213703,7.862925529,7.835451603,4.925117970,7.832023621,7.834714890,7.855443478,7.864355564",Kontiki,32,0,Potentially Dangerous,Media,6,DPI,"22" +1,ip4,10.25.32.59,64.200.148.86,udp,19948,8888,finished,10,22,1213662198289578,1213662198988100,1213662198992190,4,0,217,1241,591,24254,0,13,45197.9,607738,118031.4,13931400192.0,2.6,"198615,212422,193796,607738,3074,5780,31191,29960,8831,9093,72,244,17,19380,18261,96,127,127,114,15289,14893,16,235,114,13,97,15924,15357,18,115,125",32,804.4,1269,568.0,322604.6,4.5,"32,32,32,48,56,245,499,232,204,118,1269,1269,1269,1269,44,1269,1269,1269,1269,1269,44,1269,1269,1269,1269,1269,1269,44,1269,1269,1269,1269","7,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0,0,0,0,0,0,0,0","0,0,0,0,1,0,1,0,1,0,1,1,1,1,0,1,1,1,1,1,0,1,1,1,1,1,1,0,1,1,1,1","4.327819824,4.390319824,4.390319824,4.808207035,5.107008457,6.254767418,7.256530285,7.013645172,6.874151707,6.231850147,7.871051788,7.843012333,7.837141991,7.838663578,4.925117970,7.837912083,7.840578079,7.843400478,7.848168850,7.821814060,4.879663467,7.851324558,7.825254917,7.844458103,7.841213703,7.862925529,7.835451603,4.925117970,7.832023621,7.834714890,7.855443478,7.864355564",Kontiki,32,0,Potentially Dangerous,Media,6,DPI,"22,46" diff --git a/test/results/flow-analyse/line.pcap.out b/test/results/flow-analyse/default/line.pcap.out index a9fb03321..a9fb03321 100644 --- a/test/results/flow-analyse/line.pcap.out +++ b/test/results/flow-analyse/default/line.pcap.out diff --git a/test/results/flow-analyse/mssql_tds.pcap.out b/test/results/flow-analyse/default/linecall_falsepositve.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mssql_tds.pcap.out +++ b/test/results/flow-analyse/default/linecall_falsepositve.pcap.out diff --git a/test/results/flow-analyse/munin.pcap.out b/test/results/flow-analyse/default/lisp_registration.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/munin.pcap.out +++ b/test/results/flow-analyse/default/lisp_registration.pcap.out diff --git a/test/results/flow-analyse/log4j-webapp-exploit.pcap.out b/test/results/flow-analyse/default/log4j-webapp-exploit.pcap.out index fc41abd03..fc41abd03 100644 --- a/test/results/flow-analyse/log4j-webapp-exploit.pcap.out +++ b/test/results/flow-analyse/default/log4j-webapp-exploit.pcap.out diff --git a/test/results/flow-analyse/long_tls_certificate.pcap.out b/test/results/flow-analyse/default/long_tls_certificate.pcap.out index 629b68617..629b68617 100644 --- a/test/results/flow-analyse/long_tls_certificate.pcap.out +++ b/test/results/flow-analyse/default/long_tls_certificate.pcap.out diff --git a/test/results/flow-analyse/mysql-8.pcap.out b/test/results/flow-analyse/default/lru_ipv6_caches.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/mysql-8.pcap.out +++ b/test/results/flow-analyse/default/lru_ipv6_caches.pcapng.out diff --git a/test/results/flow-analyse/natpmp.pcap.out b/test/results/flow-analyse/default/malformed_dns.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/natpmp.pcap.out +++ b/test/results/flow-analyse/default/malformed_dns.pcap.out diff --git a/test/results/flow-analyse/nats.pcap.out b/test/results/flow-analyse/default/malformed_icmp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/nats.pcap.out +++ b/test/results/flow-analyse/default/malformed_icmp.pcap.out diff --git a/test/results/flow-analyse/ndpi_match_string_subprotocol__error.pcapng.out b/test/results/flow-analyse/default/malware.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ndpi_match_string_subprotocol__error.pcapng.out +++ b/test/results/flow-analyse/default/malware.pcap.out diff --git a/test/results/flow-analyse/netbios_wildcard_dns_query.pcap.out b/test/results/flow-analyse/default/memcached.cap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/netbios_wildcard_dns_query.pcap.out +++ b/test/results/flow-analyse/default/memcached.cap.out diff --git a/test/results/flow-analyse/default/merakicloud.pcapng.out b/test/results/flow-analyse/default/merakicloud.pcapng.out new file mode 100644 index 000000000..f05424cc9 --- /dev/null +++ b/test/results/flow-analyse/default/merakicloud.pcapng.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,2.36.234.133,209.206.59.34,udp,47301,7351,finished,16,16,1673444916586594,1673445166592687,1673445166786552,112,0,155,148,2007,1246,0,185099,16135679.0,25010608,11213935.0,125752330682368.0,4.4,"185099,25000825,24997097,25000212,25005070,25000662,24996065,25000606,25010608,25000568,24997458,25000731,24998623,25000698,24997255,25000418,25005650,25000559,25008551,6242649,6445427,200886,201754,201009,201123,200007,200026,199896,198997,17753487,17954035",74,129.7,183,43.4,1881.8,4.9,"140,74,140,74,140,74,140,74,140,74,140,74,140,74,140,74,140,74,140,74,176,183,176,183,176,183,176,183,176,183,140,74","0,0,0,11,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,11,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,0,1,0,0,1","5.828664303,4.613403797,5.810577869,4.640430927,5.848342419,4.630228996,5.771522522,4.640430927,5.791199684,4.667457581,5.868019581,4.630228996,5.832838535,4.667457104,5.791912556,4.640430927,5.823272228,4.640430450,5.805485725,4.694484234,6.490767479,6.480163097,6.449603081,6.561568260,6.490767956,6.556210518,6.465298176,6.530937672,6.547586918,6.608176708,5.825162888,4.694484234",MerakiCloud,66,0,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/netflow-fritz.pcap.out b/test/results/flow-analyse/default/mgcp.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/netflow-fritz.pcap.out +++ b/test/results/flow-analyse/default/mgcp.pcapng.out diff --git a/test/results/flow-analyse/modbus.pcap.out b/test/results/flow-analyse/default/modbus.pcap.out index 8c9240e41..820e7855c 100644 --- a/test/results/flow-analyse/modbus.pcap.out +++ b/test/results/flow-analyse/default/modbus.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.110.131,192.168.110.138,tcp,2074,502,finished,16,16,1223541953927963,1223541960939284,1223541960940128,12,0,12,11,192,176,1,835,452370.5,1014211,497296.8,247304159232.0,3.8,"1135,1208,905,1013603,1014211,1539,891,986516,986873,1217,900,1000224,1000513,1187,905,1000230,1000558,1232,911,1000222,1000609,1645,915,999845,1000447,1173,835,1000242,1000645,1238,912",51,51.5,52,0.5,0.2,5.0,"52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.526987553,4.730195045,4.438603878,4.877732754,4.429176807,4.636961937,4.429176331,4.877732754,4.622483730,4.730195045,4.589393616,4.838517189,4.622483730,4.730195045,4.550931931,4.916948318,4.569504738,4.769410610,4.627855301,4.916948318,4.622483730,4.730195045,4.627855301,4.916948795,4.622483730,4.769410610,4.627855301,4.862931252,4.607966423,4.769410610,4.627855301,4.916948318",Modbus,44,0,Acceptable,IoT-Scada,6,DPI,"" +1,ip4,192.168.110.131,192.168.110.138,tcp,2074,502,finished,16,16,1223541953927963,1223541960939284,1223541960940128,12,0,12,11,192,176,1,835,452370.5,1014211,497296.8,247304159232.0,3.8,"1135,1208,905,1013603,1014211,1539,891,986516,986873,1217,900,1000224,1000513,1187,905,1000230,1000558,1232,911,1000222,1000609,1645,915,999845,1000447,1173,835,1000242,1000645,1238,912",51,51.5,52,0.5,0.2,5.0,"52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51,52,51","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.526987553,4.730195045,4.438603878,4.877732754,4.429176807,4.636961937,4.429176331,4.877732754,4.622483730,4.730195045,4.589393616,4.838517189,4.622483730,4.730195045,4.550931931,4.916948318,4.569504738,4.769410610,4.627855301,4.916948318,4.622483730,4.730195045,4.627855301,4.916948795,4.622483730,4.769410610,4.627855301,4.862931252,4.607966423,4.769410610,4.627855301,4.916948318",Modbus,44,0,Acceptable,IoT-Scada,6,DPI,"46" diff --git a/test/results/flow-analyse/monero.pcap.out b/test/results/flow-analyse/default/monero.pcap.out index 0c30263f1..0c30263f1 100644 --- a/test/results/flow-analyse/monero.pcap.out +++ b/test/results/flow-analyse/default/monero.pcap.out diff --git a/test/results/flow-analyse/netflowv9.pcap.out b/test/results/flow-analyse/default/mongo_false_positive.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/netflowv9.pcap.out +++ b/test/results/flow-analyse/default/mongo_false_positive.pcapng.out diff --git a/test/results/flow-analyse/oracle12.pcapng.out b/test/results/flow-analyse/default/mongodb.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/oracle12.pcapng.out +++ b/test/results/flow-analyse/default/mongodb.pcap.out diff --git a/test/results/flow-analyse/os_detected.pcapng.out b/test/results/flow-analyse/default/mpeg-dash.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/os_detected.pcapng.out +++ b/test/results/flow-analyse/default/mpeg-dash.pcap.out diff --git a/test/results/flow-analyse/ospfv2_add_new_prefix.pcap.out b/test/results/flow-analyse/default/mpeg.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ospfv2_add_new_prefix.pcap.out +++ b/test/results/flow-analyse/default/mpeg.pcap.out diff --git a/test/results/flow-analyse/pgsql.pcap.out b/test/results/flow-analyse/default/mpegts.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/pgsql.pcap.out +++ b/test/results/flow-analyse/default/mpegts.pcap.out diff --git a/test/results/flow-analyse/pim.pcap.out b/test/results/flow-analyse/default/mqtt.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/pim.pcap.out +++ b/test/results/flow-analyse/default/mqtt.pcap.out diff --git a/test/results/flow-analyse/pluralsight.pcap.out b/test/results/flow-analyse/default/mssql_tds.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/pluralsight.pcap.out +++ b/test/results/flow-analyse/default/mssql_tds.pcap.out diff --git a/test/results/flow-analyse/pop3.pcap.out b/test/results/flow-analyse/default/munin.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/pop3.pcap.out +++ b/test/results/flow-analyse/default/munin.pcap.out diff --git a/test/results/flow-analyse/pops.pcapng.out b/test/results/flow-analyse/default/mysql-8.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/pops.pcapng.out +++ b/test/results/flow-analyse/default/mysql-8.pcap.out diff --git a/test/results/flow-analyse/pptp.pcap.out b/test/results/flow-analyse/default/natpmp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/pptp.pcap.out +++ b/test/results/flow-analyse/default/natpmp.pcap.out diff --git a/test/results/flow-analyse/punycode-idn.pcap.out b/test/results/flow-analyse/default/nats.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/punycode-idn.pcap.out +++ b/test/results/flow-analyse/default/nats.pcap.out diff --git a/test/results/flow-analyse/quic-23.pcap.out b/test/results/flow-analyse/default/ndpi_match_string_subprotocol__error.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-23.pcap.out +++ b/test/results/flow-analyse/default/ndpi_match_string_subprotocol__error.pcapng.out diff --git a/test/results/flow-analyse/nest_log_sink.pcap.out b/test/results/flow-analyse/default/nest_log_sink.pcap.out index ddc9ad2db..ddc9ad2db 100644 --- a/test/results/flow-analyse/nest_log_sink.pcap.out +++ b/test/results/flow-analyse/default/nest_log_sink.pcap.out diff --git a/test/results/flow-analyse/netbios.pcap.out b/test/results/flow-analyse/default/netbios.pcap.out index 38ff16d08..38ff16d08 100644 --- a/test/results/flow-analyse/netbios.pcap.out +++ b/test/results/flow-analyse/default/netbios.pcap.out diff --git a/test/results/flow-analyse/quic-24.pcap.out b/test/results/flow-analyse/default/netbios_wildcard_dns_query.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-24.pcap.out +++ b/test/results/flow-analyse/default/netbios_wildcard_dns_query.pcap.out diff --git a/test/results/flow-analyse/netflix.pcap.out b/test/results/flow-analyse/default/netflix.pcap.out index c32b6f49c..30555f8d1 100644 --- a/test/results/flow-analyse/netflix.pcap.out +++ b/test/results/flow-analyse/default/netflix.pcap.out @@ -1,32 +1,27 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.1.7,54.69.204.241,tcp,53105,443,finished,18,14,1484319032888907,1484319033506287,1484319033504279,0,0,356,1448,1665,5139,0,72,39766.2,363670,81851.3,6699630080.0,3.2,"46025,48575,597,54003,1611,989,54938,11050,13463,9437,301,377,58747,4648,50832,1878,237,59545,562,62143,8477,4734,310931,590,363670,5842,131,72,58058,152,137",52,265.2,1500,396.8,157454.8,3.9,"64,60,52,260,52,1500,1500,52,215,52,127,58,97,52,103,52,408,362,52,992,52,112,52,408,361,52,992,107,86,52,52,52","11,1,1,0,0,0,1,0,0,2,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,4,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,1,1,0,1,0,0,0,1,1,1,1,0,0,0","4.566831589,5.323234081,5.131024837,5.723237514,5.246409416,7.251158237,7.324303627,5.131024837,6.880544662,5.169486523,6.374709129,5.113821983,6.051860332,5.246409416,5.890006065,5.169486523,7.472100735,7.415780067,5.176993370,7.832669258,5.131024837,6.117320061,5.131024361,7.427300930,7.397639751,5.246409416,7.802502632,6.080207348,5.833016396,5.207947731,5.207947731,5.131024361",TLS.NetFlix,91.133,1,Fun,Video,6,DPI,"" -1,ip4,192.168.1.7,52.32.196.36,tcp,53116,443,info,17,15,1484319032986624,1484319033498318,1484319033554363,0,0,1448,1448,4381,7721,0,191,34820.4,199917,47580.3,2263883008.0,3.8,"45497,51828,277,66352,510,13769,75518,25611,26489,15622,271,195,60990,421,44123,5113,191,57731,67780,234,2712,130987,13830,8367,10032,8058,2353,2270,141147,1238,199917",52,430.8,1500,557.4,310647.7,4.0,"64,60,52,284,52,1500,1500,52,245,52,127,58,97,52,103,52,1500,728,52,1500,415,1500,52,1116,52,261,52,101,52,1436,567,52","10,1,1,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0","5,2,0,0,0,0,2,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,1,1,1,1,0,1,0,1,0,1,0,0,0,1","4.598081589,5.335815907,5.169486523,5.856084347,5.169486523,7.248301983,7.321610928,5.246409893,7.068851471,5.132945538,6.268332958,5.113822460,5.960739613,5.092563629,6.027123928,5.207948208,7.879599094,7.736606598,5.169486523,7.866442680,7.495402336,7.875605583,5.207948208,7.821874619,5.092563152,7.123493671,5.131024837,6.085196495,5.169486523,7.864480019,7.601682663,5.169486523",,,,,,,,"" 1,ip4,192.168.1.7,52.89.39.139,tcp,53133,443,info,16,16,1484319035080111,1484319035720714,1484319035719060,0,0,1448,1448,2402,12882,0,143,41275.9,350146,77246.2,5966969856.0,3.5,"50833,52103,3892,68860,549,14675,80527,16948,16635,16128,355,222,66675,773,50716,3176,284,61420,291182,143,350146,11846,12750,24110,12460,12309,13854,13662,2679,13302,16338",52,530.2,1500,630.5,397553.6,4.0,"64,60,52,260,52,1500,1500,52,245,52,127,58,97,52,103,52,1500,672,52,1500,1500,52,1500,1402,52,1500,52,237,52,1500,1019,52","11,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","4,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,7,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,1,1,1,0,1,1,0,1,0,1,0,1,1,0","4.598081589,5.235815525,5.131024837,6.023412704,5.154969215,7.255973339,7.303249359,5.092563152,7.001137733,5.056022167,6.255658627,5.007929802,6.001976490,5.169486523,5.942530632,5.054101467,7.891292572,7.683557510,5.169486523,7.859122753,7.883965492,5.131024837,7.876591682,7.866814137,5.092563152,7.900776386,4.979098797,7.052536488,5.054101467,7.870380402,7.793371201,5.131024361",,,,,,,,"" 1,ip4,192.168.1.7,52.89.39.139,tcp,53132,443,info,17,15,1484319035079531,1484319042786338,1484319042922798,0,0,1448,1448,4576,5220,0,147,501615.3,7507819,1826252.6,3335198867456.0,1.4,"49499,50871,4368,54319,2439,996,53513,42973,42827,12725,273,205,57417,5098,49336,4198,388,49955,75766,32147,2030,911,5107,4712,147,7402221,150,7507819,929,35745,990",52,358.8,1500,520.7,271128.8,3.8,"64,60,52,260,52,1500,1500,52,245,52,127,58,97,52,103,52,1500,661,52,52,184,96,86,52,52,52,1500,789,52,52,1500,474","10,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","6,3,0,0,1,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,1,0,1,1,1,0,0,0,0,0,1,1,1,1","4.566831589,5.335815907,5.094483852,6.025682926,5.169486523,7.256491661,7.325493813,5.092563152,7.129077435,5.092563152,6.393805504,5.100806713,6.014647961,5.169486523,5.965332508,5.169486523,7.872792244,7.651345730,5.207947731,5.207948208,6.796521664,6.094137192,5.926040173,5.169486523,5.207948208,5.169486046,7.868273258,7.747731686,5.169486046,5.169486523,7.861037254,7.536938190",,,,,,,,"" -1,ip4,192.168.1.7,184.25.204.25,tcp,53149,80,finished,7,25,1484319043013015,1484319044532732,1484319044504314,0,0,245,1448,245,33304,0,6882,97129.5,1300093,229777.6,52797755392.0,3.4,"22705,29125,36813,70338,13255,32378,25989,101810,6882,28009,25233,44994,56409,27146,27165,53793,54320,26078,52109,80662,53766,398536,54325,39942,109640,40469,26128,51507,108074,13323,1300093",52,1101.9,1500,637.7,406609.6,4.6,"64,60,52,297,52,1500,1500,1500,52,52,1500,1500,52,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,80","6,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,23,0,0","0,1,0,0,1,1,1,1,0,0,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0","4.538909912,5.312702179,5.079966545,5.942044735,5.308815479,7.330718994,7.743900776,7.712044239,5.233813286,5.000318527,7.842275620,7.821234226,5.156889915,7.816409111,7.847937107,7.841120243,7.664994240,7.793088913,7.822535038,7.766201496,7.754564285,7.803048134,7.810695171,7.784301758,7.848053455,7.850491524,7.814136028,7.845249176,7.833446503,7.828612804,7.832110882,5.393421650",HTTP.NetFlix,7.133,0,Fun,Video,6,DPI,"" 1,ip4,192.168.1.7,54.201.191.132,tcp,53151,80,finished,12,20,1484319048780859,1484319049236027,1484319049229808,0,0,1448,1448,2612,21687,0,193,29165.1,187154,42322.7,1791214592.0,4.0,"44122,45598,3902,10660,193,60003,5736,990,135055,302,187154,5655,5706,13881,14022,13277,14383,27821,13324,13128,9212,13280,22521,13399,39251,13309,13303,13855,13324,13288,124463",52,812.3,1500,674.9,455511.9,4.4,"64,60,52,365,1500,903,52,52,52,714,1500,52,1500,52,1500,52,1500,1500,52,1012,52,1500,1293,52,1500,1500,1500,1500,1500,1500,1500,64","9,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,13,0,0","0,1,0,0,0,0,1,1,1,1,1,0,1,0,1,0,1,1,0,1,0,1,1,0,1,1,1,1,1,1,1,0","4.538909912,5.279368401,5.156889915,5.705281258,5.964499474,6.056532860,5.272274971,5.272274494,5.310736179,6.005652428,5.696421623,5.094483852,6.091891766,5.233812809,5.866946220,5.038780212,5.796521664,5.782927513,5.195351601,5.831374168,5.233812809,5.802160263,5.817751884,5.195351124,5.813166142,5.771504402,5.781269550,5.780963898,5.817500591,5.785477638,5.779314995,5.163660049",HTTP.NetFlix,7.133,0,Fun,Video,6,DPI,"" 1,ip4,192.168.1.7,184.25.204.25,tcp,53148,80,finished,14,18,1484319043012652,1484319049640319,1484319049653906,0,0,246,1448,491,23168,0,590,428029.7,6030936,1231580.9,1516791529472.0,2.3,"22448,28943,26758,57708,590,13165,40076,31828,42757,26526,25526,50240,53221,30909,25521,54871,53768,27167,52693,79537,53772,544724,1519985,11557,27351,27280,28765,635381,3643850,6030936,1068",52,795.6,1500,706.6,499284.2,4.3,"64,60,52,298,52,1500,1500,52,1500,52,1500,1500,52,1500,1500,1500,1500,1500,1500,1500,1500,1500,80,80,80,72,64,52,52,297,1500,1500","12,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0","0,1,0,0,1,1,1,0,1,0,1,1,0,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0,1,1","4.570159912,5.187539101,5.118428230,5.866323471,5.308815956,7.539054394,7.823310852,5.094483852,7.811959267,5.038779736,7.799767494,7.796337128,5.156889439,7.762200832,7.778352737,7.834424973,7.823929787,7.799146652,7.830269337,7.869925976,7.880800724,7.877037048,5.357215405,5.224027157,5.307214737,5.376956940,5.259624004,5.233813286,5.195351601,5.825244904,7.190491676,7.824782848",HTTP.NetFlix,7.133,0,Fun,Video,6,DPI,"" -1,ip4,192.168.1.7,23.246.11.145,tcp,53163,80,finished,11,21,1484319050652467,1484319051912595,1484319051940613,0,0,356,1448,356,28027,0,3794,82202.4,651024,153564.6,23582076928.0,3.6,"24769,26290,3794,42485,4828,43771,27157,40474,69366,43854,44827,78254,38808,79815,102619,28781,14718,354324,85041,14066,12423,12747,651024,22850,582496,8619,27490,16417,16392,14698,15077",52,940.8,1500,683.5,467159.1,4.5,"64,60,52,408,567,1500,52,1500,1500,52,1500,52,1500,1500,1500,1500,1500,1500,80,1500,1500,1500,1500,64,52,1500,1500,52,1500,52,1500,1500","10,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0","0,1,0,0,1,1,0,1,1,0,1,0,1,1,1,1,1,1,0,1,1,1,1,0,0,1,1,0,1,0,1,1","4.550704956,5.312702179,5.103910923,6.388577938,5.862974167,3.576230049,5.195351124,2.528419971,2.540967226,5.077241421,2.547356844,5.115703106,2.543488026,2.552008152,2.558917999,3.816826105,3.805565357,3.816280365,5.256690979,3.890866995,3.462315798,3.461706400,3.458227158,5.071470261,5.154164314,3.470844507,3.517976761,5.154164314,3.546975851,4.955154419,3.560742617,3.579237461",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.10.139,tcp,53164,80,finished,13,19,1484319052216458,1484319053577715,1484319053589492,0,0,356,1448,356,25132,0,1043,88202.9,638852,151898.7,23073200128.0,3.7,"18792,21375,5144,35741,1043,5439,35508,13242,13983,20324,20435,13235,116191,170244,28107,56564,51631,31663,27571,12760,327583,131379,638852,579987,19881,15021,30035,13582,42286,118688,118005",52,851.9,1500,697.4,486427.5,4.4,"64,60,52,408,568,1500,1500,52,1500,52,1500,52,1500,52,1500,1500,1500,1500,1500,1500,1500,80,1500,80,1500,72,1500,64,52,1500,52,1500","12,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0","0,1,0,0,1,1,1,0,1,0,1,0,1,0,1,1,1,1,1,1,1,0,1,0,1,0,1,0,0,1,0,1","4.451259136,5.200120449,5.003043175,6.363925457,5.826877117,3.573564768,2.540809155,5.079966545,2.553215742,4.950064659,2.546205282,4.961856842,2.557531357,4.985801220,2.554388523,2.558952808,3.302551985,3.777240515,3.820478201,3.802512646,3.817392588,5.302858829,3.877096891,5.277858257,3.521096945,5.267232895,3.547756672,5.124750137,4.947339535,3.545200109,4.894361019,3.575657606",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.3.140,tcp,53171,80,finished,10,22,1484319054101585,1484319054294236,1484319054480080,0,0,354,1448,354,29479,0,2187,18424.1,44333,10032.7,100655136.0,4.7,"30791,32492,5528,44333,2187,41107,2921,12763,15575,14938,14982,12802,12713,26425,12767,11943,13284,17180,31033,13321,13566,25571,14329,13905,26660,13805,13288,27210,13255,13305,27167",52,984.9,1500,672.7,452466.1,4.5,"64,60,52,406,571,1500,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","9,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,20,0,0","0,1,0,0,1,1,0,1,1,0,1,0,1,1,0,1,0,1,1,0,1,0,1,1,1,1,1,1,1,1,1,1","4.527114868,5.266787052,5.118428230,6.362258911,5.831311226,3.571949720,5.233812809,2.540643215,2.558721066,5.195351124,2.550262213,5.038779736,2.557194710,2.582848072,5.195351124,2.547422886,5.038780212,2.553757429,2.570932388,5.195351124,2.541049719,5.115703106,3.780845165,3.769821644,3.779848337,3.819229603,3.784283876,3.803048134,3.786687374,3.790169001,3.883657932,3.464622736",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53180,80,finished,21,11,1484319056241489,1484319059351882,1484319059371795,0,0,360,1448,360,13550,0,394,201312.9,2097549,403399.4,162731114496.0,3.6,"61813,72267,473,134860,394,125851,1162295,73601,899,212949,11519,409208,101075,1892,70852,2097549,79500,52131,129820,120649,42895,59919,67076,69354,174355,284029,29385,65003,252681,150502,125903",52,493.7,1500,638.1,407212.3,3.9,"64,60,52,412,570,1500,52,80,80,80,80,80,80,64,64,52,1500,52,1500,52,1500,1500,52,1500,52,1500,64,52,52,1500,52,1500","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,1,0,1,0,1,1,0,1,0,1,0,0,0,1,0,1","4.601409912,5.346035957,5.041505337,6.346901894,5.793770790,4.440931797,5.065449238,5.202858448,5.202857018,5.262294292,5.341651440,5.366651535,5.317899227,5.165874004,5.228374004,5.195351601,4.782721043,5.156889915,4.790072441,5.101186275,4.825405598,4.817777157,5.233812809,4.752513409,5.024262905,4.806689262,5.165874004,5.195351124,5.195351124,4.632717133,5.024262905,4.635102272",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53177,80,finished,20,12,1484319056233255,1484319060551613,1484319060618267,0,0,360,1448,360,13563,0,135,280753.9,1046959,300914.6,90549583872.0,4.2,"43730,45845,23628,124789,4917,111637,635898,176069,176,135,41643,37401,940199,857,45449,434520,483806,1046959,74656,202356,418896,472205,955340,169880,525271,694311,167240,252312,98045,326303,148897",52,490.1,1500,638.9,408170.9,3.9,"64,60,52,412,571,1500,52,72,72,64,64,64,52,88,1476,52,52,52,1500,1500,52,52,52,1500,52,52,1500,52,1500,1500,52,1500","19,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,8,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,1,1,0,0,0,1,1,0,0,0,1,0,0,1,0,1,1,0,1","4.527114868,5.312702179,5.003043652,6.355251789,5.803568363,4.440690517,5.118427753,5.277718067,5.249940395,5.146419048,5.208919048,5.134624004,5.056021690,4.908463001,4.253908634,5.156889915,5.156889439,5.118427753,4.918218613,4.902011871,5.000318050,5.118427753,5.118427753,4.876659870,4.985801220,5.017560482,4.758782864,4.961856365,4.610503674,4.658255100,5.118427753,4.789437294",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53175,80,finished,20,12,1484319056221799,1484319060594060,1484319060664663,0,0,357,1448,357,14998,0,569,284358.9,1636184,362564.9,131453321216.0,4.0,"16087,19422,23622,88585,4002,82236,1105315,26930,21843,19608,569,13093,381586,1636184,66410,119030,421421,408128,882662,90167,143374,490378,519431,92259,120978,487097,597701,217631,227512,270000,221864",52,536.6,1500,657.9,432827.8,3.9,"64,60,52,409,570,1500,52,72,72,72,64,64,64,64,1500,1500,52,64,52,1500,1500,52,52,1500,1500,52,52,1500,52,1500,64,1500","19,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,1,1,0,0,0,1,1,0,0,1,1,0,0,1,0,1,0,1","4.538909912,5.333454132,5.142372608,6.390935421,5.823237419,4.453172207,5.118427753,5.333272934,5.385473251,5.387441158,5.216578960,5.208919048,5.216578960,5.228374004,3.805912256,4.418298721,5.156889915,5.072124004,5.233813286,4.401393414,4.419836998,5.233812809,5.195351124,4.383244514,4.387027740,5.233812809,5.209868431,4.311857224,5.000318527,4.386717796,5.240169048,4.585660934",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.133,tcp,53173,80,finished,16,16,1484319056210218,1484319060695068,1484319060746254,0,0,357,1448,357,20790,0,4949,290996.3,1397235,314333.5,98805530624.0,4.2,"23914,25117,18248,72539,4949,71292,152183,249467,985618,26703,1397235,519076,299466,499851,482346,40528,55620,206768,137068,537495,535230,174291,571825,775969,198842,230534,89909,283953,128056,116304,110490",52,716.2,1500,699.0,488561.8,4.2,"64,60,52,409,570,1500,52,1500,52,80,80,1500,72,1500,64,1500,1500,1500,52,1500,52,1500,52,52,1500,52,1500,1500,52,1500,52,1500","15,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0","0,1,0,0,1,1,0,1,0,0,0,1,0,1,0,1,1,1,0,1,0,1,0,0,1,0,1,1,0,1,0,1","4.601409912,5.266787052,5.036415577,6.391139984,5.809580326,4.456539154,5.041504860,4.186237812,4.961856842,5.322779179,5.322779179,4.373055458,5.331886292,4.362320423,5.228374004,4.324150085,4.463343143,4.271175385,5.118428230,4.316685200,5.142372608,4.338371277,5.077241421,5.195351124,4.538278103,5.038779736,4.711270332,4.737337112,5.079966545,4.685406208,5.233812809,4.710971355",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53182,80,finished,21,11,1484319056264541,1484319060916913,1484319060915445,0,0,358,1448,358,13550,0,342,300105.7,2716440,539188.2,290723889152.0,3.6,"61747,63082,19443,172653,342,153906,1162512,94154,1429,12319,104280,65945,674747,41474,39967,488929,2716440,44869,75746,28743,32797,29468,133613,256105,742961,71312,1131465,569658,135441,73631,104098",52,492.6,1500,638.8,408052.9,3.9,"64,60,52,410,570,1500,52,80,72,72,72,72,72,72,64,52,52,1500,1500,52,1500,52,1500,52,1500,64,52,1500,52,1500,1500,52","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,1,0,1,0,1,0,1,0,0,1,0,1,1,0","4.601409912,5.379369259,5.103910923,6.382707119,5.801897049,4.439589024,5.156889439,5.282214642,5.359663963,5.304108143,5.359663963,5.304108143,5.263877869,5.293623924,5.290874004,5.156889915,5.038779736,4.572134495,4.543495178,5.115703106,4.553971767,4.993616104,4.540792465,4.955154419,4.553669930,5.177669048,5.079966545,4.316857815,4.961856842,4.387219906,4.488969326,5.079966545",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53174,80,finished,22,10,1484319056214323,1484319060947278,1484319060861747,0,0,358,1448,358,12102,0,137,302592.9,3094333,556136.4,309287714816.0,3.7,"19993,22151,5332,69145,137,72224,626011,606979,26604,520264,51479,55493,593239,41657,80288,418048,3094333,65564,425655,469983,40810,84995,52141,54303,117697,383081,387305,709380,53664,73805,158619",52,447.8,1500,616.5,380048.7,3.8,"64,60,52,410,570,1500,52,72,72,72,72,64,64,72,64,52,52,1500,64,64,1500,1500,52,1500,52,1500,52,64,1500,64,1500,52","21,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,1,0,1,0,1,0,0,1,0,1,0","4.538909912,5.312702179,5.065449715,6.359480381,5.816523552,4.445319176,5.065449238,5.277717590,5.387441635,5.387441635,5.248553276,5.259624004,5.228374004,5.331886292,5.259624004,5.272274494,5.115703106,4.653451920,5.163660049,5.185328960,4.692939758,4.660350800,5.065449715,4.689436913,5.077241898,4.606202602,5.156889439,5.290874004,4.357360840,5.290874004,4.495481014,5.233812809",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53181,80,finished,22,10,1484319056264215,1484319061168059,1484319060482194,0,0,359,1448,359,12101,0,266,294252.3,2608516,529173.0,280024055808.0,3.5,"61899,63035,8952,155118,266,150147,1152400,92133,498,591361,113696,141666,52293,522,39853,381137,2608516,28241,68204,27169,29555,26620,56459,81742,44814,43749,497350,496550,1208877,807442,91559",52,449.2,1500,615.6,378913.2,3.8,"64,60,52,411,569,1500,52,80,80,80,80,72,64,64,64,52,64,1500,1500,52,1500,52,1500,1500,52,1500,52,64,52,1500,72,72","21,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,1,0,1,0,1,1,0,1,0,0,0,1,0,0","4.570159912,5.346035480,5.065449715,6.363940239,5.804843426,4.442625046,5.142372608,5.362294197,5.337294102,5.312294006,5.287294388,5.333272934,5.197124004,5.240169048,5.240169048,5.156889439,5.152518272,4.990313053,4.973003864,5.195351124,4.964061737,5.000318050,4.996945381,4.996238232,5.156889439,4.959667683,5.038779736,5.146419048,5.003043175,4.680668831,5.247971535,5.333272934",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.133,tcp,53172,80,finished,21,11,1484319056204111,1484319061128980,1484319061270358,0,0,358,1448,358,13550,0,79,322294.1,3064500,576519.8,332375130112.0,3.6,"11668,15660,2402,60224,1206,79,57126,107813,316921,313910,536684,811161,71198,122498,693690,84709,585634,3064500,52838,57895,98411,231468,526235,115101,671,585669,117652,1178873,25807,79129,64284",52,495.0,1500,637.2,406023.8,3.9,"64,60,52,410,570,1500,1500,52,52,1500,52,80,80,80,80,72,64,72,1500,72,1500,64,1500,80,64,52,64,52,1500,52,1500,1500","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,1,0,0,1,0,0,0,0,0,0,0,0,1,0,1,0,1,0,0,0,0,0,1,0,1,1","4.507659912,5.233454227,4.964581966,6.333802700,5.821110249,4.461877346,4.201263905,5.132945538,5.014835358,3.777186632,4.976373672,5.144669533,5.135233879,5.169670582,5.169669628,5.192996979,5.140319824,5.248552799,4.282153130,5.248552322,4.242815018,4.995864868,4.290421486,5.085232735,5.140319824,5.132945538,5.140319824,5.056022167,4.478749752,5.053297043,4.467899799,4.518882275",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53178,80,finished,21,11,1484319056233602,1484319061706774,1484319061794702,0,0,357,1448,357,13550,0,240,355944.2,3546297,682699.4,466078498816.0,3.5,"43247,45294,13187,106701,4927,97880,1317695,102059,98186,240,515839,59813,1148424,57207,54890,165165,3546297,68400,92258,155981,131046,69975,95851,103962,104462,205130,729427,91959,551213,1189389,68168",52,493.2,1500,638.4,407523.4,3.9,"64,60,52,409,570,1500,52,80,80,72,72,72,72,72,64,64,52,1500,52,1500,52,1500,1500,52,1500,52,1500,64,52,52,1500,1500","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,1,1,0,1,0,1,0,0,0,1,1","4.515677452,5.333454132,5.041505337,6.377946854,5.816387177,4.450622082,5.118428230,5.366649628,5.366649628,5.359663963,5.333272934,5.387441635,5.387441635,5.293623924,5.290874004,5.322124004,5.272274494,4.440482140,5.209868431,4.489046574,5.014835358,4.480661392,4.471484184,5.233812809,4.471359730,5.062724590,4.458212852,5.290874004,5.233812809,5.000318527,4.395615101,4.444458961",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53179,80,finished,20,12,1484319056234960,1484319062638948,1484319062680623,0,0,358,1448,358,14998,0,72,414504.9,4457097,811357.3,658300731392.0,3.6,"41445,43452,2932,82082,72,78739,1252127,77707,132171,828,525346,100674,510044,513013,40289,4457097,87034,1392951,522404,574888,39602,91204,57625,58127,138968,449063,380142,69915,139503,473414,516793",52,538.1,1500,656.8,431419.8,3.9,"64,60,52,410,570,1500,52,80,80,72,72,72,72,72,64,64,1500,1500,52,52,1500,1500,52,1500,52,1500,52,1500,1500,52,52,1500","19,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,1,1,0,0,1,1,0,1,0,1,0,1,1,0,0,1","4.538909912,5.312702179,5.026988029,6.353898048,5.812767506,4.447575092,5.118428230,5.316649437,5.391650200,5.387441635,5.387441635,5.361050606,5.333272934,5.331886292,5.228374004,5.228374004,4.410194397,4.460495949,5.079966545,5.195351124,4.415517807,4.454523087,5.195351601,4.441005707,5.077241421,4.548726559,5.156889915,4.299219608,4.319707394,5.195351601,5.156889439,4.440834999",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.11.141,tcp,53176,80,finished,23,9,1484319056232857,1484319062946776,1484319063015567,0,0,358,1448,358,10653,0,682,435375.1,4431980,814478.7,663375511552.0,3.6,"43856,45826,13429,88623,4898,81946,1250769,92472,118428,682,544165,69196,495457,501654,62886,1143862,28583,39116,4431980,82976,87813,169881,586445,795488,292945,509017,501170,1203523,55860,83014,70669",52,404.2,1500,589.2,347103.4,3.7,"64,60,52,410,569,1500,52,80,80,72,72,72,72,72,64,64,64,64,64,1500,52,1500,64,52,1500,64,52,52,1500,1500,52,1500","22,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,1,0,0,0,1,1,0,1","4.570159912,5.166786671,4.974009037,6.366189480,5.841994762,4.452114582,5.079966545,5.252857208,5.332214355,5.359663963,5.387441635,5.293623924,5.359663486,5.276330948,5.290874004,5.144205093,5.290874004,5.259624004,5.154078960,4.322241306,5.038779736,4.343337059,5.163660049,5.156889439,4.373079300,5.208919048,5.180834293,5.195351124,4.324346066,4.345085144,5.195351124,4.404635906",HTTP,7,0,Acceptable,Web,6,DPI,"12" +1,ip4,192.168.1.7,23.246.11.145,tcp,53163,80,finished,11,21,1484319050652467,1484319051912595,1484319051940613,0,0,356,1448,356,28027,0,3794,82202.4,651024,153564.6,23582076928.0,3.6,"24769,26290,3794,42485,4828,43771,27157,40474,69366,43854,44827,78254,38808,79815,102619,28781,14718,354324,85041,14066,12423,12747,651024,22850,582496,8619,27490,16417,16392,14698,15077",52,940.8,1500,683.5,467159.1,4.5,"64,60,52,408,567,1500,52,1500,1500,52,1500,52,1500,1500,1500,1500,1500,1500,80,1500,1500,1500,1500,64,52,1500,1500,52,1500,52,1500,1500","10,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19,0,0","0,1,0,0,1,1,0,1,1,0,1,0,1,1,1,1,1,1,0,1,1,1,1,0,0,1,1,0,1,0,1,1","4.550704956,5.312702179,5.103910923,6.388577938,5.862974167,3.576230049,5.195351124,2.528419971,2.540967226,5.077241421,2.547356844,5.115703106,2.543488026,2.552008152,2.558917999,3.816826105,3.805565357,3.816280365,5.256690979,3.890866995,3.462315798,3.461706400,3.458227158,5.071470261,5.154164314,3.470844507,3.517976761,5.154164314,3.546975851,4.955154419,3.560742617,3.579237461",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.3.140,tcp,53171,80,finished,10,22,1484319054101585,1484319054294236,1484319054480080,0,0,354,1448,354,29479,0,2187,18424.1,44333,10032.7,100655136.0,4.7,"30791,32492,5528,44333,2187,41107,2921,12763,15575,14938,14982,12802,12713,26425,12767,11943,13284,17180,31033,13321,13566,25571,14329,13905,26660,13805,13288,27210,13255,13305,27167",52,984.9,1500,672.7,452466.1,4.5,"64,60,52,406,571,1500,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","9,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,20,0,0","0,1,0,0,1,1,0,1,1,0,1,0,1,1,0,1,0,1,1,0,1,0,1,1,1,1,1,1,1,1,1,1","4.527114868,5.266787052,5.118428230,6.362258911,5.831311226,3.571949720,5.233812809,2.540643215,2.558721066,5.195351124,2.550262213,5.038779736,2.557194710,2.582848072,5.195351124,2.547422886,5.038780212,2.553757429,2.570932388,5.195351124,2.541049719,5.115703106,3.780845165,3.769821644,3.779848337,3.819229603,3.784283876,3.803048134,3.786687374,3.790169001,3.883657932,3.464622736",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53180,80,finished,21,11,1484319056241489,1484319059351882,1484319059371795,0,0,360,1448,360,13550,0,394,201312.9,2097549,403399.4,162731114496.0,3.6,"61813,72267,473,134860,394,125851,1162295,73601,899,212949,11519,409208,101075,1892,70852,2097549,79500,52131,129820,120649,42895,59919,67076,69354,174355,284029,29385,65003,252681,150502,125903",52,493.7,1500,638.1,407212.3,3.9,"64,60,52,412,570,1500,52,80,80,80,80,80,80,64,64,52,1500,52,1500,52,1500,1500,52,1500,52,1500,64,52,52,1500,52,1500","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,1,0,1,0,1,1,0,1,0,1,0,0,0,1,0,1","4.601409912,5.346035957,5.041505337,6.346901894,5.793770790,4.440931797,5.065449238,5.202858448,5.202857018,5.262294292,5.341651440,5.366651535,5.317899227,5.165874004,5.228374004,5.195351601,4.782721043,5.156889915,4.790072441,5.101186275,4.825405598,4.817777157,5.233812809,4.752513409,5.024262905,4.806689262,5.165874004,5.195351124,5.195351124,4.632717133,5.024262905,4.635102272",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53177,80,finished,20,12,1484319056233255,1484319060551613,1484319060618267,0,0,360,1448,360,13563,0,135,280753.9,1046959,300914.6,90549583872.0,4.2,"43730,45845,23628,124789,4917,111637,635898,176069,176,135,41643,37401,940199,857,45449,434520,483806,1046959,74656,202356,418896,472205,955340,169880,525271,694311,167240,252312,98045,326303,148897",52,490.1,1500,638.9,408170.9,3.9,"64,60,52,412,571,1500,52,72,72,64,64,64,52,88,1476,52,52,52,1500,1500,52,52,52,1500,52,52,1500,52,1500,1500,52,1500","19,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,8,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,1,1,0,0,0,1,1,0,0,0,1,0,0,1,0,1,1,0,1","4.527114868,5.312702179,5.003043652,6.355251789,5.803568363,4.440690517,5.118427753,5.277718067,5.249940395,5.146419048,5.208919048,5.134624004,5.056021690,4.908463001,4.253908634,5.156889915,5.156889439,5.118427753,4.918218613,4.902011871,5.000318050,5.118427753,5.118427753,4.876659870,4.985801220,5.017560482,4.758782864,4.961856365,4.610503674,4.658255100,5.118427753,4.789437294",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53175,80,finished,20,12,1484319056221799,1484319060594060,1484319060664663,0,0,357,1448,357,14998,0,569,284358.9,1636184,362564.9,131453321216.0,4.0,"16087,19422,23622,88585,4002,82236,1105315,26930,21843,19608,569,13093,381586,1636184,66410,119030,421421,408128,882662,90167,143374,490378,519431,92259,120978,487097,597701,217631,227512,270000,221864",52,536.6,1500,657.9,432827.8,3.9,"64,60,52,409,570,1500,52,72,72,72,64,64,64,64,1500,1500,52,64,52,1500,1500,52,52,1500,1500,52,52,1500,52,1500,64,1500","19,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,1,1,0,0,0,1,1,0,0,1,1,0,0,1,0,1,0,1","4.538909912,5.333454132,5.142372608,6.390935421,5.823237419,4.453172207,5.118427753,5.333272934,5.385473251,5.387441158,5.216578960,5.208919048,5.216578960,5.228374004,3.805912256,4.418298721,5.156889915,5.072124004,5.233813286,4.401393414,4.419836998,5.233812809,5.195351124,4.383244514,4.387027740,5.233812809,5.209868431,4.311857224,5.000318527,4.386717796,5.240169048,4.585660934",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.133,tcp,53173,80,finished,16,16,1484319056210218,1484319060695068,1484319060746254,0,0,357,1448,357,20790,0,4949,290996.3,1397235,314333.5,98805530624.0,4.2,"23914,25117,18248,72539,4949,71292,152183,249467,985618,26703,1397235,519076,299466,499851,482346,40528,55620,206768,137068,537495,535230,174291,571825,775969,198842,230534,89909,283953,128056,116304,110490",52,716.2,1500,699.0,488561.8,4.2,"64,60,52,409,570,1500,52,1500,52,80,80,1500,72,1500,64,1500,1500,1500,52,1500,52,1500,52,52,1500,52,1500,1500,52,1500,52,1500","15,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,14,0,0","0,1,0,0,1,1,0,1,0,0,0,1,0,1,0,1,1,1,0,1,0,1,0,0,1,0,1,1,0,1,0,1","4.601409912,5.266787052,5.036415577,6.391139984,5.809580326,4.456539154,5.041504860,4.186237812,4.961856842,5.322779179,5.322779179,4.373055458,5.331886292,4.362320423,5.228374004,4.324150085,4.463343143,4.271175385,5.118428230,4.316685200,5.142372608,4.338371277,5.077241421,5.195351124,4.538278103,5.038779736,4.711270332,4.737337112,5.079966545,4.685406208,5.233812809,4.710971355",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53182,80,finished,21,11,1484319056264541,1484319060916913,1484319060915445,0,0,358,1448,358,13550,0,342,300105.7,2716440,539188.2,290723889152.0,3.6,"61747,63082,19443,172653,342,153906,1162512,94154,1429,12319,104280,65945,674747,41474,39967,488929,2716440,44869,75746,28743,32797,29468,133613,256105,742961,71312,1131465,569658,135441,73631,104098",52,492.6,1500,638.8,408052.9,3.9,"64,60,52,410,570,1500,52,80,72,72,72,72,72,72,64,52,52,1500,1500,52,1500,52,1500,52,1500,64,52,1500,52,1500,1500,52","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,1,0,1,0,1,0,1,0,0,1,0,1,1,0","4.601409912,5.379369259,5.103910923,6.382707119,5.801897049,4.439589024,5.156889439,5.282214642,5.359663963,5.304108143,5.359663963,5.304108143,5.263877869,5.293623924,5.290874004,5.156889915,5.038779736,4.572134495,4.543495178,5.115703106,4.553971767,4.993616104,4.540792465,4.955154419,4.553669930,5.177669048,5.079966545,4.316857815,4.961856842,4.387219906,4.488969326,5.079966545",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53174,80,finished,22,10,1484319056214323,1484319060947278,1484319060861747,0,0,358,1448,358,12102,0,137,302592.9,3094333,556136.4,309287714816.0,3.7,"19993,22151,5332,69145,137,72224,626011,606979,26604,520264,51479,55493,593239,41657,80288,418048,3094333,65564,425655,469983,40810,84995,52141,54303,117697,383081,387305,709380,53664,73805,158619",52,447.8,1500,616.5,380048.7,3.8,"64,60,52,410,570,1500,52,72,72,72,72,64,64,72,64,52,52,1500,64,64,1500,1500,52,1500,52,1500,52,64,1500,64,1500,52","21,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,1,0,1,0,1,0,0,1,0,1,0","4.538909912,5.312702179,5.065449715,6.359480381,5.816523552,4.445319176,5.065449238,5.277717590,5.387441635,5.387441635,5.248553276,5.259624004,5.228374004,5.331886292,5.259624004,5.272274494,5.115703106,4.653451920,5.163660049,5.185328960,4.692939758,4.660350800,5.065449715,4.689436913,5.077241898,4.606202602,5.156889439,5.290874004,4.357360840,5.290874004,4.495481014,5.233812809",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53181,80,finished,22,10,1484319056264215,1484319061168059,1484319060482194,0,0,359,1448,359,12101,0,266,294252.3,2608516,529173.0,280024055808.0,3.5,"61899,63035,8952,155118,266,150147,1152400,92133,498,591361,113696,141666,52293,522,39853,381137,2608516,28241,68204,27169,29555,26620,56459,81742,44814,43749,497350,496550,1208877,807442,91559",52,449.2,1500,615.6,378913.2,3.8,"64,60,52,411,569,1500,52,80,80,80,80,72,64,64,64,52,64,1500,1500,52,1500,52,1500,1500,52,1500,52,64,52,1500,72,72","21,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,1,0,1,0,1,1,0,1,0,0,0,1,0,0","4.570159912,5.346035480,5.065449715,6.363940239,5.804843426,4.442625046,5.142372608,5.362294197,5.337294102,5.312294006,5.287294388,5.333272934,5.197124004,5.240169048,5.240169048,5.156889439,5.152518272,4.990313053,4.973003864,5.195351124,4.964061737,5.000318050,4.996945381,4.996238232,5.156889439,4.959667683,5.038779736,5.146419048,5.003043175,4.680668831,5.247971535,5.333272934",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.133,tcp,53172,80,finished,21,11,1484319056204111,1484319061128980,1484319061270358,0,0,358,1448,358,13550,0,79,322294.1,3064500,576519.8,332375130112.0,3.6,"11668,15660,2402,60224,1206,79,57126,107813,316921,313910,536684,811161,71198,122498,693690,84709,585634,3064500,52838,57895,98411,231468,526235,115101,671,585669,117652,1178873,25807,79129,64284",52,495.0,1500,637.2,406023.8,3.9,"64,60,52,410,570,1500,1500,52,52,1500,52,80,80,80,80,72,64,72,1500,72,1500,64,1500,80,64,52,64,52,1500,52,1500,1500","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,1,0,0,1,0,0,0,0,0,0,0,0,1,0,1,0,1,0,0,0,0,0,1,0,1,1","4.507659912,5.233454227,4.964581966,6.333802700,5.821110249,4.461877346,4.201263905,5.132945538,5.014835358,3.777186632,4.976373672,5.144669533,5.135233879,5.169670582,5.169669628,5.192996979,5.140319824,5.248552799,4.282153130,5.248552322,4.242815018,4.995864868,4.290421486,5.085232735,5.140319824,5.132945538,5.140319824,5.056022167,4.478749752,5.053297043,4.467899799,4.518882275",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53178,80,finished,21,11,1484319056233602,1484319061706774,1484319061794702,0,0,357,1448,357,13550,0,240,355944.2,3546297,682699.4,466078498816.0,3.5,"43247,45294,13187,106701,4927,97880,1317695,102059,98186,240,515839,59813,1148424,57207,54890,165165,3546297,68400,92258,155981,131046,69975,95851,103962,104462,205130,729427,91959,551213,1189389,68168",52,493.2,1500,638.4,407523.4,3.9,"64,60,52,409,570,1500,52,80,80,72,72,72,72,72,64,64,52,1500,52,1500,52,1500,1500,52,1500,52,1500,64,52,52,1500,1500","20,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,1,1,0,1,0,1,0,0,0,1,1","4.515677452,5.333454132,5.041505337,6.377946854,5.816387177,4.450622082,5.118428230,5.366649628,5.366649628,5.359663963,5.333272934,5.387441635,5.387441635,5.293623924,5.290874004,5.322124004,5.272274494,4.440482140,5.209868431,4.489046574,5.014835358,4.480661392,4.471484184,5.233812809,4.471359730,5.062724590,4.458212852,5.290874004,5.233812809,5.000318527,4.395615101,4.444458961",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53179,80,finished,20,12,1484319056234960,1484319062638948,1484319062680623,0,0,358,1448,358,14998,0,72,414504.9,4457097,811357.3,658300731392.0,3.6,"41445,43452,2932,82082,72,78739,1252127,77707,132171,828,525346,100674,510044,513013,40289,4457097,87034,1392951,522404,574888,39602,91204,57625,58127,138968,449063,380142,69915,139503,473414,516793",52,538.1,1500,656.8,431419.8,3.9,"64,60,52,410,570,1500,52,80,80,72,72,72,72,72,64,64,1500,1500,52,52,1500,1500,52,1500,52,1500,52,1500,1500,52,52,1500","19,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,1,1,0,0,1,1,0,1,0,1,0,1,1,0,0,1","4.538909912,5.312702179,5.026988029,6.353898048,5.812767506,4.447575092,5.118428230,5.316649437,5.391650200,5.387441635,5.387441635,5.361050606,5.333272934,5.331886292,5.228374004,5.228374004,4.410194397,4.460495949,5.079966545,5.195351124,4.415517807,4.454523087,5.195351601,4.441005707,5.077241421,4.548726559,5.156889915,4.299219608,4.319707394,5.195351601,5.156889439,4.440834999",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" +1,ip4,192.168.1.7,23.246.11.141,tcp,53176,80,finished,23,9,1484319056232857,1484319062946776,1484319063015567,0,0,358,1448,358,10653,0,682,435375.1,4431980,814478.7,663375511552.0,3.6,"43856,45826,13429,88623,4898,81946,1250769,92472,118428,682,544165,69196,495457,501654,62886,1143862,28583,39116,4431980,82976,87813,169881,586445,795488,292945,509017,501170,1203523,55860,83014,70669",52,404.2,1500,589.2,347103.4,3.7,"64,60,52,410,569,1500,52,80,80,72,72,72,72,72,64,64,64,64,64,1500,52,1500,64,52,1500,64,52,52,1500,1500,52,1500","22,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0","0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,1,0,0,0,1,1,0,1","4.570159912,5.166786671,4.974009037,6.366189480,5.841994762,4.452114582,5.079966545,5.252857208,5.332214355,5.359663963,5.387441635,5.293623924,5.359663486,5.276330948,5.290874004,5.144205093,5.290874004,5.259624004,5.154078960,4.322241306,5.038779736,4.343337059,5.163660049,5.156889439,4.373079300,5.208919048,5.180834293,5.195351124,4.324346066,4.345085144,5.195351124,4.404635906",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" 1,ip4,192.168.1.7,54.69.204.241,tcp,53118,443,info,17,15,1484319033631945,1484319063959877,1484319064010312,0,0,1448,1448,6334,4142,0,136,1958267.8,30086001,7379834.5,54461959503872.0,1.1,"47011,48359,1676,53080,2562,989,62283,11050,5991,10798,261,350,60341,3416,50128,4429,893,563,55944,50485,306,42722,3984,5077,5232,136,57719,311,30033380,30086001,822",52,380.0,1500,556.9,310128.2,3.8,"64,60,52,281,52,1500,1500,52,215,52,127,58,97,52,103,52,1402,1500,1500,52,1500,337,52,52,52,993,112,52,52,52,83,52","9,1,1,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,3,0,0","9,2,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,0,1,0,0,1,1,1,1,1,0,0,0,1,1","4.484876633,5.289900780,5.078045845,5.808425426,5.131024837,7.255376339,7.317865372,5.092562675,6.901146412,5.131024361,6.124006748,5.004364967,6.039024830,5.169486046,6.007705688,5.169486046,7.873569965,7.881214619,7.864243507,5.169486046,7.845795155,7.405421257,5.116507530,5.078045845,5.131024361,7.806305885,6.290623188,5.169486046,5.092563152,5.094483852,5.825018406,5.132945538",,,,,,,,"" 1,ip4,192.168.1.7,54.69.204.241,tcp,53119,443,info,18,14,1484319033943762,1484319064712006,1484319034278653,0,0,1448,1448,6319,4140,0,74,1003326.9,30431499,5372888.5,28867930619904.0,0.2,"44924,46321,7446,58250,1844,979,55802,12140,9904,9342,287,206,60460,132,50780,11459,460,157,72134,60865,339,50757,444,15673,16944,136,74,82928,303,146,30431499",52,379.5,1500,557.0,310204.4,3.8,"64,60,52,281,52,1500,1500,52,215,52,127,58,97,52,103,52,1402,1500,1500,52,1500,322,52,52,52,993,107,86,52,52,52,52","10,1,1,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,3,0,0","7,3,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,0,1,0,0,1,1,1,1,1,1,0,0,0,0","4.598081589,5.256567001,5.131024837,5.819132805,5.246409416,7.227420330,7.332920074,5.092563152,6.984497547,5.169486046,6.274277210,5.113821983,5.948767662,5.284871101,6.050486565,5.246409416,7.870395660,7.873335838,7.867392540,5.246409416,7.876014709,7.339691162,5.169486046,5.284871101,5.284871101,7.775086403,6.215628147,5.873826027,5.246409416,5.169486046,5.154969215,5.003043175",,,,,,,,"" -1,ip4,192.168.1.7,54.191.17.51,tcp,53193,443,info,23,9,1484319064669455,1484319065388464,1484319065423935,0,0,1448,1448,23355,2633,0,105,47531.9,266118,57373.9,3291763968.0,4.0,"53359,54641,4455,73724,451,53617,123531,11602,72543,62717,1529,55777,52363,2209,208,426,218,96299,96364,227,131,105,82592,81689,880,205,155,38176,40581,146597,266118",52,865.4,1500,680.5,463015.4,4.4,"64,60,52,569,52,1500,1132,52,178,103,52,1044,106,52,1500,1500,1500,1500,52,1500,1500,1500,1500,52,1500,1500,1500,1500,1500,1500,1500,72","5,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,15,0,0","5,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,1,0,0,1,0,0,1,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,1","4.578626633,5.335815907,5.207947731,4.350263596,5.169486523,7.184256554,7.647752762,5.207947731,6.566578865,6.006330490,5.169486046,7.810021400,6.234852314,5.215455055,7.860099316,7.858446598,7.850243568,7.875246525,5.284871101,7.867991447,7.875946045,7.875228882,7.851313114,5.246409416,7.892469883,7.867894650,7.855500698,7.875078678,7.889169693,7.874140739,7.858912468,5.388828278",,,,,,,,"" 1,ip4,192.168.1.7,54.191.17.51,tcp,53202,443,info,19,13,1484319064671268,1484319065492035,1484319065478679,0,0,1448,1448,9240,6755,0,182,52521.9,282465,58168.2,3383536896.0,4.2,"50844,52144,6261,61059,40719,74658,170395,11813,79420,67625,2032,57431,55801,1745,844,219,182,82546,79700,249,94600,127478,60574,282465,10583,27617,37968,39882,42871,7730,723",52,552.5,1500,629.7,396553.7,4.0,"64,60,52,569,52,1500,1132,52,178,103,52,1043,106,52,1500,1500,1500,1500,52,1500,387,52,52,1243,52,1500,1486,52,101,52,83,52","10,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0","5,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,1,2,0,0","0,1,0,0,1,1,1,0,0,1,0,0,1,0,0,0,0,0,1,0,0,1,1,1,0,1,1,0,1,0,0,0","4.598081589,5.369149208,5.169486046,4.365832806,5.154969215,7.171761036,7.662086964,5.169486523,6.518167496,5.984750271,5.100070000,7.782325745,6.202902317,5.246409416,7.867114544,7.871539593,7.857532978,7.870780945,5.078046322,7.856834412,7.434062958,5.154969215,5.154969215,7.833981991,5.246409416,7.884502411,7.878024578,5.246409416,6.160539627,5.207947731,5.791826725,5.094483852",,,,,,,,"" 1,ip4,192.168.1.7,52.37.36.252,tcp,53203,443,info,22,10,1484319064711690,1484319065635020,1484319065630720,0,0,1448,1448,19082,3110,0,105,59431.0,332646,83335.9,6944879104.0,3.8,"69450,70962,2650,55568,49103,64385,167918,331939,332646,26549,653,732,87677,534,60709,8817,7117,449,81078,62803,767,160,105,68135,67101,803,163,105,111161,109572,2549",52,746.1,1500,703.8,495333.0,4.2,"64,60,52,281,52,1500,1500,52,215,52,127,58,97,52,103,52,1403,1500,1500,52,1500,1500,1500,1500,52,1500,1500,1500,1500,52,1500,1500","6,1,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,12,0,0","6,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0","4.578626633,5.323234081,5.169486046,5.810972691,5.131024837,7.231025219,7.326107502,5.154969215,6.940334797,5.169486523,6.230382919,5.079339504,6.149899960,5.207948208,5.992234230,5.193430901,7.859437466,7.874912739,7.853219032,5.207947731,7.901949883,7.848706245,7.875315189,7.851129055,5.207947731,7.874441147,7.863263607,7.860793114,7.870314598,5.207947731,7.870880127,7.866354465",,,,,,,,"" -1,ip4,192.168.1.7,23.246.11.141,tcp,53184,80,finished,16,16,1484319064593980,1484319066015206,1484319066064571,0,0,515,1448,1024,19133,0,2593,93284.4,471964,119313.2,14235634688.0,4.1,"26070,27491,2593,46530,5363,49411,29634,29502,8466,38422,5397,39840,38400,39693,140326,138333,356578,206910,471964,29274,417442,40849,81521,44012,43364,83015,187750,28619,25160,184386,25502",52,684.8,1500,659.1,434476.8,4.2,"64,60,52,561,621,1500,52,663,52,567,629,1500,52,1500,52,1500,1500,80,1500,64,52,1500,1500,52,1500,52,1500,72,64,52,1500,1500","14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0","0,1,0,0,1,1,0,1,0,0,1,1,0,1,0,1,1,0,1,0,0,1,1,0,1,0,1,0,0,0,1,1","4.570159912,5.266787052,5.065449715,6.275901794,5.797811985,4.453124046,5.118428230,4.223619461,5.089393616,6.289565086,5.782683849,3.849286318,5.103911400,6.893377781,5.000318050,7.605064869,7.871351719,5.248013020,7.860187054,5.187250137,5.077241421,7.867404461,7.859804153,5.065449238,7.885848045,5.000318527,7.863960743,5.267232895,5.115169048,5.079966545,7.857268333,7.882204533",HTTP,7,0,Acceptable,Web,6,DPI,"12" -1,ip4,192.168.1.7,23.246.3.140,tcp,53183,80,finished,17,15,1484319064590230,1484319066598421,1484319065741809,0,0,512,1448,1017,17969,0,5292,101928.1,730898,155663.8,24231225344.0,4.0,"30477,31515,13216,64005,5292,56409,6142,68156,5406,71534,109518,202677,164827,560321,47319,78954,279545,27696,94465,26601,26144,15824,70512,85885,39451,39774,41592,84438,730898,41457,39720",52,648.3,1500,653.4,426995.3,4.2,"64,60,52,557,618,951,52,564,628,1500,52,1500,1500,1500,72,64,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,64,72,64,52","15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,1,1,0,1,1,1,0,0,0,1,1,0,1,0,1,1,0,1,0,1,0,0,0,0","4.476409912,5.212701797,5.156889915,6.230133057,5.778679371,3.867035151,5.079966545,6.195135117,5.745929718,3.167200804,5.094483852,7.856627464,7.824065208,7.816611290,5.331886292,5.165874004,5.118428230,7.781126976,7.831735134,5.118428230,7.778219700,4.961856365,5.882567406,7.827349663,5.103910923,7.794489861,4.961856365,7.814080238,4.958919048,5.244518280,5.083919048,5.079966545",HTTP,7,0,Acceptable,Web,6,DPI,"12" +1,ip4,192.168.1.7,23.246.3.140,tcp,53183,80,finished,17,15,1484319064590230,1484319066598421,1484319065741809,0,0,512,1448,1017,17969,0,5292,101928.1,730898,155663.8,24231225344.0,4.0,"30477,31515,13216,64005,5292,56409,6142,68156,5406,71534,109518,202677,164827,560321,47319,78954,279545,27696,94465,26601,26144,15824,70512,85885,39451,39774,41592,84438,730898,41457,39720",52,648.3,1500,653.4,426995.3,4.2,"64,60,52,557,618,951,52,564,628,1500,52,1500,1500,1500,72,64,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,64,72,64,52","15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,1,1,0,1,1,1,0,0,0,1,1,0,1,0,1,1,0,1,0,1,0,0,0,0","4.476409912,5.212701797,5.156889915,6.230133057,5.778679371,3.867035151,5.079966545,6.195135117,5.745929718,3.167200804,5.094483852,7.856627464,7.824065208,7.816611290,5.331886292,5.165874004,5.118428230,7.781126976,7.831735134,5.118428230,7.778219700,4.961856365,5.882567406,7.827349663,5.103910923,7.794489861,4.961856365,7.814080238,4.958919048,5.244518280,5.083919048,5.079966545",HTTP,7,0,Acceptable,Download,6,DPI,"4,12" 1,ip4,192.168.1.7,52.41.30.5,tcp,53249,443,finished,16,16,1484319117826887,1484319118140455,1484319118145946,0,0,1448,1448,2205,9578,0,140,20407.3,141407,28956.2,838464256.0,3.9,"52701,54230,4655,50068,892,45987,1145,402,2281,621,48897,36085,58570,140,1031,141407,13303,12185,4698,8739,8491,4498,3692,4536,12375,12816,15153,13884,6123,6182,6840",52,420.8,1500,506.4,256458.0,4.1,"64,60,52,260,52,197,52,58,97,1500,550,52,52,1500,213,1500,52,545,52,991,52,425,52,1292,52,1392,52,646,52,794,52,707","12,1,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","4,0,0,0,1,1,0,0,0,0,0,1,0,0,0,1,0,0,1,0,1,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,2,0,0","0,1,0,0,1,1,0,0,0,0,0,1,1,1,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.494096756,5.269149303,5.100070000,6.003353119,5.215455055,6.547097206,5.138531685,5.182787418,6.044509888,7.866807461,7.609665394,5.140452385,5.215455055,7.873748302,6.994494438,7.847311020,5.138531685,7.632858276,5.138531685,7.760740280,5.176993370,7.540992260,5.061608315,7.843688965,5.176993370,7.880697250,5.138531685,7.689140797,5.100070000,7.779115677,5.138531685,7.737319469",TLS.NetFlix,91.133,1,Fun,Video,6,DPI,"15" 1,ip4,192.168.1.7,52.41.30.5,tcp,53239,443,info,17,15,1484319117605859,1484319118414034,1484319118767393,0,0,1448,1448,4896,7589,0,95,63539.0,500942,121518.7,14766798848.0,3.3,"58292,61223,1798,70566,2939,1016,71265,11570,12325,13054,147,95,65707,781,52265,3649,191,91649,51753,301,140150,3732,3446,3903,5462,6438,5030,437212,863,500942,291945",52,442.8,1500,552.3,305076.8,4.0,"64,60,52,569,52,1500,1500,52,245,52,127,58,97,52,103,52,1500,789,52,1500,476,52,448,52,751,52,86,52,1500,672,52,1500","10,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","5,2,0,0,0,0,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,1,0,1,0,0,0,0,1,1,0,0,0,1,1,1,0,1,0,1,0,1,0,0,0,1,1","4.586286545,5.335815430,5.169486523,4.098951340,5.025067329,7.251211166,7.301212311,5.207947731,7.012731075,5.246409416,6.273766041,5.113821983,5.990005016,5.132945538,5.992234230,5.246409893,7.870625973,7.755266190,5.171407223,7.853860855,7.522392750,5.169486046,7.574260712,5.131024361,7.742949009,5.207947731,5.956426620,5.207947731,7.856410503,7.668289185,5.038780212,7.883280277",,,,,,,,"" 1,ip4,192.168.1.7,184.25.204.10,tcp,53252,80,finished,6,26,1484319118658049,1484319118854817,1484319119584735,0,0,245,1448,245,34752,0,508,36240.5,99830,21554.2,464585632.0,4.7,"16679,17740,11985,38478,508,12702,40101,27115,27112,58536,99830,81106,33879,23672,53768,53762,65076,48010,65429,13865,30914,13324,28733,40448,54528,28786,29443,29431,27518,25487,25489",52,1146.7,1500,613.3,376142.5,4.7,"64,60,52,297,52,1500,1500,52,1500,52,1500,64,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500","5,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,24,0,0","0,1,0,0,1,1,1,0,1,0,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","4.495864868,5.233453751,5.156889915,5.883365631,5.270353794,7.005603790,7.481070995,5.118428230,7.677317619,5.077241421,7.654481411,5.151865005,7.832942486,7.813632965,7.788673401,7.782803535,7.834435940,7.821334362,7.827250957,7.843655586,7.828696728,7.842951298,7.865435123,7.847778320,7.855163097,7.835734844,7.856423378,7.842322826,7.854029179,7.863353252,7.834544182,7.849704266",HTTP.NetFlix,7.133,0,Fun,Video,6,DPI,"" diff --git a/test/results/flow-analyse/quic-27.pcap.out b/test/results/flow-analyse/default/netflow-fritz.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-27.pcap.out +++ b/test/results/flow-analyse/default/netflow-fritz.pcap.out diff --git a/test/results/flow-analyse/quic-29.pcap.out b/test/results/flow-analyse/default/netflowv9.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-29.pcap.out +++ b/test/results/flow-analyse/default/netflowv9.pcap.out diff --git a/test/results/flow-analyse/nfsv2.pcap.out b/test/results/flow-analyse/default/nfsv2.pcap.out index 6ab06562c..b7361e7f5 100644 --- a/test/results/flow-analyse/nfsv2.pcap.out +++ b/test/results/flow-analyse/default/nfsv2.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,139.25.22.2,139.25.22.102,udp,1023,2049,finished,16,16,944207338490000,944207338580000,944207338580000,124,0,172,128,2168,1208,0,0,5806.5,40000,10088.1,101768992.0,3.3,"0,0,0,40000,40000,0,0,0,10000,10000,0,0,0,0,0,10000,10000,10000,10000,0,0,0,0,10000,10000,0,0,0,0,10000,10000",56,133.5,200,43.1,1860.8,4.9,"152,124,152,76,160,56,160,56,192,156,152,124,152,124,160,156,184,124,160,156,160,56,160,56,160,156,160,56,200,56,152,124","0,0,0,5,9,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,0,5,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","3.371484280,3.525987864,3.379018784,3.466069698,3.343606710,3.300534248,3.343606710,3.300534248,3.290571213,3.348722219,3.371484280,3.323238611,3.371484280,3.487642050,3.331106663,3.335901976,3.693611860,3.362390041,3.331106663,3.362183094,3.365244627,3.300534248,3.365244627,3.215625525,3.331106663,3.379842520,3.352744579,3.300534248,3.235463142,3.225106239,3.358326435,3.513812542",NFS,11,0,Acceptable,DataTransfer,6,DPI,"" +1,ip4,139.25.22.2,139.25.22.102,udp,1023,2049,finished,16,16,944207338490000,944207338580000,944207338580000,124,0,172,128,2168,1208,0,0,5806.5,40000,10088.1,101768992.0,3.3,"0,0,0,40000,40000,0,0,0,10000,10000,0,0,0,0,0,10000,10000,10000,10000,0,0,0,0,10000,10000,0,0,0,0,10000,10000",56,133.5,200,43.1,1860.8,4.9,"152,124,152,76,160,56,160,56,192,156,152,124,152,124,160,156,184,124,160,156,160,56,160,56,160,156,160,56,200,56,152,124","0,0,0,5,9,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,0,5,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","3.371484280,3.525987864,3.379018784,3.466069698,3.343606710,3.300534248,3.343606710,3.300534248,3.290571213,3.348722219,3.371484280,3.323238611,3.371484280,3.487642050,3.331106663,3.335901976,3.693611860,3.362390041,3.331106663,3.362183094,3.365244627,3.300534248,3.365244627,3.215625525,3.331106663,3.379842520,3.352744579,3.300534248,3.235463142,3.225106239,3.358326435,3.513812542",NFS,11,0,Acceptable,DataTransfer,6,DPI,"46" diff --git a/test/results/flow-analyse/nfsv3.pcap.out b/test/results/flow-analyse/default/nfsv3.pcap.out index 4a6aa4604..739589cf3 100644 --- a/test/results/flow-analyse/nfsv3.pcap.out +++ b/test/results/flow-analyse/default/nfsv3.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,139.25.22.2,139.25.22.102,udp,1022,2049,finished,16,16,944207397400000,944207397500000,944207397500000,128,0,184,272,2256,2044,0,0,6451.6,50000,12325.8,151925088.0,3.2,"0,0,10000,10000,0,0,0,50000,50000,0,0,0,10000,10000,0,0,0,10000,10000,0,0,0,10000,10000,0,0,0,10000,10000,0,0",60,162.4,300,63.4,4021.9,4.9,"156,140,156,192,156,196,156,168,164,60,164,60,212,300,156,140,192,172,164,60,164,60,164,268,164,60,208,288,164,268,164,60","0,0,0,0,13,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,6,0,2,2,2,0,2,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","3.326711178,3.327016592,3.326071262,3.163861752,3.338891745,3.169299841,3.334052563,3.097134829,3.262883663,3.180556774,3.262883902,3.113889694,2.862895966,3.295031309,3.326711178,3.137918949,3.170489788,3.257602215,3.320102930,3.147223234,3.332298279,3.147223234,3.250688314,3.172522783,3.332298279,3.180556774,3.225916147,3.296354771,3.267486334,3.381330967,3.502039671,3.180556774",NFS,11,0,Acceptable,DataTransfer,6,DPI,"" +1,ip4,139.25.22.2,139.25.22.102,udp,1022,2049,finished,16,16,944207397400000,944207397500000,944207397500000,128,0,184,272,2256,2044,0,0,6451.6,50000,12325.8,151925088.0,3.2,"0,0,10000,10000,0,0,0,50000,50000,0,0,0,10000,10000,0,0,0,10000,10000,0,0,0,10000,10000,0,0,0,10000,10000,0,0",60,162.4,300,63.4,4021.9,4.9,"156,140,156,192,156,196,156,168,164,60,164,60,212,300,156,140,192,172,164,60,164,60,164,268,164,60,208,288,164,268,164,60","0,0,0,0,13,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,6,0,2,2,2,0,2,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","3.326711178,3.327016592,3.326071262,3.163861752,3.338891745,3.169299841,3.334052563,3.097134829,3.262883663,3.180556774,3.262883902,3.113889694,2.862895966,3.295031309,3.326711178,3.137918949,3.170489788,3.257602215,3.320102930,3.147223234,3.332298279,3.147223234,3.250688314,3.172522783,3.332298279,3.180556774,3.225916147,3.296354771,3.267486334,3.381330967,3.502039671,3.180556774",NFS,11,0,Acceptable,DataTransfer,6,DPI,"46" diff --git a/test/results/flow-analyse/nintendo.pcap.out b/test/results/flow-analyse/default/nintendo.pcap.out index f05c95e62..f966d73c1 100644 --- a/test/results/flow-analyse/nintendo.pcap.out +++ b/test/results/flow-analyse/default/nintendo.pcap.out @@ -1,6 +1,6 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.12.114,91.8.243.35,udp,52119,49432,finished,16,16,1500731320644357,1500731323575958,1500731323714896,60,0,188,812,1264,2736,0,53,193617.4,1729670,331922.2,110172323840.0,3.6,"87919,239629,335441,89838,30639,131192,103304,499986,507312,130872,234805,19308,15810,5164,16850,12585,53490,8758,197,60833,14170,505639,501514,5142,514446,94641,233,1729670,53,52619,81",88,153.0,840,179.5,32207.0,4.5,"88,88,184,216,104,88,136,104,88,104,136,120,104,104,104,840,104,840,88,88,104,88,88,88,88,88,104,104,104,104,104,104","0,7,7,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,4,8,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,1,0,1,0,1,1,0,1,0,0,1,0,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1","6.054771423,6.070055008,6.784899235,6.928938866,6.170448780,6.114374638,6.682166576,6.236359596,6.114374638,6.332513809,6.593932629,6.402483463,6.228141308,6.167903423,6.240113258,6.264906406,6.300350189,5.915572166,5.837212563,5.851361752,6.208909988,5.936699867,6.078633785,6.168406963,6.024600983,5.979146481,6.063282490,6.067996502,6.005589962,6.166695118,6.181211948,6.193184376",Nintendo,173,0,Fun,Game,6,DPI,"" +1,ip4,192.168.12.114,91.8.243.35,udp,52119,49432,finished,16,16,1500731320644357,1500731323575958,1500731323714896,60,0,188,812,1264,2736,0,53,193617.4,1729670,331922.2,110172323840.0,3.6,"87919,239629,335441,89838,30639,131192,103304,499986,507312,130872,234805,19308,15810,5164,16850,12585,53490,8758,197,60833,14170,505639,501514,5142,514446,94641,233,1729670,53,52619,81",88,153.0,840,179.5,32207.0,4.5,"88,88,184,216,104,88,136,104,88,104,136,120,104,104,104,840,104,840,88,88,104,88,88,88,88,88,104,104,104,104,104,104","0,7,7,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,4,8,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,1,0,1,0,1,1,0,1,0,0,1,0,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1","6.054771423,6.070055008,6.784899235,6.928938866,6.170448780,6.114374638,6.682166576,6.236359596,6.114374638,6.332513809,6.593932629,6.402483463,6.228141308,6.167903423,6.240113258,6.264906406,6.300350189,5.915572166,5.837212563,5.851361752,6.208909988,5.936699867,6.078633785,6.168406963,6.024600983,5.979146481,6.063282490,6.067996502,6.005589962,6.166695118,6.181211948,6.193184376",Nintendo,173,0,Fun,Game,6,DPI,"46" 1,ip4,54.187.10.185,192.168.12.114,tcp,443,48328,finished,19,13,1500731322454625,1500731342015923,1500731342041758,0,0,334,405,1090,1094,1,43,1262852.6,14019058,3442938.0,11853821378560.0,2.4,"6277,307132,3508675,3481620,246,43,276417,18546,55237,145,35743,210876,214177,255332,13944464,14019058,757,51,5265,332523,29922,280387,254222,215658,3394,13561,231064,4335,258992,453544,730768",52,120.2,457,98.4,9678.6,4.6,"152,103,52,119,52,110,99,52,103,152,152,52,52,103,52,457,52,99,386,152,52,103,52,368,52,109,99,52,103,52,152,103","8,5,0,5,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,6,1,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,0,1,1,0,0,1,0,1,0,1,0,0,0,0,1,1,0,1,0,0,0,1,1,0,0,1","6.479545116,5.785408020,5.038780212,5.979954243,4.955154419,6.040005207,6.008045197,5.003043652,5.726619720,6.592999458,6.614606380,4.988526344,5.077241898,5.668902874,5.000318527,7.493407249,5.115703106,6.091131687,7.370351791,6.507602692,5.003043175,5.784872532,5.077241898,7.341584682,5.077241898,6.192684174,5.995468616,5.079966545,5.751333237,5.077241898,6.654079914,5.719826698",TLS,91,1,Safe,Web,6,DPI,"" -1,ip4,192.168.12.114,185.118.169.65,udp,55915,27520,finished,22,10,1500731342849734,1500731344006747,1500731344120690,60,0,844,844,2472,1560,0,25,78321.6,754134,152593.1,23284658176.0,3.2,"280,397,210011,243,431,203806,304,212,311877,2339,183,754134,1127,30674,588,242272,245592,5517,2752,1899,125604,98,25,109131,222,10721,20118,10437,105846,2222,28907",88,154.0,872,186.2,34652.0,4.5,"104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,88,104,104,104,104,872,88,872,104,104,88","0,2,18,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,6,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,1,0,0,0,0,1,1,1,0,0,1,0,0,1,1,1","6.027614594,6.162230015,5.955404758,6.008383274,6.027614117,5.981129169,5.969922066,6.066075802,6.046844959,5.974635601,6.058817387,6.054103374,6.103913307,6.176122665,6.046596527,6.109002590,6.645735741,5.936699867,6.072710037,6.149633408,6.658484459,6.054296017,6.158073902,6.254228115,6.048765182,6.142750740,5.609991074,5.891245842,5.565810204,6.126870632,6.246969700,5.874088764",Nintendo,173,0,Fun,Game,6,DPI,"" -1,ip4,192.168.12.114,93.237.131.235,udp,55915,56066,finished,22,10,1500731343061460,1500731344751616,1500731344671142,60,0,844,844,4168,1560,0,67,106446.4,757918,188381.8,35487694848.0,3.4,"726,2728,200750,236,363,313750,216,309,757918,67,245897,246,38434,238,116689,3047,25905,110485,1189,79734,7959,87905,10077,91853,20145,506365,607064,9714,10174,12917,36738",88,207.0,872,231.8,53743.0,4.4,"104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,168,88,872,88,872,88,104,104,88,344,840,472,472","0,3,13,0,1,0,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,6,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,1,1,1,0,0,1,1,0,0,1,1,1,0,0,0,0,0","6.039587021,6.058817387,5.969922066,6.032328129,6.054103374,6.019590855,6.073334694,6.111796379,6.092565060,6.168863773,6.214584351,6.109002590,6.140205860,6.123519897,6.154723167,6.208508015,6.138843060,6.726152897,5.973575592,6.683043003,5.940660000,5.584841251,5.973575592,5.570620537,5.787140369,6.150815010,6.182018280,6.004880905,7.315718174,5.846724510,6.181584358,6.204835892",Nintendo,173,0,Fun,Game,6,DPI,"" -1,ip4,192.168.12.114,81.61.158.138,udp,55915,51769,finished,20,12,1500731343266581,1500731344811760,1500731344805333,60,0,844,844,2304,1712,0,137,99481.6,649265,183756.7,33766533120.0,3.2,"295,399,313495,260,289,284287,137,381,629371,5230,43658,5349,61371,137,131610,65365,7948,186,836,31052,435,67583,2946,484,7525,105852,5669,103301,9836,549379,649265",88,153.5,872,186.3,34709.8,4.4,"104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,104,104,88,104,104,872,88,872,88,104,104,88","0,3,15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,8,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,1,0,0,0,0,1,1,1,1,1,1,0,0,1,1,1,0","6.066075802,6.142999172,6.123768806,6.032328606,6.188719273,6.181460857,6.181460857,6.169488430,6.111796379,6.038962364,6.065451622,6.120974541,6.128233433,6.053479195,6.116261482,6.740974426,6.004880905,6.097030163,6.166695118,6.774616718,6.150815487,6.220480442,5.905394077,6.170046329,6.234997272,5.541868210,5.928121090,5.589448929,6.027608395,6.189277172,6.140205860,6.004880905",Nintendo,173,0,Fun,Game,6,DPI,"" +1,ip4,192.168.12.114,185.118.169.65,udp,55915,27520,finished,22,10,1500731342849734,1500731344006747,1500731344120690,60,0,844,844,2472,1560,0,25,78321.6,754134,152593.1,23284658176.0,3.2,"280,397,210011,243,431,203806,304,212,311877,2339,183,754134,1127,30674,588,242272,245592,5517,2752,1899,125604,98,25,109131,222,10721,20118,10437,105846,2222,28907",88,154.0,872,186.2,34652.0,4.5,"104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,88,104,104,104,104,872,88,872,104,104,88","0,2,18,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,6,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,1,0,0,0,0,1,1,1,0,0,1,0,0,1,1,1","6.027614594,6.162230015,5.955404758,6.008383274,6.027614117,5.981129169,5.969922066,6.066075802,6.046844959,5.974635601,6.058817387,6.054103374,6.103913307,6.176122665,6.046596527,6.109002590,6.645735741,5.936699867,6.072710037,6.149633408,6.658484459,6.054296017,6.158073902,6.254228115,6.048765182,6.142750740,5.609991074,5.891245842,5.565810204,6.126870632,6.246969700,5.874088764",Nintendo,173,0,Fun,Game,6,DPI,"46" +1,ip4,192.168.12.114,93.237.131.235,udp,55915,56066,finished,22,10,1500731343061460,1500731344751616,1500731344671142,60,0,844,844,4168,1560,0,67,106446.4,757918,188381.8,35487694848.0,3.4,"726,2728,200750,236,363,313750,216,309,757918,67,245897,246,38434,238,116689,3047,25905,110485,1189,79734,7959,87905,10077,91853,20145,506365,607064,9714,10174,12917,36738",88,207.0,872,231.8,53743.0,4.4,"104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,168,88,872,88,872,88,104,104,88,344,840,472,472","0,3,13,0,1,0,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,6,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,1,1,1,0,0,1,1,0,0,1,1,1,0,0,0,0,0","6.039587021,6.058817387,5.969922066,6.032328129,6.054103374,6.019590855,6.073334694,6.111796379,6.092565060,6.168863773,6.214584351,6.109002590,6.140205860,6.123519897,6.154723167,6.208508015,6.138843060,6.726152897,5.973575592,6.683043003,5.940660000,5.584841251,5.973575592,5.570620537,5.787140369,6.150815010,6.182018280,6.004880905,7.315718174,5.846724510,6.181584358,6.204835892",Nintendo,173,0,Fun,Game,6,DPI,"46" +1,ip4,192.168.12.114,81.61.158.138,udp,55915,51769,finished,20,12,1500731343266581,1500731344811760,1500731344805333,60,0,844,844,2304,1712,0,137,99481.6,649265,183756.7,33766533120.0,3.2,"295,399,313495,260,289,284287,137,381,629371,5230,43658,5349,61371,137,131610,65365,7948,186,836,31052,435,67583,2946,484,7525,105852,5669,103301,9836,549379,649265",88,153.5,872,186.3,34709.8,4.4,"104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,104,104,88,104,104,872,88,872,88,104,104,88","0,3,15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,8,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,1,0,0,0,0,1,1,1,1,1,1,0,0,1,1,1,0","6.066075802,6.142999172,6.123768806,6.032328606,6.188719273,6.181460857,6.181460857,6.169488430,6.111796379,6.038962364,6.065451622,6.120974541,6.128233433,6.053479195,6.116261482,6.740974426,6.004880905,6.097030163,6.166695118,6.774616718,6.150815487,6.220480442,5.905394077,6.170046329,6.234997272,5.541868210,5.928121090,5.589448929,6.027608395,6.189277172,6.140205860,6.004880905",Nintendo,173,0,Fun,Game,6,DPI,"46" diff --git a/test/results/flow-analyse/nntp.pcap.out b/test/results/flow-analyse/default/nntp.pcap.out index c8e5e5053..c8e5e5053 100644 --- a/test/results/flow-analyse/nntp.pcap.out +++ b/test/results/flow-analyse/default/nntp.pcap.out diff --git a/test/results/flow-analyse/no_sni.pcap.out b/test/results/flow-analyse/default/no_sni.pcap.out index 54b5cfe30..54b5cfe30 100644 --- a/test/results/flow-analyse/no_sni.pcap.out +++ b/test/results/flow-analyse/default/no_sni.pcap.out diff --git a/test/results/flow-analyse/ocs.pcap.out b/test/results/flow-analyse/default/ocs.pcap.out index 528377701..677d8991d 100644 --- a/test/results/flow-analyse/ocs.pcap.out +++ b/test/results/flow-analyse/default/ocs.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -12,ip4,192.168.180.2,178.248.208.54,tcp,49881,80,finished,32,0,1449652787983929,1449652790713183,1449652787983929,0,0,663,0,663,0,0,450,88040.5,928563,172609.9,29794174976.0,3.5,"83797,14275,246872,572,450,68391,1837,71492,506,5433,4137,41728,146026,90832,71054,77421,63432,3718,80468,1653,86121,564,67336,32599,43283,386587,73735,2510,928563,31722,2140",52,83.1,715,113.8,12942.2,4.5,"60,52,715,64,72,72,80,72,72,72,72,72,64,52,64,64,64,52,52,52,52,64,64,64,64,52,52,64,64,52,64,64","31,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.517588139,5.123517990,6.025798798,5.070159912,5.236322403,5.173415184,5.239589214,5.201192856,5.264100075,5.236322403,5.236322403,5.182154179,5.152114868,5.091758728,5.194910049,5.194910049,5.132410049,5.154164791,5.115703106,5.115703106,5.032077789,5.132410049,5.163660049,5.132410049,5.163660049,5.115703106,5.168681622,5.220060349,5.169355392,5.008133411,5.120864868,5.077819824",HTTP.OCS,7.218,0,Fun,Media,6,DPI,"" -12,ip4,192.168.180.2,178.248.208.210,tcp,42590,80,finished,32,0,1449652842628827,1449652843470951,1449652842628827,0,0,152,0,152,0,0,77,27165.3,79495,29589.7,875550464.0,4.0,"71399,1526,54762,1106,3570,59902,605,77,5328,64776,1667,1533,79495,5458,58361,1849,64604,1987,67520,26503,42864,25995,65439,972,48553,1253,1960,1270,75524,1445,4821",52,63.9,204,26.3,690.5,4.9,"60,52,204,52,52,52,52,52,64,64,64,64,72,64,64,72,72,72,64,64,64,52,52,52,52,52,52,52,52,52,64,72","31,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.550921917,5.046595097,5.875504971,5.154164791,5.115703106,5.154164791,5.192625999,5.154164791,5.194910049,5.226160049,5.194910049,5.226160049,5.329917908,5.226160049,5.251310349,5.296718597,5.391922951,5.336368084,5.251310349,5.294355392,5.294355392,5.207143307,5.154164314,5.168681622,5.091758728,5.168681622,5.168681622,5.130220413,5.168681622,5.207143307,5.313810349,5.324496269",HTTP.OCS,7.218,0,Fun,Media,6,DPI,"" +12,ip4,192.168.180.2,178.248.208.54,tcp,49881,80,finished,32,0,1449652787983929,1449652790713183,1449652787983929,0,0,663,0,663,0,0,450,88040.5,928563,172609.9,29794174976.0,3.5,"83797,14275,246872,572,450,68391,1837,71492,506,5433,4137,41728,146026,90832,71054,77421,63432,3718,80468,1653,86121,564,67336,32599,43283,386587,73735,2510,928563,31722,2140",52,83.1,715,113.8,12942.2,4.5,"60,52,715,64,72,72,80,72,72,72,72,72,64,52,64,64,64,52,52,52,52,64,64,64,64,52,52,64,64,52,64,64","31,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.517588139,5.123517990,6.025798798,5.070159912,5.236322403,5.173415184,5.239589214,5.201192856,5.264100075,5.236322403,5.236322403,5.182154179,5.152114868,5.091758728,5.194910049,5.194910049,5.132410049,5.154164791,5.115703106,5.115703106,5.032077789,5.132410049,5.163660049,5.132410049,5.163660049,5.115703106,5.168681622,5.220060349,5.169355392,5.008133411,5.120864868,5.077819824",HTTP.OCS,7.218,0,Fun,Media,6,DPI,"46" +12,ip4,192.168.180.2,178.248.208.210,tcp,42590,80,finished,32,0,1449652842628827,1449652843470951,1449652842628827,0,0,152,0,152,0,0,77,27165.3,79495,29589.7,875550464.0,4.0,"71399,1526,54762,1106,3570,59902,605,77,5328,64776,1667,1533,79495,5458,58361,1849,64604,1987,67520,26503,42864,25995,65439,972,48553,1253,1960,1270,75524,1445,4821",52,63.9,204,26.3,690.5,4.9,"60,52,204,52,52,52,52,52,64,64,64,64,72,64,64,72,72,72,64,64,64,52,52,52,52,52,52,52,52,52,64,72","31,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.550921917,5.046595097,5.875504971,5.154164791,5.115703106,5.154164791,5.192625999,5.154164791,5.194910049,5.226160049,5.194910049,5.226160049,5.329917908,5.226160049,5.251310349,5.296718597,5.391922951,5.336368084,5.251310349,5.294355392,5.294355392,5.207143307,5.154164314,5.168681622,5.091758728,5.168681622,5.168681622,5.130220413,5.168681622,5.207143307,5.313810349,5.324496269",HTTP.OCS,7.218,0,Fun,Media,6,DPI,"11,46" diff --git a/test/results/flow-analyse/ocsp.pcapng.out b/test/results/flow-analyse/default/ocsp.pcapng.out index 7089e7994..185dcf655 100644 --- a/test/results/flow-analyse/ocsp.pcapng.out +++ b/test/results/flow-analyse/default/ocsp.pcapng.out @@ -1,5 +1,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.128,142.250.184.99,tcp,54154,80,finished,17,15,1623222699655905,1623222817722827,1623222807485567,0,0,394,702,788,1404,0,0,7286986.5,10243102,4408149.5,19431782612992.0,4.5,"3376,7013,0,7440,102951,109262,10007824,10012989,10151666,10151973,10240500,10240566,10243102,10242877,10236097,10235872,10239925,10240468,10239857,10239497,5617732,5617894,102927,109302,10148797,10155034,10236056,10236089,10239827,10239709,10239962",104,173.0,806,189.1,35745.5,4.5,"112,112,104,498,104,806,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,498,104,806,104,104,104,104,104,104,104,104","15,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,1,0","3.897244453,4.342274189,4.040620327,6.236268997,4.387147903,7.122592449,4.465434074,4.446203232,4.328273296,4.336050510,4.381251812,4.426972389,4.335968971,4.426972389,4.400482655,4.446203232,4.335968971,4.446203232,4.400482655,4.446203232,4.369279861,6.204105377,4.350049019,7.039563656,4.419713497,4.426972389,4.419713497,4.369279861,4.419713497,4.381252289,4.407741547,4.381689072",HTTP.OCSP,7.63,0,Safe,Cloud,6,DPI,"" +1,ip4,192.168.1.128,142.250.184.99,tcp,54154,80,finished,17,15,1623222699655905,1623222817722827,1623222807485567,0,0,394,702,788,1404,0,0,7286986.5,10243102,4408149.5,19431782612992.0,4.5,"3376,7013,0,7440,102951,109262,10007824,10012989,10151666,10151973,10240500,10240566,10243102,10242877,10236097,10235872,10239925,10240468,10239857,10239497,5617732,5617894,102927,109302,10148797,10155034,10236056,10236089,10239827,10239709,10239962",104,173.0,806,189.1,35745.5,4.5,"112,112,104,498,104,806,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,498,104,806,104,104,104,104,104,104,104,104","15,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,1,0","3.897244453,4.342274189,4.040620327,6.236268997,4.387147903,7.122592449,4.465434074,4.446203232,4.328273296,4.336050510,4.381251812,4.426972389,4.335968971,4.426972389,4.400482655,4.446203232,4.335968971,4.446203232,4.400482655,4.446203232,4.369279861,6.204105377,4.350049019,7.039563656,4.419713497,4.426972389,4.419713497,4.369279861,4.419713497,4.381252289,4.407741547,4.381689072",HTTP.OCSP,7.63,0,Safe,Network,6,DPI,"" 1,ip4,192.168.1.128,92.122.95.235,tcp,43728,80,finished,17,15,1623222785863296,1623222906298417,1623222896069773,0,0,386,889,772,1778,0,280,7440051.5,10244049,4398639.5,19348030750720.0,4.5,"12043,16085,280,19618,157130,176931,7779779,7796085,1344,16621,10045906,10060740,10239929,10239733,10239821,10240037,10244027,10243851,10239937,10239981,10236031,10236118,10243927,10244049,10235957,10235895,10239975,10239809,10240030,10240044,10239885",104,184.2,993,228.7,52281.3,4.4,"112,112,104,490,104,993,104,490,104,993,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104","15,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0","3.854789734,4.210582733,4.061213493,6.305238724,4.330295086,6.969508171,4.388510704,6.307199955,4.399959564,6.995585918,4.388510704,4.446203232,4.362458229,4.407741547,4.380728722,4.362020969,4.380728722,4.407741547,4.342267036,4.388510704,4.335008621,4.362458229,4.335008621,4.381251812,4.373470306,4.369279861,4.335008621,4.407741547,4.354239464,4.400482655,4.354321003,4.343227386",HTTP.OCSP,7.63,0,Safe,Network,6,DPI,"" 1,ip4,192.168.1.128,93.184.220.29,tcp,47904,80,finished,18,14,1623226796047107,1623226898935296,1623226888697884,0,0,387,799,1161,2397,0,297,6307708.5,10240173,4932344.5,24328020164608.0,4.3,"3075,7547,2588,10413,297,8000,10198565,10205648,10239932,10239686,10240046,10239807,10240147,10240173,10239675,10239894,594543,595404,7786,346,7916,7271,10142015,10148632,10239909,10240023,10239943,10239865,10239954,10239944,10239922",104,215.7,903,247.8,61420.8,4.3,"112,112,104,491,104,903,104,104,104,104,104,104,104,104,104,104,104,491,903,104,491,903,104,104,104,104,104,104,104,104,104,104","15,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1,0,0,1,0,1,0,1,0,1,0","3.868270159,4.279380798,4.030010700,6.270659924,4.342348576,7.048072815,4.407741547,4.407741547,4.327831268,4.388510704,4.373551369,4.383797169,4.361579418,4.395769119,4.336050510,4.388510704,4.327831268,6.267565727,7.008815289,4.357307434,6.261363029,7.018546581,4.348686218,4.395769119,4.303886890,4.330818176,4.342348576,4.395769119,4.342348576,4.414999962,4.272684097,4.376538277",HTTP.OCSP,7.63,0,Safe,Network,6,DPI,"" 1,ip4,192.168.1.128,151.101.2.133,tcp,59922,80,finished,17,15,1623227472211039,1623227587349174,1623227584757187,0,0,401,1344,401,1998,0,0,7344654.5,10240632,4532510.5,20543650660352.0,4.5,"3378,7400,923,8114,615,0,9140,0,10126876,10134843,10240392,10240491,10239169,10239578,10239933,10239705,10239910,10239519,10239942,10240185,10239877,10240084,10240632,10240175,10239571,10239443,10239518,10240005,10239975,10240013,2594877",104,179.5,1448,263.0,69147.6,4.2,"112,112,104,505,104,1448,758,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104","16,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,1,0,0,1,1,1,0,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0","3.821438313,4.185985565,4.099675179,6.228553295,4.350049019,6.867750645,7.448840618,4.438944817,4.354762554,4.362021446,4.304766178,4.350049019,4.400483131,4.381252289,4.400483131,4.354762554,4.328273296,4.342790604,4.381252289,4.419713974,4.400483131,4.419713974,4.373993397,4.347504139,4.362021446,4.362021446,4.400483131,4.400483131,4.400483131,4.354762554,4.381252289,4.362021446",HTTP.OCSP,7.63,0,Safe,Network,6,DPI,"" diff --git a/test/results/flow-analyse/quic-33.pcapng.out b/test/results/flow-analyse/default/oicq.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-33.pcapng.out +++ b/test/results/flow-analyse/default/oicq.pcap.out diff --git a/test/results/flow-analyse/quic-34.pcap.out b/test/results/flow-analyse/default/ookla.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-34.pcap.out +++ b/test/results/flow-analyse/default/ookla.pcap.out diff --git a/test/results/flow-analyse/openvpn.pcap.out b/test/results/flow-analyse/default/openvpn.pcap.out index 59dcf4b01..59dcf4b01 100644 --- a/test/results/flow-analyse/openvpn.pcap.out +++ b/test/results/flow-analyse/default/openvpn.pcap.out diff --git a/test/results/flow-analyse/quic-fuzz-overflow.pcapng.out b/test/results/flow-analyse/default/oracle12.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-fuzz-overflow.pcapng.out +++ b/test/results/flow-analyse/default/oracle12.pcapng.out diff --git a/test/results/flow-analyse/quic-mvfst-27.pcapng.out b/test/results/flow-analyse/default/os_detected.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-mvfst-27.pcapng.out +++ b/test/results/flow-analyse/default/os_detected.pcapng.out diff --git a/test/results/flow-analyse/quic-mvfst-exp.pcap.out b/test/results/flow-analyse/default/ospfv2_add_new_prefix.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-mvfst-exp.pcap.out +++ b/test/results/flow-analyse/default/ospfv2_add_new_prefix.pcap.out diff --git a/test/results/flow-analyse/quic-v2-01.pcapng.out b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_1.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic-v2-01.pcapng.out +++ b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_1.pcapng.out diff --git a/test/results/flow-analyse/quic_0RTT.pcap.out b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_2.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_0RTT.pcap.out +++ b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_2.pcapng.out diff --git a/test/results/flow-analyse/quic_crypto_aes_auth_size.pcap.out b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_3.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_crypto_aes_auth_size.pcap.out +++ b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_3.pcapng.out diff --git a/test/results/flow-analyse/quic_frags_ch_in_multiple_packets.pcapng.out b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_4.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_frags_ch_in_multiple_packets.pcapng.out +++ b/test/results/flow-analyse/default/ossfuzz_seed_fake_traces_4.pcapng.out diff --git a/test/results/flow-analyse/pgm.pcap.out b/test/results/flow-analyse/default/pgm.pcap.out index 381157287..381157287 100644 --- a/test/results/flow-analyse/pgm.pcap.out +++ b/test/results/flow-analyse/default/pgm.pcap.out diff --git a/test/results/flow-analyse/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out b/test/results/flow-analyse/default/pgsql.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out +++ b/test/results/flow-analyse/default/pgsql.pcap.out diff --git a/test/results/flow-analyse/quic_interop_V.pcapng.out b/test/results/flow-analyse/default/pim.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_interop_V.pcapng.out +++ b/test/results/flow-analyse/default/pim.pcap.out diff --git a/test/results/flow-analyse/pinterest.pcap.out b/test/results/flow-analyse/default/pinterest.pcap.out index dd7cab743..3c5e710cb 100644 --- a/test/results/flow-analyse/pinterest.pcap.out +++ b/test/results/flow-analyse/default/pinterest.pcap.out @@ -5,12 +5,10 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2600:1901::7a0b::,tcp,47032,443,finished,18,14,1605289714558209,1605289714795031,1605289714793606,0,0,517,1208,1778,5802,0,0,15232.9,132689,29577.9,874849472.0,3.1,"23500,23520,222,32278,1902,1,0,33966,35,25,324,0,242,8,1731,75,102,35078,5741,3731,0,1,42641,14,135,39228,93613,132689,1225,118,74",72,309.4,1280,401.1,160869.7,4.1,"80,80,72,589,72,1280,1280,1280,72,72,72,1280,173,72,72,136,164,451,72,72,652,103,72,72,72,103,72,330,72,111,229,571","11,1,2,0,1,0,0,0,0,0,0,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,0,0,0,0","4.656593323,5.123788357,5.017778397,4.494572163,4.850525856,7.806178570,7.820445061,7.825618267,4.990000248,4.985159874,5.017777920,7.793226242,6.582598209,5.045556068,5.045556068,6.051473618,6.341272354,7.424715996,4.850525856,4.812263489,7.613498688,5.540113449,4.850525856,5.073333740,5.073333740,5.737332821,4.822747707,7.185048103,5.017778397,5.884420395,6.843392372,7.591670513",TLS,91,1,Safe,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:7854,tcp,33280,443,info,16,16,1605289714658043,1605289714873020,1605289714873010,0,0,517,1048,1043,6264,0,0,13869.2,89623,22425.8,502918720.0,3.3,"39835,39893,388,39880,1850,1,41296,35,60,0,18,4,565,0,563,29,2922,2605,564,39805,119,1086,1924,0,36819,15,203,49740,40102,0,89623",72,300.8,1120,374.8,140490.0,4.1,"80,80,72,589,72,1120,1120,72,72,1120,1120,72,72,1120,154,72,72,165,171,368,72,72,72,330,138,72,72,110,72,516,246,72","11,1,1,1,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,2,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,1,0,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,1,0","4.759509563,5.142373085,5.117740154,4.564804554,4.953123093,6.789499283,4.442035198,5.175263882,5.103079796,6.610801220,7.126421452,5.203041553,5.203041553,7.603042603,6.151700974,5.175263882,5.175263882,6.101224422,6.300935745,7.262635231,4.980900764,5.036456108,4.980900764,7.043718815,6.196548939,5.175263882,5.175263882,5.631328106,5.036456108,7.479037762,6.852047443,5.230819225",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a04:4e42:1d::720,tcp,57050,443,info,16,16,1605289714782619,1605289714902517,1605289714903070,0,0,517,1388,1077,12561,0,0,7753.2,50337,15382.7,236626480.0,2.9,"50290,50337,220,31719,3102,0,34561,13,675,659,1179,1,1182,11,2643,116,155,32346,0,0,0,1,29460,6,548,1,0,514,15,6,589",72,498.7,1460,595.9,355070.7,4.0,"80,80,72,589,72,1460,1460,72,72,1460,72,1460,1205,72,72,165,171,440,72,72,72,330,138,72,72,1460,1460,1460,72,72,72,1460","12,0,1,1,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,8,0,0,0,0","0,1,0,0,1,1,1,0,0,1,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,1,1,1,0,0,0,1","4.703702927,5.136080265,5.124309540,4.545345783,5.017591953,6.717867374,4.853471756,5.096531868,5.124309540,7.395221710,5.124309540,7.321218014,7.643990993,5.124309540,5.152087212,5.949683189,6.333797455,7.364598274,5.017591953,5.017591953,4.989814281,7.067564487,6.163845539,5.152087212,5.124309540,7.852941513,7.865815639,7.871354580,5.096531868,5.124309540,5.053668499,7.834792614",,,,,,,,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:806::200e,tcp,54416,443,finished,16,16,1605289715221747,1605289715430506,1605289715430565,0,0,517,1208,965,10223,0,0,13470.2,79486,22212.4,493390560.0,3.3,"51607,51735,639,27991,20462,0,1,47699,14,8,3349,184,136,69956,1,28,13172,79486,329,8681,8388,16746,3,2,2,16717,40,14,21,164,2",72,422.1,1280,496.1,246097.6,4.1,"80,80,72,589,72,1280,1280,312,72,72,72,136,164,333,72,72,72,652,72,103,103,72,988,1280,1280,1280,72,72,72,72,1280,1280","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,0,0,1,0,1,1,1,1,0,0,0,0,1,1","4.905388832,5.201737404,5.194384098,4.447809696,5.069574356,7.796703339,7.816472054,7.245393753,5.222161770,5.194384098,5.194384098,6.221469402,6.666475773,7.225831985,5.059089661,5.086867332,5.097352028,7.629415512,5.222161770,5.833802700,5.730946064,5.211677074,7.792719841,7.812408924,7.862325191,7.810635090,5.211677074,5.249939442,5.222161770,5.222161770,7.816607952,7.836236000",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a03:2880:f030:13:face:b00c::3,tcp,51292,443,finished,18,14,1605289715274358,1605289715471680,1605289715427326,0,0,517,1380,1347,5004,0,0,11299.7,93180,21751.5,473125984.0,3.0,"26987,27077,236,32338,1,0,32042,17,3873,399,116,64739,93180,2,1,290,2,3,2,24343,46,12,9,157,3,2,82,23,41,4388,39879",72,271.0,1452,368.4,135732.3,4.1,"80,80,72,589,72,1452,979,72,72,136,164,330,330,72,72,72,251,152,116,653,72,72,72,72,483,1452,114,72,72,72,103,199","12,0,2,1,0,0,0,0,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,2,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0","0,1,0,0,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,1,0,0,0,0,1,1,1,0,0,0,0,0","5.086080074,5.358260632,5.421088219,4.582517624,5.325077534,7.824724197,7.800261974,5.487128258,5.459350586,6.217577457,6.494597435,7.339631081,7.344889641,5.269522190,5.231259823,5.286815166,7.021345615,6.361854553,5.947217464,7.648275852,5.393310547,5.421088219,5.393310547,5.448865891,7.531715393,7.878327370,6.086453915,5.448865891,5.421088219,5.365532398,5.884278774,6.731818199",TLS.Facebook,91.119,1,Fun,SocialNetwork,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:805::2003,tcp,43562,443,finished,9,23,1605289716168715,1605289716199465,1605289716199511,0,0,158,1208,281,21058,1,0,1985.4,28590,6415.7,41161208.0,1.8,"202,23469,160,5107,2,28590,251,1,1,2,214,4,31,0,19,391,1,0,1,397,8,1304,0,0,1,0,1316,72,1,1,0",72,738.8,1280,578.2,334348.7,4.5,"230,195,72,72,263,1280,72,1280,1280,1280,1280,72,72,1280,1280,72,1280,1280,1280,1280,72,72,1280,1280,237,111,199,72,1280,1280,1280,1280","7,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,1,0,1,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0,0,0,0,0,0,0,0,0","0,0,1,1,1,1,0,1,1,1,1,0,0,1,1,0,1,1,1,1,0,0,1,1,1,1,1,0,1,1,1,1","6.948834896,6.675073147,5.125129700,5.125129700,6.977108479,7.855700493,5.182512760,7.824506283,7.846910477,7.827116013,7.838431835,5.116472721,5.137442112,7.839233875,7.849976540,5.154735088,7.852743149,7.835449219,7.826992035,7.859686375,5.182512760,5.182512760,7.806921482,7.824195862,6.883517742,5.810838699,6.706934929,5.109664440,7.833899021,7.836830139,7.838667870,7.830160618",TLS,91,1,Safe,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:816::200a,tcp,47790,443,finished,17,15,1605289715966342,1605289717653626,1605289716195463,0,0,517,1208,1280,4020,0,0,61819.5,1485939,260701.6,67965321216.0,1.6,"55481,55557,2604,45080,17803,15,60231,16,286,275,9398,2484,606,42880,0,228,1,30633,193,14864,14650,23014,0,23014,8,85,0,70,1606,29384,1485939",72,238.1,1280,317.7,100919.6,4.1,"80,80,72,589,72,1280,1280,72,72,573,72,136,164,444,72,72,72,652,72,103,103,72,462,135,72,72,111,72,72,111,72,237","11,1,2,0,0,1,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,2,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,0,0,0,0,1,1,1,1,0,0,1,0,1,1,0,0,1,1,0,0,1,0","4.830388546,5.236173153,5.083273411,4.664566517,5.024503708,7.801916599,7.849427700,5.232646465,5.204868793,7.603487968,5.204868793,6.090775967,6.470489025,7.520395279,5.107836723,5.107836723,5.080059052,7.600295067,5.194384098,5.756132126,5.672693253,5.166606426,7.483500957,6.249640465,5.177091122,5.204868793,5.886195660,5.135614395,5.204868793,5.955920696,5.135614395,6.860337257",TLS.GoogleServices,91.239,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:816::200d,tcp,40894,443,finished,16,16,1605289717548570,1605289717681759,1605289717681662,0,0,517,1208,959,10121,0,0,8589.7,42968,12964.6,168080032.0,3.5,"23434,23612,605,27825,5261,2,0,32335,48,7,3191,171,159,42968,880,1,157,40413,894,3393,2534,21369,1,21337,22,7799,1,0,1,7829,32",72,418.8,1280,492.4,242485.9,4.1,"80,80,72,589,72,1280,1280,322,72,72,72,136,164,327,72,72,72,652,72,103,103,72,876,1280,72,72,1280,1280,1280,1280,72,72","12,0,2,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,0,0,1,0,1,1,0,0,1,1,1,1,0,0","4.905389309,5.361174107,5.232646465,4.557852268,5.107836723,7.817549706,7.840916157,7.180346489,5.232646465,5.260424137,5.260424137,6.185771942,6.393667221,7.196280479,5.107836723,5.107836723,5.107836723,7.630718231,5.204868793,5.782878876,5.796528339,5.222161770,7.750598431,7.833017826,5.260424137,5.260424137,7.845281124,7.848848343,7.857541561,7.841633797,5.194384098,5.232646465",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a03:2880:f11f:83:face:b00c::25de,tcp,60340,443,finished,16,16,1605289715782853,1605289717682629,1605289717754541,0,0,546,1380,1620,4362,0,0,124885.9,1522186,365675.9,133718884352.0,2.3,"51050,51117,702,184290,1,0,183671,66,7538,8559,3870,48706,3,10603,0,1,1,39192,55,6,1700,5826,4025,34675,42375,77042,1489773,1522186,1,32460,71970",72,259.4,1452,363.6,132225.8,4.1,"80,80,72,589,72,1452,980,72,72,136,164,442,72,72,72,243,152,103,72,72,72,103,107,72,72,492,72,618,72,107,72,1374","11,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,2,1,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0","0,1,0,0,1,1,1,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,0,1,1,0,0,1,1,0,1","5.147778988,5.386569977,5.363564491,4.530324936,5.275225163,7.856009483,7.774714947,5.419119835,5.348239422,6.266700268,6.486256123,7.484294891,5.260424137,5.260424137,5.232646465,6.926154137,6.485898972,5.898414135,5.275390625,5.325302124,5.275390625,5.898528576,5.995410442,5.391342163,5.286815166,7.551696301,5.363564491,7.633099079,5.342370510,6.001532078,5.391342163,7.830712318",TLS.Facebook,91.119,1,Fun,SocialNetwork,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80a::200e,tcp,45126,443,finished,17,15,1605289732972740,1605289733216831,1605289733216812,0,0,517,1208,969,9927,0,0,15747.2,157269,35268.1,1243837184.0,2.7,"46894,46909,201,112030,45428,0,2,157269,9,5,2935,270,2964,37660,1,0,1100,1,0,32562,12,3,631,955,1,0,0,308,7,3,3",72,413.0,1280,486.7,236885.8,4.1,"80,80,72,589,72,1280,1280,549,72,72,72,136,164,337,72,72,72,652,486,1280,72,72,72,103,1280,1280,1280,1280,72,72,72,72","13,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,1,1,1,0,0,0,0","4.855388165,5.286173344,5.149313450,4.600729942,5.080059052,7.797164440,7.832664490,7.507453918,5.138828754,5.081305504,5.166606903,6.092433929,6.575641632,7.259848118,5.043183804,5.097352505,5.052281380,7.626473904,7.461633682,7.832756042,5.149313450,5.132019997,5.083273411,5.775549889,7.833918095,7.851273537,7.839205742,7.857754707,5.121535778,5.177091122,5.111051083,5.177091122",TLS.Google,91.126,1,Acceptable,Advertisement,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a04:4e42:1d::84,tcp,38546,443,info,15,17,1605289732959160,1605289733287022,1605289733341107,0,0,517,1388,1151,10308,0,0,22897.1,135965,39614.3,1569289984.0,3.2,"46509,46553,392,49783,3591,0,52945,10,1267,1,1272,3,2358,266,496,109019,0,0,1,0,1,105909,5,6,6499,35807,111148,135965,1,2,0",72,430.6,1460,544.3,296293.8,4.0,"80,80,72,589,72,1460,1460,72,72,1460,1230,72,72,165,171,338,72,72,330,138,72,570,72,72,72,110,72,210,72,1460,1460,1460","9,1,1,1,1,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,1,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,6,0,0,0,0","0,1,0,0,1,1,1,0,0,1,1,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,0,1,1,1,1","4.684510231,5.128057957,5.091930866,4.525407314,4.980900764,6.391155720,5.165083408,5.175263882,5.175263882,7.346390247,7.633969307,5.175263882,5.109223843,6.098253250,6.329233170,7.209453583,5.008678436,4.970416069,7.086939812,6.058278084,4.925345421,7.519527912,5.175263882,5.147486210,5.175263882,5.594966412,4.980900764,6.689027309,4.980900764,7.853739262,7.845409870,7.847467899",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:7a6e,tcp,40114,443,info,16,16,1605289733399863,1605289733500742,1605289733511200,0,0,517,1048,1017,8749,0,1,6845.7,45476,12150.2,147627232.0,3.2,"20965,21014,506,37100,8905,1,45476,39,2004,2,1,1,1959,29,12,7,90,33,7803,454,394,31006,1,387,1,22756,38,359,8296,2575,2",72,377.7,1120,441.2,194656.5,4.1,"80,80,72,589,72,1120,1120,72,72,1120,1120,1120,1120,72,72,72,72,113,72,165,171,342,72,72,330,138,72,72,110,72,1120,1120","11,1,1,1,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,1,1,1,0,0,0,0,1,0,0,0,0,1,1,1,1,0,0,0,1,1,1","4.809510231,5.143908501,5.203041553,4.540377140,5.064233780,6.870509624,5.058271885,5.230819225,5.230819225,6.720662117,7.193079948,7.346520901,7.621092319,5.230819225,5.137001038,5.203041553,5.175263882,5.649272442,5.175263405,6.019917488,6.380431175,7.094295502,5.064233780,5.064233780,7.049797535,6.150704861,5.203041077,5.203041553,5.667691708,5.008678436,7.799199581,7.796170235",,,,,,,,"" diff --git a/test/results/flow-analyse/quic_q43.pcap.out b/test/results/flow-analyse/default/pluralsight.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_q43.pcap.out +++ b/test/results/flow-analyse/default/pluralsight.pcap.out diff --git a/test/results/flow-analyse/default/pop3.pcap.out b/test/results/flow-analyse/default/pop3.pcap.out new file mode 100644 index 000000000..d3c71ca39 --- /dev/null +++ b/test/results/flow-analyse/default/pop3.pcap.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.0.4,212.227.15.166,tcp,26383,110,finished,14,18,1377201783749577,1377201784718387,1377201784718464,0,0,66,1460,124,8905,0,67,62506.4,111543,37805.0,1429214336.0,4.6,"48715,48825,52076,85284,79802,1152,96824,99740,95016,92446,96843,111543,96817,82417,95960,94961,97000,96016,95243,97960,1952,51026,3189,67,3235,44696,56453,59665,2391,50284,99",40,324.9,1500,545.2,297234.1,3.5,"52,52,40,97,46,58,66,46,131,52,58,106,131,46,58,46,72,46,132,48,58,1500,40,1500,1500,40,1229,48,58,1500,40,1500","13,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,2,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,5,0,0","0,1,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,1,1,0,1,0,1,1,0,1","4.421030998,4.853535175,4.780641556,5.658839703,4.965921879,5.375223160,5.222204208,4.922443390,5.467526913,5.038779736,5.202809334,5.763947487,5.449919701,4.922443390,5.142296314,4.835486412,5.067367077,4.922443390,5.701879501,4.967222214,5.271774769,6.020136833,4.780641556,5.349530697,5.308346272,4.780641556,5.390463829,4.951495647,5.306257725,5.634154797,4.730641365,5.796863556",POP3,2,0,Unsafe,Email,6,DPI,"22" diff --git a/test/results/flow-analyse/pop3_stls.pcap.out b/test/results/flow-analyse/default/pop3_stls.pcap.out index 4768e25c9..4768e25c9 100644 --- a/test/results/flow-analyse/pop3_stls.pcap.out +++ b/test/results/flow-analyse/default/pop3_stls.pcap.out diff --git a/test/results/flow-analyse/quic_q46.pcap.out b/test/results/flow-analyse/default/pops.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_q46.pcap.out +++ b/test/results/flow-analyse/default/pops.pcapng.out diff --git a/test/results/flow-analyse/pps.pcap.out b/test/results/flow-analyse/default/pps.pcap.out index fe7726ade..5856930ad 100644 --- a/test/results/flow-analyse/pps.pcap.out +++ b/test/results/flow-analyse/default/pps.pcap.out @@ -4,6 +4,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,118.171.15.56,192.168.115.8,udp,5544,22793,info,10,22,1467353136433806,1467353136571752,1467353136559870,1065,0,1065,37,10650,814,0,98,8516.5,26979,8440.4,71240384.0,4.1,"354,233,4927,176,24291,18871,121,5388,6873,160,19127,17570,126,13829,13759,135,13082,15439,116,26979,24414,172,9012,10973,385,1993,887,14115,8282,98,12123",65,386.2,1093,476.5,227043.4,4.0,"1093,65,65,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,22,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,1,1,0,1,1,0","7.718708038,5.110659122,5.110659122,5.055125713,5.055125713,7.786316872,5.085895061,5.085895061,7.777331829,5.172197342,5.172197342,7.830995560,5.055125713,5.055125713,7.799821854,5.043511868,5.043511868,7.781206608,5.055126190,5.055126190,7.756371021,5.172197819,5.172197819,7.778749943,5.141428471,5.141428471,5.018351555,5.018351555,7.782123089,5.141428471,5.141428471,7.801887989",,,,,,,,"" 1,ip4,192.168.115.8,219.228.107.156,udp,22793,1250,info,24,8,1467353136440165,1467353136804834,1467353136804280,37,0,37,1065,888,8520,0,67,23509.2,69635,21390.8,457567520.0,4.2,"416,29926,29688,118,32027,32808,298,45715,281,69635,23035,67,41991,41569,116,35956,327,59526,23042,142,31796,32196,302,44442,309,68337,22748,167,30877,30767,160",65,322.0,1093,445.1,198147.0,3.9,"65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65","0,24,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,1,0,0,1,0,0","5.112839222,5.112839222,7.812224865,5.155221939,5.155221939,7.822898388,5.222122192,5.222122192,5.222122192,5.222122192,7.815716267,5.252891541,5.252891541,7.813511848,5.068920135,5.068920135,5.148970604,5.148970604,7.791888237,5.150506973,5.150506973,7.805237770,5.160583973,5.160583973,5.192889690,5.192889690,7.800968647,5.088968277,5.088968277,7.814544201,4.920591831,4.920591831",,,,,,,,"" 1,ip4,192.168.115.8,222.197.138.12,udp,22793,6956,info,24,8,1467353136439640,1467353136868041,1467353136900861,37,0,37,1065,888,7474,0,67,28697.5,108044,30689.6,941853376.0,4.0,"939,52844,52258,255,55452,67,77746,21970,217,78270,79276,484,437,117,46524,44383,93,18436,18537,325,35971,83,108044,71536,720,28274,507,45891,16142,358,33466",47,289.3,1093,425.3,180865.5,3.8,"65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,65,65,1093,65,65,47","0,24,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,1","5.252891541,5.252891541,7.807993889,5.259143829,5.259143829,5.252891541,5.252891541,7.789888382,5.197358608,5.197358608,7.823671818,4.976612091,4.976612091,5.056662560,5.056662560,7.801744938,5.179739475,5.179739475,7.702906132,5.148970127,5.148970127,5.069812298,5.069812298,7.822528839,5.131350994,5.131350994,5.119737625,5.119737625,7.810484409,5.131350517,5.131350517,4.884167194",,,,,,,,"" -1,ip4,192.168.115.8,223.26.106.19,tcp,50505,80,finished,2,30,1467353189325739,1467353189360764,1467353189374572,144,0,148,1260,292,37052,1,0,2705.1,35765,8658.9,74976944.0,1.8,"2901,35025,35765,2,54,1038,2,1,1,1,1,1,4098,1,1,1,1,0,557,2,0,1,1,4317,82,1,1,1,0,0,1",184,1207.0,1300,293.9,86398.0,4.9,"184,552,188,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300","0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,29,0,0,0,0,0,0,0,0","0,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.565698147,5.713972092,5.579771042,4.387238026,0.303162068,0.301623583,3.732781410,6.116701126,5.907885075,6.110567570,6.000755787,6.220743179,6.106208801,5.965834141,6.086260319,5.932269096,6.297639847,6.179096699,6.268159389,6.412519932,5.845352650,6.157920837,6.009664059,6.058042526,6.120846272,6.430628300,6.278068542,5.995249271,6.119624615,6.003195763,6.359897137,6.283394337",HTTP,7,0,Acceptable,Web,6,DPI,"" -1,ip4,192.168.115.8,223.26.106.20,tcp,50778,80,finished,1,31,1467353196856069,1467353196856069,1467353196981279,249,0,249,1260,249,39060,1,0,4039.0,61439,12542.6,157315936.0,1.8,"61439,3,3,0,1,1,30336,2,1,1,25868,1,0,484,2,1,0,1,574,0,2,3519,3,772,1,1,1,1,0,1,2191",289,1268.4,1300,175.9,30943.1,5.0,"289,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300","0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,31,0,0,0,0,0,0,0,0","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.680209637,7.104508400,7.815409660,7.799874306,7.795087337,7.821745396,7.813271046,7.853199959,7.800473690,7.816552639,7.802090645,7.825591564,7.808625698,7.787723064,7.801823139,7.815733910,7.747669697,7.812804699,7.828133106,7.820801258,7.831765652,7.796298027,7.782429695,7.798837185,7.797708988,7.815753460,7.803283215,7.828951836,7.803116322,7.810623646,7.793246269,7.812668324",HTTP.PPStream,7.54,0,Fun,Streaming,6,DPI,"" -1,ip4,192.168.115.8,223.26.106.20,tcp,50780,80,finished,1,31,1467353198532645,1467353198532645,1467353198686720,249,0,249,1260,249,39060,1,0,4970.2,62853,15415.3,237632432.0,1.7,"62853,7,1,1,1,1,28633,3,0,1,57886,1,1,29,1,1,276,1,0,311,1,3236,49,2,773,2,0,1,1,0,2",289,1268.4,1300,175.9,30943.1,5.0,"289,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300","0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,31,0,0,0,0,0,0,0,0","0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.692187786,7.093656063,7.763891220,7.770260334,7.793470383,7.754670143,7.762333870,7.736806870,7.762505054,7.806702614,7.785463810,7.806148052,7.807487488,7.792947292,7.799264908,7.823724270,7.810103416,7.827909470,7.809601784,7.808609962,7.806282997,7.797142029,7.799598694,7.803467274,7.787366390,7.806374073,7.817587852,7.813340664,7.816604614,7.807970047,7.816948891,7.823331356",HTTP.PPStream,7.54,0,Fun,Streaming,6,DPI,"" diff --git a/test/results/flow-analyse/quic_q46_b.pcap.out b/test/results/flow-analyse/default/pptp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_q46_b.pcap.out +++ b/test/results/flow-analyse/default/pptp.pcap.out diff --git a/test/results/flow-analyse/psiphon3.pcap.out b/test/results/flow-analyse/default/psiphon3.pcap.out index b3deb9cdc..b3deb9cdc 100644 --- a/test/results/flow-analyse/psiphon3.pcap.out +++ b/test/results/flow-analyse/default/psiphon3.pcap.out diff --git a/test/results/flow-analyse/quic_q50.pcap.out b/test/results/flow-analyse/default/punycode-idn.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_q50.pcap.out +++ b/test/results/flow-analyse/default/punycode-idn.pcap.out diff --git a/test/results/flow-analyse/quic_t50.pcap.out b/test/results/flow-analyse/default/quic-23.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_t50.pcap.out +++ b/test/results/flow-analyse/default/quic-23.pcap.out diff --git a/test/results/flow-analyse/quic_t51.pcap.out b/test/results/flow-analyse/default/quic-24.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/quic_t51.pcap.out +++ b/test/results/flow-analyse/default/quic-24.pcap.out diff --git a/test/results/flow-analyse/radius_false_positive.pcapng.out b/test/results/flow-analyse/default/quic-27.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/radius_false_positive.pcapng.out +++ b/test/results/flow-analyse/default/quic-27.pcap.out diff --git a/test/results/flow-analyse/quic-28.pcap.out b/test/results/flow-analyse/default/quic-28.pcap.out index 921b8913e..ca475b535 100644 --- a/test/results/flow-analyse/quic-28.pcap.out +++ b/test/results/flow-analyse/default/quic-28.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.9.0.2,104.26.11.240,udp,60106,443,finished,13,19,1591267474847575,1591267474935131,1591267474949617,43,0,1200,1197,4297,5362,0,2,6116.1,20960,7174.9,51478880.0,3.9,"13634,13791,13932,1053,15111,1394,4,2,2195,342,15,8,10,14715,11,4,4,3,4,4,3,13849,1181,10523,11750,5487,19948,6547,20960,4038,19076",71,329.8,1228,425.6,181138.2,4.0,"1228,75,1228,99,189,1228,1224,1225,245,138,89,71,71,154,98,543,71,71,96,71,71,71,71,71,686,71,133,71,845,71,108,72","0,6,1,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0","0,9,3,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,1,1,0,0,0,0,0,1,1,1,1,1,1,1,1,0,1,1,0,0,1,1,0,0,1","7.825420856,5.391368389,7.839229107,6.043497086,6.731246471,7.843968391,7.815639019,7.852266788,7.065521240,6.543905735,6.067143917,5.873550892,5.873550892,6.748120308,6.120771885,7.600786686,5.845381737,5.732706547,6.072868347,5.683273315,5.722074032,5.818619251,5.778411865,5.760875225,7.744878292,5.750242710,6.580695629,5.778411865,7.773950577,5.873550892,6.249063969,5.721802711",QUIC,188,1,Acceptable,Web,6,DPI,"" +1,ip4,10.9.0.2,104.26.11.240,udp,60106,443,finished,13,19,1591267474847575,1591267474935131,1591267474949617,43,0,1200,1197,4297,5362,0,2,6116.1,20960,7174.9,51478880.0,3.9,"13634,13791,13932,1053,15111,1394,4,2,2195,342,15,8,10,14715,11,4,4,3,4,4,3,13849,1181,10523,11750,5487,19948,6547,20960,4038,19076",71,329.8,1228,425.6,181138.2,4.0,"1228,75,1228,99,189,1228,1224,1225,245,138,89,71,71,154,98,543,71,71,96,71,71,71,71,71,686,71,133,71,845,71,108,72","0,6,1,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0","0,9,3,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,1,1,0,0,0,0,0,1,1,1,1,1,1,1,1,0,1,1,0,0,1,1,0,0,1","7.825420856,5.391368389,7.839229107,6.043497086,6.731246471,7.843968391,7.815639019,7.852266788,7.065521240,6.543905735,6.067143917,5.873550892,5.873550892,6.748120308,6.120771885,7.600786686,5.845381737,5.732706547,6.072868347,5.683273315,5.722074032,5.818619251,5.778411865,5.760875225,7.744878292,5.750242710,6.580695629,5.778411865,7.773950577,5.873550892,6.249063969,5.721802711",QUIC,188,1,Acceptable,Web,6,DPI,"46" diff --git a/test/results/flow-analyse/raknet.pcap.out b/test/results/flow-analyse/default/quic-29.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/raknet.pcap.out +++ b/test/results/flow-analyse/default/quic-29.pcap.out diff --git a/test/results/flow-analyse/riotgames.pcap.out b/test/results/flow-analyse/default/quic-33.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/riotgames.pcap.out +++ b/test/results/flow-analyse/default/quic-33.pcapng.out diff --git a/test/results/flow-analyse/rsh-syslog-false-positive.pcap.out b/test/results/flow-analyse/default/quic-34.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/rsh-syslog-false-positive.pcap.out +++ b/test/results/flow-analyse/default/quic-34.pcap.out diff --git a/test/results/flow-analyse/rsh.pcap.out b/test/results/flow-analyse/default/quic-fuzz-overflow.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/rsh.pcap.out +++ b/test/results/flow-analyse/default/quic-fuzz-overflow.pcapng.out diff --git a/test/results/flow-analyse/quic-mvfst-22.pcap.out b/test/results/flow-analyse/default/quic-mvfst-22.pcap.out index 40311ad48..e23477c00 100644 --- a/test/results/flow-analyse/quic-mvfst-22.pcap.out +++ b/test/results/flow-analyse/default/quic-mvfst-22.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,10.0.2.15,31.13.86.8,udp,35601,443,finished,12,20,24710880,27201767,27283563,31,0,1232,1252,6836,11997,0,0,163341.0,2090987,507077.5,257127612416.0,2.1,"6626,174,24,23,15783,192,68,25740,0,16544,24398,2090987,2072824,30640,212689,1822,115,243417,45,25374,21896,80671,49,21,8,9,96673,35817,60860,70,11",52,616.5,1280,577.0,332915.8,4.3,"1260,1280,1280,221,81,1260,106,95,66,261,59,52,1128,56,60,598,1260,1221,56,56,60,52,1280,1280,1280,1280,84,65,52,1280,1280,1280","1,3,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,3,0,0,0,0,0,0,0,0,0","6,3,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0","0,1,1,1,1,0,0,0,1,1,0,1,0,1,0,0,0,0,1,1,0,1,1,1,1,1,1,0,1,1,1,1","7.865873814,7.840335846,7.856841087,6.935217857,5.841008663,7.844548225,5.975329399,6.068257332,5.408033371,7.120600224,5.413970470,5.168682098,7.824946880,5.206433296,5.433454037,7.633729935,7.839689255,7.820494652,5.385004520,5.200210571,5.379368782,5.130220413,7.847099781,7.835284233,7.857980728,7.824029922,5.854679585,5.473884106,5.168681622,7.866020203,7.849047184,7.840563774",QUIC.Facebook,188.119,1,Fun,SocialNetwork,6,DPI,"" +1,ip4,10.0.2.15,31.13.86.8,udp,35601,443,finished,12,20,24710880,27201767,27283563,31,0,1232,1252,6836,11997,0,0,163341.0,2090987,507077.5,257127612416.0,2.1,"6626,174,24,23,15783,192,68,25740,0,16544,24398,2090987,2072824,30640,212689,1822,115,243417,45,25374,21896,80671,49,21,8,9,96673,35817,60860,70,11",52,616.5,1280,577.0,332915.8,4.3,"1260,1280,1280,221,81,1260,106,95,66,261,59,52,1128,56,60,598,1260,1221,56,56,60,52,1280,1280,1280,1280,84,65,52,1280,1280,1280","1,3,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,3,0,0,0,0,0,0,0,0,0","6,3,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0","0,1,1,1,1,0,0,0,1,1,0,1,0,1,0,0,0,0,1,1,0,1,1,1,1,1,1,0,1,1,1,1","7.865873814,7.840335846,7.856841087,6.935217857,5.841008663,7.844548225,5.975329399,6.068257332,5.408033371,7.120600224,5.413970470,5.168682098,7.824946880,5.206433296,5.433454037,7.633729935,7.839689255,7.820494652,5.385004520,5.200210571,5.379368782,5.130220413,7.847099781,7.835284233,7.857980728,7.824029922,5.854679585,5.473884106,5.168681622,7.866020203,7.849047184,7.840563774",QUIC.Facebook,188.119,1,Fun,SocialNetwork,6,DPI,"46" diff --git a/test/results/flow-analyse/rsync.pcap.out b/test/results/flow-analyse/default/quic-mvfst-22_decryption_error.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/rsync.pcap.out +++ b/test/results/flow-analyse/default/quic-mvfst-22_decryption_error.pcap.out diff --git a/test/results/flow-analyse/rtmp.pcap.out b/test/results/flow-analyse/default/quic-mvfst-27.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/rtmp.pcap.out +++ b/test/results/flow-analyse/default/quic-mvfst-27.pcapng.out diff --git a/test/results/flow-analyse/rtsp_setup_http.pcapng.out b/test/results/flow-analyse/default/quic-mvfst-exp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/rtsp_setup_http.pcapng.out +++ b/test/results/flow-analyse/default/quic-mvfst-exp.pcap.out diff --git a/test/results/flow-analyse/salesforce.pcap.out b/test/results/flow-analyse/default/quic-v2-01.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/salesforce.pcap.out +++ b/test/results/flow-analyse/default/quic-v2-01.pcapng.out diff --git a/test/results/flow-analyse/quic.pcap.out b/test/results/flow-analyse/default/quic.pcap.out index 5e6acde97..35b503f30 100644 --- a/test/results/flow-analyse/quic.pcap.out +++ b/test/results/flow-analyse/default/quic.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.109,216.58.212.101,udp,57833,443,finished,16,16,1431155536815947,1431155545866860,1431155545859249,37,0,1350,1350,4333,4661,0,7,583684.4,3197585,963931.8,929164558336.0,3.4,"46000,60057,14787,65380,2487,93393,168067,168088,622738,681338,42,58036,3119141,3197585,40,12,54064,25544,1951118,28580,2034695,28303,25,7,56884,470823,496378,2190158,2289756,44685,126004",47,309.1,1378,382.9,146578.8,4.1,"1378,464,1378,65,60,711,68,711,65,200,494,56,68,180,156,55,87,68,65,241,149,63,57,226,47,74,201,65,1176,63,744,455","0,8,0,1,1,1,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0","4,4,0,0,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,0,1,0,1,1,0,1,0,0,1,1,0,0,1,1,1,0,0,0,0,1,1,1,1,0,1,0,0,1,1,0","4.785362720,7.506221294,7.842458248,5.653138161,5.515064240,7.661302567,5.705106735,7.653655529,5.683907509,6.901843548,7.549375057,5.423249722,5.793341637,6.893099785,6.626470089,5.353907585,6.017427444,5.664593697,5.555222511,7.050589561,6.613369942,5.496887207,5.372109413,7.016873360,5.139485359,5.793843269,6.920541286,5.579985619,7.860387802,5.401647568,7.762588978,7.570559025",QUIC.GMail,188.122,1,Acceptable,Email,6,DPI,"" -1,ip4,192.168.1.109,216.58.210.206,udp,35236,443,finished,12,20,1463075953299562,1463075954259331,1463075954259852,37,0,1350,1350,3706,22849,0,11,61937.4,828641,198595.2,39440068608.0,2.0,"565,35358,43,40485,132,24017,25957,16828,62,532,35459,51659,446,11,26638,25576,828641,25,803246,620,371,204,811,210,360,238,291,204,540,286,244",61,857.8,1378,620.8,385421.5,4.5,"1378,373,1378,1378,1378,369,65,68,1378,61,61,71,1378,1378,1174,68,65,1378,1378,68,1378,1378,1378,68,1378,68,1378,1378,1378,68,1378,1378","0,8,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,16,0,0,0,0,0","0,0,1,1,0,0,1,0,1,1,1,0,1,1,1,0,0,1,1,0,1,1,1,0,1,0,1,1,1,0,1,1","5.050794601,7.427186489,7.589700222,2.645882607,5.424244404,7.418235779,5.309068680,5.493865013,7.858019829,5.512544155,5.545331001,5.716576576,7.892964363,7.881204605,7.816042900,5.554157257,5.641524315,7.888419628,7.861907005,5.675695419,7.860325336,7.873119831,7.856549263,5.635182381,7.861664295,5.694005013,7.863921165,7.839401245,7.861547947,5.558049202,7.862613201,7.852869511",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"" +1,ip4,192.168.1.109,216.58.212.101,udp,57833,443,finished,16,16,1431155536815947,1431155545866860,1431155545859249,37,0,1350,1350,4333,4661,0,7,583684.4,3197585,963931.8,929164558336.0,3.4,"46000,60057,14787,65380,2487,93393,168067,168088,622738,681338,42,58036,3119141,3197585,40,12,54064,25544,1951118,28580,2034695,28303,25,7,56884,470823,496378,2190158,2289756,44685,126004",47,309.1,1378,382.9,146578.8,4.1,"1378,464,1378,65,60,711,68,711,65,200,494,56,68,180,156,55,87,68,65,241,149,63,57,226,47,74,201,65,1176,63,744,455","0,8,0,1,1,1,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0","4,4,0,0,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,0,1,0,1,1,0,1,0,0,1,1,0,0,1,1,1,0,0,0,0,1,1,1,1,0,1,0,0,1,1,0","4.785362720,7.506221294,7.842458248,5.653138161,5.515064240,7.661302567,5.705106735,7.653655529,5.683907509,6.901843548,7.549375057,5.423249722,5.793341637,6.893099785,6.626470089,5.353907585,6.017427444,5.664593697,5.555222511,7.050589561,6.613369942,5.496887207,5.372109413,7.016873360,5.139485359,5.793843269,6.920541286,5.579985619,7.860387802,5.401647568,7.762588978,7.570559025",QUIC.GMail,188.122,1,Acceptable,Email,6,DPI,"46" +1,ip4,192.168.1.109,216.58.210.206,udp,35236,443,finished,12,20,1463075953299562,1463075954259331,1463075954259852,37,0,1350,1350,3706,22849,0,11,61937.4,828641,198595.2,39440068608.0,2.0,"565,35358,43,40485,132,24017,25957,16828,62,532,35459,51659,446,11,26638,25576,828641,25,803246,620,371,204,811,210,360,238,291,204,540,286,244",61,857.8,1378,620.8,385421.5,4.5,"1378,373,1378,1378,1378,369,65,68,1378,61,61,71,1378,1378,1174,68,65,1378,1378,68,1378,1378,1378,68,1378,68,1378,1378,1378,68,1378,1378","0,8,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,16,0,0,0,0,0","0,0,1,1,0,0,1,0,1,1,1,0,1,1,1,0,0,1,1,0,1,1,1,0,1,0,1,1,1,0,1,1","5.050794601,7.427186489,7.589700222,2.645882607,5.424244404,7.418235779,5.309068680,5.493865013,7.858019829,5.512544155,5.545331001,5.716576576,7.892964363,7.881204605,7.816042900,5.554157257,5.641524315,7.888419628,7.861907005,5.675695419,7.860325336,7.873119831,7.856549263,5.635182381,7.861664295,5.694005013,7.863921165,7.839401245,7.861547947,5.558049202,7.862613201,7.852869511",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"46" diff --git a/test/results/flow-analyse/quic046.pcap.out b/test/results/flow-analyse/default/quic046.pcap.out index 796bd2480..2dd95db4f 100644 --- a/test/results/flow-analyse/quic046.pcap.out +++ b/test/results/flow-analyse/default/quic046.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.236,216.58.206.86,udp,50587,443,finished,13,19,1584456191933380,1584456191967570,1584456191967633,28,0,1350,1350,4485,23197,0,176,2207.8,29469,6263.4,39229868.0,2.6,"987,559,560,557,592,573,584,606,710,21225,29469,423,216,240,242,250,248,254,253,253,237,265,240,242,256,252,6530,176,509,707,228",48,893.1,1378,591.6,350034.9,4.6,"1378,560,114,187,185,185,186,185,191,188,1378,1378,255,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,56,48,1378,56,1378","2,0,1,0,5,2,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,0,1","4.104627609,7.586378098,6.310873032,6.874300003,6.880319118,6.833760738,6.876335144,6.910101891,6.969146729,6.870172024,4.098705292,7.858126640,7.073942184,7.867921352,7.889789104,7.868343830,7.839922428,7.858704567,7.859090805,7.875567436,7.864448547,7.848357201,7.879473686,7.877913952,7.860894203,7.857960701,7.861531734,5.436729908,5.095174789,7.816503525,5.401014805,7.861771584",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"" +1,ip4,192.168.1.236,216.58.206.86,udp,50587,443,finished,13,19,1584456191933380,1584456191967570,1584456191967633,28,0,1350,1350,4485,23197,0,176,2207.8,29469,6263.4,39229868.0,2.6,"987,559,560,557,592,573,584,606,710,21225,29469,423,216,240,242,250,248,254,253,253,237,265,240,242,256,252,6530,176,509,707,228",48,893.1,1378,591.6,350034.9,4.6,"1378,560,114,187,185,185,186,185,191,188,1378,1378,255,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,56,48,1378,56,1378","2,0,1,0,5,2,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,17,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,0,1,1,0,1","4.104627609,7.586378098,6.310873032,6.874300003,6.880319118,6.833760738,6.876335144,6.910101891,6.969146729,6.870172024,4.098705292,7.858126640,7.073942184,7.867921352,7.889789104,7.868343830,7.839922428,7.858704567,7.859090805,7.875567436,7.864448547,7.848357201,7.879473686,7.877913952,7.860894203,7.857960701,7.861531734,5.436729908,5.095174789,7.816503525,5.401014805,7.861771584",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"46" diff --git a/test/results/flow-analyse/sccp_hw_conf_register.pcapng.out b/test/results/flow-analyse/default/quic_0RTT.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/sccp_hw_conf_register.pcapng.out +++ b/test/results/flow-analyse/default/quic_0RTT.pcap.out diff --git a/test/results/flow-analyse/sctp.cap.out b/test/results/flow-analyse/default/quic_crypto_aes_auth_size.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/sctp.cap.out +++ b/test/results/flow-analyse/default/quic_crypto_aes_auth_size.pcap.out diff --git a/test/results/flow-analyse/selfsigned.pcap.out b/test/results/flow-analyse/default/quic_frags_ch_in_multiple_packets.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/selfsigned.pcap.out +++ b/test/results/flow-analyse/default/quic_frags_ch_in_multiple_packets.pcapng.out diff --git a/test/results/flow-analyse/sflow.pcap.out b/test/results/flow-analyse/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/sflow.pcap.out +++ b/test/results/flow-analyse/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out diff --git a/test/results/flow-analyse/sip_hello.pcapng.out b/test/results/flow-analyse/default/quic_interop_V.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/sip_hello.pcapng.out +++ b/test/results/flow-analyse/default/quic_interop_V.pcapng.out diff --git a/test/results/flow-analyse/quic_q39.pcap.out b/test/results/flow-analyse/default/quic_q39.pcap.out index 965e5a651..ab1560e7e 100644 --- a/test/results/flow-analyse/quic_q39.pcap.out +++ b/test/results/flow-analyse/default/quic_q39.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,170.216.16.209,21.157.183.227,udp,38620,443,finished,16,16,1509098995610775,1509099004752497,1509099004382425,41,0,1350,1350,14377,2074,0,7,577850.7,6514643,1531988.4,2346988339200.0,2.7,"8931,36678,89781,7,404130,1367,298294,119221,31,434781,6185342,12819,6514643,11351,11378,22730,702601,702694,435266,435159,11351,11442,16019,15861,397203,9235,397732,33897,93428,52,499948",46,542.2,1378,603.7,364512.4,4.1,"1378,1160,63,1378,59,69,69,58,291,46,69,256,1378,64,1378,1378,61,1378,60,1378,62,1378,62,1378,62,1378,716,62,62,90,46,84","0,4,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,9,0,0,0,0,0","4,10,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,0,1,1,1,0,0,1,1,1,0,0,0,1,0,0,1,0,1,0,1,0,1,0,1,0,0,1,1,1,1,0","4.179285526,7.832315445,4.966748714,7.846248627,5.380072594,5.640916824,5.720768929,5.299251080,7.336034775,4.816403389,5.818665504,7.074090958,7.867320538,5.431150436,7.827050686,7.874505997,5.477433681,7.859999657,5.412702084,7.863677979,5.373553276,7.855113029,5.379174232,7.856376648,5.502585888,7.846080780,7.718618870,5.508206844,5.470327377,6.029057026,4.816403389,5.969577789",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"" +1,ip4,170.216.16.209,21.157.183.227,udp,38620,443,finished,16,16,1509098995610775,1509099004752497,1509099004382425,41,0,1350,1350,14377,2074,0,7,577850.7,6514643,1531988.4,2346988339200.0,2.7,"8931,36678,89781,7,404130,1367,298294,119221,31,434781,6185342,12819,6514643,11351,11378,22730,702601,702694,435266,435159,11351,11442,16019,15861,397203,9235,397732,33897,93428,52,499948",46,542.2,1378,603.7,364512.4,4.1,"1378,1160,63,1378,59,69,69,58,291,46,69,256,1378,64,1378,1378,61,1378,60,1378,62,1378,62,1378,62,1378,716,62,62,90,46,84","0,4,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,9,0,0,0,0,0","4,10,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0","0,0,1,1,1,0,0,1,1,1,0,0,0,1,0,0,1,0,1,0,1,0,1,0,1,0,0,1,1,1,1,0","4.179285526,7.832315445,4.966748714,7.846248627,5.380072594,5.640916824,5.720768929,5.299251080,7.336034775,4.816403389,5.818665504,7.074090958,7.867320538,5.431150436,7.827050686,7.874505997,5.477433681,7.859999657,5.412702084,7.863677979,5.373553276,7.855113029,5.379174232,7.856376648,5.502585888,7.846080780,7.718618870,5.508206844,5.470327377,6.029057026,4.816403389,5.969577789",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"46" diff --git a/test/results/flow-analyse/skype_udp.pcap.out b/test/results/flow-analyse/default/quic_q43.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/skype_udp.pcap.out +++ b/test/results/flow-analyse/default/quic_q43.pcap.out diff --git a/test/results/flow-analyse/smb_frags.pcap.out b/test/results/flow-analyse/default/quic_q46.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/smb_frags.pcap.out +++ b/test/results/flow-analyse/default/quic_q46.pcap.out diff --git a/test/results/flow-analyse/smbv1.pcap.out b/test/results/flow-analyse/default/quic_q46_b.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/smbv1.pcap.out +++ b/test/results/flow-analyse/default/quic_q46_b.pcap.out diff --git a/test/results/flow-analyse/smpp_in_general.pcap.out b/test/results/flow-analyse/default/quic_q50.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/smpp_in_general.pcap.out +++ b/test/results/flow-analyse/default/quic_q50.pcap.out diff --git a/test/results/flow-analyse/smtps.pcapng.out b/test/results/flow-analyse/default/quic_t50.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/smtps.pcapng.out +++ b/test/results/flow-analyse/default/quic_t50.pcap.out diff --git a/test/results/flow-analyse/snapchat.pcap.out b/test/results/flow-analyse/default/quic_t51.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/snapchat.pcap.out +++ b/test/results/flow-analyse/default/quic_t51.pcap.out diff --git a/test/results/flow-analyse/quickplay.pcap.out b/test/results/flow-analyse/default/quickplay.pcap.out index d6a9285c3..d6a9285c3 100644 --- a/test/results/flow-analyse/quickplay.pcap.out +++ b/test/results/flow-analyse/default/quickplay.pcap.out diff --git a/test/results/flow-analyse/snmp.pcap.out b/test/results/flow-analyse/default/radius_false_positive.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/snmp.pcap.out +++ b/test/results/flow-analyse/default/radius_false_positive.pcapng.out diff --git a/test/results/flow-analyse/soap.pcap.out b/test/results/flow-analyse/default/raknet.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/soap.pcap.out +++ b/test/results/flow-analyse/default/raknet.pcap.out diff --git a/test/results/flow-analyse/rdp.pcap.out b/test/results/flow-analyse/default/rdp.pcap.out index 15de7d326..15de7d326 100644 --- a/test/results/flow-analyse/rdp.pcap.out +++ b/test/results/flow-analyse/default/rdp.pcap.out diff --git a/test/results/flow-analyse/reasm_crash_anon.pcapng.out b/test/results/flow-analyse/default/reasm_crash_anon.pcapng.out index dc6317e03..dc6317e03 100644 --- a/test/results/flow-analyse/reasm_crash_anon.pcapng.out +++ b/test/results/flow-analyse/default/reasm_crash_anon.pcapng.out diff --git a/test/results/flow-analyse/reasm_segv_anon.pcapng.out b/test/results/flow-analyse/default/reasm_segv_anon.pcapng.out index d870881d9..0dfa9fc31 100644 --- a/test/results/flow-analyse/reasm_segv_anon.pcapng.out +++ b/test/results/flow-analyse/default/reasm_segv_anon.pcapng.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,145.76.2.236,187.96.52.85,udp,2152,2152,finished,9,23,1550422828553466,1550422833287234,1550422833289770,64,0,80,1448,640,27912,0,1,305486.2,1859119,563984.9,318078976000.0,3.1,"396021,83822,1376171,124,2,2,1,3,2,2,113,124,1859119,964928,439709,439658,123,2,1,1,1,121,163901,20078,1615354,1799040,121,3,155764,155637,124",76,920.2,1476,651.3,424215.9,4.5,"92,92,92,1476,1476,1476,1476,1476,1476,1476,1476,1476,1476,100,1476,100,1476,1476,1476,1476,1372,1476,1476,108,108,100,76,388,1164,100,76,388","0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,17,0,0","0,0,0,1,1,1,1,1,1,1,1,1,1,0,1,0,1,1,1,1,1,1,1,0,0,0,1,1,1,0,1,1","5.396138191,5.404344082,5.439617157,7.876337528,7.839885235,7.778254986,7.872960091,7.839048862,7.805950642,7.829119205,7.848347187,7.849987984,7.779471874,5.402985096,7.775711060,5.441986561,7.838281155,7.873279095,7.848281860,7.860656261,7.849815845,7.850412846,7.844122410,5.518630505,5.537148952,5.382984638,5.187358379,7.340617657,7.811021328,5.454438686,5.151109695,7.382753849",GTP.GTP_U,152.271,0,Acceptable,Network,6,DPI,"" +1,ip4,145.76.2.236,187.96.52.85,udp,2152,2152,finished,9,23,1550422828553466,1550422833287234,1550422833289770,64,0,80,1448,640,27912,0,1,305486.2,1859119,563984.9,318078976000.0,3.1,"396021,83822,1376171,124,2,2,1,3,2,2,113,124,1859119,964928,439709,439658,123,2,1,1,1,121,163901,20078,1615354,1799040,121,3,155764,155637,124",76,920.2,1476,651.3,424215.9,4.5,"92,92,92,1476,1476,1476,1476,1476,1476,1476,1476,1476,1476,100,1476,100,1476,1476,1476,1476,1372,1476,1476,108,108,100,76,388,1164,100,76,388","0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,17,0,0","0,0,0,1,1,1,1,1,1,1,1,1,1,0,1,0,1,1,1,1,1,1,1,0,0,0,1,1,1,0,1,1","5.396138191,5.404344082,5.439617157,7.876337528,7.839885235,7.778254986,7.872960091,7.839048862,7.805950642,7.829119205,7.848347187,7.849987984,7.779471874,5.402985096,7.775711060,5.441986561,7.838281155,7.873279095,7.848281860,7.860656261,7.849815845,7.850412846,7.844122410,5.518630505,5.537148952,5.382984638,5.187358379,7.340617657,7.811021328,5.454438686,5.151109695,7.382753849",GTP.GTP_U,152.271,0,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/reddit.pcap.out b/test/results/flow-analyse/default/reddit.pcap.out index 38a643d5b..dd0722254 100644 --- a/test/results/flow-analyse/reddit.pcap.out +++ b/test/results/flow-analyse/default/reddit.pcap.out @@ -1,14 +1,9 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80a::200a,tcp,40028,443,finished,16,16,1605291684451133,1605291684654464,1605291684654375,0,0,824,1208,2166,4508,0,0,13115.3,75646,23104.5,533820192.0,3.2,"24940,24984,493,75646,0,1,1,75219,11,11,8777,4975,582,741,37567,3490,25948,1187,485,1611,1121,59921,1,0,1,1,0,1,58810,38,10",72,281.1,1280,342.1,117045.1,4.2,"80,80,72,589,72,1280,1280,572,72,72,72,136,164,896,710,72,652,72,72,103,72,103,72,72,384,422,285,111,139,72,72,72","11,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,1,0,0,0,1,0,0,1,1,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,1,1,0,1,1,0,0,1,1,1,1,1,1,1,0,0,0","4.711516857,5.217300892,5.071401596,4.609335899,4.946592331,7.806063652,7.848966122,7.544353485,5.166606426,5.045011044,5.138829231,6.070029259,6.486535549,7.761092186,7.700193405,5.014019012,7.592603683,5.138829231,5.097352028,5.692110538,5.138829231,5.768221378,5.097352028,5.041796684,7.336868286,7.405985832,7.111319542,5.950567245,6.190017700,5.111051083,5.111051559,5.081305504",TLS.GoogleServices,91.239,1,Acceptable,Web,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:798c,tcp,56558,443,info,14,18,1605291684452132,1605291685883411,1605291685884221,0,0,517,1048,1120,9354,0,0,92366.7,1287577,306947.3,94216675328.0,1.8,"33174,33242,863,66592,1,1,1,1,65678,11,9,6,13203,712,517,42062,2,0,27621,483,471,1369,59921,136,1228856,1287577,855,2,1,1,0",72,399.8,1120,437.6,191482.0,4.2,"80,80,72,589,72,1120,1120,1120,587,72,72,72,72,165,171,445,72,330,72,72,138,72,110,72,72,1120,72,1120,1120,1120,203,1120","9,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,1,0,1,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,1,0,0,0,0,0,0,0,1,1,1,0,1,0,0,1,1,1,0,1,1,1,1,1","4.907011032,5.304951668,5.190349579,4.499736786,5.055853844,6.898099899,7.358309269,7.317547321,7.583971977,5.273682594,5.245904922,5.273682594,5.273682594,6.093073368,6.340588570,7.416254044,5.083631516,7.073973179,5.083631516,5.218127251,6.225534439,5.218127251,5.702238560,5.055853844,5.111409664,7.793631554,5.218127251,7.806817532,7.807598114,7.795763016,6.697732925,7.803894997",,,,,,,,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:798c,tcp,56578,443,info,15,17,1605291686060652,1605291686199280,1605291686201936,0,0,517,1048,1550,9238,0,0,9029.4,48292,15572.2,242494768.0,3.2,"38700,38720,198,38531,1,38345,41,14,329,0,334,4,2216,2804,187,210,6465,48292,2910,39329,6844,2704,1,9551,251,801,2129,0,0,1,0",72,409.6,1120,435.5,189657.0,4.2,"80,80,72,589,72,1120,72,1120,72,1120,602,72,72,165,171,436,468,115,72,330,72,72,72,138,72,110,72,1120,1120,1120,1120,1120","8,2,1,1,0,0,0,0,0,0,0,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,0,0,0,0,0,1,1,0,1,1,1,0,0,1,1,1,1,1,1","4.734510422,5.203058243,5.273682594,4.560284615,5.139187336,6.919415474,5.273682594,7.320698738,5.273682594,7.355862617,7.598192215,5.301460266,5.301460266,6.043826580,6.386544228,7.400215149,7.219000340,5.771939278,5.139187336,7.067717552,5.190349579,5.055854321,5.055854321,6.171116352,5.245904922,5.665874481,5.111409664,7.825948715,7.822474480,7.825513840,7.821124554,7.834854126",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:798c,tcp,56592,443,info,16,16,1605291686084954,1605291686233012,1605291686233017,0,0,517,1048,1107,8188,0,0,9552.3,52464,18854.0,355471904.0,2.8,"44627,44653,347,50980,1843,1,0,0,52464,10,3,2,2413,668,102,121,49031,1,45760,75,169,1186,0,1,1,1443,16,7,133,49,15",72,363.0,1120,422.8,178733.3,4.1,"80,80,72,589,72,1120,1120,1120,602,72,72,72,72,165,171,389,153,72,330,72,72,72,138,72,1120,1118,72,72,72,1120,72,1120","11,0,2,1,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,1,0,0,0,0,0,0,0,0,1,1,0,1,1,1,1,1,1,0,0,0,1,0,1","4.907011986,5.354953289,5.301460266,4.552157402,5.139187336,6.938700199,7.322981834,7.354511738,7.534717083,5.245904922,5.218127251,5.245904922,5.273682594,6.089848042,6.412801743,7.335155964,6.124976635,5.139187336,7.085140228,5.273682594,5.111409664,5.028076649,6.191080093,5.111409664,7.845114708,7.817538738,5.273682594,5.245904922,5.263197899,7.819205284,5.245904922,7.795106411",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:798c,tcp,56594,443,info,17,15,1605291686301196,1605291686469619,1605291686468646,0,0,517,1048,1078,8227,0,0,10834.6,91996,22155.6,490868928.0,2.8,"25838,25880,395,66367,26055,91996,835,0,0,829,7,4,1579,121,254,42141,1,1,6209,0,2,0,0,1,46395,10,6,2,1,4,940",72,363.3,1120,424.0,179781.3,4.1,"80,80,72,589,72,1120,72,1120,1120,623,72,72,72,165,171,403,72,72,72,346,138,1120,1120,1120,1120,72,72,72,72,72,72,110","12,1,1,1,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0","4.907011986,5.304953098,5.301460266,4.568593025,5.139187336,6.968538761,5.258596897,7.334045410,7.344312668,7.577483654,5.301460266,5.329237938,5.301460266,6.086132526,6.472829342,7.337939262,5.128702641,5.166965008,5.166965008,7.241396427,6.241778851,7.834823132,7.795830250,7.800470352,7.816886902,5.273682594,5.301460266,5.273682594,5.329237938,5.301460266,5.329237938,5.684057236",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:805::2002,tcp,50960,443,finished,16,16,1605291686985114,1605291687110047,1605291687110135,0,0,517,1208,965,10234,0,0,8063.0,43636,14163.2,200595904.0,3.1,"31477,31507,233,36835,7050,0,43636,16,599,576,2431,165,135,37718,689,1069,36764,111,89,22,531,8580,9121,90,75,174,0,158,5,98,0",72,422.5,1280,490.0,240053.7,4.1,"80,80,72,589,72,1280,1280,72,72,533,72,136,164,333,72,72,652,72,103,72,103,72,778,72,1280,72,1280,1280,72,72,1280,1280","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,0,0,0,0,1,1,1,0,1,0,0,1,1,0,1,0,1,1,0,0,1,1","4.794175148,5.301737785,5.137723446,4.609352589,5.163392067,7.822265148,7.828993320,5.193279266,5.193279266,7.574356556,5.165501595,6.187675953,6.451539040,7.193062782,5.135614395,5.135614395,7.646523952,5.182794571,5.842692375,5.165501595,5.903290272,5.163392067,7.712309837,5.193279266,7.843823910,5.165501595,7.846527100,7.838549614,5.193279266,5.165501118,7.822370052,7.826137066",TLS.GoogleServices,91.239,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::df9:21c6,tcp,43492,443,info,17,15,1605291686985710,1605291687112023,1605291687112006,0,0,517,1388,962,11490,0,0,8148.7,51019,15066.4,226995168.0,3.0,"38538,38619,398,37312,14166,1,0,0,1,51019,20,3,2,2,2408,107,140,31274,2,1645,1,30239,111,3355,1,0,0,3233,8,2,2",72,461.6,1460,586.5,343946.1,4.0,"80,80,72,589,72,1460,1460,1460,1460,387,72,72,72,72,72,136,164,330,72,72,72,143,72,103,1460,1460,1460,1460,72,72,72,72","13,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0","0,1,0,0,1,1,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,0,0,1,1,1,1,0,0,0,0","4.836891651,5.211080551,5.205674171,4.514605999,5.057240963,7.814661026,7.847680092,7.865528107,7.842185020,7.380033970,5.243936539,5.243936539,5.155763149,5.188381195,5.132825851,6.139283180,6.518441677,7.254546165,5.029463291,5.029463291,5.057240963,6.252353668,5.243936539,5.873327255,7.877524853,7.827719688,7.871821880,7.839930534,5.243936539,5.243936539,5.271714211,5.271714211",,,,,,,,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::6853:b3b6,tcp,38320,443,finished,15,17,1605291686996891,1605291687186026,1605291687186023,0,0,517,1388,998,10536,0,0,12202.2,72269,18508.9,342577632.0,3.4,"27356,27416,299,37313,35299,1,0,72269,38,3,2523,128,130,31242,0,2117,15088,1,0,45626,28,24,154,29754,10263,39831,697,0,0,1,666",72,432.9,1460,553.5,306346.9,4.0,"80,80,72,589,72,1460,1460,310,72,72,72,152,164,350,72,72,72,343,343,142,72,72,72,103,72,1460,72,1445,1460,1445,1460,72","11,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,1,0,0,0,0,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,5,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,1,1,0,0,0,0,1,1,0,1,1,1,1,0","4.857011795,5.304952145,5.190349579,4.366506100,5.111409664,7.825345039,7.835193157,7.203350067,5.273682594,5.245904922,5.245904922,6.284915447,6.470990181,7.367970467,5.111409664,5.139187336,5.055853844,7.210521698,7.280154705,6.282705784,5.207642555,5.273682594,5.245904922,5.913538456,5.139187336,7.867059231,5.245904922,7.855923176,7.844721794,7.856983662,7.858796120,5.273682594",TLS,91,1,Safe,Web,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::acd9:12c2,tcp,51026,443,finished,16,16,1605291687485783,1605291687606682,1605291687608302,0,0,517,1388,978,10865,0,0,7852.2,49462,14324.2,205184016.0,3.1,"27211,27234,262,32139,7460,39332,541,0,528,9,1876,115,75,39448,325,0,11758,0,49462,14,229,1909,2,0,1682,24,5,95,52,1631,0",72,442.6,1460,558.6,312025.4,4.0,"80,80,72,589,72,1460,72,1460,174,72,72,136,164,346,72,72,72,652,103,72,72,103,508,1460,1460,72,72,72,1460,72,1460,1460","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0","0,1,0,0,1,1,0,1,1,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,1,0,0,0,1,0,1,1","4.882011414,5.229951859,5.245904922,4.668323040,5.111409664,7.823575497,5.218127251,7.840838909,6.577263832,5.273682594,5.245904922,6.141845703,6.526543617,7.249311924,5.028076172,5.028076649,5.028076172,7.620381832,5.685565948,5.134794235,5.107016563,5.797031403,7.461103439,7.863368988,7.879219532,5.218127251,5.218127251,5.218127251,7.865433216,5.218127251,7.849226475,7.844064713",TLS.Google,91.126,1,Acceptable,Advertisement,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:789d,tcp,48240,443,info,17,15,1605291687514756,1605291687641122,1605291687641103,0,0,517,1048,1012,8292,0,0,8152.0,61125,15844.6,251049776.0,2.9,"30377,30415,332,47450,13993,61125,95,1,0,49,10,2,3286,115,139,30628,2061,91,0,29231,1271,1309,181,374,3,2,1,161,6,3,2",72,363.2,1120,425.8,181298.7,4.1,"80,80,72,589,72,1120,72,1120,1120,704,72,72,72,165,171,337,72,72,72,330,72,138,72,110,1120,1120,1120,1120,72,72,72,72","12,1,1,1,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,1,1,0,0,0,0,0,0,1,1,1,1,0,1,0,0,1,1,1,1,0,0,0,0","4.882011890,5.254952908,5.245904922,4.537001133,5.045369625,6.921907902,5.119708538,7.178970814,7.321282864,7.568989754,5.190349579,5.162571907,5.096531868,5.980709553,6.354322433,7.210721493,5.083631516,5.139187336,5.111409664,7.047548294,5.218127251,6.254519463,5.162571907,5.573678017,7.803915977,7.831707001,7.839641571,7.817306042,5.245904922,5.245904922,5.245904922,5.245904922",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:816::2008,tcp,39520,443,finished,16,16,1605291687642048,1605291687769797,1605291687770512,0,0,517,1208,967,10018,0,0,8264.9,43870,14337.0,205550432.0,3.2,"34309,34348,1675,38053,7520,1,0,43870,15,3,2990,179,332,37258,1,401,1,34144,24,176,2332,6921,9068,836,1,863,34,109,28,721,0",72,415.8,1280,486.5,236643.5,4.1,"80,80,72,589,72,1280,1280,550,72,72,72,136,164,335,72,72,652,103,72,72,103,72,545,72,1280,1280,72,72,1280,72,1280,1280","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,0,0,0,1,1,0,1,1,0,0,1,0,1,1","4.845952988,5.276736736,5.138828754,4.602811337,5.041796684,7.803936958,7.832890034,7.552286625,5.166606426,5.194384098,5.194384098,6.037216187,6.610102654,7.276579857,5.041796684,5.041796684,7.656215668,5.660604000,5.183899403,5.183899403,5.788832664,5.069574356,7.590582848,5.222161770,7.845970631,7.817458153,5.222161770,5.222161770,7.842357159,5.222161770,7.846263409,7.836318970",TLS.GoogleServices,91.239,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2620:116:800d:21:f916:5049:f87f:108e,tcp,48648,443,info,16,16,1605291687933355,1605291688258109,1605291688258300,0,0,517,1388,1296,10685,0,0,20958.0,180245,38814.9,1506599424.0,3.3,"41345,41375,239,45639,16078,1,0,61463,16,3,3880,365,125,94049,180245,10480,2,92307,53,428,5467,8019,1891,14882,15513,1,15533,36,263,0,1",72,446.9,1460,554.6,307585.9,4.0,"80,80,72,589,72,1460,1460,660,72,72,72,198,171,330,330,72,346,141,72,72,110,72,72,110,72,1460,1460,72,72,1460,1460,1460","10,1,0,2,0,0,0,0,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,1,1,1,0,0,0,1,1,1,0,1,1,0,0,1,1,1","5.270193100,5.621731281,5.459350586,4.656135082,5.421088219,6.918155670,7.356199741,7.583865643,5.431572914,5.431572914,5.348239899,6.523558617,6.440567493,7.245548248,7.233427525,5.403794765,7.155272961,6.347721100,5.459350586,5.459350586,5.820535183,5.393310547,5.355048180,6.026633739,5.409216881,7.855928898,7.870290756,5.487128258,5.459350586,7.867146015,7.870689869,7.867941856",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::d83a:d1e6,tcp,51100,443,finished,18,14,1605291688324076,1605291688488430,1605291688495517,0,0,517,1388,1402,4278,0,1,10832.1,42730,14959.8,223794400.0,3.6,"41079,41100,165,31856,11033,42730,469,1,470,25,2812,1299,93,34223,10205,1,40205,536,1458,1,938,16571,1,3,16547,20,17,4417,310,12670,24540",72,250.0,1460,362.6,131502.0,4.0,"80,80,72,589,72,1460,72,1460,172,72,72,136,164,486,72,652,72,72,103,72,103,72,793,103,111,72,72,72,111,107,282,72","11,2,2,0,0,0,1,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0","0,1,0,0,1,1,0,1,1,0,0,0,0,0,1,1,1,0,0,1,1,0,1,1,1,0,0,0,0,0,0,1","4.857011318,5.329952717,5.273682594,4.540163040,5.139187336,7.843326092,5.273682594,7.862450600,6.539532185,5.273682594,5.273682594,6.134756088,6.541216850,7.446951866,5.166965008,7.636521339,5.100924969,5.273682594,5.932955742,5.111409664,5.777672768,5.263197899,7.737014294,5.703792095,5.962306976,5.301460266,5.329237938,5.329237938,6.057867527,5.878192425,7.107053280,5.166965008",TLS.Google,91.126,1,Acceptable,Advertisement,6,DPI,"" @@ -16,11 +11,8 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2606:2800:134:1a0d:1429:742:782:b6,tcp,39736,443,finished,16,16,1605291688611238,1605291688786771,1605291688811895,0,0,523,1208,1624,5905,0,0,12135.2,51136,17866.3,319203328.0,3.5,"43010,43065,309,41280,10189,51136,400,38397,3509,41489,471,1,468,4,62,52,2291,169,102,38533,0,1,0,35978,9,3,58,5162,2233,17560,249",72,307.8,1280,396.4,157103.1,4.1,"80,80,72,589,72,171,72,595,72,1280,72,1280,1280,72,72,409,72,146,164,459,72,327,327,168,72,72,72,103,72,72,103,1280","11,0,2,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,0,2,0,0,0,2,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,0,1,1,0,0,1,0,0,0,0,1,1,1,1,0,0,0,0,1,1,1,1","5.156615734,5.498501778,5.447478771,4.680018902,5.305136681,6.159050465,5.343176365,5.095525742,5.322429657,7.814732552,5.475256443,7.833696365,7.860356808,5.419701099,5.436994553,7.369849682,5.475256443,6.433616161,6.626874924,7.528322220,5.360692024,7.254635811,7.262678146,6.541914940,5.447478771,5.475256443,5.447478771,6.000376225,5.388469696,5.360692024,5.934231758,7.832221508",TLS.Twitter,91.120,1,Fun,SocialNetwork,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:805::2004,tcp,57282,443,finished,16,16,1605291688749044,1605291688895635,1605291688895679,0,0,517,1208,990,9898,0,0,9458.9,62320,17558.3,308293920.0,3.0,"37391,37416,173,47446,15044,0,62320,24,361,320,2535,232,269,39947,114,0,2294,39328,242,2903,2650,782,796,254,1,2,253,13,20,95,1",72,412.8,1280,483.3,233579.9,4.1,"80,80,72,589,72,1280,1280,72,72,289,72,136,164,358,72,72,72,652,72,103,497,72,1280,72,1280,1280,1280,72,72,72,1280,292","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,2,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,0,0,0,0,1,1,1,1,0,0,1,0,1,0,1,1,1,0,0,0,1,1","4.742643356,5.251736641,5.156122208,4.431118965,5.052281380,7.795456409,7.833138943,5.183899879,5.183899879,7.222666740,5.183899879,6.136840343,6.526112080,7.291018963,5.080059052,5.080059052,5.107836723,7.666177273,5.098598480,5.762085438,7.464744568,5.183899879,7.830111027,5.156122208,7.819734097,7.865944386,7.829904556,5.128344536,5.156122208,5.100566864,7.822502613,7.162058353",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:805::2001,tcp,58122,443,finished,15,17,1605291688830061,1605291689005944,1605291689006046,0,0,517,1208,1039,8982,0,0,11350.6,68993,22767.9,518376128.0,2.8,"63745,63780,224,68524,719,1,1,1,68993,14,7,6,49,23,8336,2581,2495,40185,1017,0,0,27807,170,1594,1,1430,17,147,0,1,0",72,385.7,1280,459.2,210886.5,4.1,"80,80,72,589,72,1280,1280,1280,1280,72,72,72,72,469,72,136,164,407,72,652,72,72,72,103,103,503,72,72,1280,1280,328,111","11,0,2,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,0,0,0,0,0,0,1,0,0,0,1,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,1,0,0,0,0,1,0,0,0,0,1,1,1,1,0,0,1,1,0,0,1,1,1,1","4.810268402,5.216053009,5.081305027,4.495285511,5.070961475,7.775168419,7.813756466,7.830919743,7.820947170,5.175122738,5.202900410,5.175122738,5.164638042,7.419659138,5.202900410,6.144525528,6.597908497,7.465239525,5.081446171,7.628419399,5.025890350,5.081446171,5.136860371,5.834997177,5.649486065,7.575581074,5.202900410,5.202900410,7.817056179,7.851086140,7.198029995,5.871317387",TLS.YouTube,91.124,1,Fun,Media,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80c::2003,tcp,47302,443,finished,16,16,1605291688843899,1605291689013039,1605291689013078,0,0,517,1208,1086,9699,0,0,10913.5,73480,20451.9,418282080.0,3.0,"45331,45373,379,65680,8193,73480,42,0,21,5,12589,926,174,173,41157,1595,28896,105,3348,1,0,3744,1,0,1,6991,22,3,3,85,1",72,409.5,1280,484.5,234727.2,4.1,"80,80,72,589,72,1280,72,1280,341,72,72,136,164,373,153,72,652,72,103,72,72,72,466,1280,1280,1280,72,72,72,72,1280,1280","11,0,3,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,1,0,0,0,0,0,0,1,1,0,0,1,1,1,1,1,1,1,0,0,0,0,1,1","4.855388641,5.270608902,5.232646942,4.480056286,5.091208458,7.815004349,5.193278790,7.850385666,7.281913757,5.248834610,5.137723923,6.052643776,6.521836281,7.361442566,6.438180447,5.052281380,7.594014645,5.288202286,5.794967651,5.135614395,5.191169739,5.137001514,7.486030579,7.839892864,7.804619789,7.849721909,5.260424614,5.260424614,5.288202286,5.277717590,7.826467514,7.832191467",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:815::2016,tcp,52296,443,finished,16,16,1605291688831210,1605291689029453,1605291689029440,0,0,517,1208,1007,10130,0,0,12789.5,67787,22343.4,499229344.0,3.2,"63335,63360,1131,67787,769,1,1,67414,6,6,11732,1751,188,41623,368,28482,452,4153,0,1923,5466,17937,17942,106,77,226,1,0,0,229,7",72,420.5,1280,488.8,238946.4,4.1,"80,80,72,589,72,1280,1280,751,72,72,72,136,164,375,72,652,72,103,72,72,103,72,456,72,1280,72,1280,1280,1280,1280,72,72","12,0,2,0,0,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,0,0,1,1,1,0,1,0,1,0,1,1,1,1,0,0","4.855387688,5.286172390,5.166606426,4.403482437,5.097352028,7.810871601,7.864149094,7.683444977,5.164638042,5.232646465,5.288201809,6.259301662,6.552115440,7.385071278,5.107836723,7.668366432,5.149313450,5.867877483,5.069574356,5.080059052,5.803856373,5.204868793,7.481070042,5.260424137,7.860325813,5.260424137,7.834439754,7.818997860,7.817288876,7.835785389,5.232646465,5.260424137",TLS.YouTube,91.124,1,Fun,Media,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:798c,tcp,56640,443,info,16,16,1605291689408040,1605291689629927,1605291689672104,0,0,517,1048,1710,4392,0,0,15675.8,144189,36484.9,1331146624.0,2.7,"25745,25768,203,144189,2,0,143997,4,71,1,41,7,2508,597,1253,49737,1,0,1,45397,18,103,1,65,704,437,888,38392,2516,1067,2238",72,263.2,1120,320.8,102914.8,4.2,"80,80,72,589,72,1120,1120,72,72,1120,587,72,72,165,171,471,72,72,330,138,72,72,72,439,72,110,566,142,72,72,72,114","9,1,2,1,0,0,0,0,0,0,0,0,1,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,1,1,0,0,0,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,1,0,0,0,0,0,1,1,1,1,0,0,1,1,0,0,0,0,1,1,1,1","4.857011795,5.259831905,5.179864883,4.529115200,5.055853844,6.908260822,7.364731312,5.245904922,5.218127251,7.327914715,7.541935444,5.162571907,5.218127251,6.139030457,6.351455688,7.439690113,5.166965008,5.139187336,7.125073433,6.245332241,5.235420227,5.273682594,5.139187336,7.450459003,5.273682594,5.556783676,7.574505329,6.164192200,5.085018635,5.139187336,5.139187336,5.963419437",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80b::2002,tcp,59336,443,finished,17,15,1605291690384370,1605291690495032,1605291690511816,0,0,517,1208,1020,5622,0,1,7680.9,45875,12464.9,155373568.0,3.4,"18528,18557,358,37185,9026,1,2,1,45875,10,14,14,8672,419,266,33620,1,89,1151,1,25433,25,482,7313,1,1,6808,24,7,3698,20526",72,280.1,1280,371.7,138197.8,4.1,"80,80,72,589,72,1280,1280,1280,273,72,72,72,72,136,164,349,72,72,72,652,103,72,72,103,775,516,111,72,72,72,111,72","12,1,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,0,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,1,0,0,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,1,0,0,0,0,1","4.830388546,5.286173820,5.175123215,4.582562923,5.135614395,7.820514202,7.848834991,7.840905190,7.029392242,5.204868793,5.232646465,5.232646465,5.232646465,6.256432056,6.550828457,7.277585983,5.097352028,5.107836723,5.107836723,7.629249096,5.686814308,5.260424137,5.260424137,5.854413509,7.698106289,7.556940079,5.871694088,5.222162247,5.166606903,5.166606903,5.962721825,5.004921436",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80b::2001,tcp,59624,443,finished,17,15,1605291690421002,1605291690527565,1605291690527527,0,0,517,1208,1054,6986,0,0,6873.8,34221,11275.4,127133528.0,3.4,"28106,28139,660,33241,1626,34221,71,30,636,643,4625,213,224,27018,3512,25468,241,4283,1409,5453,77,6348,1,0,6424,34,8,196,1,158,22",72,323.8,1280,408.2,166632.7,4.1,"80,80,72,589,72,1280,72,1280,72,534,72,136,164,422,72,652,72,103,72,103,72,72,482,1280,1280,72,72,72,704,111,72,72","13,0,2,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,1,0,0,0,0,1,1,0,0,1,1,0,1,1,1,1,0,0,0,1,1,0,0","4.750831604,5.256616592,5.147345066,5.037306786,5.025890827,7.794999599,5.175122738,7.849133015,5.175122738,7.594861984,5.147345066,6.103534698,6.601645947,7.415776730,5.023922443,7.687021732,5.175123215,5.854413509,4.959850788,5.758662224,5.147345066,5.053668499,7.493776798,7.824415684,7.830970287,5.175122738,5.175122738,5.147345066,7.700448990,5.878117561,5.175122738,5.175122738",TLS.Google,91.126,1,Acceptable,Advertisement,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:808::2001,tcp,46806,443,finished,15,17,1605291690926655,1605291691043702,1605291691043566,0,0,517,1208,1291,11382,0,0,7547.0,42183,12243.2,149896752.0,3.3,"25564,25583,1059,31489,7154,1,37586,36,127,1,1,0,1,87,28,7124,13598,568,199,42183,2,20688,340,10112,7,263,1,3,2,10101,50",72,468.5,1280,513.4,263601.8,4.2,"80,80,72,589,72,1280,1280,72,72,1280,1280,1280,1280,220,72,72,136,164,342,389,72,652,72,103,72,72,72,1062,1280,1280,72,72","10,0,2,0,0,0,0,0,1,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,1,1,1,1,0,0,0,0,0,0,1,1,0,0,1,1,1,1,1,1,0,0","4.825832367,5.281616688,5.136860847,4.553145885,5.043183804,7.811286926,7.839466095,5.164638519,5.164638519,7.864381790,7.859279633,7.843964577,7.841698170,6.810353279,5.109083176,5.136860847,6.135817528,6.436379910,7.296087742,7.276475906,5.025890350,7.637989998,5.136860847,5.737908840,5.098739147,5.043183804,5.070961475,7.799327850,7.850948334,7.827920914,5.136860847,5.136860847",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80f::2001,tcp,36964,443,finished,16,16,1605291690926912,1605291691067608,1605291691069122,0,0,517,1208,1326,6622,0,0,9126.0,45897,14144.4,200064000.0,3.4,"29535,29546,105,39799,6197,1,1,45897,20,10,16645,7440,877,217,45409,188,20393,461,14689,1873,1,1,16098,2949,2,0,2950,29,8,1564,1",72,320.9,1280,398.4,158685.9,4.1,"80,80,72,589,72,1280,1280,311,72,72,72,136,164,391,375,72,652,72,103,72,103,72,72,72,551,398,207,72,72,72,1280,1280","11,0,2,0,0,0,0,0,0,2,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,0,0,1,0,0,1,0,0,1,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,1,1,0,0,1,1,1,1,0,1,1,1,0,0,0,1,1","4.860268116,5.316052437,5.175122738,4.626070023,5.053668499,7.798489094,7.858765125,7.213901043,5.175122738,5.175122738,5.136860371,6.074123383,6.494878292,7.385508060,7.250154495,4.998777390,7.691906452,5.175122738,5.820339203,5.053668022,5.765991211,5.015406132,5.015406132,5.147345066,7.610651970,7.403194427,6.718353748,5.175122738,5.175122738,5.114727020,7.829133987,7.837005138",TLS.Google,91.126,1,Acceptable,Advertisement,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:811::200a,tcp,38166,443,finished,16,16,1605291690926867,1605291691075065,1605291691075150,0,0,517,1208,987,5335,0,0,9563.9,43801,13475.5,181588928.0,3.6,"28655,28663,221,37924,6057,43801,75,33,588,595,16415,9761,878,43789,3898,20653,579,14876,1700,0,16044,10542,2,1,1,10492,40,13,10,172,3",72,270.1,1280,336.6,113301.5,4.2,"80,80,72,589,72,1280,72,1280,72,572,72,136,164,355,72,652,72,103,72,103,72,72,531,897,272,357,72,72,72,72,111,72","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,0,0,0,0,1,0,1,0,0,0,0,0,1,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,1,0,1,0,0,0,0,1,1,0,0,1,1,1,0,1,1,1,1,0,0,0,0,1,1","4.786516666,5.247180939,5.070820332,4.566688538,5.043183804,7.807061672,5.053527355,7.847422123,5.025749683,7.577804089,5.043042660,6.031175137,6.392292976,7.341467381,4.977143764,7.597589493,5.081305027,5.788832188,5.004921436,5.547259808,5.015406132,5.081305027,7.471312523,7.741707325,7.060866833,7.323482037,5.109082699,5.109082699,5.064012051,5.053527355,5.763209343,5.043183804",TLS.GoogleServices,91.239,1,Acceptable,Web,6,DPI,"" diff --git a/test/results/flow-analyse/socks-http-example.pcap.out b/test/results/flow-analyse/default/riot.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/socks-http-example.pcap.out +++ b/test/results/flow-analyse/default/riot.pcapng.out diff --git a/test/results/flow-analyse/someip-tp.pcap.out b/test/results/flow-analyse/default/riotgames.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/someip-tp.pcap.out +++ b/test/results/flow-analyse/default/riotgames.pcap.out diff --git a/test/results/flow-analyse/someip-udp-method-call.pcapng.out b/test/results/flow-analyse/default/rsh-syslog-false-positive.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/someip-udp-method-call.pcapng.out +++ b/test/results/flow-analyse/default/rsh-syslog-false-positive.pcap.out diff --git a/test/results/flow-analyse/someip_sd_sample.pcap.out b/test/results/flow-analyse/default/rsh.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/someip_sd_sample.pcap.out +++ b/test/results/flow-analyse/default/rsh.pcap.out diff --git a/test/results/flow-analyse/sql_injection.pcap.out b/test/results/flow-analyse/default/rsync.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/sql_injection.pcap.out +++ b/test/results/flow-analyse/default/rsync.pcap.out diff --git a/test/results/flow-analyse/ssdp-m-search-ua.pcap.out b/test/results/flow-analyse/default/rtmp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ssdp-m-search-ua.pcap.out +++ b/test/results/flow-analyse/default/rtmp.pcap.out diff --git a/test/results/flow-analyse/rtsp.pcap.out b/test/results/flow-analyse/default/rtsp.pcap.out index 1103f7f49..1103f7f49 100644 --- a/test/results/flow-analyse/rtsp.pcap.out +++ b/test/results/flow-analyse/default/rtsp.pcap.out diff --git a/test/results/flow-analyse/ssdp-m-search.pcap.out b/test/results/flow-analyse/default/rtsp_setup_http.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ssdp-m-search.pcap.out +++ b/test/results/flow-analyse/default/rtsp_setup_http.pcapng.out diff --git a/test/results/flow-analyse/rx.pcap.out b/test/results/flow-analyse/default/rx.pcap.out index dc4ec9d38..dc4ec9d38 100644 --- a/test/results/flow-analyse/rx.pcap.out +++ b/test/results/flow-analyse/default/rx.pcap.out diff --git a/test/results/flow-analyse/s7comm.pcap.out b/test/results/flow-analyse/default/s7comm.pcap.out index 9a151dbe3..b090c7120 100644 --- a/test/results/flow-analyse/s7comm.pcap.out +++ b/test/results/flow-analyse/default/s7comm.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.10,192.168.1.40,tcp,4185,102,finished,21,11,1408528803880679,1408528803957564,1408528803957480,7,0,33,221,396,794,1,66,4957.6,9013,3321.6,11033309.0,4.5,"3735,3883,3114,3055,66,6981,6927,4642,8989,4385,568,7037,6437,271,5970,5746,295,9009,8666,204,8975,8763,201,9013,8819,232,8990,8762,250,4988,4713",47,77.2,261,40.3,1625.5,4.9,"62,62,65,67,47,73,121,47,73,121,47,73,261,47,73,121,47,69,101,47,69,101,47,69,101,47,69,101,47,71,77,47","17,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,5,3,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0","4.432188988,4.290980816,4.257703304,3.892863989,4.469065666,4.562385082,3.916244507,4.469065666,4.445193291,3.499234200,4.469065666,4.517119408,2.438902855,4.367897987,4.497249603,3.901077271,4.469065666,4.394919872,4.398461342,4.469065666,4.423905373,4.398461342,4.426512718,4.412964821,4.410789013,4.469065666,4.412964821,4.372174263,4.410450935,4.692483425,4.443362713,4.469065666",s7comm,249,0,Acceptable,Network,6,DPI,"" +1,ip4,192.168.1.10,192.168.1.40,tcp,4185,102,finished,21,11,1408528803880679,1408528803957564,1408528803957480,7,0,33,221,396,794,1,66,4957.6,9013,3321.6,11033309.0,4.5,"3735,3883,3114,3055,66,6981,6927,4642,8989,4385,568,7037,6437,271,5970,5746,295,9009,8666,204,8975,8763,201,9013,8819,232,8990,8762,250,4988,4713",47,77.2,261,40.3,1625.5,4.9,"62,62,65,67,47,73,121,47,73,121,47,73,261,47,73,121,47,69,101,47,69,101,47,69,101,47,69,101,47,71,77,47","17,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,5,3,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0","4.432188988,4.290980816,4.257703304,3.892863989,4.469065666,4.562385082,3.916244507,4.469065666,4.445193291,3.499234200,4.469065666,4.517119408,2.438902855,4.367897987,4.497249603,3.901077271,4.469065666,4.394919872,4.398461342,4.469065666,4.423905373,4.398461342,4.426512718,4.412964821,4.410789013,4.469065666,4.412964821,4.372174263,4.410450935,4.692483425,4.443362713,4.469065666",s7comm,249,0,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/default/safari.pcap.out b/test/results/flow-analyse/default/safari.pcap.out new file mode 100644 index 000000000..b159d8bbe --- /dev/null +++ b/test/results/flow-analyse/default/safari.pcap.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.1.178,146.48.58.18,tcp,55267,443,finished,14,18,1620898025216866,1620898025482937,1620898025510399,0,0,442,1440,1135,16958,0,2,18051.7,118862,28694.5,823374080.0,3.5,"29610,29665,2362,30524,2,28159,51917,8877,77853,8496,625,1248,27408,129,120,247,131,125,259,123,123,248,503,122,637,24023,24010,84464,7818,118862,914",52,618.0,1492,660.5,436248.1,4.1,"64,60,52,263,52,193,52,103,494,52,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1029,52,52,483,52,1492","10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0,0,0,1,1","4.365527153,5.154205322,4.884933472,5.833237171,5.047091484,6.387271881,4.923395157,5.485030651,7.478204250,4.994112968,4.772770882,7.875178814,7.866140842,4.961856842,7.872851372,7.874671459,4.961856842,7.876760006,7.864192009,4.884933472,7.871975422,7.883419514,4.961856842,7.874213696,7.878833771,4.923395157,7.820206165,4.961856842,4.839769840,7.462142944,5.085553646,7.865268230",TLS,91,1,Safe,Web,6,DPI,"15" diff --git a/test/results/flow-analyse/ssl-cert-name-mismatch.pcap.out b/test/results/flow-analyse/default/salesforce.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ssl-cert-name-mismatch.pcap.out +++ b/test/results/flow-analyse/default/salesforce.pcap.out diff --git a/test/results/flow-analyse/steam.pcap.out b/test/results/flow-analyse/default/sccp_hw_conf_register.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/steam.pcap.out +++ b/test/results/flow-analyse/default/sccp_hw_conf_register.pcapng.out diff --git a/test/results/flow-analyse/steam_datagram_relay_ping.pcapng.out b/test/results/flow-analyse/default/sctp.cap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/steam_datagram_relay_ping.pcapng.out +++ b/test/results/flow-analyse/default/sctp.cap.out diff --git a/test/results/flow-analyse/syncthing.pcap.out b/test/results/flow-analyse/default/selfsigned.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/syncthing.pcap.out +++ b/test/results/flow-analyse/default/selfsigned.pcap.out diff --git a/test/results/flow-analyse/synscan.pcap.out b/test/results/flow-analyse/default/sflow.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/synscan.pcap.out +++ b/test/results/flow-analyse/default/sflow.pcap.out diff --git a/test/results/flow-analyse/signal.pcap.out b/test/results/flow-analyse/default/signal.pcap.out index abf5e723b..abf5e723b 100644 --- a/test/results/flow-analyse/signal.pcap.out +++ b/test/results/flow-analyse/default/signal.pcap.out diff --git a/test/results/flow-analyse/simple-dnscrypt.pcap.out b/test/results/flow-analyse/default/simple-dnscrypt.pcap.out index ef1267381..ef1267381 100644 --- a/test/results/flow-analyse/simple-dnscrypt.pcap.out +++ b/test/results/flow-analyse/default/simple-dnscrypt.pcap.out diff --git a/test/results/flow-analyse/sip.pcap.out b/test/results/flow-analyse/default/sip.pcap.out index c4566261a..391bc85c4 100644 --- a/test/results/flow-analyse/sip.pcap.out +++ b/test/results/flow-analyse/default/sip.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.2,212.242.33.35,udp,5060,5060,finished,21,11,1120469572844249,1120470235521078,1120470235448732,5,0,825,593,7448,4947,0,25935,42751008.0,279041814,57873684.0,3349363405357056.0,4.0,"136757,17415627,17424961,49834,89928591,89874891,17280679,17290428,150200040,150188219,17325180,17335822,73916043,73902652,17325038,17333170,25935,17724998,29031776,29092737,34118166,34119076,29272359,29031830,29031631,29031476,17104967,497671,1001842,279041814,227102",33,415.3,853,273.0,74531.7,4.6,"495,514,708,334,374,495,514,708,519,495,514,708,519,495,514,708,334,498,33,33,33,33,33,33,33,33,33,853,853,853,621,368","9,0,0,0,0,0,0,0,0,0,1,0,0,0,4,0,0,0,0,0,0,4,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,2,1,0,0,0,1,6,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0","5.741633415,5.745016098,5.709460258,5.733335018,5.724183083,5.734008312,5.752299309,5.705936909,5.742718697,5.746319294,5.735527039,5.694232941,5.749829292,5.746265888,5.718012810,5.700710297,5.702609062,5.648171425,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.037749290,4.098355293,4.098355293,5.722674847,5.721789837,5.722674847,5.763523579,5.703196526",SIP,100,0,Acceptable,VoIP,6,DPI,"" +1,ip4,192.168.1.2,212.242.33.35,udp,5060,5060,finished,21,11,1120469572844249,1120470235521078,1120470235448732,5,0,825,593,7448,4947,0,25935,42751008.0,279041814,57873684.0,3349363405357056.0,4.0,"136757,17415627,17424961,49834,89928591,89874891,17280679,17290428,150200040,150188219,17325180,17335822,73916043,73902652,17325038,17333170,25935,17724998,29031776,29092737,34118166,34119076,29272359,29031830,29031631,29031476,17104967,497671,1001842,279041814,227102",33,415.3,853,273.0,74531.7,4.6,"495,514,708,334,374,495,514,708,519,495,514,708,519,495,514,708,334,498,33,33,33,33,33,33,33,33,33,853,853,853,621,368","9,0,0,0,0,0,0,0,0,0,1,0,0,0,4,0,0,0,0,0,0,4,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,2,1,0,0,0,1,6,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0","5.741633415,5.745016098,5.709460258,5.733335018,5.724183083,5.734008312,5.752299309,5.705936909,5.742718697,5.746319294,5.735527039,5.694232941,5.749829292,5.746265888,5.718012810,5.700710297,5.702609062,5.648171425,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.098355293,4.037749290,4.098355293,4.098355293,5.722674847,5.721789837,5.722674847,5.763523579,5.703196526",SIP,100,0,Acceptable,VoIP,6,DPI,"46" diff --git a/test/results/flow-analyse/syslog.pcap.out b/test/results/flow-analyse/default/sip_hello.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/syslog.pcap.out +++ b/test/results/flow-analyse/default/sip_hello.pcapng.out diff --git a/test/results/flow-analyse/sites.pcapng.out b/test/results/flow-analyse/default/sites.pcapng.out index 6bc9bfd10..6bc9bfd10 100644 --- a/test/results/flow-analyse/sites.pcapng.out +++ b/test/results/flow-analyse/default/sites.pcapng.out diff --git a/test/results/flow-analyse/skinny.pcap.out b/test/results/flow-analyse/default/skinny.pcap.out index 9e0aadc33..a639fbf95 100644 --- a/test/results/flow-analyse/skinny.pcap.out +++ b/test/results/flow-analyse/default/skinny.pcap.out @@ -1,8 +1,8 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.195.58,192.168.193.12,tcp,49399,2000,finished,13,19,1317801130501299,1317801134312976,1317801134286303,0,0,52,324,248,1620,1,14,245054.2,3609828,877176.1,769437794304.0,1.5,"2211,18,14,5962,3780,258,15,49,20014,19685,10391,48806,3559643,16,82,3609828,11683,20052,16478,36490,7020,23440,32822,19981,11660,17,20000,11522,27273,50735,26736",46,100.2,364,74.3,5521.7,4.7,"64,68,56,64,46,364,68,76,68,46,200,60,46,64,180,76,46,252,46,88,46,184,46,184,46,184,172,46,92,92,46,92","9,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,2,0,0,5,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,1,0,1,1,1,1,0,1,0,1,1,1,1,0,1,0,0,1,1,0,1,0,1,1,0,0,0,1,0","3.922401428,4.000817776,4.543873787,4.299025536,4.398030758,3.738415241,4.369860649,4.173765659,4.555430412,4.446094513,4.498068333,4.266249657,4.654558659,4.450102329,2.632452726,4.180215836,4.398030758,4.264904022,4.549461365,3.957430601,4.654558659,2.670037031,4.549461365,2.689654589,4.478915215,2.567897081,4.683412552,4.398031235,4.043387413,3.999909163,4.567602158,4.021648407",CiscoSkinny,164,0,Acceptable,VoIP,6,DPI,"" +1,ip4,192.168.195.58,192.168.193.12,tcp,49399,2000,finished,13,19,1317801130501299,1317801134312976,1317801134286303,0,0,52,324,248,1620,1,14,245054.2,3609828,877176.1,769437794304.0,1.5,"2211,18,14,5962,3780,258,15,49,20014,19685,10391,48806,3559643,16,82,3609828,11683,20052,16478,36490,7020,23440,32822,19981,11660,17,20000,11522,27273,50735,26736",46,100.2,364,74.3,5521.7,4.7,"64,68,56,64,46,364,68,76,68,46,200,60,46,64,180,76,46,252,46,88,46,184,46,184,46,184,172,46,92,92,46,92","9,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,2,0,0,5,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,1,0,1,1,1,1,0,1,0,1,1,1,1,0,1,0,0,1,1,0,1,0,1,1,0,0,0,1,0","3.922401428,4.000817776,4.543873787,4.299025536,4.398030758,3.738415241,4.369860649,4.173765659,4.555430412,4.446094513,4.498068333,4.266249657,4.654558659,4.450102329,2.632452726,4.180215836,4.398030758,4.264904022,4.549461365,3.957430601,4.654558659,2.670037031,4.549461365,2.689654589,4.478915215,2.567897081,4.683412552,4.398031235,4.043387413,3.999909163,4.567602158,4.021648407",CiscoSkinny,164,0,Acceptable,VoIP,6,DPI,"46" 1,ip4,192.168.195.58,192.168.195.50,udp,32144,17718,finished,18,14,1317801134322976,1317801134482957,1317801134468575,172,0,172,172,3096,2408,0,4,9857.4,25564,10215.5,104355640.0,3.9,"25,19949,10,25564,11,20009,15,19949,15,19947,7,19983,8,20009,7,20042,7,20010,7,19977,4,19971,13,19997,11,20024,12,20020,11,19956,10",200,200.0,200,0.0,0.0,5.0,"200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200","0,0,0,0,0,18,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0","4.233760357,4.233760357,4.755019665,4.755019665,4.365148544,4.365148544,5.067544460,5.067544460,4.363914013,4.363914013,4.870802402,4.870802402,5.547243595,5.547243595,5.061565876,5.061565876,5.180966377,5.180966377,5.064822674,5.064822674,5.333183289,5.333183289,5.182554245,5.182554245,5.614361763,5.614361763,5.808181763,5.808181763,5.246697903,5.246697903,5.232192516,5.232192516",RTP,87,0,Acceptable,Media,6,DPI,"" 1,ip4,192.168.195.58,192.168.193.24,udp,32150,9395,finished,32,0,1317801134322539,1317801134942562,1317801134322539,172,0,172,0,5504,0,0,19901,20000.7,20073,35.0,1222.2,5.0,"20010,20035,19901,20015,19977,20040,20015,20006,19996,20018,19974,20009,19997,20001,20001,19982,20073,20009,20000,19999,20061,19944,19990,19953,20026,19940,20010,20055,20010,19978,19998",200,200.0,200,0.0,0.0,5.0,"200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200","0,0,0,0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.253760338,4.786761761,5.077544212,4.880802631,5.060857296,5.094822407,5.175570965,5.860004425,5.252192497,4.811758041,5.051555157,5.202684879,4.826058388,4.792474747,4.938888073,4.741405487,4.472463608,4.580914974,4.584398270,4.538744450,4.508350849,4.288617134,4.379649162,4.592761517,4.371983528,4.385575771,4.512448788,4.759740829,4.715042114,4.770418644,3.938650370,4.306789398",RTP,87,0,Acceptable,Media,6,DPI,"" 1,ip4,192.168.195.50,192.168.193.24,udp,17726,9399,finished,32,0,1317801134348136,1317801134968092,1317801134348136,172,0,172,0,5504,0,0,19962,19998.6,20095,27.6,759.7,5.0,"19962,19969,20095,19966,20007,20019,20010,19970,19996,20019,19982,19965,20001,20006,19994,20032,19986,19999,19985,19996,20021,19995,20005,19995,19975,19984,19971,20037,20033,19973,20008",200,200.0,200,0.0,0.0,5.0,"200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200","0,0,0,0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.382149220,4.433072090,5.554677963,5.245295525,5.359684944,5.638034821,5.272410393,5.136450291,4.824490070,4.458597660,4.762297153,4.430035591,4.140134811,3.858884573,3.769583702,3.278017282,3.433972836,3.403135061,3.567106962,4.292976856,4.648509502,4.789345264,4.830762386,4.555335999,4.442068100,6.184312344,4.938612938,6.346918106,6.461272717,6.171940327,6.510017872,6.460319996",RTP,87,0,Acceptable,Media,6,DPI,"" 1,ip4,192.168.195.58,192.168.193.24,udp,32152,9396,finished,32,0,1317801134349579,1317801134969420,1317801134349579,172,0,172,0,5504,0,0,19475,19994.9,20520,142.6,20347.9,5.0,"19831,19959,20146,19907,20018,20014,20011,20005,20001,20003,20045,19895,20035,19968,20008,20010,19972,20003,20520,19475,20014,19970,20034,19981,19987,19986,19966,20048,20036,19972,20021",200,200.0,200,0.0,0.0,5.0,"200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200","0,0,0,0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.393408298,4.432039738,5.622674942,5.222123623,5.373581886,5.658831120,5.279973507,5.143450737,4.839715958,4.427013874,4.767832279,4.403833866,4.120435238,3.834218979,3.762180805,3.235242844,3.409477234,3.386922836,3.548633337,4.268260479,4.605560303,4.771471977,4.801124096,4.541038036,4.446225643,6.169005394,4.927167892,6.350693703,6.448822498,6.188875198,6.544920921,6.452270985",RTP,87,0,Acceptable,Media,6,DPI,"" 1,ip4,192.168.195.50,192.168.193.24,udp,17732,9400,finished,32,0,1317801134383882,1317801135003916,1317801134383882,172,0,172,0,5504,0,0,19941,20001.1,20100,38.1,1453.4,5.0,"19977,19980,20100,19974,19997,19973,19984,19994,20002,20000,19996,19991,19980,20100,20004,19971,19986,20073,19948,19997,19947,20007,19941,20015,20065,19981,19993,20024,20019,20002,20013",200,200.0,200,0.0,0.0,5.0,"200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200","0,0,0,0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.886732578,5.045310974,5.069633007,5.162554741,5.808761120,5.197607994,4.773752689,5.019257545,5.175136566,4.783205986,4.789572239,4.908454418,4.722610474,4.455634594,4.590435505,4.554622650,4.530591965,4.497926712,4.290644169,4.361923218,4.586849689,4.387413979,4.413131237,4.509451866,4.762583256,4.689284325,4.748415470,3.920776129,4.292247295,5.242364883,5.593360424,5.532413960",RTP,87,0,Acceptable,Media,6,DPI,"" -1,ip4,192.168.193.12,192.168.195.50,tcp,2000,51532,finished,18,14,1317801130506133,1317801141425306,1317801141427620,0,0,492,52,1512,244,1,15,704537.4,7045910,1877203.8,3523893788672.0,2.2,"15,57,704,686,19914,3582983,19282,3622236,2065,19,22,17967,15924,20052,36329,2146,19966,30884,40036,6899,19067,13061,64116,28324,103909,42273,80357,6999604,16,5837,7045910",46,96.9,532,93.8,8793.0,4.6,"76,68,72,46,252,46,60,60,46,68,56,64,46,532,46,184,184,46,184,46,88,172,46,92,92,46,92,46,68,68,64,46","10,2,0,0,4,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","10,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,0,1,1,1,0,0,0,0,1,0,1,0,0,1,0,1,1,0,1,1,1,0,1,0,0,0,0,1","4.173766136,4.678438187,4.574613094,4.565872192,4.279353142,4.501398087,4.236247540,4.455914497,4.565872669,4.052432537,4.485925674,4.342070580,4.370963097,3.259213448,4.414441586,2.680906296,2.637759447,4.414441109,2.672017574,4.419027328,3.803910494,4.757339001,4.522394180,3.983498335,3.940019846,4.627491474,4.013442516,4.584012985,4.549689770,4.584219933,4.418852329,4.565872192",CiscoSkinny,164,0,Acceptable,VoIP,6,DPI,"" +1,ip4,192.168.193.12,192.168.195.50,tcp,2000,51532,finished,18,14,1317801130506133,1317801141425306,1317801141427620,0,0,492,52,1512,244,1,15,704537.4,7045910,1877203.8,3523893788672.0,2.2,"15,57,704,686,19914,3582983,19282,3622236,2065,19,22,17967,15924,20052,36329,2146,19966,30884,40036,6899,19067,13061,64116,28324,103909,42273,80357,6999604,16,5837,7045910",46,96.9,532,93.8,8793.0,4.6,"76,68,72,46,252,46,60,60,46,68,56,64,46,532,46,184,184,46,184,46,88,172,46,92,92,46,92,46,68,68,64,46","10,2,0,0,4,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","10,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,0,1,1,1,0,0,0,0,1,0,1,0,0,1,0,1,1,0,1,1,1,0,1,0,0,0,0,1","4.173766136,4.678438187,4.574613094,4.565872192,4.279353142,4.501398087,4.236247540,4.455914497,4.565872669,4.052432537,4.485925674,4.342070580,4.370963097,3.259213448,4.414441586,2.680906296,2.637759447,4.414441109,2.672017574,4.419027328,3.803910494,4.757339001,4.522394180,3.983498335,3.940019846,4.627491474,4.013442516,4.584012985,4.549689770,4.584219933,4.418852329,4.565872192",CiscoSkinny,164,0,Acceptable,VoIP,6,DPI,"46" diff --git a/test/results/flow-analyse/skype-conference-call.pcap.out b/test/results/flow-analyse/default/skype-conference-call.pcap.out index 7752c86cf..1454cd593 100644 --- a/test/results/flow-analyse/skype-conference-call.pcap.out +++ b/test/results/flow-analyse/default/skype-conference-call.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.2.20,104.46.40.49,udp,49282,60642,finished,16,16,1501061916646303,1501061916821040,1501061916812989,43,0,915,167,6417,1824,0,59,11013.6,100094,22446.4,503839616.0,3.0,"7339,44500,54477,177,54879,336,10342,20091,24441,100094,319,61,211,59,179,235,59,177,199,208,82,2810,14708,381,241,219,267,215,202,197,3718",63,285.5,943,317.0,100457.8,4.3,"132,132,100,100,132,100,136,138,131,123,195,63,155,155,155,155,155,155,155,155,155,155,100,71,943,943,943,943,943,943,155,121","0,1,4,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,2,12,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0,0","5.475533962,5.430079460,5.716311932,5.616310120,5.445230961,5.668762684,5.554492950,6.549376011,6.536014080,6.412748814,6.806855679,5.203801155,6.467489243,6.520809174,6.645484924,6.590196609,6.458263397,6.501328468,6.432456017,6.550292969,6.547129631,6.477230072,5.552665234,5.568275928,7.755900860,7.787482262,7.793358326,7.793142319,7.798308849,7.784828663,6.622673988,6.318281174",STUN.Skype_TeamsCall,78.38,0,Acceptable,VoIP,6,DPI,"5" +1,ip4,192.168.2.20,104.46.40.49,udp,49282,60642,finished,16,16,1501061916646303,1501061916821040,1501061916812989,43,0,915,167,6417,1824,0,59,11013.6,100094,22446.4,503839616.0,3.0,"7339,44500,54477,177,54879,336,10342,20091,24441,100094,319,61,211,59,179,235,59,177,199,208,82,2810,14708,381,241,219,267,215,202,197,3718",63,285.5,943,317.0,100457.8,4.3,"132,132,100,100,132,100,136,138,131,123,195,63,155,155,155,155,155,155,155,155,155,155,100,71,943,943,943,943,943,943,155,121","0,1,4,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,2,12,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0,0","5.475533962,5.430079460,5.716311932,5.616310120,5.445230961,5.668762684,5.554492950,6.549376011,6.536014080,6.412748814,6.806855679,5.203801155,6.467489243,6.520809174,6.645484924,6.590196609,6.458263397,6.501328468,6.432456017,6.550292969,6.547129631,6.477230072,5.552665234,5.568275928,7.755900860,7.787482262,7.793358326,7.793142319,7.798308849,7.784828663,6.622673988,6.318281174",STUN.Skype_TeamsCall,78.38,0,Acceptable,VoIP,6,DPI,"5,46" diff --git a/test/results/flow-analyse/skype.pcap.out b/test/results/flow-analyse/default/skype.pcap.out index 5454e73d1..5454e73d1 100644 --- a/test/results/flow-analyse/skype.pcap.out +++ b/test/results/flow-analyse/default/skype.pcap.out diff --git a/test/results/flow-analyse/skype_no_unknown.pcap.out b/test/results/flow-analyse/default/skype_no_unknown.pcap.out index c48c5fb08..c48c5fb08 100644 --- a/test/results/flow-analyse/skype_no_unknown.pcap.out +++ b/test/results/flow-analyse/default/skype_no_unknown.pcap.out diff --git a/test/results/flow-analyse/targusdataspeed_false_positives.pcap.out b/test/results/flow-analyse/default/skype_udp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/targusdataspeed_false_positives.pcap.out +++ b/test/results/flow-analyse/default/skype_udp.pcap.out diff --git a/test/results/flow-analyse/smb_deletefile.pcap.out b/test/results/flow-analyse/default/smb_deletefile.pcap.out index 9ccb845ea..14e52470d 100644 --- a/test/results/flow-analyse/smb_deletefile.pcap.out +++ b/test/results/flow-analyse/default/smb_deletefile.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.118,192.168.1.187,tcp,56848,445,finished,20,12,1584368315417275,1584368317627960,1584368317628867,0,0,412,500,2972,3826,1,20,142654.1,2158424,529256.2,280112168960.0,1.2,"1172,1225,2157281,2158424,1159,87,1253,1160,7461,9355,1883,124,103,75,20,492,151,550,5618,5637,4741,5866,1131,107,1245,1127,130,997,857,25951,26895",40,252.6,540,190.9,36432.9,4.5,"420,540,40,364,508,40,380,524,40,452,166,40,540,40,144,140,46,144,40,116,40,380,524,40,420,396,40,284,356,40,388,452","10,0,0,2,0,0,0,1,0,0,4,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,1,2,0,0,0,0,0,1,0,1,1,0,1,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,0,1,0,0,1,0,1,0,0,0,1,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1","3.069277287,3.365245581,4.461769104,2.731584549,2.957580328,4.511769295,2.886561632,3.152696133,4.511769295,2.994292021,3.490118504,4.511769295,2.920198441,4.511769295,3.495491743,3.175110340,4.402616024,3.673908472,4.461769104,3.397419930,4.511769295,2.886561632,3.164842129,4.511769295,3.078800917,2.788191795,4.461769104,2.814971924,2.968542337,4.511769295,2.599048853,2.976962328",NetBIOS.SMBv23,10.41,0,Acceptable,System,6,DPI,"" +1,ip4,192.168.1.118,192.168.1.187,tcp,56848,445,finished,20,12,1584368315417275,1584368317627960,1584368317628867,0,0,412,500,2972,3826,1,20,142654.1,2158424,529256.2,280112168960.0,1.2,"1172,1225,2157281,2158424,1159,87,1253,1160,7461,9355,1883,124,103,75,20,492,151,550,5618,5637,4741,5866,1131,107,1245,1127,130,997,857,25951,26895",40,252.6,540,190.9,36432.9,4.5,"420,540,40,364,508,40,380,524,40,452,166,40,540,40,144,140,46,144,40,116,40,380,524,40,420,396,40,284,356,40,388,452","10,0,0,2,0,0,0,1,0,0,4,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,1,2,0,0,0,0,0,1,0,1,1,0,1,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,0,1,0,0,1,0,1,0,0,0,1,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1","3.069277287,3.365245581,4.461769104,2.731584549,2.957580328,4.511769295,2.886561632,3.152696133,4.511769295,2.994292021,3.490118504,4.511769295,2.920198441,4.511769295,3.495491743,3.175110340,4.402616024,3.673908472,4.461769104,3.397419930,4.511769295,2.886561632,3.164842129,4.511769295,3.078800917,2.788191795,4.461769104,2.814971924,2.968542337,4.511769295,2.599048853,2.976962328",NetBIOS.SMBv23,10.41,0,Acceptable,System,6,DPI,"46" diff --git a/test/results/flow-analyse/teredo.pcap.out b/test/results/flow-analyse/default/smb_frags.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/teredo.pcap.out +++ b/test/results/flow-analyse/default/smb_frags.pcap.out diff --git a/test/results/flow-analyse/threema.pcap.out b/test/results/flow-analyse/default/smbv1.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/threema.pcap.out +++ b/test/results/flow-analyse/default/smbv1.pcap.out diff --git a/test/results/flow-analyse/tk.pcap.out b/test/results/flow-analyse/default/smpp_in_general.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tk.pcap.out +++ b/test/results/flow-analyse/default/smpp_in_general.pcap.out diff --git a/test/results/flow-analyse/smtp-starttls.pcap.out b/test/results/flow-analyse/default/smtp-starttls.pcap.out index aed123c4f..c3170c73f 100644 --- a/test/results/flow-analyse/smtp-starttls.pcap.out +++ b/test/results/flow-analyse/default/smtp-starttls.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,10.0.0.1,173.194.68.26,tcp,57406,25,finished,15,17,1388017124762850,1388017125217215,1388017125228642,0,0,686,1418,1384,4627,0,26,29682.5,156957,34710.8,1204840832.0,4.2,"11168,11193,11857,11849,79,11152,39169,67072,28169,11489,12210,262,12322,26,24821,37890,13457,11887,11608,11639,11817,51431,103694,156957,13622,11529,11126,16410,67319,42853,94080",52,240.3,1470,368.1,135468.5,4.0,"60,60,52,103,52,80,52,206,62,82,164,1470,1470,52,905,366,262,105,217,113,117,113,52,158,738,52,80,52,128,52,83,133","9,3,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,3,1,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0","0,1,0,1,0,0,1,1,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,1,0,0,1","4.527644634,5.164738178,4.944975376,5.655648708,4.868052483,4.887005329,4.983437061,5.795777798,5.058248043,5.413370609,5.231037617,6.553743362,7.414661884,4.893245220,7.240818024,7.277081490,6.869879723,5.969118595,6.897389412,6.050327778,6.234992027,6.200943947,4.944975376,6.499523640,7.703155994,4.906513691,5.556689262,4.868052006,6.265826702,4.776611805,5.571072102,6.285814285",SMTPS.Google,29.126,1,Acceptable,Email,6,DPI,"7" -1,ip6,2003:de:2016:125:fc36:8317:4e86:cb72,2003:de:2016:120::a08:53,tcp,7562,25,finished,16,16,1524746968365832,1524746968662121,1524746968661622,0,0,1034,1140,1734,2097,0,2,19099.3,202908,48707.1,2372380928.0,2.8,"744,995,19017,29506,11113,127,1248,999,1000,6126,12754,624,8625,202034,202908,998,7251,6751,7252,7260,1247,2128,2995,378,21009,21750,990,6762,2,6750,736",60,180.5,1200,257.1,66086.8,4.2,"72,72,60,118,110,60,212,70,90,242,1200,186,139,318,227,60,149,103,123,103,95,126,60,1094,60,125,95,104,91,60,91,60","7,4,2,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,4,2,0,1,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,1,0,1,0,1,0,0,1,1,0,0,1,0,1,0,1,1,0,1,1,0,1,0,0,1,0","4.281427383,4.959185600,4.579100609,5.619654655,5.411477089,4.829739571,5.596319675,4.894675732,5.166758537,5.366472721,7.601028442,6.201757908,5.921764851,7.156020164,6.896310806,4.658349514,6.097513199,5.672229767,5.596776009,5.715824604,5.162304878,6.073466778,4.799921513,7.803120613,4.833254814,6.058705330,5.062202930,5.764057636,4.995513916,4.579101086,5.463903904,4.446732044",SMTPS,29,1,Safe,Email,6,DPI,"6,15" +1,ip6,2003:de:2016:125:fc36:8317:4e86:cb72,2003:de:2016:120::a08:53,tcp,7562,25,finished,16,16,1524746968365832,1524746968662121,1524746968661622,0,0,1034,1140,1734,2097,0,2,19099.3,202908,48707.1,2372380928.0,2.8,"744,995,19017,29506,11113,127,1248,999,1000,6126,12754,624,8625,202034,202908,998,7251,6751,7252,7260,1247,2128,2995,378,21009,21750,990,6762,2,6750,736",60,180.5,1200,257.1,66086.8,4.2,"72,72,60,118,110,60,212,70,90,242,1200,186,139,318,227,60,149,103,123,103,95,126,60,1094,60,125,95,104,91,60,91,60","7,4,2,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,4,2,0,1,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,1,0,1,0,1,0,0,1,1,0,0,1,0,1,0,1,1,0,1,1,0,1,0,0,1,0","4.281427383,4.959185600,4.579100609,5.619654655,5.411477089,4.829739571,5.596319675,4.894675732,5.166758537,5.366472721,7.601028442,6.201757908,5.921764851,7.156020164,6.896310806,4.658349514,6.097513199,5.672229767,5.596776009,5.715824604,5.162304878,6.073466778,4.799921513,7.803120613,4.833254814,6.058705330,5.062202930,5.764057636,4.995513916,4.579101086,5.463903904,4.446732044",SMTPS,29,1,Safe,Email,6,DPI,"6,15,33" diff --git a/test/results/flow-analyse/smtp.pcap.out b/test/results/flow-analyse/default/smtp.pcap.out index 2d2ed729e..2d2ed729e 100644 --- a/test/results/flow-analyse/smtp.pcap.out +++ b/test/results/flow-analyse/default/smtp.pcap.out diff --git a/test/results/flow-analyse/tls-esni-fuzzed.pcap.out b/test/results/flow-analyse/default/smtps.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls-esni-fuzzed.pcap.out +++ b/test/results/flow-analyse/default/smtps.pcapng.out diff --git a/test/results/flow-analyse/tls-rdn-extract.pcap.out b/test/results/flow-analyse/default/snapchat.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls-rdn-extract.pcap.out +++ b/test/results/flow-analyse/default/snapchat.pcap.out diff --git a/test/results/flow-analyse/snapchat_call.pcapng.out b/test/results/flow-analyse/default/snapchat_call.pcapng.out index bc3da92e7..bc3da92e7 100644 --- a/test/results/flow-analyse/snapchat_call.pcapng.out +++ b/test/results/flow-analyse/default/snapchat_call.pcapng.out diff --git a/test/results/flow-analyse/default/snapchat_call_v1.pcapng.out b/test/results/flow-analyse/default/snapchat_call_v1.pcapng.out new file mode 100644 index 000000000..841c90e97 --- /dev/null +++ b/test/results/flow-analyse/default/snapchat_call_v1.pcapng.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.12.169,34.246.231.140,udp,47520,443,finished,21,11,1642584090467068,1642584091097462,1642584091088958,33,0,1200,1200,10528,3826,0,18,40396.3,284273,69954.6,4893651456.0,3.5,"43831,48,18,47171,5912,7197,49242,50,34720,7943,33195,29741,120469,284273,668,11816,262103,35232,126423,262,9441,12613,6510,7068,102933,21,6234,340,1312,2360,3138",53,476.6,1228,428.3,183471.5,4.4,"1228,1228,1228,433,1228,117,610,446,104,62,360,61,90,53,70,70,198,53,53,88,1147,1148,1148,703,523,72,104,525,525,525,525,525","0,6,1,0,0,1,0,0,0,0,0,0,0,0,0,6,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,2,0,2,0,0,0,0,0,0,0,0,0,0","3,1,2,0,0,0,0,0,0,0,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,1,1,0,0,0,1,1,0,1,0,0,1,0,0,0,1,1,0,0,0,0,0,0,1,1,0,0,0,0,0","7.846151352,7.818212032,7.842855453,7.458201885,7.834816933,6.378828526,7.731168270,7.464651108,6.216168880,5.760650158,7.392130375,5.557705879,6.136295319,5.508872986,5.957851410,5.707712650,6.936640739,5.357929230,5.395664692,5.928121090,7.845738411,7.830622196,7.823609829,7.678224087,7.645185947,5.669923306,6.181212425,7.564388752,7.568304062,7.613670826,7.625892639,7.577367783",QUIC.SnapchatCall,188.255,1,Acceptable,VoIP,6,DPI,"" diff --git a/test/results/flow-analyse/tls_2_reasms.pcapng.out b/test/results/flow-analyse/default/snmp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_2_reasms.pcapng.out +++ b/test/results/flow-analyse/default/snmp.pcap.out diff --git a/test/results/flow-analyse/tls_2_reasms_b.pcapng.out b/test/results/flow-analyse/default/soap.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_2_reasms_b.pcapng.out +++ b/test/results/flow-analyse/default/soap.pcap.out diff --git a/test/results/flow-analyse/tls_alert.pcap.out b/test/results/flow-analyse/default/socks-http-example.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_alert.pcap.out +++ b/test/results/flow-analyse/default/socks-http-example.pcap.out diff --git a/test/results/flow-analyse/default/softether.pcap.out b/test/results/flow-analyse/default/softether.pcap.out new file mode 100644 index 000000000..52394c715 --- /dev/null +++ b/test/results/flow-analyse/default/softether.pcap.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.2.100,130.158.6.113,udp,51381,5004,finished,17,15,1657762868392000,1657907318692000,1657907318946000,1,0,480,328,975,1020,0,257000,36711136.0,1566080232,215702336.0,46527500976652288.0,2.7,"257000,27676000,27674000,26195000,26194000,26159000,26161000,10299000,10301000,14858000,14853000,27814000,27815000,25788000,1540291232,1566080232,18689000,18689000,5427000,5426000,27856000,27856000,26072000,26072000,26524000,26524000,24993000,24993000,25093000,862645000,887738000",29,90.3,508,132.5,17556.2,4.1,"29,56,29,56,29,56,29,56,508,356,29,56,29,56,29,29,56,508,356,29,56,29,56,29,56,29,56,29,56,29,29,56","15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1","4.513154984,5.059597492,4.582120895,5.059597492,4.582120895,4.988168716,4.582120895,5.059597492,5.016859055,4.526149750,4.582120895,5.059597492,4.513154984,5.010403156,4.582120895,4.582120895,5.001649380,5.023393631,4.521674156,4.582120895,5.001649380,4.582120895,5.059597492,4.513154984,5.059597492,4.582120895,5.059597492,4.582120895,5.059597492,4.582120895,4.582120895,4.988168716",Softether,290,1,Acceptable,VPN,6,DPI,"" diff --git a/test/results/flow-analyse/tls_cipher_lens.pcap.out b/test/results/flow-analyse/default/someip-tp.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_cipher_lens.pcap.out +++ b/test/results/flow-analyse/default/someip-tp.pcap.out diff --git a/test/results/flow-analyse/tls_client_certificate_with_missing_server_one.pcapng.out b/test/results/flow-analyse/default/someip-udp-method-call.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_client_certificate_with_missing_server_one.pcapng.out +++ b/test/results/flow-analyse/default/someip-udp-method-call.pcapng.out diff --git a/test/results/flow-analyse/tls_esni_sni_both.pcap.out b/test/results/flow-analyse/default/someip_sd_sample.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_esni_sni_both.pcap.out +++ b/test/results/flow-analyse/default/someip_sd_sample.pcap.out diff --git a/test/results/flow-analyse/tls_false_positives.pcapng.out b/test/results/flow-analyse/default/source_engine.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_false_positives.pcapng.out +++ b/test/results/flow-analyse/default/source_engine.pcap.out diff --git a/test/results/flow-analyse/tls_invalid_reads.pcap.out b/test/results/flow-analyse/default/sql_injection.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_invalid_reads.pcap.out +++ b/test/results/flow-analyse/default/sql_injection.pcap.out diff --git a/test/results/flow-analyse/tls_missing_ch_frag.pcap.out b/test/results/flow-analyse/default/ssdp-m-search-ua.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_missing_ch_frag.pcap.out +++ b/test/results/flow-analyse/default/ssdp-m-search-ua.pcap.out diff --git a/test/results/flow-analyse/tls_multiple_synack_different_seq.pcapng.out b/test/results/flow-analyse/default/ssdp-m-search.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_multiple_synack_different_seq.pcapng.out +++ b/test/results/flow-analyse/default/ssdp-m-search.pcap.out diff --git a/test/results/flow-analyse/ssh.pcap.out b/test/results/flow-analyse/default/ssh.pcap.out index f21fe1d5f..f21fe1d5f 100644 --- a/test/results/flow-analyse/ssh.pcap.out +++ b/test/results/flow-analyse/default/ssh.pcap.out diff --git a/test/results/flow-analyse/tls_port_80.pcapng.out b/test/results/flow-analyse/default/ssl-cert-name-mismatch.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_port_80.pcapng.out +++ b/test/results/flow-analyse/default/ssl-cert-name-mismatch.pcap.out diff --git a/test/results/flow-analyse/starcraft_battle.pcap.out b/test/results/flow-analyse/default/starcraft_battle.pcap.out index 428330260..428330260 100644 --- a/test/results/flow-analyse/starcraft_battle.pcap.out +++ b/test/results/flow-analyse/default/starcraft_battle.pcap.out diff --git a/test/results/flow-analyse/tls_torrent.pcapng.out b/test/results/flow-analyse/default/steam.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_torrent.pcapng.out +++ b/test/results/flow-analyse/default/steam.pcap.out diff --git a/test/results/flow-analyse/tls_unidirectional.pcap.out b/test/results/flow-analyse/default/steam_datagram_relay_ping.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tls_unidirectional.pcap.out +++ b/test/results/flow-analyse/default/steam_datagram_relay_ping.pcapng.out diff --git a/test/results/flow-analyse/stun.pcap.out b/test/results/flow-analyse/default/stun.pcap.out index 635985fe9..635985fe9 100644 --- a/test/results/flow-analyse/stun.pcap.out +++ b/test/results/flow-analyse/default/stun.pcap.out diff --git a/test/results/flow-analyse/stun_signal.pcapng.out b/test/results/flow-analyse/default/stun_signal.pcapng.out index e8a795c40..e73c7e752 100644 --- a/test/results/flow-analyse/stun_signal.pcapng.out +++ b/test/results/flow-analyse/default/stun_signal.pcapng.out @@ -1,4 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.12.169,18.195.131.143,udp,43068,61156,finished,16,16,1636901958294242,1636901960601813,1636901960620966,28,0,104,96,1032,1012,0,25,149493.4,679364,200828.1,40331911168.0,3.9,"83894,37,92476,7793,46066,91419,25,37867,39955,9097,41868,367689,125,441001,43,600796,610250,117949,49918,49758,64212,212886,679364,8747,45,503798,102888,200994,101814,9344,62177",56,91.9,132,24.9,621.5,4.9,"124,92,124,92,132,132,92,124,92,92,124,92,84,56,84,56,124,92,84,84,124,92,56,84,56,56,56,124,92,84,56,84","4,3,4,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,4,5,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,0,1,1,0,1,1,0,0,0,1,1,0,1,0,1,1,0,0,1,1,1,0,0,1,0,0,1","5.768973827,5.811776161,5.931350708,5.819116592,5.739065170,5.636717796,5.871664047,5.907987118,5.819117546,5.781831741,5.903046608,5.775639534,5.668575764,5.083614826,5.811898232,5.271638393,5.861793995,5.810910702,5.781786919,5.698687553,5.893005371,5.819117069,5.083614826,5.770115376,5.235924244,5.200210571,5.083615780,5.835623741,5.811777115,5.606133938,5.119328976,5.779102325",STUN,78,0,Acceptable,Network,6,DPI,"5" -1,ip4,35.158.183.167,192.168.12.169,icmp,,,finished,30,2,1636901936083692,1636901980739508,1636901940925734,56,0,64,104,1760,208,0,15,1596705.0,17079364,3547473.5,12584568750080.0,2.8,"4084,63003,42,180775,3510,1499231,2002773,15,4841966,76,17079364,30045,28084,9989,178591,30710,1472432,2000483,30998,3968781,29896,37348,7808,7927339,28492,35381,6539,7931223,29238,34577,5065",76,81.5,124,11.6,133.8,5.0,"76,76,84,84,76,76,76,76,76,124,124,76,76,84,84,76,76,76,76,76,76,76,84,84,76,76,84,84,76,76,84,84","0,20,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.045846939,5.151109695,5.089153290,5.017724991,5.072162628,5.124794006,5.045846939,5.035913944,5.088545322,5.533661366,5.689179420,4.953483582,4.999665260,4.975942135,4.999751568,4.937100887,4.999665260,5.025980949,5.025980949,4.999665260,4.989732265,4.983282089,4.999751568,4.975942135,5.025980949,5.062229633,5.056357384,5.008738518,4.999665260,5.035913944,5.008738041,5.056357384",ICMP,81,0,Acceptable,Network,6,DPI,"" -1,ip4,192.168.12.169,18.195.131.143,udp,47767,61498,finished,16,16,1636902000073738,1636902002442030,1636902002440493,28,0,104,96,1068,1052,0,43,152743.5,665020,189167.3,35784253440.0,4.0,"68482,50,70303,29273,44732,113365,45,43187,26522,8477,31033,313588,306,410657,43,665020,630540,122450,190474,61616,378076,7868,325508,42160,76005,424878,96788,5410,434339,47676,66176",56,94.2,132,24.6,605.9,4.9,"124,92,124,92,132,132,92,124,92,92,124,92,84,56,84,56,124,92,124,92,84,84,56,56,56,84,124,84,56,92,124,92","3,3,5,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,3,5,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,0,1,1,0,1,1,0,0,0,1,1,0,1,1,0,0,1,1,0,1,1,0,0,0,1,1,0","5.861794472,5.759229183,5.867881298,5.702216148,5.875429153,5.754216671,5.819118500,5.958508492,5.832649708,5.805582047,5.875729084,5.797377586,5.796609879,5.155043602,5.748991013,5.105850220,5.758409977,5.819116116,5.891858101,5.702215672,5.716967583,5.862202168,5.155044079,5.141563416,5.119328976,5.772800446,5.887964725,5.772800446,5.119329453,5.783843040,5.817300797,5.830357552",STUN.SignalVoip,78.269,0,Acceptable,VoIP,6,DPI,"5" +1,ip4,35.158.183.167,192.168.12.169,icmp,,,finished,30,2,1636901936083692,1636901980739508,1636901940925734,56,0,64,104,1760,208,0,15,1596705.0,17079364,3547473.5,12584568750080.0,2.8,"4084,63003,42,180775,3510,1499231,2002773,15,4841966,76,17079364,30045,28084,9989,178591,30710,1472432,2000483,30998,3968781,29896,37348,7808,7927339,28492,35381,6539,7931223,29238,34577,5065",76,81.5,124,11.6,133.8,5.0,"76,76,84,84,76,76,76,76,76,124,124,76,76,84,84,76,76,76,76,76,76,76,84,84,76,76,84,84,76,76,84,84","0,20,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.045846939,5.151109695,5.089153290,5.017724991,5.072162628,5.124794006,5.045846939,5.035913944,5.088545322,5.533661366,5.689179420,4.953483582,4.999665260,4.975942135,4.999751568,4.937100887,4.999665260,5.025980949,5.025980949,4.999665260,4.989732265,4.983282089,4.999751568,4.975942135,5.025980949,5.062229633,5.056357384,5.008738518,4.999665260,5.035913944,5.008738041,5.056357384",ICMP,81,0,Acceptable,Network,6,DPI,"46" +1,ip4,192.168.12.169,18.195.131.143,udp,47767,61498,finished,16,16,1636902000073738,1636902002442030,1636902002440493,28,0,104,96,1068,1052,0,43,152743.5,665020,189167.3,35784253440.0,4.0,"68482,50,70303,29273,44732,113365,45,43187,26522,8477,31033,313588,306,410657,43,665020,630540,122450,190474,61616,378076,7868,325508,42160,76005,424878,96788,5410,434339,47676,66176",56,94.2,132,24.6,605.9,4.9,"124,92,124,92,132,132,92,124,92,92,124,92,84,56,84,56,124,92,124,92,84,84,56,56,56,84,124,84,56,92,124,92","3,3,5,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,3,5,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,0,1,1,0,1,1,0,0,0,1,1,0,1,1,0,0,1,1,0,1,1,0,0,0,1,1,0","5.861794472,5.759229183,5.867881298,5.702216148,5.875429153,5.754216671,5.819118500,5.958508492,5.832649708,5.805582047,5.875729084,5.797377586,5.796609879,5.155043602,5.748991013,5.105850220,5.758409977,5.819116116,5.891858101,5.702215672,5.716967583,5.862202168,5.155044079,5.141563416,5.119328976,5.772800446,5.887964725,5.772800446,5.119329453,5.783843040,5.817300797,5.830357552",STUN.SignalVoip,78.269,0,Acceptable,VoIP,6,DPI,"5,46" diff --git a/test/results/flow-analyse/toca-boca.pcap.out b/test/results/flow-analyse/default/syncthing.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/toca-boca.pcap.out +++ b/test/results/flow-analyse/default/syncthing.pcap.out diff --git a/test/results/flow-analyse/tuya_lp.pcap.out b/test/results/flow-analyse/default/synscan.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/tuya_lp.pcap.out +++ b/test/results/flow-analyse/default/synscan.pcap.out diff --git a/test/results/flow-analyse/ubntac2.pcap.out b/test/results/flow-analyse/default/syslog.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/ubntac2.pcap.out +++ b/test/results/flow-analyse/default/syslog.pcap.out diff --git a/test/results/flow-analyse/default/tailscale.pcap.out b/test/results/flow-analyse/default/tailscale.pcap.out new file mode 100644 index 000000000..e00ba32c4 --- /dev/null +++ b/test/results/flow-analyse/default/tailscale.pcap.out @@ -0,0 +1,2 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.88.3,18.196.71.179,udp,41641,41641,finished,13,19,1623328901893092,1623328910935194,1623328911751937,92,0,128,128,1430,2162,0,7,609708.0,1999684,605237.1,366311899136.0,4.2,"1831567,1832853,459337,19,7,851239,689283,1999684,305038,1197527,993302,17713,10,118067,686079,686069,167240,28515,268363,28631,1001510,1709853,809387,161594,38729,229122,33650,39336,1000927,1009891,706405",120,140.2,156,15.4,237.9,5.0,"120,120,138,156,156,156,156,120,138,156,120,138,156,120,138,120,138,120,156,138,156,156,120,138,120,156,156,138,156,156,156,120","0,0,4,5,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,6,3,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,1,1,1,0,1,0,1,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,1,0,1,1","6.258774757,6.327646255,6.564895153,6.334487915,6.307401657,6.374646664,6.326507568,6.403507233,6.611924648,6.410363674,6.506895065,6.510478020,6.402382374,6.340927124,6.480768204,6.334637165,6.568448067,6.498397350,6.475291729,6.619921207,6.387466908,6.409846783,6.390228748,6.538738251,6.500603676,6.552214622,6.461646080,6.474994183,6.375043869,6.467308998,6.309903622,6.317968845",Tailscale,24,1,Acceptable,VPN,6,DPI,"46" diff --git a/test/results/flow-analyse/upnp.pcap.out b/test/results/flow-analyse/default/targusdataspeed_false_positives.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/upnp.pcap.out +++ b/test/results/flow-analyse/default/targusdataspeed_false_positives.pcap.out diff --git a/test/results/flow-analyse/vrrp3.pcapng.out b/test/results/flow-analyse/default/tcp_scan.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/vrrp3.pcapng.out +++ b/test/results/flow-analyse/default/tcp_scan.pcapng.out diff --git a/test/results/flow-analyse/teams.pcap.out b/test/results/flow-analyse/default/teams.pcap.out index 2cfaa518e..2df3c6049 100644 --- a/test/results/flow-analyse/teams.pcap.out +++ b/test/results/flow-analyse/default/teams.pcap.out @@ -9,9 +9,9 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,192.168.1.6,13.107.18.11,tcp,60549,443,info,18,14,1587041684306115,1587041684950374,1587041684410372,0,0,1440,1452,3472,5797,0,1,24145.7,539594,94604.1,8949939200.0,1.9,"11504,11610,262,11878,32500,90,44163,247,1,223,3839,7741,325,72,14634,1492,13,4159,11,266,6513,474,6734,4309,9884,14215,10718,10725,539594,6,314",40,331.5,1492,473.5,224192.2,3.9,"64,52,40,251,46,1492,1492,40,1492,80,40,198,133,578,172,46,366,109,40,40,78,46,78,40,46,689,40,359,40,1480,694,248","9,1,1,0,2,0,2,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","5,2,1,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0","0,1,0,0,1,1,1,0,1,1,0,0,0,0,0,1,1,1,0,0,0,1,1,0,1,1,0,1,0,0,0,0","4.428027153,4.893245220,4.521928310,5.397158146,4.505983353,6.671830177,7.464404583,4.630641460,7.577803612,5.737496376,4.680641174,6.516131401,6.154890537,7.647973537,6.500202656,4.505983353,7.196300030,5.817581654,4.611769199,4.561769485,5.250086308,4.457919598,5.392898560,4.630641460,4.522393227,7.690679073,4.680641174,7.335716724,4.680641174,7.846065521,7.720572472,6.957527637",,,,,,,,"" 1,ip4,192.168.1.6,52.113.194.132,tcp,60554,443,info,14,18,1587041685240465,1587041685469669,1587041685469973,0,0,1082,1452,1426,15976,0,3,14797.2,153955,35697.7,1274323968.0,2.8,"12903,12995,473,12371,1988,1502,15362,129,134,115,3,85,21608,33026,11480,11732,109,11784,570,13396,140399,715,153955,248,230,250,250,503,25,129,243",40,585.7,1492,671.4,450756.0,4.0,"64,52,40,226,46,1492,1492,40,1492,40,1492,168,40,147,46,91,46,91,40,1122,46,1492,1492,40,1317,40,1492,1492,40,40,1492,1492","10,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,10,0,0","0,1,0,0,1,1,1,0,1,0,1,1,0,0,1,0,1,1,0,0,1,1,1,0,1,0,1,1,0,0,1,1","4.365527153,4.878727913,4.471928596,5.502106190,4.402616024,7.277978420,7.489027023,4.630640984,7.478912354,4.521928310,7.663036823,6.686788082,4.630640984,6.493359089,4.462505341,5.681205750,4.462504864,5.560394764,4.580641270,7.802004814,4.565872192,7.879904747,7.863986492,4.580641270,7.860152721,4.580640793,7.874552727,7.850657463,4.580641270,4.471928596,7.869473934,7.878328800",,,,,,,,"" 1,ip4,192.168.1.6,52.114.77.33,tcp,60559,443,finished,21,11,1587041686239545,1587041686542441,1587041686541501,0,0,1428,1440,14115,4699,0,2,19511.4,52987,22191.7,492470496.0,3.9,"48601,48710,307,51003,89,50699,16,253,253,1686,49778,48144,1391,5,2,50498,49101,4,2,3,37233,37219,5,11525,11515,965,36039,15972,52987,736,111",52,640.9,1492,667.9,446080.7,4.1,"64,60,52,258,1492,1492,64,52,1375,52,145,103,52,1480,1480,1480,52,1480,1480,1480,1480,52,1480,1480,52,985,52,52,497,52,83,52","9,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0","6,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0","0,1,0,0,1,1,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,1,0,1,1,1,0,0,0","4.396777153,5.256567955,4.923395157,6.033491611,7.275527000,7.277948856,5.071470261,4.945419312,7.645617962,4.976373672,5.915142536,5.707202435,4.976374149,7.861220360,7.878036976,7.850315571,5.131024837,7.877380371,7.857055187,7.886486053,7.876827240,5.169486523,7.849795818,7.874622822,5.078045845,7.791067600,5.131024837,5.207948208,7.563468933,5.053297043,5.290699482,4.969671726",TLS.Microsoft,91.212,1,Safe,Cloud,6,DPI,"15" -1,ip4,192.168.1.6,104.40.187.151,tcp,60562,443,finished,19,13,1587041687436782,1587041687725655,1587041687725568,0,0,1313,1440,2206,7143,0,3,18634.2,125561,31723.1,1006353792.0,3.4,"29516,29616,237,45747,220,45693,117,89,54,132,3,86,615,23250,232,30155,31,6115,4,245,22863,22646,1494,1434,2892,30,32749,246,30074,125513,125561",52,345.2,1492,499.9,249913.2,3.9,"64,60,52,266,1492,1492,64,1492,52,52,1492,281,52,145,145,424,103,121,52,52,90,90,52,548,52,1365,135,52,94,52,510,52","12,1,3,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0","2,3,1,0,0,0,0,1,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,1,0,0,1,1,0,0,0,0,1,1,0,0,0,1,0,1,0,0,0,1,1,0,1,0","4.365527153,5.169149399,4.868495941,5.580047131,7.357915878,7.526344776,4.919355392,7.363313675,4.945419312,4.786791325,7.588277340,7.143245697,4.983880997,5.918394089,6.257330894,7.398386002,5.555244923,6.105889320,4.945419312,4.945419312,5.368302345,5.567127228,4.945419312,7.528010845,4.983880997,7.854734421,6.103594780,5.100070000,5.655968666,4.983880520,7.545987606,4.861793995",TLS,91,1,Safe,Web,6,DPI,"" +1,ip4,192.168.1.6,104.40.187.151,tcp,60562,443,finished,19,13,1587041687436782,1587041687725655,1587041687725568,0,0,1313,1440,2206,7143,0,3,18634.2,125561,31723.1,1006353792.0,3.4,"29516,29616,237,45747,220,45693,117,89,54,132,3,86,615,23250,232,30155,31,6115,4,245,22863,22646,1494,1434,2892,30,32749,246,30074,125513,125561",52,345.2,1492,499.9,249913.2,3.9,"64,60,52,266,1492,1492,64,1492,52,52,1492,281,52,145,145,424,103,121,52,52,90,90,52,548,52,1365,135,52,94,52,510,52","12,1,3,0,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0","2,3,1,0,0,0,0,1,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,1,0,0,1,1,0,0,0,0,1,1,0,0,0,1,0,1,0,0,0,1,1,0,1,0","4.365527153,5.169149399,4.868495941,5.580047131,7.357915878,7.526344776,4.919355392,7.363313675,4.945419312,4.786791325,7.588277340,7.143245697,4.983880997,5.918394089,6.257330894,7.398386002,5.555244923,6.105889320,4.945419312,4.945419312,5.368302345,5.567127228,4.945419312,7.528010845,4.983880997,7.854734421,6.103594780,5.100070000,5.655968666,4.983880520,7.545987606,4.861793995",TLS.Skype_Teams,91.125,1,Acceptable,VoIP,3,DPI (partial),"" 1,ip4,192.168.1.6,52.114.77.33,tcp,60561,443,info,20,12,1587041687245112,1587041687718851,1587041687768506,0,0,1428,1440,17623,4254,0,2,32165.6,161774,44327.4,1964919296.0,3.6,"48418,48527,459,88180,136486,113743,249,161774,129,117,1072,74551,73518,1076,4,2,50124,49022,3,3,12,48400,48413,4,15,2,1599,1536,46881,1065,1749",52,736.7,1492,694.0,481656.1,4.2,"64,60,52,258,258,64,1492,1492,52,1375,52,145,103,52,1480,1480,1480,52,1480,1480,1480,1480,52,1480,1480,1480,1480,52,1462,52,52,52","5,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0,0","8,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,2,0,0","0,1,0,0,0,1,1,1,0,1,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,0,0,1,0,1,1,1","4.396777153,5.256567478,4.923395157,5.966666698,5.971492767,5.091578960,7.290405750,7.275161743,4.961856842,7.668800354,5.000318527,6.002202988,5.583368301,4.961856842,7.860765934,7.857263088,7.894361019,5.193430901,7.864349842,7.853641510,7.869278908,7.874048233,5.054101944,7.853607655,7.866478443,7.865472317,7.878810406,5.154969692,7.853725433,5.193431377,5.154969692,5.154969692",,,,,,,,"" 1,ip4,192.168.1.6,52.114.108.8,tcp,60565,443,finished,18,14,1587041691149774,1587041691305451,1587041691582252,0,0,994,1440,2028,8121,0,3,18972.7,276869,49493.9,2449644032.0,2.9,"19199,19302,171,22008,34,21827,18,184,203,246,14,193,1070,12295,280,19893,29,6313,3,603,11971,11399,1472,1415,54998,62106,42,25528,33,18437,276869",52,370.2,1492,512.1,262257.7,3.9,"64,60,52,274,1492,1492,64,52,1492,52,1492,471,52,178,145,525,103,121,52,52,90,90,52,511,52,52,1046,134,52,94,52,1335","11,1,2,1,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,3,1,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,4,0,0","0,1,0,0,1,1,0,0,1,0,1,1,0,0,0,0,1,1,0,0,0,1,0,1,0,1,0,0,1,1,0,1","4.396777153,5.256567478,4.923395634,5.577177048,7.100010395,7.346216679,4.975505829,4.976374149,7.520713806,4.854287148,7.591184139,7.492725372,4.937912464,6.281796932,6.325607300,7.565563679,5.628156662,5.942033768,4.976374149,4.937912464,5.421134472,5.660066128,5.014835358,7.536164761,4.976373672,5.169486523,7.784315586,6.192806721,5.169486523,5.596017838,5.014835358,7.848025322",TLS.Teams,91.250,1,Safe,Collaborative,6,DPI,"" 1,ip4,192.168.1.6,52.114.76.48,tcp,60544,443,finished,16,16,1587041682376166,1587041682938651,1587041692001418,0,0,1060,1452,2113,7396,0,2,328636.7,8978171,1582353.1,2503841415168.0,0.8,"47150,47228,506,44398,29,43913,16,46,186,124,2,213,4,4433,9743,291,46519,32116,477,409,98,18910,1378,20235,62883,403234,424977,8978171,32,9,7",40,339.2,1492,486.1,236250.5,3.9,"64,52,40,276,1492,1492,52,40,40,1492,1492,309,40,40,198,133,568,91,40,109,40,78,46,409,40,46,1100,46,411,415,86,78","10,1,1,0,1,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,3,1,0,0,0,0,0,1,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,0,0,1,1,1,0,0,0,0,0,1,0,1,0,0,1,1,0,1,0,1,1,1,1,1","4.334277153,4.946223736,4.571928501,5.576080799,7.377434731,7.334023952,4.748329639,4.630640984,4.571928501,7.530410290,7.590536594,7.109602451,4.680641174,4.630641460,6.484649181,6.111595631,7.563093662,5.442209721,4.630641460,5.902398109,4.630641460,5.214766979,4.462505341,7.402733803,4.680641174,4.505983353,7.828750610,4.609350681,7.428915024,7.453095436,5.564571857,5.463537216",TLS.Teams,91.250,1,Safe,Collaborative,6,DPI,"" 1,ip4,192.168.1.6,52.114.250.123,tcp,50018,443,finished,19,13,1587041693516414,1587041693824623,1587041695435566,0,0,187,1452,477,6361,0,1,71850.4,1566873,274680.6,75449425920.0,1.9,"44968,45079,183,47440,47249,164,13,124,2,107,17,104,3,107,2,120,2,1,8026,8,35,52434,1246,45626,48613,92238,43679,69083,272,113543,1566873",40,256.9,1492,427.0,182315.3,3.7,"64,52,40,227,1492,52,1492,588,52,52,1492,588,52,40,588,166,40,40,40,147,46,85,46,91,40,141,224,40,71,40,46,46","15,1,0,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0","0,1,0,0,1,0,1,1,0,0,1,1,0,0,1,1,0,0,0,0,0,0,1,1,0,0,1,0,0,0,1,1","4.396777153,4.946223736,4.453056812,5.436062336,7.472877979,4.624014378,7.357961178,6.174726009,4.707639694,4.669178009,7.651301384,7.035131931,4.669178009,4.492897511,7.576755524,6.572272301,4.384184361,4.492897511,4.492897034,6.376044750,4.495644569,5.773638725,4.565871716,5.388861179,4.561769009,6.442826271,6.864662647,4.511769295,5.438062191,4.384184361,4.565872192,4.565872192",TLS.Teams,91.250,1,Safe,Collaborative,6,DPI,"15" -1,ip4,93.71.110.205,192.168.1.6,udp,16332,50016,finished,25,7,1587041695305290,1587041697913583,1587041697668816,38,0,1214,1214,4324,2890,0,1,160381.3,1168245,365653.3,133702352896.0,2.7,"24795,221,101349,1168245,1167037,967065,50759,1119237,13,25,50990,80302,1990,2655,3736,4,1,2,10681,24170,9306,21453,4525,19907,25341,9245,24382,24626,9496,26004,24257",66,253.4,1242,374.4,140199.2,4.0,"140,116,140,116,144,116,138,136,66,1242,1242,136,101,66,1242,1242,70,194,126,94,96,103,108,110,102,98,112,106,103,101,102,102","0,2,16,4,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,1,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.443928242,5.441569805,5.550033092,5.533423424,5.469605446,5.457950115,6.418050289,5.494081497,5.274568558,7.835727215,7.805037022,5.427760124,6.064149857,5.328952789,7.830739975,7.834946632,5.426148415,6.862842083,6.378197670,5.942782402,6.043297768,6.096649170,5.395052433,6.251680851,6.123402596,6.007471561,6.260177612,6.012121677,6.079421997,6.215091705,6.135609150,6.155217648",STUN.Skype_TeamsCall,78.38,0,Acceptable,VoIP,6,DPI,"5" +1,ip4,93.71.110.205,192.168.1.6,udp,16332,50016,finished,25,7,1587041695305290,1587041697913583,1587041697668816,38,0,1214,1214,4324,2890,0,1,160381.3,1168245,365653.3,133702352896.0,2.7,"24795,221,101349,1168245,1167037,967065,50759,1119237,13,25,50990,80302,1990,2655,3736,4,1,2,10681,24170,9306,21453,4525,19907,25341,9245,24382,24626,9496,26004,24257",66,253.4,1242,374.4,140199.2,4.0,"140,116,140,116,144,116,138,136,66,1242,1242,136,101,66,1242,1242,70,194,126,94,96,103,108,110,102,98,112,106,103,101,102,102","0,2,16,4,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,1,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.443928242,5.441569805,5.550033092,5.533423424,5.469605446,5.457950115,6.418050289,5.494081497,5.274568558,7.835727215,7.805037022,5.427760124,6.064149857,5.328952789,7.830739975,7.834946632,5.426148415,6.862842083,6.378197670,5.942782402,6.043297768,6.096649170,5.395052433,6.251680851,6.123402596,6.007471561,6.260177612,6.012121677,6.079421997,6.215091705,6.135609150,6.155217648",STUN.Skype_TeamsCall,78.38,0,Acceptable,VoIP,6,DPI,"5,46" diff --git a/test/results/flow-analyse/teamspeak3.pcap.out b/test/results/flow-analyse/default/teamspeak3.pcap.out index 3736facff..3736facff 100644 --- a/test/results/flow-analyse/teamspeak3.pcap.out +++ b/test/results/flow-analyse/default/teamspeak3.pcap.out diff --git a/test/results/flow-analyse/teamviewer.pcap.out b/test/results/flow-analyse/default/teamviewer.pcap.out index 9efe640b3..9efe640b3 100644 --- a/test/results/flow-analyse/teamviewer.pcap.out +++ b/test/results/flow-analyse/default/teamviewer.pcap.out diff --git a/test/results/flow-analyse/telegram.pcap.out b/test/results/flow-analyse/default/telegram.pcap.out index 474d09676..feb1aa20f 100644 --- a/test/results/flow-analyse/telegram.pcap.out +++ b/test/results/flow-analyse/default/telegram.pcap.out @@ -1,7 +1,7 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.1.75,224.0.0.251,udp,5353,5353,finished,32,0,1588779596708234,1588779604771519,1588779596708234,100,0,266,0,5014,0,0,424,260106.0,1089013,238284.9,56779681792.0,4.4,"549364,840,252816,249231,102809,152763,104881,141371,2649,102162,252500,506171,1089013,524484,451,254547,249123,108883,146831,101026,145194,2416,102114,255962,497942,504741,600172,564928,424,248284,249193",128,184.7,294,56.4,3176.8,4.9,"128,219,294,155,139,155,139,197,170,294,139,153,261,128,219,294,155,139,155,139,197,170,294,139,153,197,153,128,219,294,155,139","0,0,0,18,2,6,0,1,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.085784912,5.440144539,5.167281628,5.217712402,4.744915485,5.209679604,4.709530830,5.181225777,5.157635212,5.184309006,4.657408237,4.791635990,5.077552319,5.091682434,5.425326347,5.176321030,5.207327843,4.744915009,5.230615616,4.669892788,5.180718899,5.192929745,5.173479080,4.723919392,4.791635990,5.190871239,4.722968102,5.085784912,5.449277401,5.181741714,5.181521416,4.739484310",MDNS,8,0,Acceptable,Network,6,DPI,"" 1,ip6,fe80::4ba:91a:7817:e318,ff02::fb,udp,5353,5353,finished,32,0,1588779596708683,1588779604771558,1588779596708683,100,0,266,0,5014,0,0,368,260092.7,1088510,238249.1,56762626048.0,4.4,"549636,368,252675,249340,102637,153314,104807,140890,2645,102602,252497,506250,1088510,524637,499,254511,249377,108993,147062,100772,145197,1893,102609,256062,497966,504718,600438,564206,375,249009,248380",148,204.7,314,56.4,3176.8,4.9,"148,239,314,175,159,175,159,217,190,314,159,173,281,148,239,314,175,159,175,159,217,190,314,159,173,217,173,148,239,314,175,159","0,0,0,18,2,6,0,1,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.905550957,5.334246159,5.128689289,5.078598976,4.487797260,5.078598976,4.471708298,5.059122086,5.029262066,5.128689289,4.471708298,4.521756649,4.957518101,4.905550957,5.322719574,5.127128124,5.090027332,4.483049393,5.090027332,4.471708298,5.044167519,5.029262066,5.127128124,4.471708298,4.533317089,5.044167519,4.533317089,4.886936188,5.334246159,5.125041962,5.090027332,4.500375748",MDNS,8,0,Acceptable,Network,6,DPI,"" -1,ip4,192.168.1.77,91.108.8.7,udp,23174,521,finished,10,22,1588779616036528,1588779617856756,1588779617876992,32,0,96,192,672,3040,0,658,118086.8,500928,112055.1,12556351488.0,4.4,"33725,303789,500928,195774,135671,308435,212114,658,38919,154099,154494,74510,133656,63749,29902,38640,63854,177395,37753,25997,43596,64156,189778,58771,4478,63507,64504,42995,64523,315929,64393",60,144.0,220,57.3,3288.0,4.9,"68,92,124,68,92,124,124,60,124,76,68,92,220,124,220,124,220,204,124,124,204,220,204,68,92,204,204,188,204,204,124,220","0,5,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,4,4,0,8,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,0,1,0,0,1,0,1,1,0,1,1,1,1,0,1,1,1,1,0,1,1,1,1,1,1,0,1","4.868813038,5.080193996,6.484322071,4.938737869,5.058454990,6.613354206,6.541945457,4.581729889,6.581096649,5.095970154,4.909326553,5.058454990,7.109486580,6.431981564,6.988621235,6.484322548,7.029896736,7.015371323,6.468193054,6.439083576,6.959566116,7.054485798,6.952973843,4.898225307,5.050249577,6.888344765,6.828825951,6.886248589,6.965054512,6.968754292,6.432657719,7.008387089",Telegram,185,1,Acceptable,Chat,6,DPI,"" +1,ip4,192.168.1.77,91.108.8.7,udp,23174,521,finished,10,22,1588779616036528,1588779617856756,1588779617876992,32,0,96,192,672,3040,0,658,118086.8,500928,112055.1,12556351488.0,4.4,"33725,303789,500928,195774,135671,308435,212114,658,38919,154099,154494,74510,133656,63749,29902,38640,63854,177395,37753,25997,43596,64156,189778,58771,4478,63507,64504,42995,64523,315929,64393",60,144.0,220,57.3,3288.0,4.9,"68,92,124,68,92,124,124,60,124,76,68,92,220,124,220,124,220,204,124,124,204,220,204,68,92,204,204,188,204,204,124,220","0,5,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,4,4,0,8,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,1,0,1,0,0,1,0,1,1,0,1,1,1,1,0,1,1,1,1,0,1,1,1,1,1,1,0,1","4.868813038,5.080193996,6.484322071,4.938737869,5.058454990,6.613354206,6.541945457,4.581729889,6.581096649,5.095970154,4.909326553,5.058454990,7.109486580,6.431981564,6.988621235,6.484322548,7.029896736,7.015371323,6.468193054,6.439083576,6.959566116,7.054485798,6.952973843,4.898225307,5.050249577,6.888344765,6.828825951,6.886248589,6.965054512,6.968754292,6.432657719,7.008387089",Telegram,185,1,Acceptable,Chat,6,DPI,"46" 1,ip4,192.168.1.77,192.168.1.52,udp,23174,31480,info,13,19,1588779617174153,1588779621221417,1588779621214760,48,0,192,240,2016,3216,0,42308,260899.1,1998754,472680.0,223426379776.0,3.6,"176557,505731,492773,1175336,327643,331901,1681273,64229,63452,64312,42308,63943,1998754,63768,58341,64131,69558,64360,57812,43094,58078,62201,58103,63786,58195,64166,58195,62003,69553,66619,57696",76,191.5,268,54.5,2971.8,4.9,"108,108,108,76,92,76,92,220,252,268,252,252,236,204,220,220,220,204,188,220,204,204,204,220,204,204,204,204,220,204,220,220","0,1,2,0,0,6,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,3,0,0,5,6,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,1,0,0,1,1,1,1,1,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0","6.355636597,6.144942760,6.288552284,5.822080135,6.003186226,5.769448280,5.982532501,6.929369450,7.114085197,7.222516537,7.114981174,7.110270023,7.085702419,6.970178127,6.995306969,7.109033108,6.973239422,6.927752018,6.818934441,7.038531780,6.999271870,7.012288094,6.925349712,6.947623730,6.895937443,6.919244766,6.867631435,6.885515690,7.022007465,6.852213383,7.018121719,7.103372574",,,,,,,,"" -1,ip4,192.168.1.77,91.108.8.8,udp,28150,529,finished,23,9,1588779637543816,1588779639059745,1588779639085148,32,0,192,96,3024,688,0,8183,98621.3,504672,137715.2,18965475328.0,4.0,"38704,504672,472194,31371,48787,83063,90104,75511,57499,58021,58053,58125,51991,386634,9517,8470,27260,36050,21667,40197,58112,58011,58152,57862,69999,57869,58016,8183,436304,11258,25605",60,144.0,220,55.4,3064.0,4.9,"68,92,68,124,92,124,124,60,204,204,204,220,204,68,124,124,204,92,124,204,76,204,204,188,204,188,204,204,68,124,124,92","0,5,0,4,0,13,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,0,0,0,0,0,0,0,1,0,0,1,0,0,1,0,0,0,0,0,0,0,0,1,0,1","4.808521748,5.009398460,4.808521271,6.399723530,4.941553116,6.478234291,6.493558407,4.513398170,6.960375786,6.945446968,6.939341545,6.983797073,6.888330936,4.878446102,6.548838615,6.455212116,7.004271030,5.031137943,6.436948776,6.903464317,5.093001842,6.935152531,6.904445171,6.829572678,6.978069782,6.828165054,6.847532749,7.033680439,4.937269211,6.449124336,6.467387676,4.965919971",Telegram,185,1,Acceptable,Chat,6,DPI,"" -1,ip4,192.168.1.77,91.108.8.1,udp,28150,533,finished,8,24,1588779637543824,1588779639102885,1588779639500175,32,0,96,176,480,3200,0,7087,113400.4,504936,151181.6,22855886848.0,4.1,"34096,504936,476895,26281,48588,90140,359286,474896,22927,53992,44091,48774,32735,70515,63740,63677,64572,42031,447918,51385,12513,7087,54201,56023,36226,28925,63945,41904,63934,64562,64617",60,143.0,204,54.2,2943.0,4.9,"68,92,68,124,92,124,60,68,124,92,124,76,124,204,204,188,204,204,204,68,124,204,92,124,204,124,204,204,188,204,188,204","0,5,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,4,5,0,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,0,0,1,1,0,1,1,1,1,1,1,1,1,0,1,1,1,0,1,1,1,1,1,1,1,1","4.966681004,5.096354961,4.937269211,6.506538868,5.044672012,6.487470627,4.580064774,4.937269211,6.484322548,5.052877426,6.310050964,5.093001842,6.474280834,6.938044071,6.986575603,6.864440918,6.966351032,6.935151577,6.996869087,4.937269211,6.502585888,6.988362312,5.031137943,6.294727325,6.920350552,6.415852547,6.915544987,6.900125980,6.926725864,7.031893730,6.898294926,7.013583183",Telegram,185,1,Acceptable,Chat,6,DPI,"" +1,ip4,192.168.1.77,91.108.8.8,udp,28150,529,finished,23,9,1588779637543816,1588779639059745,1588779639085148,32,0,192,96,3024,688,0,8183,98621.3,504672,137715.2,18965475328.0,4.0,"38704,504672,472194,31371,48787,83063,90104,75511,57499,58021,58053,58125,51991,386634,9517,8470,27260,36050,21667,40197,58112,58011,58152,57862,69999,57869,58016,8183,436304,11258,25605",60,144.0,220,55.4,3064.0,4.9,"68,92,68,124,92,124,124,60,204,204,204,220,204,68,124,124,204,92,124,204,76,204,204,188,204,188,204,204,68,124,124,92","0,5,0,4,0,13,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,0,0,0,0,0,0,0,1,0,0,1,0,0,1,0,0,0,0,0,0,0,0,1,0,1","4.808521748,5.009398460,4.808521271,6.399723530,4.941553116,6.478234291,6.493558407,4.513398170,6.960375786,6.945446968,6.939341545,6.983797073,6.888330936,4.878446102,6.548838615,6.455212116,7.004271030,5.031137943,6.436948776,6.903464317,5.093001842,6.935152531,6.904445171,6.829572678,6.978069782,6.828165054,6.847532749,7.033680439,4.937269211,6.449124336,6.467387676,4.965919971",Telegram,185,1,Acceptable,Chat,6,DPI,"46" +1,ip4,192.168.1.77,91.108.8.1,udp,28150,533,finished,8,24,1588779637543824,1588779639102885,1588779639500175,32,0,96,176,480,3200,0,7087,113400.4,504936,151181.6,22855886848.0,4.1,"34096,504936,476895,26281,48588,90140,359286,474896,22927,53992,44091,48774,32735,70515,63740,63677,64572,42031,447918,51385,12513,7087,54201,56023,36226,28925,63945,41904,63934,64562,64617",60,143.0,204,54.2,2943.0,4.9,"68,92,68,124,92,124,60,68,124,92,124,76,124,204,204,188,204,204,204,68,124,204,92,124,204,124,204,204,188,204,188,204","0,5,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,4,5,0,14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,1,0,0,0,1,1,0,1,1,1,1,1,1,1,1,0,1,1,1,0,1,1,1,1,1,1,1,1","4.966681004,5.096354961,4.937269211,6.506538868,5.044672012,6.487470627,4.580064774,4.937269211,6.484322548,5.052877426,6.310050964,5.093001842,6.474280834,6.938044071,6.986575603,6.864440918,6.966351032,6.935151577,6.996869087,4.937269211,6.502585888,6.988362312,5.031137943,6.294727325,6.920350552,6.415852547,6.915544987,6.900125980,6.926725864,7.031893730,6.898294926,7.013583183",Telegram,185,1,Acceptable,Chat,6,DPI,"46" diff --git a/test/results/flow-analyse/telnet.pcap.out b/test/results/flow-analyse/default/telnet.pcap.out index b2a28eb13..b2a28eb13 100644 --- a/test/results/flow-analyse/telnet.pcap.out +++ b/test/results/flow-analyse/default/telnet.pcap.out diff --git a/test/results/flow-analyse/websocket.pcap.out b/test/results/flow-analyse/default/teredo.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/websocket.pcap.out +++ b/test/results/flow-analyse/default/teredo.pcap.out diff --git a/test/results/flow-analyse/tftp.pcap.out b/test/results/flow-analyse/default/tftp.pcap.out index 8dae6218e..8dae6218e 100644 --- a/test/results/flow-analyse/tftp.pcap.out +++ b/test/results/flow-analyse/default/tftp.pcap.out diff --git a/test/results/flow-analyse/whatsapp.pcap.out b/test/results/flow-analyse/default/threema.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/whatsapp.pcap.out +++ b/test/results/flow-analyse/default/threema.pcap.out diff --git a/test/results/flow-analyse/tinc.pcap.out b/test/results/flow-analyse/default/tinc.pcap.out index 37dded29f..63d037264 100644 --- a/test/results/flow-analyse/tinc.pcap.out +++ b/test/results/flow-analyse/default/tinc.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,131.114.168.27,185.83.218.112,udp,55655,55655,finished,17,15,1495983428000367,1495983431160747,1495983430158623,148,0,1468,1460,19148,16284,0,23,171568.9,1069532,377387.1,142420983808.0,2.5,"157,27472,47,25,27522,244,68,237,181,126,15445,30,41839,33,23,1057953,304,258,1003680,53,1840,184,45315,102,25,1024085,82,1069532,137,1001358,279",176,1135.2,1496,450.4,202833.5,4.9,"672,720,224,1472,768,216,1256,176,1296,1464,760,672,720,1264,176,1296,1344,1464,1360,1472,1488,1472,1480,1344,1472,1360,1488,1488,1488,1480,1496,1480","0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,2,0,0,2,6,0,0","0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,2,0,0,0,6,0,0","0,0,1,1,1,0,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,0,0,1,1,1,1,1,0,0,0,0","7.665557861,7.732561588,7.082343578,7.846774578,7.752214432,6.906925201,7.855091572,6.755141735,7.856310368,7.846433163,7.747685909,7.710433006,7.733560562,7.868661880,6.790736675,7.858621597,7.869617462,7.873907566,7.874854565,7.877315998,7.870153904,7.874608040,7.878478050,7.845719337,7.883452892,7.855854511,7.886187077,7.874522686,7.870358467,7.871251106,7.874283314,7.868322849",TINC,209,0,Acceptable,VPN,5,DPI (cache),"5" -1,ip4,185.83.218.112,131.114.168.27,udp,55656,55656,finished,12,20,1495983428043218,1495983432571150,1495983432526055,148,0,1444,1452,10944,20512,0,24,290670.0,2412459,558680.6,312123949056.0,2.9,"50,27,594,482,207,142,1049148,39,24,1048033,86,239,119,120,91,44079,43,25,1044735,279,1021999,20586,1001463,275,241,363633,1001240,149,123,2412459,39",104,1011.0,1480,450.3,202783.0,4.8,"752,1472,944,720,1256,1472,944,1056,656,320,1048,176,1296,512,656,320,176,1296,512,1464,1360,1360,1360,1472,1336,1304,104,1480,1464,1328,1376,1360","0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,1,0,0,0,1,0,0,1,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,1,0,2,1,0,0,1,0,0","0,0,1,0,1,0,0,0,0,1,0,0,0,0,0,1,0,0,0,1,0,1,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,1,2,2,2,0,0,2,3,0,0","0,0,0,1,1,1,1,0,0,0,1,1,1,1,1,1,0,0,0,1,1,0,1,1,1,1,1,1,1,1,0,0","7.690577507,7.881368160,7.775002003,7.728326797,7.851398468,7.867018700,7.774654388,7.831391335,7.688314915,7.329430103,7.812694550,6.669548035,7.843146801,7.557564259,7.679370403,7.194211483,6.957363605,7.850227833,7.572175503,7.873534679,7.858608246,7.866045952,7.839975357,7.845044613,7.866905689,7.841031551,6.193184853,7.882274628,7.896846294,7.859506130,7.852632523,7.876025200",TINC,209,0,Acceptable,VPN,5,DPI (cache),"5" +1,ip4,131.114.168.27,185.83.218.112,udp,55655,55655,finished,17,15,1495983428000367,1495983431160747,1495983430158623,148,0,1468,1460,19148,16284,0,23,171568.9,1069532,377387.1,142420983808.0,2.5,"157,27472,47,25,27522,244,68,237,181,126,15445,30,41839,33,23,1057953,304,258,1003680,53,1840,184,45315,102,25,1024085,82,1069532,137,1001358,279",176,1135.2,1496,450.4,202833.5,4.9,"672,720,224,1472,768,216,1256,176,1296,1464,760,672,720,1264,176,1296,1344,1464,1360,1472,1488,1472,1480,1344,1472,1360,1488,1488,1488,1480,1496,1480","0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,2,0,0,2,6,0,0","0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,2,0,0,0,6,0,0","0,0,1,1,1,0,0,0,0,0,0,1,1,1,1,1,0,0,0,1,1,0,0,1,1,1,1,1,0,0,0,0","7.665557861,7.732561588,7.082343578,7.846774578,7.752214432,6.906925201,7.855091572,6.755141735,7.856310368,7.846433163,7.747685909,7.710433006,7.733560562,7.868661880,6.790736675,7.858621597,7.869617462,7.873907566,7.874854565,7.877315998,7.870153904,7.874608040,7.878478050,7.845719337,7.883452892,7.855854511,7.886187077,7.874522686,7.870358467,7.871251106,7.874283314,7.868322849",TINC,209,0,Acceptable,VPN,5,DPI (cache),"5,46" +1,ip4,185.83.218.112,131.114.168.27,udp,55656,55656,finished,12,20,1495983428043218,1495983432571150,1495983432526055,148,0,1444,1452,10944,20512,0,24,290670.0,2412459,558680.6,312123949056.0,2.9,"50,27,594,482,207,142,1049148,39,24,1048033,86,239,119,120,91,44079,43,25,1044735,279,1021999,20586,1001463,275,241,363633,1001240,149,123,2412459,39",104,1011.0,1480,450.3,202783.0,4.8,"752,1472,944,720,1256,1472,944,1056,656,320,1048,176,1296,512,656,320,176,1296,512,1464,1360,1360,1360,1472,1336,1304,104,1480,1464,1328,1376,1360","0,0,0,0,1,0,0,0,0,1,0,0,0,0,0,1,0,0,0,1,0,0,1,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,1,0,2,1,0,0,1,0,0","0,0,1,0,1,0,0,0,0,1,0,0,0,0,0,1,0,0,0,1,0,1,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,1,2,2,2,0,0,2,3,0,0","0,0,0,1,1,1,1,0,0,0,1,1,1,1,1,1,0,0,0,1,1,0,1,1,1,1,1,1,1,1,0,0","7.690577507,7.881368160,7.775002003,7.728326797,7.851398468,7.867018700,7.774654388,7.831391335,7.688314915,7.329430103,7.812694550,6.669548035,7.843146801,7.557564259,7.679370403,7.194211483,6.957363605,7.850227833,7.572175503,7.873534679,7.858608246,7.866045952,7.839975357,7.845044613,7.866905689,7.841031551,6.193184853,7.882274628,7.896846294,7.859506130,7.852632523,7.876025200",TINC,209,0,Acceptable,VPN,5,DPI (cache),"5,46" diff --git a/test/results/flow-analyse/whois.pcapng.out b/test/results/flow-analyse/default/tk.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/whois.pcapng.out +++ b/test/results/flow-analyse/default/tk.pcap.out diff --git a/test/results/flow-analyse/tls-appdata.pcap.out b/test/results/flow-analyse/default/tls-appdata.pcap.out index 9726e0d6c..9726e0d6c 100644 --- a/test/results/flow-analyse/tls-appdata.pcap.out +++ b/test/results/flow-analyse/default/tls-appdata.pcap.out diff --git a/test/results/flow-analyse/windowsupdate_over_http.pcap.out b/test/results/flow-analyse/default/tls-esni-fuzzed.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/windowsupdate_over_http.pcap.out +++ b/test/results/flow-analyse/default/tls-esni-fuzzed.pcap.out diff --git a/test/results/flow-analyse/wow.pcap.out b/test/results/flow-analyse/default/tls-rdn-extract.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/wow.pcap.out +++ b/test/results/flow-analyse/default/tls-rdn-extract.pcap.out diff --git a/test/results/flow-analyse/xdmcp.pcap.out b/test/results/flow-analyse/default/tls_2_reasms.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/xdmcp.pcap.out +++ b/test/results/flow-analyse/default/tls_2_reasms.pcapng.out diff --git a/test/results/flow-analyse/xiaomi.pcap.out b/test/results/flow-analyse/default/tls_2_reasms_b.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/xiaomi.pcap.out +++ b/test/results/flow-analyse/default/tls_2_reasms_b.pcapng.out diff --git a/test/results/flow-analyse/xss.pcap.out b/test/results/flow-analyse/default/tls_alert.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/xss.pcap.out +++ b/test/results/flow-analyse/default/tls_alert.pcap.out diff --git a/test/results/flow-analyse/tls_certificate_too_long.pcap.out b/test/results/flow-analyse/default/tls_certificate_too_long.pcap.out index 00734a16b..00734a16b 100644 --- a/test/results/flow-analyse/tls_certificate_too_long.pcap.out +++ b/test/results/flow-analyse/default/tls_certificate_too_long.pcap.out diff --git a/test/results/flow-analyse/z3950.pcapng.out b/test/results/flow-analyse/default/tls_cipher_lens.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/z3950.pcapng.out +++ b/test/results/flow-analyse/default/tls_cipher_lens.pcap.out diff --git a/test/results/flow-analyse/zabbix.pcap.out b/test/results/flow-analyse/default/tls_client_certificate_with_missing_server_one.pcapng.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/zabbix.pcap.out +++ b/test/results/flow-analyse/default/tls_client_certificate_with_missing_server_one.pcapng.out diff --git a/test/results/flow-analyse/zattoo.pcap.out b/test/results/flow-analyse/default/tls_esni_sni_both.pcap.out index bab73746f..bab73746f 100644 --- a/test/results/flow-analyse/zattoo.pcap.out +++ b/test/results/flow-analyse/default/tls_esni_sni_both.pcap.out diff --git a/test/results/flow-analyse/default/tls_false_positives.pcapng.out b/test/results/flow-analyse/default/tls_false_positives.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_false_positives.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/tls_invalid_reads.pcap.out b/test/results/flow-analyse/default/tls_invalid_reads.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_invalid_reads.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/tls_long_cert.pcap.out b/test/results/flow-analyse/default/tls_long_cert.pcap.out index aefbd1ef3..aefbd1ef3 100644 --- a/test/results/flow-analyse/tls_long_cert.pcap.out +++ b/test/results/flow-analyse/default/tls_long_cert.pcap.out diff --git a/test/results/flow-analyse/default/tls_missing_ch_frag.pcap.out b/test/results/flow-analyse/default/tls_missing_ch_frag.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_missing_ch_frag.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/tls_multiple_synack_different_seq.pcapng.out b/test/results/flow-analyse/default/tls_multiple_synack_different_seq.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_multiple_synack_different_seq.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/tls_port_80.pcapng.out b/test/results/flow-analyse/default/tls_port_80.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_port_80.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/tls_torrent.pcapng.out b/test/results/flow-analyse/default/tls_torrent.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_torrent.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/tls_unidirectional.pcap.out b/test/results/flow-analyse/default/tls_unidirectional.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tls_unidirectional.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/tls_verylong_certificate.pcap.out b/test/results/flow-analyse/default/tls_verylong_certificate.pcap.out index ff8030d12..ff8030d12 100644 --- a/test/results/flow-analyse/tls_verylong_certificate.pcap.out +++ b/test/results/flow-analyse/default/tls_verylong_certificate.pcap.out diff --git a/test/results/flow-analyse/default/toca-boca.pcap.out b/test/results/flow-analyse/default/toca-boca.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/toca-boca.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/tor.pcap.out b/test/results/flow-analyse/default/tor.pcap.out index 7f15bb9c6..5f87109a2 100644 --- a/test/results/flow-analyse/tor.pcap.out +++ b/test/results/flow-analyse/default/tor.pcap.out @@ -1,6 +1,6 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.1.252,38.229.70.53,tcp,51112,443,finished,14,18,1383821668403824,1383821704424659,1383821704566665,0,0,586,1460,4598,5464,0,113,2328505.8,31166013,7549668.5,56997495963648.0,1.9,"143824,144206,386,152663,157,159633,171698,164686,190851,113,190713,627,185098,185495,145105,5747,151688,184201,104686,289985,146556,2535956,2930532,30770666,31166013,871,147027,185685,696487,885191,147130",40,355.8,1500,354.9,125974.5,4.3,"52,52,46,264,40,969,238,99,114,1500,126,46,626,40,626,40,626,626,40,626,626,40,626,46,626,40,626,626,40,626,626,40","4,0,1,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,1,0,1,1,0,0,1,1,0,1,1,0,1","4.463158131,4.830034256,4.398030758,5.447000027,4.784183979,7.571198463,6.865525723,5.932188988,6.092850685,7.880095005,6.536722183,4.338141918,7.694956303,4.765311718,7.651318550,4.834183693,7.635929585,7.668802738,4.680641174,7.700941086,7.633764267,4.834183693,7.670955658,4.311074257,7.633520603,4.630640984,7.649660587,7.669915199,4.784183979,7.648267269,7.643295765,4.684184074",TLS.Tor,91.163,1,Potentially Dangerous,VPN,6,DPI,"7,16,22" -1,ip4,192.168.1.252,91.143.93.242,tcp,51110,443,finished,14,18,1383821665420161,1383821704889950,1383821704958016,0,0,586,1460,3939,9093,0,120,2548633.8,37995839,9273754.0,86002509021184.0,1.4,"70996,71325,6669,104314,10783,112643,88567,84606,73691,120,73665,754,108431,107711,67797,2260,74630,103567,101811,113368,368689,686539,37720424,37995839,68191,67504,104050,189003,360821,68695,181",40,448.8,1500,476.2,226793.4,4.2,"52,52,46,255,40,788,174,99,114,1500,142,46,626,40,626,40,626,626,626,626,40,626,46,626,40,626,40,626,1500,46,1500,1500","5,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,0,1,1,0,0,1,0,1,1,1,0,1,1","4.540081501,4.945419312,4.484987259,5.397112370,4.884183884,7.396267891,6.599942207,5.960015774,6.090528011,7.870100975,6.529747963,4.484987259,7.677678108,4.884183884,7.605023384,4.884183884,7.649974346,7.648893833,7.709483624,7.672764301,4.834183693,7.653419495,4.441509247,7.662259102,4.884183884,7.661063194,4.884183884,7.656208992,7.855939388,4.484987259,7.873313904,7.885534286",TLS,91,1,Safe,Web,6,DPI,"7" +1,ip4,192.168.1.252,91.143.93.242,tcp,51110,443,finished,14,18,1383821665420161,1383821704889950,1383821704958016,0,0,586,1460,3939,9093,0,120,2548633.8,37995839,9273754.0,86002509021184.0,1.4,"70996,71325,6669,104314,10783,112643,88567,84606,73691,120,73665,754,108431,107711,67797,2260,74630,103567,101811,113368,368689,686539,37720424,37995839,68191,67504,104050,189003,360821,68695,181",40,448.8,1500,476.2,226793.4,4.2,"52,52,46,255,40,788,174,99,114,1500,142,46,626,40,626,40,626,626,626,626,40,626,46,626,40,626,40,626,1500,46,1500,1500","5,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,0,1,1,0,0,1,0,1,1,1,0,1,1","4.540081501,4.945419312,4.484987259,5.397112370,4.884183884,7.396267891,6.599942207,5.960015774,6.090528011,7.870100975,6.529747963,4.484987259,7.677678108,4.884183884,7.605023384,4.884183884,7.649974346,7.648893833,7.709483624,7.672764301,4.834183693,7.653419495,4.441509247,7.662259102,4.884183884,7.661063194,4.884183884,7.656208992,7.855939388,4.484987259,7.873313904,7.885534286",TLS,91,1,Safe,Web,6,DPI,"7,41" 1,ip4,192.168.1.252,46.59.52.31,tcp,51111,443,finished,15,17,1383821666407384,1383821774388112,1383821702813857,0,0,586,1460,3946,5300,0,90,4657651.5,71328355,14789051.0,218716025389056.0,1.8,"73367,74408,357,74070,3203,80209,86098,83238,77261,90,76164,838,117183,116350,75240,23977,101877,114494,465564,429267,3455,80828,117031,388775,507320,75910,393949,666205,34353103,34399015,71328355",40,330.6,1500,347.1,120444.2,4.2,"52,52,46,262,40,789,174,99,114,1500,142,46,626,40,626,40,626,626,40,626,40,626,626,40,626,626,40,626,46,626,46,46","6,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,0,1,1,0,1,1,0,1,1,0,1,0,0","4.540081024,4.892440796,4.398030758,5.485852242,4.734183788,7.345484734,6.684501171,5.938382626,6.188065529,7.865236759,6.545697212,4.398030758,7.637940407,4.784183979,7.634158611,4.784183979,7.710437775,7.659512520,4.784183979,7.657443523,4.834184170,7.637063503,7.660885811,4.834184170,7.674984455,7.682085514,4.765312195,7.644844532,4.544876099,7.636578560,4.347350597,4.457919598",TLS.Tor,91.163,1,Potentially Dangerous,VPN,6,DPI,"7,16,22" -1,ip4,192.168.1.252,91.143.93.242,tcp,51175,443,finished,14,18,1383822129897135,1383822132138706,1383822132203451,0,0,586,1460,4523,5299,0,146,146706.0,990883,220400.9,48576569344.0,3.9,"64392,65808,9514,82112,4238,79785,91000,88446,79568,146,78186,925,110026,109380,69120,1548,80197,113582,35660,145791,70785,343658,637547,693937,990883,1625,71983,109022,69049,180072,69902",40,348.2,1500,347.1,120448.8,4.3,"52,52,46,253,40,788,174,99,114,1500,142,46,626,40,626,40,626,626,40,626,626,40,626,46,626,40,626,626,40,626,626,40","4,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,1,0,1,1,0,0,1,1,0,1,1,0,1","4.477674961,4.945419312,4.398030758,5.406278133,4.834183693,7.371150017,6.711827278,5.947438717,6.057762146,7.837278366,6.586953163,4.398030758,7.662993908,4.834183693,7.681317329,4.734183788,7.663327694,7.608054161,4.734183788,7.639224529,7.648303986,4.734183788,7.669913292,4.441509247,7.652542591,4.834183693,7.641192913,7.661419868,4.784183979,7.663778782,7.666988373,4.734183788",TLS.Tor,91.163,1,Potentially Dangerous,VPN,6,DPI,"7,16,22" -1,ip4,192.168.1.252,212.83.155.250,tcp,51174,443,finished,16,16,1383822129889928,1383822265160118,1383822265159585,0,0,586,1460,2761,5864,0,319,8727092.0,72890007,22568808.0,509351076823040.0,2.1,"59390,61607,13819,72120,2062,62909,63545,60042,79423,319,78805,1749,98338,96626,56518,4501,61844,64873,64036,73717,275721,252847,50798,9733,261423,61538274,61491411,72591366,72890007,3990,98034",40,312.0,1500,345.9,119666.8,4.2,"52,52,46,249,40,783,174,99,114,1500,126,46,626,40,626,40,626,626,626,626,626,46,626,52,626,46,626,46,46,40,40,46","9,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0,0,1,1,0","4.501619816,4.930902481,4.441508770,5.332808495,4.834183693,7.397306919,6.658778667,6.048449516,6.157279968,7.876633167,6.546604156,4.441508770,7.673907757,4.834183693,7.638509750,4.884183884,7.663495541,7.670399189,7.645442486,7.664111614,7.640780926,4.484987259,7.650365353,4.880648136,7.645416737,4.544876099,7.673004150,4.457919598,4.457919598,4.734183788,4.734183788,4.501397610",TLS,91,1,Safe,Web,6,DPI,"7" +1,ip4,192.168.1.252,91.143.93.242,tcp,51175,443,finished,14,18,1383822129897135,1383822132138706,1383822132203451,0,0,586,1460,4523,5299,0,146,146706.0,990883,220400.9,48576569344.0,3.9,"64392,65808,9514,82112,4238,79785,91000,88446,79568,146,78186,925,110026,109380,69120,1548,80197,113582,35660,145791,70785,343658,637547,693937,990883,1625,71983,109022,69049,180072,69902",40,348.2,1500,347.1,120448.8,4.3,"52,52,46,253,40,788,174,99,114,1500,142,46,626,40,626,40,626,626,40,626,626,40,626,46,626,40,626,626,40,626,626,40","4,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,1,0,1,1,0,0,1,1,0,1,1,0,1","4.477674961,4.945419312,4.398030758,5.406278133,4.834183693,7.371150017,6.711827278,5.947438717,6.057762146,7.837278366,6.586953163,4.398030758,7.662993908,4.834183693,7.681317329,4.734183788,7.663327694,7.608054161,4.734183788,7.639224529,7.648303986,4.734183788,7.669913292,4.441509247,7.652542591,4.834183693,7.641192913,7.661419868,4.784183979,7.663778782,7.666988373,4.734183788",TLS.Tor,91.163,1,Potentially Dangerous,VPN,6,DPI,"7,16,22,41" +1,ip4,192.168.1.252,212.83.155.250,tcp,51174,443,finished,16,16,1383822129889928,1383822265160118,1383822265159585,0,0,586,1460,2761,5864,0,319,8727092.0,72890007,22568808.0,509351076823040.0,2.1,"59390,61607,13819,72120,2062,62909,63545,60042,79423,319,78805,1749,98338,96626,56518,4501,61844,64873,64036,73717,275721,252847,50798,9733,261423,61538274,61491411,72591366,72890007,3990,98034",40,312.0,1500,345.9,119666.8,4.2,"52,52,46,249,40,783,174,99,114,1500,126,46,626,40,626,40,626,626,626,626,626,46,626,52,626,46,626,46,46,40,40,46","9,0,1,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","0,1,0,0,1,1,0,1,0,1,1,0,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,0,0,1,1,0","4.501619816,4.930902481,4.441508770,5.332808495,4.834183693,7.397306919,6.658778667,6.048449516,6.157279968,7.876633167,6.546604156,4.441508770,7.673907757,4.834183693,7.638509750,4.884183884,7.663495541,7.670399189,7.645442486,7.664111614,7.640780926,4.484987259,7.650365353,4.880648136,7.645416737,4.544876099,7.673004150,4.457919598,4.457919598,4.734183788,4.734183788,4.501397610",TLS,91,1,Safe,Web,6,DPI,"7,41" diff --git a/test/results/flow-analyse/tplink_shp.pcap.out b/test/results/flow-analyse/default/tplink_shp.pcap.out index c47162d78..c47162d78 100644 --- a/test/results/flow-analyse/tplink_shp.pcap.out +++ b/test/results/flow-analyse/default/tplink_shp.pcap.out diff --git a/test/results/flow-analyse/trickbot.pcap.out b/test/results/flow-analyse/default/trickbot.pcap.out index 16bd1474f..16bd1474f 100644 --- a/test/results/flow-analyse/trickbot.pcap.out +++ b/test/results/flow-analyse/default/trickbot.pcap.out diff --git a/test/results/flow-analyse/tumblr.pcap.out b/test/results/flow-analyse/default/tumblr.pcap.out index f0f60fc9d..47b6035e0 100644 --- a/test/results/flow-analyse/tumblr.pcap.out +++ b/test/results/flow-analyse/default/tumblr.pcap.out @@ -1,6 +1,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::98c7:1593,tcp,42908,443,finished,16,16,1605292103810303,1605292105112205,1605292105112063,0,0,382,1400,607,11474,1,1,83989.1,700859,188930.8,35694845952.0,2.6,"870,91738,194148,2,1,2772,104383,700859,700827,1324,5830,44963,352,357119,395282,1534,2,2,1,1,1,1,2,1529,39,13,18,11,13,13,12",72,449.5,1472,576.4,332266.9,4.0,"454,111,111,72,72,72,111,72,944,72,107,184,72,72,1460,72,84,1472,1472,1472,1472,835,1472,1472,72,72,72,72,72,72,72,72","11,3,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,0","0,0,0,1,1,1,1,0,1,0,0,0,1,1,1,0,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,0","7.475968361,5.973469734,5.991487980,5.083631992,5.055854321,5.055854321,5.836178780,5.218127251,7.768151760,5.245904922,5.915576458,6.683409691,5.034884930,5.073147297,7.871325970,5.162571907,5.437397003,7.868166924,7.884456158,7.861326694,7.846504688,7.733069897,7.846429825,7.853037357,5.218127251,5.218127251,5.218127251,5.218127251,5.218127251,5.190349579,5.245904922,5.190349579",TLS,91,1,Safe,Web,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::c000:4d28,tcp,43420,443,info,16,16,1605292105170049,1605292105221617,1605292105221612,0,0,160,1400,311,12058,1,1,3326.8,37135,8084.0,65351828.0,2.7,"469,25881,1104,10603,37135,1897,1,1911,13,717,678,9927,9935,107,1,101,8,237,229,116,116,308,309,92,91,472,1,479,15,99,79",72,458.5,1472,599.1,358951.0,3.9,"232,223,72,72,891,72,111,1460,72,72,84,72,1472,72,1472,1460,72,72,84,72,1472,72,1472,72,1460,72,84,1460,72,72,84,72","14,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0","0,0,1,1,1,0,1,1,0,0,1,0,1,0,1,1,0,0,1,0,1,0,1,0,1,0,1,1,0,0,1,0","6.975117207,6.780508041,5.008678436,4.980900764,7.727560043,5.257209778,5.876837730,7.865436077,5.284987926,5.284987926,5.396960735,5.284987926,7.861420155,5.257210255,7.855777740,7.835244179,5.201654911,5.257210255,5.387974262,5.257210255,7.869387627,5.229432106,7.851236820,5.229432583,7.862463474,5.201654911,5.316545486,7.846337318,5.257210255,5.284987926,5.396960735,5.284987926",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::c000:4d28,tcp,43434,443,info,16,16,1605292105171046,1605292105231565,1605292105231522,0,0,112,1400,362,16800,1,1,3903.1,45055,9416.3,88667112.0,2.8,"365,4822,355,27249,2992,337,2701,17288,45055,519,518,603,1,579,9,7282,1,7292,34,289,2,248,25,174,1,157,27,1036,1,1005,28",72,608.3,1472,669.7,448506.0,4.1,"184,111,183,172,72,72,72,72,1472,72,1472,72,1472,1472,72,72,1472,1472,72,72,1472,1472,72,72,1472,1472,72,72,1472,1472,72,72","12,1,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0,0,0","0,0,0,0,1,1,1,1,1,0,1,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0","6.587406158,5.914531231,6.603403568,6.519369125,4.980900764,4.980900764,4.894209862,4.980900764,7.851428509,5.118321419,7.864492416,5.118321419,7.853987694,7.848294735,5.062766075,5.080059052,7.860019684,7.828007221,5.118321419,5.118321419,7.856985092,7.866126060,5.118321419,5.080059052,7.856244087,7.840456009,5.146099091,5.080059052,7.871989727,7.857123375,5.118321419,5.118321419",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2606:2800:135:155a:23ba:b2a:25ff:122d,tcp,58380,443,finished,16,16,1605292105197307,1605292105347875,1605292105347850,0,0,523,1208,1519,5784,0,0,9713.3,47694,16101.6,259260704.0,3.2,"33179,33247,488,47694,0,47160,1225,37725,2106,0,0,38598,23,3,754,718,796,796,2589,248,171,60,26260,592,1,74,1362,0,0,25234,8",72,300.7,1280,381.9,145812.8,4.1,"80,80,72,589,72,171,72,595,72,1280,1280,1280,72,72,72,544,72,1055,72,146,164,329,128,72,72,72,72,327,327,168,72,72","10,1,2,0,0,0,0,0,1,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,0,2,0,0,0,2,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,1,1,1,0,0,0,1,0,1,0,0,0,0,0,1,1,1,1,1,1,1,0,0","5.295193195,5.637294769,5.563652992,4.598795891,5.459350586,6.223492146,5.497612953,5.044443607,5.487128258,7.814322472,7.863967419,7.842244625,5.591430664,5.503256798,5.563652992,7.612953186,5.591430664,7.763548851,5.563652992,6.558448792,6.685117722,7.291459560,6.278277397,5.487128258,5.487128258,5.431572914,5.487128258,7.317289352,7.268368721,6.510692596,5.591430664,5.563652992",TLS,91,1,Safe,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::c000:4d03,tcp,56794,443,info,14,18,1605292105669051,1605292105720296,1605292105720289,0,0,130,1400,525,11113,1,0,3305.9,36646,8575.8,73544632.0,2.4,"375,92,385,236,26419,36646,2159,0,376,0,10012,21697,203,197,169,221,0,406,8,175,469,1,0,620,51,101,150,197,535,21,562",72,435.7,1472,586.0,343353.7,3.9,"192,111,201,202,143,108,72,72,72,72,72,1472,72,1472,72,1460,84,1472,72,72,1460,84,1327,103,72,72,111,1460,72,84,1460,72","8,2,1,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,7,0,0,0,0","0,0,0,0,0,0,1,1,1,1,1,1,0,1,0,1,1,1,0,0,1,1,1,1,0,0,1,1,0,1,1,0","6.771437645,5.700867176,6.623061657,6.706957817,6.270517826,5.792555332,5.008678436,5.036456108,5.008678436,5.036456108,5.008678436,7.827867985,5.069574833,7.856517315,5.080059528,7.842531681,5.292736530,7.873940468,5.069574833,5.034988403,7.877679825,5.307831764,7.852031708,5.639400959,5.146099567,5.090544224,5.719091892,7.856316566,5.118321896,5.301723003,7.853841305,5.090544224",,,,,,,,"" @@ -8,4 +7,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::9765:789d,tcp,48240,443,info,15,17,1605292102602965,1605292122118409,1605292122118430,0,0,86,1048,132,16768,1,0,1259061.5,19513573,4788586.0,22930555666432.0,1.0,"19473275,346,19513573,0,40000,58,0,14,3,47,46,590,601,1080,1,1,0,1,0,0,1081,15,50,4,2,3,4,112,1,0,1",72,600.1,1120,520.1,270533.2,4.4,"72,158,118,72,1120,72,1120,1120,72,72,1120,72,1120,72,1120,1120,1120,1120,1120,1120,1120,72,72,72,72,72,72,72,1120,1120,1120,1120","13,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,1,0,1,1,0,0,1,0,1,0,1,1,1,1,1,1,1,0,0,0,0,0,0,0,1,1,1,1","5.300073624,6.172540188,5.808043480,5.111409664,7.793330193,5.244518280,7.816789150,7.806469440,5.188962936,5.244518280,7.817547321,5.216740131,7.782293320,5.272295952,7.814203739,7.825418949,7.833592415,7.796096325,7.794456482,7.800365925,7.831590176,5.300073624,5.244518280,5.272295952,5.300073624,5.216740608,5.244518280,5.272295475,7.782464504,7.824431896,7.817936897,7.808838844",,,,,,,,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:80b::200a,tcp,38608,443,finished,17,15,1605292122095843,1605292122274057,1605292122274042,0,0,517,1208,982,8808,0,0,11497.2,67472,19899.9,396007328.0,3.2,"67445,67472,269,44078,5271,1,49097,3,94,53,18571,10150,718,42370,0,12940,229,14297,2020,1,16083,2556,1,2570,25,64,1,0,22,4,8",72,378.4,1280,464.3,215557.6,4.1,"80,80,72,589,72,1280,1280,72,72,572,72,136,164,350,72,652,72,103,72,103,72,72,521,1280,72,72,1280,1280,1280,72,72,72","13,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,1,0,0,0,0,1,1,0,0,1,1,1,0,1,1,0,0,1,1,1,0,0,0","4.880388737,5.286173344,5.204868793,4.536604404,5.107836723,7.787920475,7.830109596,5.260424137,5.232646465,7.542898178,5.232646465,6.192057133,6.535644054,7.298229218,5.014019012,7.680838585,5.232646465,5.914041996,5.041796684,5.815946102,5.052281380,5.166606426,7.546278477,7.846930027,5.117859364,5.138828754,7.830280781,7.832926273,7.840851784,5.194384098,5.099461079,5.156121731",TLS.GoogleServices,91.239,1,Acceptable,Web,6,DPI,"" 1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,2a00:1450:4007:809::200e,tcp,49548,443,finished,16,16,1605292122064463,1605292122281616,1605292122282509,0,0,517,1208,962,9011,0,0,14038.7,83018,20606.9,424642560.0,3.6,"30258,30298,226,70679,12575,2,1,83018,62,4,882,32413,0,31475,5911,16277,137,34580,1914,14156,7168,10659,16853,1,0,1,34679,24,2,2,942",72,384.2,1280,474.8,225406.5,4.1,"80,80,72,589,72,1280,1280,311,72,72,72,136,72,652,72,164,103,330,72,103,72,72,72,985,1280,1280,1280,72,72,72,72,1280","12,0,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,6,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,1,1,0,0,0,0,1,1,0,1,1,1,1,1,1,0,0,0,0,1","4.836515903,5.311173439,5.222161770,4.516429901,5.097352028,7.813626766,7.833569527,7.238987446,5.249939442,5.211677551,5.222161770,6.183825970,5.163392067,7.648269653,5.182794571,6.507936478,5.802297115,7.243775845,5.097352028,5.700409889,5.249939919,5.097352028,5.163392067,7.756225586,7.832665920,7.840676308,7.826161861,5.222161770,5.222161770,5.166606426,5.183899403,7.820078373",TLS.Google,91.126,1,Acceptable,Web,6,DPI,"" -1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::6006:749,tcp,39152,443,finished,17,15,1605292105418417,1605292122813676,1605292122725006,0,0,764,1279,4217,4676,0,98,1119414.5,16588707,4059258.8,16477581213696.0,1.4,"29466,29487,204,37942,9029,46759,696,98,30996,1834,7035,39073,52635,52694,371915,406395,20731,55185,2451,32929,9268,39721,16556740,16588707,11402,43353,16903,58413,9807,93158,46822",72,350.4,1351,367.9,135349.6,4.3,"80,80,72,692,72,342,72,152,489,72,72,359,72,1259,72,824,72,855,72,836,72,342,72,500,72,1351,72,644,72,672,72,656","9,0,1,0,0,0,0,0,0,0,0,0,0,2,0,0,0,1,1,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,0,1,1,1,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0","4.797575951,5.229953289,5.190349579,7.030211926,4.972520828,6.811050892,5.091930866,6.334684849,7.516590118,5.055853844,5.055853844,7.313119888,5.190349579,7.806543827,5.218127251,7.745193005,5.000298500,7.694315910,5.134794235,7.706961155,5.028076172,7.266840458,5.190349579,7.564545631,4.972520828,7.854704857,5.162571907,7.655811310,5.000298500,7.622268677,5.134794235,7.624323368",TLS,91,1,Safe,Advertisement,6,DPI,"" +1,ip6,2a01:cb01:2049:8b07:991d:ec85:28df:f629,64:ff9b::6006:749,tcp,39152,443,finished,17,15,1605292105418417,1605292122813676,1605292122725006,0,0,764,1279,4217,4676,0,98,1119414.5,16588707,4059258.8,16477581213696.0,1.4,"29466,29487,204,37942,9029,46759,696,98,30996,1834,7035,39073,52635,52694,371915,406395,20731,55185,2451,32929,9268,39721,16556740,16588707,11402,43353,16903,58413,9807,93158,46822",72,350.4,1351,367.9,135349.6,4.3,"80,80,72,692,72,342,72,152,489,72,72,359,72,1259,72,824,72,855,72,836,72,342,72,500,72,1351,72,644,72,672,72,656","9,0,1,0,0,0,0,0,0,0,0,0,0,2,0,0,0,1,1,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","8,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,0,1,1,1,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0","4.797575951,5.229953289,5.190349579,7.030211926,4.972520828,6.811050892,5.091930866,6.334684849,7.516590118,5.055853844,5.055853844,7.313119888,5.190349579,7.806543827,5.218127251,7.745193005,5.000298500,7.694315910,5.134794235,7.706961155,5.028076172,7.266840458,5.190349579,7.564545631,4.972520828,7.854704857,5.162571907,7.655811310,5.000298500,7.622268677,5.134794235,7.624323368",TLS.ADS_Analytic_Track,91.107,1,Tracker\/Ads,Advertisement,6,DPI,"" diff --git a/test/results/flow-analyse/tunnelbear.pcap.out b/test/results/flow-analyse/default/tunnelbear.pcap.out index 4905c4868..4905c4868 100644 --- a/test/results/flow-analyse/tunnelbear.pcap.out +++ b/test/results/flow-analyse/default/tunnelbear.pcap.out diff --git a/test/results/flow-analyse/default/tuya_lp.pcap.out b/test/results/flow-analyse/default/tuya_lp.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/tuya_lp.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/ubntac2.pcap.out b/test/results/flow-analyse/default/ubntac2.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/ubntac2.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/ultrasurf.pcap.out b/test/results/flow-analyse/default/ultrasurf.pcap.out index 35a4de967..d4ac2ae9e 100644 --- a/test/results/flow-analyse/ultrasurf.pcap.out +++ b/test/results/flow-analyse/default/ultrasurf.pcap.out @@ -1,4 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,65.49.68.25,10.132.0.23,tcp,50053,37898,finished,22,10,1656652731609846,1656652731961797,1656652731903862,1280,0,2576,0,41208,0,1,2,20837.6,150485,35657.5,1271454592.0,3.6,"7,21335,5,10969,29128,61453,2,10832,4,9189,30801,10791,6,19965,5,29291,5,3,3,9324,30618,150485,11,11883,141836,4,17858,20033,9,20018,10094",80,1348.5,2628,1007.2,1014474.8,4.5,"2628,2628,1340,1340,2628,2628,80,80,1340,1340,2628,80,1340,1340,1332,2628,80,80,80,80,1340,80,1340,1340,2628,80,80,2628,1340,1340,2628,2628","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0,0,0,0,0,10","10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,1,1,0,0,0,1,0,0,0,0,1,1,1,1,0,1,0,0,0,1,1,0,0,0,0,0","7.935860634,7.912645817,7.844571114,7.831790447,7.918263912,7.928714752,5.522979259,5.447978497,7.859277725,7.870418549,7.933502197,5.497979641,7.862855911,7.853259087,7.847196579,7.913461208,5.472979069,5.319669724,5.429106236,5.429106236,7.836807251,5.479106426,7.821085453,7.859042645,7.931487560,5.538542747,5.538542747,7.931249619,7.868795395,7.859850407,7.922960758,7.932232857",UltraSurf,304,1,Acceptable,VPN,6,DPI,"" +1,ip4,65.49.68.25,10.132.0.23,tcp,50053,37898,finished,22,10,1656652731609846,1656652731961797,1656652731903862,1280,0,2576,0,41208,0,1,2,20837.6,150485,35657.5,1271454592.0,3.6,"7,21335,5,10969,29128,61453,2,10832,4,9189,30801,10791,6,19965,5,29291,5,3,3,9324,30618,150485,11,11883,141836,4,17858,20033,9,20018,10094",80,1348.5,2628,1007.2,1014474.8,4.5,"2628,2628,1340,1340,2628,2628,80,80,1340,1340,2628,80,1340,1340,1332,2628,80,80,80,80,1340,80,1340,1340,2628,80,80,2628,1340,1340,2628,2628","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,12,0,0,0,0,0,0,10","10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,1,1,0,0,0,1,0,0,0,0,1,1,1,1,0,1,0,0,0,1,1,0,0,0,0,0","7.935860634,7.912645817,7.844571114,7.831790447,7.918263912,7.928714752,5.522979259,5.447978497,7.859277725,7.870418549,7.933502197,5.497979641,7.862855911,7.853259087,7.847196579,7.913461208,5.472979069,5.319669724,5.429106236,5.429106236,7.836807251,5.479106426,7.821085453,7.859042645,7.931487560,5.538542747,5.538542747,7.931249619,7.868795395,7.859850407,7.922960758,7.932232857",UltraSurf,304,1,Acceptable,VPN,6,DPI,"46" 1,ip4,10.132.0.23,65.49.68.25,tcp,38120,50053,finished,15,17,1656652778161151,1656652779042511,1656652779222772,0,0,1348,1288,5006,4491,0,2,62676.8,270784,99488.0,9897854976.0,3.4,"211168,260384,4,269572,5,10096,9894,260379,4,20013,20030,10943,4,270784,9694,4,10276,229481,5,19977,40078,29866,14,10092,29929,210869,5,2,9,9396,4",52,349.3,1400,449.6,202163.0,4.0,"60,60,52,569,52,1340,1340,1256,52,52,52,116,138,690,107,87,83,108,83,52,94,1400,86,1148,680,650,52,87,244,187,87,113","7,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0","4,8,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,2,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,1,1,1,1,0,0,1,0,1,0,0,0,1,1,1,1,1,1","4.726680756,5.240227222,5.272274494,6.111527920,5.130220413,7.844857216,7.849434853,7.833609104,5.233813286,5.156889915,5.233813286,6.138292789,6.368075848,7.651264191,6.278759480,5.928515911,5.691242695,6.148318291,5.806828022,5.233812809,5.950813293,7.875130177,5.929117203,7.818894386,7.718791008,7.725904465,5.168681622,5.919838905,6.926432133,6.780454636,5.896851063,6.240451336",TLS,91,1,Safe,Web,6,DPI,"5,24" 1,ip4,10.132.0.23,65.49.68.25,tcp,38152,50053,finished,16,16,1656652831434184,1656652832235258,1656652832454997,0,0,1348,1288,4808,5851,0,2,58770.5,269120,100848.2,10170350592.0,3.1,"209494,239714,10,251051,6,11439,12,260675,5,9589,20029,20030,269120,19987,5,231024,5,19971,10,4,3,3,2,249606,8,2,3,3,10064,10,3",52,385.6,1400,479.7,230117.0,4.1,"60,60,52,569,52,1340,1340,1256,52,52,52,116,368,107,87,139,52,83,1400,428,1400,480,250,234,52,87,113,200,244,87,187,1340","7,0,1,0,0,1,1,0,0,1,0,1,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","3,5,1,0,2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,3,0,0,0,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1","4.680766106,5.194312096,5.041505337,6.080573082,5.168682098,7.827150345,7.863349915,7.855801105,5.156889915,5.156889915,5.118428230,6.048384190,7.387241364,5.998385429,5.810531616,6.322457314,5.118428230,5.674062252,7.876391411,7.449967384,7.849254131,7.577188969,7.053901672,7.035159111,5.130220413,5.850873470,6.129572392,6.822973251,6.886046886,5.873862267,6.798689365,7.860256195",TLS,91,1,Safe,Web,6,DPI,"5,24" diff --git a/test/results/flow-analyse/default/upnp.pcap.out b/test/results/flow-analyse/default/upnp.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/upnp.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/viber.pcap.out b/test/results/flow-analyse/default/viber.pcap.out index ac91b8317..c4b20809e 100644 --- a/test/results/flow-analyse/viber.pcap.out +++ b/test/results/flow-analyse/default/viber.pcap.out @@ -1,5 +1,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.0.17,54.230.93.53,tcp,53934,443,info,14,18,1527155641845544,1527155641984215,1527155641981830,0,0,708,1448,1017,20153,0,19,8869.6,47784,14735.4,217133360.0,3.3,"19470,21663,1023,22292,3214,249,21,217,39369,88,574,349,10837,47784,22339,40800,258,54,169,260,19,213,268,217,249,532,41188,70,47,44,1080",52,714.1,1500,673.4,453425.2,4.3,"60,60,52,235,52,1500,1500,1500,397,52,52,52,52,178,294,760,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,794,52,52,52,52,52","11,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,13,0,0","0,1,0,0,1,1,1,1,1,0,0,0,0,0,1,0,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0","4.571673393,5.231404781,5.154164791,5.626152039,5.147462368,7.170236111,7.463209152,7.511432171,7.329006195,5.115703106,5.154164791,5.192625999,5.154164791,6.447020531,7.153199196,7.703028202,7.855375767,7.870701790,7.853311062,7.869762897,7.858384132,7.891494274,7.876748085,7.889567852,7.884804249,7.876610279,7.713707447,5.154164791,5.154164314,5.115703106,5.154164314,5.109001160",,,,,,,,"" 1,ip4,192.168.0.17,52.0.253.101,tcp,33208,4244,info,17,15,1527155638428936,1527155670525718,1527155666299937,0,0,530,98,2467,404,1,97,1934444.6,10701681,2902413.2,8424002682880.0,3.5,"54240,95930,270,43992,41788,57048,16087,92087,91609,10563926,10701681,4192149,4152724,4422076,4422070,309467,309552,21641,197002,97,215011,3974475,3934854,3635331,52554,3635290,52615,12721,140816,167507,4361173",52,141.7,582,133.2,17739.8,4.5,"153,108,52,128,52,494,116,52,120,52,149,52,146,52,146,52,391,52,150,52,136,52,146,52,146,410,52,52,150,136,52,582","4,1,6,2,0,0,0,0,0,0,1,1,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","10,0,3,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,0,1,0,0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,0,1,1,1,0,1,0","6.431744576,6.016238213,4.829590321,6.209959030,4.955154419,7.559208393,6.096168518,5.008132935,6.149723053,4.916692734,6.302158833,4.921030998,6.449830055,4.959492207,6.525306225,4.921030521,7.398088932,4.997953892,6.476407528,4.969671726,6.289449215,4.997953892,6.509795189,4.997953892,6.393223286,7.421437263,4.997953892,4.997953892,6.452959538,6.382457256,4.997953892,7.597495079",,,,,,,,"" -1,ip4,192.168.0.17,18.201.4.32,udp,47171,7985,finished,17,15,1527155670640484,1527155675775126,1527155675692683,20,0,257,76,2947,930,0,129,328607.8,525007,210300.8,44226416640.0,4.6,"129,33097,500276,500261,503516,15204,503250,15302,516057,515704,477654,477626,36790,36786,524953,525007,440389,440669,68112,67828,523108,523160,411969,411845,84133,84199,517782,517791,399760,399674,114810",48,149.2,285,100.4,10086.1,4.7,"285,48,104,285,104,48,285,62,104,285,104,48,62,285,104,285,104,48,62,285,104,285,104,48,62,285,104,285,104,48,62,285","6,0,0,0,0,0,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,5,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,1,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0","6.429836750,5.092222691,3.431529284,6.457198620,3.469990969,5.092222691,6.466431141,4.018082619,3.469990969,6.511886120,3.469990969,5.092222691,3.985824585,6.440430164,3.469990969,6.468061447,3.419557333,4.967222214,3.953566313,6.441361427,3.450760365,6.449966431,3.469991207,5.050555706,4.018082619,6.492553234,3.489221811,6.449169159,3.469991207,5.050556183,4.018082619,6.452616215",Viber,144,1,Fun,VoIP,6,DPI,"" -1,ip4,192.168.0.17,18.201.4.3,udp,38190,7985,finished,19,13,1527155679411371,1527155683480847,1527155683453495,12,0,257,76,2479,778,0,49,261664.5,531417,244884.4,59968385024.0,4.1,"2549,75,31700,2304,505528,505691,496908,2109,6670,496650,8720,505323,505404,490799,100,14960,490657,15090,513169,513225,531417,103,49,531356,217,492947,492967,448249,97,448143,58424",40,129.8,285,99.7,9932.1,4.6,"285,46,48,104,62,285,104,48,40,285,62,104,285,104,48,40,285,62,104,285,104,48,40,285,62,104,285,104,48,40,62,285","10,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,5,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,1,0","6.294480801,4.507713318,5.008889198,3.477249622,4.018082619,6.362309933,3.496480465,5.050556183,4.408695221,6.358519077,3.985824585,3.458018780,6.336889267,3.458018780,4.967222214,4.408695221,6.270152092,3.909132719,3.438787937,6.396345615,3.496480465,5.008889198,4.408695221,6.346873283,3.855867863,3.496480465,6.368536949,3.477249622,5.008889198,4.408695221,3.985824585,6.367835045",Viber,144,1,Fun,VoIP,6,DPI,"" +1,ip4,192.168.0.17,18.201.4.32,udp,47171,7985,finished,17,15,1527155670640484,1527155675775126,1527155675692683,20,0,257,76,2947,930,0,129,328607.8,525007,210300.8,44226416640.0,4.6,"129,33097,500276,500261,503516,15204,503250,15302,516057,515704,477654,477626,36790,36786,524953,525007,440389,440669,68112,67828,523108,523160,411969,411845,84133,84199,517782,517791,399760,399674,114810",48,149.2,285,100.4,10086.1,4.7,"285,48,104,285,104,48,285,62,104,285,104,48,62,285,104,285,104,48,62,285,104,285,104,48,62,285,104,285,104,48,62,285","6,0,0,0,0,0,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,5,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,0,1,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0","6.429836750,5.092222691,3.431529284,6.457198620,3.469990969,5.092222691,6.466431141,4.018082619,3.469990969,6.511886120,3.469990969,5.092222691,3.985824585,6.440430164,3.469990969,6.468061447,3.419557333,4.967222214,3.953566313,6.441361427,3.450760365,6.449966431,3.469991207,5.050555706,4.018082619,6.492553234,3.489221811,6.449169159,3.469991207,5.050556183,4.018082619,6.452616215",Viber,144,1,Fun,VoIP,6,DPI,"46" +1,ip4,192.168.0.17,18.201.4.3,udp,38190,7985,finished,19,13,1527155679411371,1527155683480847,1527155683453495,12,0,257,76,2479,778,0,49,261664.5,531417,244884.4,59968385024.0,4.1,"2549,75,31700,2304,505528,505691,496908,2109,6670,496650,8720,505323,505404,490799,100,14960,490657,15090,513169,513225,531417,103,49,531356,217,492947,492967,448249,97,448143,58424",40,129.8,285,99.7,9932.1,4.6,"285,46,48,104,62,285,104,48,40,285,62,104,285,104,48,40,285,62,104,285,104,48,40,285,62,104,285,104,48,40,62,285","10,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,5,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,0,1,1,0,1,0,0,1,0","6.294480801,4.507713318,5.008889198,3.477249622,4.018082619,6.362309933,3.496480465,5.050556183,4.408695221,6.358519077,3.985824585,3.458018780,6.336889267,3.458018780,4.967222214,4.408695221,6.270152092,3.909132719,3.438787937,6.396345615,3.496480465,5.008889198,4.408695221,6.346873283,3.855867863,3.496480465,6.368536949,3.477249622,5.008889198,4.408695221,3.985824585,6.367835045",Viber,144,1,Fun,VoIP,6,DPI,"46" diff --git a/test/results/flow-analyse/default/vk.pcapng.out b/test/results/flow-analyse/default/vk.pcapng.out new file mode 100644 index 000000000..870eb5746 --- /dev/null +++ b/test/results/flow-analyse/default/vk.pcapng.out @@ -0,0 +1,3 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks +1,ip4,192.168.1.249,87.240.132.78,tcp,60436,443,info,32,0,1675334161630633,1675334162970119,1675334161630633,0,0,706,0,2285,0,1,9,43209.2,1009982,180973.6,32751437824.0,1.3,"1009982,14622,15333,1749,16345,26,12,11,29,15083,24,227705,48,13,11,2653,38,12801,28,1545,20,9,1508,1138,1634,11081,2465,1543,41,782,1207",52,125.3,758,191.1,36507.6,4.0,"638,758,52,596,501,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,64,64,64,64,64,52,52,52,52,52,52","28,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7.658514977,7.774987221,5.246409416,7.623703957,7.570796013,5.246409416,5.246409416,5.246409416,5.284871101,5.284871101,5.207947731,5.169486523,5.246409416,5.284871101,5.169486046,5.131024837,5.284871101,5.246409416,5.169486046,5.169486046,5.246409416,5.259624004,5.259624004,5.247828960,5.259624004,5.290874004,5.246409416,5.284871101,5.207947731,5.207947731,5.246409416,5.207948208",,,,,,,,"" +1,ip4,192.168.1.249,87.240.129.140,tcp,40344,443,info,32,0,1675334160592919,1675334165285590,1675334160592919,0,0,965,0,6049,0,1,12,151376.5,2006629,451077.3,203470716928.0,2.1,"37,14329,22998,2006629,46,764,13490,98211,1614502,285,99,283,260,13216,1250,18419,1704,886,6878,22622,24,179811,40,14057,67447,12,24,579540,41,1048,13719",52,241.0,1017,249.5,62251.3,4.3,"247,332,52,52,240,776,565,52,52,385,563,339,564,1017,52,52,52,52,52,52,52,52,243,316,52,52,52,52,250,563,429,52","17,0,0,0,0,2,2,0,3,0,1,1,0,0,0,2,2,0,0,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7.151976109,7.356266499,5.207948208,5.169486523,6.965931416,7.731954098,7.617059708,5.131024837,5.207947731,7.360937595,7.613526821,7.349236012,7.610394001,7.787010193,5.092563152,5.131024837,5.061608315,5.056022644,5.131024837,5.092563152,5.131024361,5.131024361,7.143619061,7.305361271,5.116507530,5.131024361,5.169486046,5.131024361,7.176092148,7.631054878,7.485155582,5.116507530",,,,,,,,"" diff --git a/test/results/flow-analyse/vnc.pcap.out b/test/results/flow-analyse/default/vnc.pcap.out index 5ca2bdafe..5ca2bdafe 100644 --- a/test/results/flow-analyse/vnc.pcap.out +++ b/test/results/flow-analyse/default/vnc.pcap.out diff --git a/test/results/flow-analyse/default/vrrp3.pcapng.out b/test/results/flow-analyse/default/vrrp3.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/vrrp3.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/vxlan.pcap.out b/test/results/flow-analyse/default/vxlan.pcap.out index ae5f18ad6..8868c145f 100644 --- a/test/results/flow-analyse/vxlan.pcap.out +++ b/test/results/flow-analyse/default/vxlan.pcap.out @@ -1,3 +1,3 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.22.5,192.168.22.4,udp,36286,4789,finished,32,0,1639650442941597,1639650443255719,1639650442941597,74,0,1454,0,35959,0,0,10,10133.0,140558,31047.2,963930240.0,2.2,"10532,1402,105,10,11439,530,9521,113264,10571,140558,101,64,3057,190,558,175,1284,181,1316,3621,187,402,189,2282,184,313,186,833,189,694,184",102,1151.7,1482,546.6,298767.6,4.8,"110,102,1482,1482,570,102,271,102,554,102,1482,1482,856,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482","0,0,5,0,0,0,0,1,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,23,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.583852291,5.651705265,7.826985836,7.861832619,7.623077869,5.619890690,7.052967072,5.635924816,7.564305782,5.565874100,7.866837978,7.859116077,7.762131214,7.859333515,7.877618790,7.863654613,7.851696491,7.874659538,7.855105877,7.845957756,7.883800030,7.862126827,7.878228188,7.846958637,7.850887299,7.866386890,7.866912842,7.871983051,7.852091789,7.857552052,7.852843761,7.854843616",VXLAN,64,0,Acceptable,Network,6,DPI,"" -1,ip4,192.168.22.4,192.168.22.5,udp,40646,4789,finished,32,0,1639650442931548,1639650443264733,1639650442931548,74,0,392,0,3106,0,0,4,10747.9,150839,30032.6,901957440.0,2.5,"10329,305,11530,200,4,1301,10031,41817,81536,403,150839,3109,802,1504,1403,3811,602,2508,504,1003,903,802,707,803,710,2107,301,402,2307,401,201",102,125.1,420,68.2,4655.6,4.8,"110,102,420,102,102,102,166,267,102,102,285,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102","0,0,28,0,1,0,0,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.313875198,5.603603840,6.154091835,5.623211861,5.630611897,5.623211384,6.288531303,6.880884647,5.615810394,5.596202850,7.036987305,5.564387798,5.603603840,5.596202850,5.623211384,5.564388275,5.583995819,5.556987286,5.591396332,5.603603840,5.576594353,5.623211384,5.544780254,5.603603840,5.603603840,5.623211384,5.642818928,5.588801384,5.603603363,5.635418415,5.635418415,5.655025959",VXLAN,64,0,Acceptable,Network,6,DPI,"" +1,ip4,192.168.22.5,192.168.22.4,udp,36286,4789,finished,32,0,1639650442941597,1639650443255719,1639650442941597,74,0,1454,0,35959,0,0,10,10133.0,140558,31047.2,963930240.0,2.2,"10532,1402,105,10,11439,530,9521,113264,10571,140558,101,64,3057,190,558,175,1284,181,1316,3621,187,402,189,2282,184,313,186,833,189,694,184",102,1151.7,1482,546.6,298767.6,4.8,"110,102,1482,1482,570,102,271,102,554,102,1482,1482,856,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482,1482","0,0,5,0,0,0,0,1,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,23,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.583852291,5.651705265,7.826985836,7.861832619,7.623077869,5.619890690,7.052967072,5.635924816,7.564305782,5.565874100,7.866837978,7.859116077,7.762131214,7.859333515,7.877618790,7.863654613,7.851696491,7.874659538,7.855105877,7.845957756,7.883800030,7.862126827,7.878228188,7.846958637,7.850887299,7.866386890,7.866912842,7.871983051,7.852091789,7.857552052,7.852843761,7.854843616",VXLAN,64,0,Acceptable,Network,6,DPI,"46" +1,ip4,192.168.22.4,192.168.22.5,udp,40646,4789,finished,32,0,1639650442931548,1639650443264733,1639650442931548,74,0,392,0,3106,0,0,4,10747.9,150839,30032.6,901957440.0,2.5,"10329,305,11530,200,4,1301,10031,41817,81536,403,150839,3109,802,1504,1403,3811,602,2508,504,1003,903,802,707,803,710,2107,301,402,2307,401,201",102,125.1,420,68.2,4655.6,4.8,"110,102,420,102,102,102,166,267,102,102,285,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102,102","0,0,28,0,1,0,0,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.313875198,5.603603840,6.154091835,5.623211861,5.630611897,5.623211384,6.288531303,6.880884647,5.615810394,5.596202850,7.036987305,5.564387798,5.603603840,5.596202850,5.623211384,5.564388275,5.583995819,5.556987286,5.591396332,5.603603840,5.576594353,5.623211384,5.544780254,5.603603840,5.603603840,5.623211384,5.642818928,5.588801384,5.603603363,5.635418415,5.635418415,5.655025959",VXLAN,64,0,Acceptable,Network,6,DPI,"46" diff --git a/test/results/flow-analyse/wa_video.pcap.out b/test/results/flow-analyse/default/wa_video.pcap.out index cd7a7e9be..b44c8574f 100644 --- a/test/results/flow-analyse/wa_video.pcap.out +++ b/test/results/flow-analyse/default/wa_video.pcap.out @@ -1,4 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.2.12,157.240.20.53,tcp,49355,5222,info,19,13,1561455767339689,1561455770332620,1561455769794560,0,0,548,1388,1640,5261,1,0,175735.5,2404473,473951.1,224629620736.0,2.4,"51726,176830,2,0,439642,1227815,753,306057,108901,2404473,241,10,252,9,41,323,133116,635,40681,277,7651,7949,1743,1602,528764,1087,660,696,654,2651,2561",52,268.4,1440,335.2,112371.9,4.2,"600,52,1440,155,508,508,332,189,225,1440,52,52,64,52,52,52,64,228,228,52,52,228,52,404,52,214,212,206,206,206,206,206","11,0,0,0,5,2,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,0,0,1,1,4,0,0,1,0,0,1,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0","0,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,1,1,0,0,1,0,1,0,0,0,0,0,0,0,0","7.608484745,5.077241421,7.865381718,6.691146851,7.578685284,7.572544098,7.307354450,6.700509548,7.001189232,7.865732670,4.976373672,5.053297043,5.138105392,5.091758728,5.053297043,5.091758728,5.157560349,6.986247063,7.012214661,5.053297043,5.053297043,6.984363556,5.053297043,7.459637642,5.053297043,6.913162708,6.866742134,6.851969242,6.911801815,6.922309875,6.837723732,6.965609550",,,,,,,,"" -1,ip4,192.168.2.12,31.13.86.48,udp,53688,3478,finished,23,9,1561455769789452,1561455770782169,1561455770781798,6,0,472,472,8102,1614,0,95,64034.3,550126,135549.6,18373693440.0,3.1,"95,13142,1109,548212,794,550126,16210,117,20333,106,23568,573,14505,979,116,79305,29641,99,23164,167,19951,342,24390,3500,104447,150456,15882,197610,75380,2499,68245",30,331.6,500,205.8,42355.1,4.7,"154,154,72,72,154,500,72,500,500,500,500,500,500,34,500,500,30,500,500,500,500,500,500,500,154,72,48,500,48,500,500,48","3,0,0,4,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,4,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,1,1,0,1,1,0","6.493677139,6.519650936,5.235420704,5.263198376,6.488775253,7.446858406,5.290976048,7.477643013,7.460317135,7.514078140,7.471118450,7.444753170,7.528831959,4.569532394,7.478866100,7.484198570,4.453236580,7.470160961,7.456147671,7.450516224,7.440128803,7.495639801,7.433229923,7.431243420,6.496860504,5.263197899,3.812905788,7.345452785,3.812905550,7.413387775,7.430417538,4.208755493",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"" -1,ip4,192.168.2.12,91.252.56.51,udp,53688,32641,finished,26,6,1561455781352254,1561455783672290,1561455783683909,44,0,1118,182,15240,615,0,139,150054.5,1979427,383224.6,146861080576.0,2.7,"707140,619781,619147,1979427,36290,69699,132037,26361,100137,1489,36501,24632,139,224,338,341,10692,26140,102372,15137,296,563,516,886,169,757,7597,915,148,631,131189",72,523.5,1146,432.0,186635.8,4.5,"72,72,72,72,72,72,72,156,72,165,150,130,899,899,899,898,1146,194,143,198,1022,1022,1022,1022,1022,1020,150,920,920,920,1048,210","0,6,0,2,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,7,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,0,2,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,1,0,0,1,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1","5.551460743,5.652086735,5.531393051,5.607016087,5.440350056,5.499580860,5.568753719,6.624680996,5.697700977,6.683998108,6.496982574,6.426134586,7.747357368,7.800405025,7.780704021,7.774211884,7.821574688,6.735989094,6.400922298,6.908179283,7.822691441,7.800770760,7.811967850,7.818122864,7.793910027,7.785738468,6.611948967,7.770941734,7.800857544,7.760899067,7.788744450,6.986406326",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5" +1,ip4,192.168.2.12,31.13.86.48,udp,53688,3478,finished,23,9,1561455769789452,1561455770782169,1561455770781798,6,0,472,472,8102,1614,0,95,64034.3,550126,135549.6,18373693440.0,3.1,"95,13142,1109,548212,794,550126,16210,117,20333,106,23568,573,14505,979,116,79305,29641,99,23164,167,19951,342,24390,3500,104447,150456,15882,197610,75380,2499,68245",30,331.6,500,205.8,42355.1,4.7,"154,154,72,72,154,500,72,500,500,500,500,500,500,34,500,500,30,500,500,500,500,500,500,500,154,72,48,500,48,500,500,48","3,0,0,4,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,4,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,1,1,0,1,1,0","6.493677139,6.519650936,5.235420704,5.263198376,6.488775253,7.446858406,5.290976048,7.477643013,7.460317135,7.514078140,7.471118450,7.444753170,7.528831959,4.569532394,7.478866100,7.484198570,4.453236580,7.470160961,7.456147671,7.450516224,7.440128803,7.495639801,7.433229923,7.431243420,6.496860504,5.263197899,3.812905788,7.345452785,3.812905550,7.413387775,7.430417538,4.208755493",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"46" +1,ip4,192.168.2.12,91.252.56.51,udp,53688,32641,finished,26,6,1561455781352254,1561455783672290,1561455783683909,44,0,1118,182,15240,615,0,139,150054.5,1979427,383224.6,146861080576.0,2.7,"707140,619781,619147,1979427,36290,69699,132037,26361,100137,1489,36501,24632,139,224,338,341,10692,26140,102372,15137,296,563,516,886,169,757,7597,915,148,631,131189",72,523.5,1146,432.0,186635.8,4.5,"72,72,72,72,72,72,72,156,72,165,150,130,899,899,899,898,1146,194,143,198,1022,1022,1022,1022,1022,1020,150,920,920,920,1048,210","0,6,0,2,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,0,0,0,7,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,0,2,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,1,0,0,1,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1","5.551460743,5.652086735,5.531393051,5.607016087,5.440350056,5.499580860,5.568753719,6.624680996,5.697700977,6.683998108,6.496982574,6.426134586,7.747357368,7.800405025,7.780704021,7.774211884,7.821574688,6.735989094,6.400922298,6.908179283,7.822691441,7.800770760,7.811967850,7.818122864,7.793910027,7.785738468,6.611948967,7.770941734,7.800857544,7.760899067,7.788744450,6.986406326",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5,46" diff --git a/test/results/flow-analyse/wa_voice.pcap.out b/test/results/flow-analyse/default/wa_voice.pcap.out index f12ff6af2..0c4453df9 100644 --- a/test/results/flow-analyse/wa_voice.pcap.out +++ b/test/results/flow-analyse/default/wa_voice.pcap.out @@ -2,5 +2,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,192.168.2.12,157.240.20.53,tcp,49355,5222,finished,17,15,1561455688704143,1561455689377891,1561455689390636,0,0,286,1388,776,6993,0,1,43878.7,304081,76394.5,5836114944.0,3.2,"40742,137033,170366,304081,130232,56,30959,5260,28,391,1,177,42,1186,210132,335,9,41,206,11,311,41447,129925,50,6,6,5,1043,24269,131853,38",52,295.4,1440,467.5,218553.5,3.8,"64,60,52,308,52,109,103,137,1440,92,1440,155,1440,164,1440,52,52,52,52,52,52,52,1045,84,98,119,82,111,52,338,52,52","11,3,1,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,3,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0","0,1,0,0,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,1,1","4.472632408,5.115064144,5.014835358,7.171360493,5.130219936,6.068146706,5.962917328,6.548506737,7.870247841,5.888707161,7.854815006,6.678243637,7.877118111,6.722311020,7.881030083,5.014835358,5.014835358,4.976373196,5.091758251,5.091758251,5.130219936,5.008132935,7.805761337,5.645539761,5.925289631,6.203728676,5.699334145,6.150419712,4.961856842,7.298644066,5.038780212,4.955154419",WhatsApp,142,1,Acceptable,Chat,6,DPI,"" 1,ip4,192.168.2.12,31.13.86.51,tcp,50503,443,finished,17,15,1561455689909150,1561455690224696,1561455690224643,0,0,517,1388,1331,7979,0,0,20356.1,163286,46938.1,2203181824.0,2.5,"19749,127653,2783,126251,2925,28,22,21046,163,145211,12,6,5,40,5,163286,2,38,0,250,1,16,17472,279,12,8,2386,284,150,389,567",52,343.6,1440,489.7,239839.3,3.9,"64,60,52,569,52,1440,1440,335,52,52,116,98,95,87,388,311,52,223,126,83,52,100,484,52,52,52,52,1440,52,1440,1440,83","10,3,1,0,0,0,0,0,1,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,1,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,0,0,0,0,1,0,1,1,0","4.453177452,5.156567574,5.038779736,4.954115391,5.062724590,7.845219135,7.875988007,7.363695621,5.038779736,5.077241421,6.006405830,6.022478580,5.964075089,5.738524437,7.327147007,7.233700752,5.115703106,6.979569435,6.337362766,5.826725960,5.032077789,6.041212559,7.548195839,4.923395157,4.961856842,5.000318050,4.947339535,7.873440742,5.038779736,7.854992867,7.876389503,5.699865818",TLS.WhatsAppFiles,91.242,1,Acceptable,Download,6,DPI,"" 1,ip4,192.168.2.12,157.240.20.52,tcp,50504,443,finished,16,16,1561455707474558,1561455707778028,1561455707778471,0,0,517,1388,928,9370,0,5,19593.0,129132,30818.3,949767616.0,3.5,"37234,38970,11147,51469,985,103,11,42805,136,34645,3771,380,216,299,76165,5,34895,421,279,3605,27,2938,1342,3436,77447,53735,129132,1406,40,219,120",52,374.4,1440,526.3,277041.4,3.9,"64,60,52,569,52,1440,1440,333,52,52,116,98,95,87,244,223,126,52,52,83,52,83,52,87,52,52,502,52,1440,1440,1440,1440","10,3,1,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,1,0,0,1,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0","0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,1,1,0,0,0,1,1,0,1,0,1,1,0,1,1,1,1","4.421927452,5.127645493,4.947339535,4.844649315,5.024262905,7.828526497,7.880538940,7.342582226,4.947340012,4.947340012,6.096442223,5.933140755,5.903703690,5.761512756,7.014289856,6.959705353,6.368111134,4.923395157,4.923395157,5.597574711,5.062724590,5.763532162,4.985801220,5.859550953,4.947339535,4.985801220,7.559065819,4.947340012,7.871157646,7.859573364,7.846300602,7.844365597",TLS.WhatsApp,91.142,1,Acceptable,Chat,6,DPI,"" -1,ip4,192.168.2.12,31.13.86.48,udp,56328,3478,finished,12,20,1561455706912375,1561455731523132,1561455731536124,6,0,126,278,792,1833,0,1,1588209.8,12196243,3050402.8,9304956469248.0,3.2,"61,13448,128,12194152,12196243,104402,58,105108,1,108628,104619,3043264,3048902,3100925,3096031,3015294,3016553,2001940,2156,107078,164036,190107,88523,28769,198646,133957,3008088,90958,35571,314,36546",30,110.0,306,87.2,7598.9,4.6,"154,154,72,72,34,30,154,154,72,72,34,30,34,30,34,30,34,30,74,54,232,261,240,150,306,234,302,34,30,154,154,72","6,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,6,0,1,0,0,3,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,1,0,0,1,1,0,1,0,1,0,1,0,1,1,1,1,1,1,1,1,1,1,0,1,0,0,1","6.541143417,6.523254871,5.258596897,5.258596897,4.628356934,4.453236580,6.497281075,6.520071030,5.203041553,5.130857468,4.628356934,4.453236580,4.628356934,4.453236580,4.628356934,4.453236580,4.628356934,4.453236580,5.668909073,5.185353279,6.995151520,7.135284424,7.074851990,6.635347366,7.304471493,6.999480724,7.242955685,4.628356934,4.453236580,6.523254871,6.523254871,5.230819225",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"" -1,ip4,91.252.56.51,192.168.2.12,udp,32704,56328,finished,18,14,1561455730495456,1561455733316995,1561455733325980,26,0,171,273,1873,1869,0,2,182324.6,1203723,228895.9,52393320448.0,4.2,"578236,623635,1203723,72457,167216,11596,115693,158378,2,172820,173607,169808,156213,136586,155315,179817,99336,157427,38286,163380,181314,166574,142422,2967,25967,115313,6126,171847,106305,56249,143448",54,144.9,301,51.7,2672.5,4.9,"72,72,72,72,72,72,199,260,150,161,301,137,159,159,133,149,136,150,172,164,155,159,164,170,150,54,150,150,156,150,139,179","1,4,0,8,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,0,4,6,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,1,0,0,1,0,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,1,0,0,0,1,0,0,1","5.523683071,5.551460743,5.523683071,5.586590290,5.513198376,5.558812618,6.900094032,7.080634594,6.725411892,6.561889648,7.326864719,6.497554302,6.712717533,6.644547939,6.493841648,6.572838783,6.470429420,6.565414429,6.709655762,6.771090984,6.675994873,6.701801777,6.747565746,6.673988342,6.480553150,5.199332237,6.648680687,6.585022449,6.694502831,6.592251301,6.568360806,6.807644844",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5" +1,ip4,192.168.2.12,31.13.86.48,udp,56328,3478,finished,12,20,1561455706912375,1561455731523132,1561455731536124,6,0,126,278,792,1833,0,1,1588209.8,12196243,3050402.8,9304956469248.0,3.2,"61,13448,128,12194152,12196243,104402,58,105108,1,108628,104619,3043264,3048902,3100925,3096031,3015294,3016553,2001940,2156,107078,164036,190107,88523,28769,198646,133957,3008088,90958,35571,314,36546",30,110.0,306,87.2,7598.9,4.6,"154,154,72,72,34,30,154,154,72,72,34,30,34,30,34,30,34,30,74,54,232,261,240,150,306,234,302,34,30,154,154,72","6,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","7,6,0,1,0,0,3,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,1,0,0,1,1,0,1,0,1,0,1,0,1,1,1,1,1,1,1,1,1,1,0,1,0,0,1","6.541143417,6.523254871,5.258596897,5.258596897,4.628356934,4.453236580,6.497281075,6.520071030,5.203041553,5.130857468,4.628356934,4.453236580,4.628356934,4.453236580,4.628356934,4.453236580,4.628356934,4.453236580,5.668909073,5.185353279,6.995151520,7.135284424,7.074851990,6.635347366,7.304471493,6.999480724,7.242955685,4.628356934,4.453236580,6.523254871,6.523254871,5.230819225",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"46" +1,ip4,91.252.56.51,192.168.2.12,udp,32704,56328,finished,18,14,1561455730495456,1561455733316995,1561455733325980,26,0,171,273,1873,1869,0,2,182324.6,1203723,228895.9,52393320448.0,4.2,"578236,623635,1203723,72457,167216,11596,115693,158378,2,172820,173607,169808,156213,136586,155315,179817,99336,157427,38286,163380,181314,166574,142422,2967,25967,115313,6126,171847,106305,56249,143448",54,144.9,301,51.7,2672.5,4.9,"72,72,72,72,72,72,199,260,150,161,301,137,159,159,133,149,136,150,172,164,155,159,164,170,150,54,150,150,156,150,139,179","1,4,0,8,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,2,0,4,6,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,1,1,0,0,1,0,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,1,0,0,0,1,0,0,1","5.523683071,5.551460743,5.523683071,5.586590290,5.513198376,5.558812618,6.900094032,7.080634594,6.725411892,6.561889648,7.326864719,6.497554302,6.712717533,6.644547939,6.493841648,6.572838783,6.470429420,6.565414429,6.709655762,6.771090984,6.675994873,6.701801777,6.747565746,6.673988342,6.480553150,5.199332237,6.648680687,6.585022449,6.694502831,6.592251301,6.568360806,6.807644844",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5,46" diff --git a/test/results/flow-analyse/waze.pcap.out b/test/results/flow-analyse/default/waze.pcap.out index 9115ac426..9115ac426 100644 --- a/test/results/flow-analyse/waze.pcap.out +++ b/test/results/flow-analyse/default/waze.pcap.out diff --git a/test/results/flow-analyse/webex.pcap.out b/test/results/flow-analyse/default/webex.pcap.out index e3c0709d8..e3c0709d8 100644 --- a/test/results/flow-analyse/webex.pcap.out +++ b/test/results/flow-analyse/default/webex.pcap.out diff --git a/test/results/flow-analyse/default/websocket.pcap.out b/test/results/flow-analyse/default/websocket.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/websocket.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/wechat.pcap.out b/test/results/flow-analyse/default/wechat.pcap.out index f36f30abc..f36f30abc 100644 --- a/test/results/flow-analyse/wechat.pcap.out +++ b/test/results/flow-analyse/default/wechat.pcap.out diff --git a/test/results/flow-analyse/weibo.pcap.out b/test/results/flow-analyse/default/weibo.pcap.out index 6430977b6..6430977b6 100644 --- a/test/results/flow-analyse/weibo.pcap.out +++ b/test/results/flow-analyse/default/weibo.pcap.out diff --git a/test/results/flow-analyse/default/whatsapp.pcap.out b/test/results/flow-analyse/default/whatsapp.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/whatsapp.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/whatsapp_login_call.pcap.out b/test/results/flow-analyse/default/whatsapp_login_call.pcap.out index 5c618d742..79419c435 100644 --- a/test/results/flow-analyse/whatsapp_login_call.pcap.out +++ b/test/results/flow-analyse/default/whatsapp_login_call.pcap.out @@ -2,6 +2,6 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_ 1,ip4,192.168.2.4,17.178.104.12,tcp,49201,443,info,18,14,1432582227604482,1432582229309355,1432582229616362,0,0,1440,1440,6486,6050,0,9,119895.3,712466,179472.3,32210292736.0,3.4,"281831,283163,8705,294373,1121,35,286034,828,475,587,39758,240,307,326381,1436,373,2981,289942,5828,471,9,317531,1875,68938,587,382640,405162,707,17,712466,1952",40,432.9,1480,595.1,354099.2,3.8,"64,52,40,230,1480,1480,571,40,40,40,40,307,46,77,40,40,40,83,40,1480,1480,153,40,40,1480,1196,40,1480,1480,153,40,40","9,1,0,2,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0","8,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,3,0,0","0,1,0,0,1,1,1,0,0,0,0,0,0,0,1,1,1,1,0,0,0,0,1,1,1,1,0,0,0,0,1,1","4.541277409,4.887659073,4.715312004,5.559735775,7.184122086,7.417570591,6.899518967,4.931687355,4.881687641,4.931686878,4.765311718,7.230942249,4.759187222,5.742031574,4.834183693,4.834183693,4.834183693,5.811724186,4.931686878,7.864183426,7.878191471,6.699968815,4.684184074,4.684184074,7.862710953,7.817599297,4.931687355,7.865705967,7.847981453,6.673823357,4.784183979,4.834183693",,,,,,,,"" 1,ip4,192.168.2.4,184.173.179.37,tcp,49202,5222,finished,17,15,1432582227643274,1432582230649748,1432582230614203,0,0,201,78,1159,445,0,0,192819.5,709350,172077.7,29610717184.0,4.4,"153871,242175,244771,708056,709350,35643,213202,306,145666,324955,262756,250323,148242,98446,249378,163432,164508,351063,174021,177975,4,178327,331,171720,16,302683,276,301856,4,0,204047",52,102.8,253,60.8,3698.6,4.8,"64,60,52,52,218,130,73,52,52,253,84,71,73,52,227,84,52,118,84,184,84,84,186,52,85,85,252,52,85,85,85,118","9,0,2,0,2,2,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,10,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,1,0,0,0,1,0,1,0,0,1,0,0,1,0,1,1,0,0,1,1,0,0,1,1,1,0","4.535581589,5.323234558,5.284870625,5.118428230,6.648615837,6.247110844,5.434191704,5.231892109,5.169486046,7.074976444,5.807060719,5.762281895,5.680767059,5.207947731,7.065171242,5.820694447,5.246409416,6.336829185,5.802911282,6.766283989,5.781786919,5.740469933,6.833239079,5.270353794,5.863435745,5.886964798,7.017980099,5.284870625,5.854554653,5.807495594,5.816376686,6.257439613",WhatsApp,142,1,Acceptable,Chat,6,DPI,"" 1,ip4,192.168.2.4,17.173.66.102,tcp,49204,443,finished,17,15,1432582230648273,1432582231572130,1432582231504448,0,0,1440,948,5225,2717,0,15,57420.4,246332,88943.3,7910914560.0,3.4,"139279,206534,8183,215650,62,2706,195534,776,251,20,1876,267,2144,191589,2382,13135,3735,6431,14684,18,200945,301,63298,290,2226,246332,5270,14887,15,241033,179",40,289.3,1480,408.5,166890.9,3.9,"64,52,40,267,40,132,77,40,40,46,77,1480,517,596,40,40,40,40,40,988,386,40,40,1480,526,596,40,40,988,386,40,40","9,1,0,0,0,0,0,1,0,0,0,0,0,0,1,1,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","9,1,1,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,0,0,0,0,0,1,1,1,1,1,1,1,0,0,0,0,0,1,1,1,1,0,0","4.510027409,4.810735703,4.684184074,5.952049732,4.734184265,5.970739841,5.673912525,4.881687164,4.931687355,4.715708733,5.638134956,7.848487854,7.566340446,7.617396355,4.784183979,4.784183979,4.715312004,4.784183979,4.684184551,7.790213585,7.442604542,4.812815189,4.762814999,7.877933502,7.577860355,7.608998775,4.634183884,4.734184265,7.790307522,7.455507755,4.831687450,4.831687450",TLS.AppleStore,91.224,1,Safe,SoftwareUpdate,6,DPI,"15" -1,ip4,192.168.2.4,91.253.176.65,udp,51518,9344,finished,17,15,1432582258730153,1432582260754649,1432582260775626,26,0,309,289,3471,2001,0,44,131289.3,352421,70223.6,4931354624.0,4.7,"85532,95222,66134,60379,102693,208383,184141,159624,139073,188537,352421,23426,152856,55080,31139,91630,61,141160,44,163250,159227,188593,161930,163639,162107,156758,164890,143228,181638,163297,123877",50,199.0,337,98.8,9763.6,4.8,"72,72,328,72,72,301,211,297,234,301,206,134,50,235,185,134,123,54,246,54,260,120,337,103,301,103,305,229,306,317,315,291","1,2,1,1,0,1,1,1,7,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,2,3,1,1,1,3,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,1,0,0,1,1,0,1,0,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1","5.642145634,5.662571430,7.306882858,5.607016087,5.619208336,7.276579380,6.918804169,7.219153404,7.014481544,7.348511696,6.906354427,6.461464405,5.083854198,6.954874992,6.766034603,6.415629864,6.367953777,5.205786228,7.119737148,5.148316383,7.136041164,6.350277901,7.294374466,6.069901943,7.367813587,6.103599548,7.328564644,7.015753746,7.285601139,7.344736099,7.265763760,7.231878281",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5" -1,ip4,192.168.2.4,91.253.176.65,udp,52794,9665,finished,16,16,1432582303300524,1432582305119064,1432582305008654,26,0,278,200,1888,1727,0,40,113763.5,307394,86013.0,7398240768.0,4.5,"304269,307394,8384,89918,31917,6521,226162,154173,40,188009,271,163937,163420,160100,21775,153703,73,168136,122602,138908,158523,186698,16232,65895,114250,83709,193240,164541,1311,77123,55436",54,141.0,306,58.8,3453.3,4.9,"72,72,72,72,72,134,124,306,167,54,232,134,228,212,103,134,151,54,172,156,161,172,156,134,114,140,205,140,209,54,134,171","1,3,0,6,3,1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,2,2,3,4,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,1,1,0,0,1,0,1,0,0,0,1,0,1,1,0,1,1,0,1,0,1,1,0,0","5.586590290,5.634793758,5.591430664,5.548327923,5.614367962,6.343744755,6.353155136,7.262660980,6.708292484,5.199332714,6.977910042,6.582841873,7.061330318,6.964643955,6.193738461,6.469698906,6.640622616,5.205786228,6.713893890,6.594544411,6.678621769,6.732760429,6.737264633,6.418371201,6.335039139,6.527385712,6.871919632,6.504805565,6.851323605,5.199332714,6.565941334,6.741304874",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5" +1,ip4,192.168.2.4,91.253.176.65,udp,51518,9344,finished,17,15,1432582258730153,1432582260754649,1432582260775626,26,0,309,289,3471,2001,0,44,131289.3,352421,70223.6,4931354624.0,4.7,"85532,95222,66134,60379,102693,208383,184141,159624,139073,188537,352421,23426,152856,55080,31139,91630,61,141160,44,163250,159227,188593,161930,163639,162107,156758,164890,143228,181638,163297,123877",50,199.0,337,98.8,9763.6,4.8,"72,72,328,72,72,301,211,297,234,301,206,134,50,235,185,134,123,54,246,54,260,120,337,103,301,103,305,229,306,317,315,291","1,2,1,1,0,1,1,1,7,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,2,3,1,1,1,3,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,0,1,0,1,0,0,1,1,0,1,0,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1","5.642145634,5.662571430,7.306882858,5.607016087,5.619208336,7.276579380,6.918804169,7.219153404,7.014481544,7.348511696,6.906354427,6.461464405,5.083854198,6.954874992,6.766034603,6.415629864,6.367953777,5.205786228,7.119737148,5.148316383,7.136041164,6.350277901,7.294374466,6.069901943,7.367813587,6.103599548,7.328564644,7.015753746,7.285601139,7.344736099,7.265763760,7.231878281",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5,46" +1,ip4,192.168.2.4,91.253.176.65,udp,52794,9665,finished,16,16,1432582303300524,1432582305119064,1432582305008654,26,0,278,200,1888,1727,0,40,113763.5,307394,86013.0,7398240768.0,4.5,"304269,307394,8384,89918,31917,6521,226162,154173,40,188009,271,163937,163420,160100,21775,153703,73,168136,122602,138908,158523,186698,16232,65895,114250,83709,193240,164541,1311,77123,55436",54,141.0,306,58.8,3453.3,4.9,"72,72,72,72,72,134,124,306,167,54,232,134,228,212,103,134,151,54,172,156,161,172,156,134,114,140,205,140,209,54,134,171","1,3,0,6,3,1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,2,2,3,4,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,1,1,0,0,1,0,1,0,0,0,1,0,1,1,0,1,1,0,1,0,1,1,0,0","5.586590290,5.634793758,5.591430664,5.548327923,5.614367962,6.343744755,6.353155136,7.262660980,6.708292484,5.199332714,6.977910042,6.582841873,7.061330318,6.964643955,6.193738461,6.469698906,6.640622616,5.205786228,6.713893890,6.594544411,6.678621769,6.732760429,6.737264633,6.418371201,6.335039139,6.527385712,6.871919632,6.504805565,6.851323605,5.199332714,6.565941334,6.741304874",STUN.WhatsAppCall,78.45,0,Acceptable,VoIP,6,DPI,"5,46" 1,ip4,192.168.2.4,17.173.66.102,tcp,49205,443,finished,17,15,1432582355253275,1432582356195572,1432582356100109,0,0,1440,948,5224,2717,0,11,57713.9,271808,91895.6,8444797952.0,3.3,"139873,225073,4218,228888,70,2672,200693,278,1388,194,2268,310,435,198176,1008,14244,4721,5042,13250,23,199875,308,34695,427,52,217025,5837,15994,11,271808,275",40,289.3,1480,408.5,166876.7,3.9,"64,52,40,267,40,132,77,40,40,46,77,1480,516,596,40,40,40,40,40,988,386,40,40,1480,526,596,40,40,988,386,40,40","9,1,0,0,0,0,0,1,0,0,0,0,0,0,1,1,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0","9,1,1,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,1,0,0,0,0,0,0,0,1,1,1,1,1,1,1,0,0,0,0,0,1,1,1,1,0,0","4.478777409,4.849197388,4.715312004,5.931038380,4.784183979,6.049894810,5.799257278,4.881687164,4.881687164,4.802665710,5.737505436,7.869925976,7.601890564,7.659376144,4.834184170,4.884183884,4.884183884,4.834183693,4.834183693,7.790913582,7.529675484,4.881687164,4.931687355,7.881880760,7.552830696,7.654625893,4.834183693,4.884183884,7.775795460,7.413623333,4.931687355,4.881687164",TLS.AppleStore,91.224,1,Safe,SoftwareUpdate,6,DPI,"15" diff --git a/test/results/flow-analyse/whatsapp_login_chat.pcap.out b/test/results/flow-analyse/default/whatsapp_login_chat.pcap.out index cb6811915..cb6811915 100644 --- a/test/results/flow-analyse/whatsapp_login_chat.pcap.out +++ b/test/results/flow-analyse/default/whatsapp_login_chat.pcap.out diff --git a/test/results/flow-analyse/whatsapp_voice_and_message.pcap.out b/test/results/flow-analyse/default/whatsapp_voice_and_message.pcap.out index 9bb5bee38..9bb5bee38 100644 --- a/test/results/flow-analyse/whatsapp_voice_and_message.pcap.out +++ b/test/results/flow-analyse/default/whatsapp_voice_and_message.pcap.out diff --git a/test/results/flow-analyse/whatsappfiles.pcap.out b/test/results/flow-analyse/default/whatsappfiles.pcap.out index af8cf32f6..af8cf32f6 100644 --- a/test/results/flow-analyse/whatsappfiles.pcap.out +++ b/test/results/flow-analyse/default/whatsappfiles.pcap.out diff --git a/test/results/flow-analyse/default/whois.pcapng.out b/test/results/flow-analyse/default/whois.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/whois.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/windowsupdate_over_http.pcap.out b/test/results/flow-analyse/default/windowsupdate_over_http.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/windowsupdate_over_http.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/wireguard.pcap.out b/test/results/flow-analyse/default/wireguard.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/wireguard.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/wow.pcap.out b/test/results/flow-analyse/default/wow.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/wow.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/xdmcp.pcap.out b/test/results/flow-analyse/default/xdmcp.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/xdmcp.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/xiaomi.pcap.out b/test/results/flow-analyse/default/xiaomi.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/xiaomi.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/xss.pcap.out b/test/results/flow-analyse/default/xss.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/xss.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/yandex.pcapng.out b/test/results/flow-analyse/default/yandex.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/yandex.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/youtube_quic.pcap.out b/test/results/flow-analyse/default/youtube_quic.pcap.out index 6a46292d2..6e4f33147 100644 --- a/test/results/flow-analyse/youtube_quic.pcap.out +++ b/test/results/flow-analyse/default/youtube_quic.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.7,216.58.198.33,udp,56074,443,finished,13,19,1489363823738796,1489363823844687,1489363823852784,38,0,1350,1350,3698,22654,0,6,7092.9,47402,13323.0,177502752.0,3.3,"43682,599,47402,292,154,45,22593,22345,6,41882,73,4311,1249,5208,1009,1199,2078,995,1205,2173,1079,939,1972,1276,1007,2312,930,1274,2300,574,7716",59,851.5,1378,620.1,384534.2,4.5,"1378,1378,1378,1378,445,163,164,63,1378,59,69,69,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1016,1378","0,8,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0","0,1,1,0,0,0,0,1,1,1,0,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1","2.490298986,7.548896313,2.557327986,5.454246521,7.513552189,6.657486916,6.667313099,5.203137398,7.879892826,5.320584774,5.540966511,5.620818138,7.837260723,7.846781731,5.625435352,7.860443115,7.869290352,5.595131874,7.865964890,7.867100716,5.462482452,7.871220112,7.858954430,5.583694935,7.863245964,7.872319698,5.564828873,7.868106365,7.885589600,5.529245377,7.780364990,7.853522778",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"" +1,ip4,192.168.1.7,216.58.198.33,udp,56074,443,finished,13,19,1489363823738796,1489363823844687,1489363823852784,38,0,1350,1350,3698,22654,0,6,7092.9,47402,13323.0,177502752.0,3.3,"43682,599,47402,292,154,45,22593,22345,6,41882,73,4311,1249,5208,1009,1199,2078,995,1205,2173,1079,939,1972,1276,1007,2312,930,1274,2300,574,7716",59,851.5,1378,620.1,384534.2,4.5,"1378,1378,1378,1378,445,163,164,63,1378,59,69,69,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1016,1378","0,8,0,0,2,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0","1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0","0,1,1,0,0,0,0,1,1,1,0,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1","2.490298986,7.548896313,2.557327986,5.454246521,7.513552189,6.657486916,6.667313099,5.203137398,7.879892826,5.320584774,5.540966511,5.620818138,7.837260723,7.846781731,5.625435352,7.860443115,7.869290352,5.595131874,7.865964890,7.867100716,5.462482452,7.871220112,7.858954430,5.583694935,7.863245964,7.872319698,5.564828873,7.868106365,7.885589600,5.529245377,7.780364990,7.853522778",QUIC.YouTube,188.124,1,Fun,Media,6,DPI,"46" diff --git a/test/results/flow-analyse/youtubeupload.pcap.out b/test/results/flow-analyse/default/youtubeupload.pcap.out index 2e4bb89f9..77fb98a8c 100644 --- a/test/results/flow-analyse/youtubeupload.pcap.out +++ b/test/results/flow-analyse/default/youtubeupload.pcap.out @@ -1,2 +1,2 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.2.27,172.217.23.111,udp,51925,443,finished,22,10,1511102576794424,1511102580012300,1511102579994904,35,0,1350,1350,18813,4860,0,80,207043.7,1883081,509890.4,259988193280.0,2.4,"56118,973,59784,1844,356,60874,87,57514,351,30658,1096880,488,1126775,721,1825776,1883081,71241,80,128481,3345,2763,363,669,1041,1120,1220,1141,1157,1131,1161,1163",44,767.8,1378,621.3,386013.8,4.4,"1378,1378,1378,66,1378,410,1378,59,69,66,58,44,597,69,63,330,64,140,44,69,373,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378","0,6,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,13,0,0,0,0,0","4,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0","0,1,1,0,0,0,1,1,0,0,1,1,1,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0","2.572486401,7.537513733,7.402596951,5.250994682,4.556015491,7.434559345,7.870773315,5.447868824,5.731709003,5.771669865,5.450197697,4.967351913,7.653637886,5.570558548,5.691562653,7.349846363,5.524900436,6.587018490,4.967351913,5.749753952,7.464030743,7.863305569,7.871096611,7.856682777,7.872458458,7.853973389,7.869896412,7.852776527,7.860300064,7.865760326,7.833461761,7.854090214",QUIC.YouTubeUpload,188.136,1,Fun,Media,6,DPI,"" +1,ip4,192.168.2.27,172.217.23.111,udp,51925,443,finished,22,10,1511102576794424,1511102580012300,1511102579994904,35,0,1350,1350,18813,4860,0,80,207043.7,1883081,509890.4,259988193280.0,2.4,"56118,973,59784,1844,356,60874,87,57514,351,30658,1096880,488,1126775,721,1825776,1883081,71241,80,128481,3345,2763,363,669,1041,1120,1220,1141,1157,1131,1161,1163",44,767.8,1378,621.3,386013.8,4.4,"1378,1378,1378,66,1378,410,1378,59,69,66,58,44,597,69,63,330,64,140,44,69,373,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378,1378","0,6,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,13,0,0,0,0,0","4,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0","0,1,1,0,0,0,1,1,0,0,1,1,1,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0","2.572486401,7.537513733,7.402596951,5.250994682,4.556015491,7.434559345,7.870773315,5.447868824,5.731709003,5.771669865,5.450197697,4.967351913,7.653637886,5.570558548,5.691562653,7.349846363,5.524900436,6.587018490,4.967351913,5.749753952,7.464030743,7.863305569,7.871096611,7.856682777,7.872458458,7.853973389,7.869896412,7.852776527,7.860300064,7.865760326,7.833461761,7.854090214",QUIC.YouTubeUpload,188.136,1,Fun,Media,6,DPI,"46" diff --git a/test/results/flow-analyse/default/z3950.pcapng.out b/test/results/flow-analyse/default/z3950.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/z3950.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/zabbix.pcap.out b/test/results/flow-analyse/default/zabbix.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/zabbix.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/default/zattoo.pcap.out b/test/results/flow-analyse/default/zattoo.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/default/zattoo.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/zcash.pcap.out b/test/results/flow-analyse/default/zcash.pcap.out index 1eac87589..1eac87589 100644 --- a/test/results/flow-analyse/zcash.pcap.out +++ b/test/results/flow-analyse/default/zcash.pcap.out diff --git a/test/results/flow-analyse/zoom.pcap.out b/test/results/flow-analyse/default/zoom.pcap.out index 6abbec486..25e9dd568 100644 --- a/test/results/flow-analyse/zoom.pcap.out +++ b/test/results/flow-analyse/default/zoom.pcap.out @@ -1,4 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.1.117,52.202.62.236,tcp,54866,443,info,15,17,1569520470022260,1569520470618561,1569520470618526,0,0,810,1452,2209,17680,0,3,38469.9,210729,59394.9,3527759616.0,3.3,"112386,112530,31116,143960,1761,226,34,114802,166,170,7182,2922,121940,111900,4272,3,116559,98015,494,36,210729,39,183,114,242,129,123,246,127,13,148",40,663.0,1492,660.1,435695.1,4.2,"64,52,40,557,46,1492,1492,1492,40,1292,40,40,231,91,40,731,850,46,1492,1492,1492,40,40,1492,1492,40,1492,1492,40,1492,445,40","11,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,11,0,0","0,1,0,0,1,1,1,1,0,1,0,0,0,1,0,0,0,1,1,1,1,0,0,1,1,0,1,1,0,1,1,0","4.416232109,4.853979111,4.521928310,4.120527744,4.501398087,7.132670879,7.329687119,7.314774990,4.730641365,7.640571117,4.630640984,4.680641174,6.885639668,5.726258755,4.730641365,7.684801102,7.726203442,4.457919598,7.862352848,7.860615253,7.859583378,4.680641174,4.621928692,7.878399849,7.862105846,4.680641174,7.872378349,7.851402760,4.630641460,7.881779194,7.526136398,4.561769009",,,,,,,,"" 1,ip4,192.168.1.117,109.94.160.99,tcp,54871,443,finished,18,14,1569520471189039,1569520471662963,1569520471590160,0,0,1440,1440,3063,8708,0,1,28227.3,156067,40349.6,1628089600.0,3.8,"31621,31782,223,32749,1986,135,18,34538,3,10485,3,10554,60088,93852,33789,375,31290,30856,4598,4,36582,6223,38193,156062,156067,114,1,94,10606,59053,3101",52,420.5,1492,552.4,305116.1,3.9,"64,60,52,569,52,1492,1492,1268,52,52,1492,79,52,178,294,52,192,118,52,1492,533,52,90,52,1317,52,1492,146,52,90,202,223","10,1,0,1,2,1,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","4,1,2,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,4,0,0","0,1,0,0,1,1,1,1,0,0,1,1,0,0,1,0,0,1,0,0,0,1,1,0,1,0,1,1,0,0,0,0","4.428027153,5.266787052,5.014835358,4.340119362,5.209868431,7.128724575,7.325717926,7.321290493,5.014835358,5.053297043,7.580979347,5.559112549,5.053297043,6.556212902,7.136325836,5.130220413,6.862732410,6.273187160,5.053297043,7.864217758,7.611272335,5.132945538,5.887335777,5.091758728,7.866543293,5.130220413,7.874340057,6.566402435,5.130220413,5.819303036,6.871904373,6.960445881",TLS.Zoom,91.189,1,Acceptable,Video,6,DPI,"15" -1,ip4,192.168.1.117,109.94.160.99,udp,58327,8801,finished,3,29,1569520471748648,1569520471785584,1569520472033049,13,0,107,1029,183,26845,0,28,10365.7,35562,8525.9,72690992.0,4.5,"31967,28,32217,4719,35562,13763,10264,10242,9996,63,10130,10327,9979,9966,107,9866,10246,10252,10251,126,10146,9980,10130,10478,32,9954,10261,9714,10315,406,9850",41,872.8,1057,383.7,147246.2,4.8,"135,63,46,41,91,71,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057","1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,26,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.872597694,4.834421635,4.434307098,4.564153194,5.116748810,4.833924294,0.510210812,0.504684150,0.513590038,0.511697888,0.528077245,0.513589978,0.515482187,0.515482187,0.513590038,0.532575667,0.515482187,0.508318722,0.515482187,0.512875855,0.532575667,0.515482187,0.511697948,0.511697888,0.513590038,0.532575667,0.515482187,0.513589978,0.510983646,0.515482187,0.532575667,0.515482187",Zoom,189,1,Acceptable,Video,6,DPI,"" +1,ip4,192.168.1.117,109.94.160.99,udp,58327,8801,finished,3,29,1569520471748648,1569520471785584,1569520472033049,13,0,107,1029,183,26845,0,28,10365.7,35562,8525.9,72690992.0,4.5,"31967,28,32217,4719,35562,13763,10264,10242,9996,63,10130,10327,9979,9966,107,9866,10246,10252,10251,126,10146,9980,10130,10478,32,9954,10261,9714,10315,406,9850",41,872.8,1057,383.7,147246.2,4.8,"135,63,46,41,91,71,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057","1,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,26,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,1,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.872597694,4.834421635,4.434307098,4.564153194,5.116748810,4.833924294,0.510210812,0.504684150,0.513590038,0.511697888,0.528077245,0.513589978,0.515482187,0.515482187,0.513590038,0.532575667,0.515482187,0.508318722,0.515482187,0.512875855,0.532575667,0.515482187,0.511697948,0.511697888,0.513590038,0.532575667,0.515482187,0.513589978,0.510983646,0.515482187,0.532575667,0.515482187",Zoom,189,1,Acceptable,Video,6,DPI,"46" diff --git a/test/results/flow-analyse/zoom2.pcap.out b/test/results/flow-analyse/default/zoom2.pcap.out index 4b1fb533d..8ff9f67fe 100644 --- a/test/results/flow-analyse/zoom2.pcap.out +++ b/test/results/flow-analyse/default/zoom2.pcap.out @@ -1,5 +1,4 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.178,144.195.73.154,tcp,50076,443,finished,17,15,1642965458402978,1642965459315313,1642965459315763,0,0,1440,1440,3004,9722,0,1,58874.8,198571,83051.8,6897604608.0,3.4,"174660,174776,564,174002,1305,35,10,9,175382,5,1,23625,1263,198571,173076,348,174461,174128,5783,7,187559,672,15,182407,110,83,84,878,803,496,2",52,450.3,1492,547.4,299645.5,4.0,"64,60,52,569,52,1492,1492,1268,814,52,52,52,52,178,103,52,208,127,52,1492,767,52,1492,442,52,200,52,102,1330,52,1330,256","11,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0","3,1,1,0,1,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,2,0,0,0,0,0,3,0,0","0,1,0,0,1,1,1,1,1,0,0,0,0,0,1,0,0,1,0,0,0,1,1,1,0,1,0,0,1,0,1,1","4.254878044,5.233453751,5.053297043,4.421474934,5.063529015,7.154266357,7.350361347,7.483180046,7.590131760,5.022342205,4.983880997,5.022342205,4.983880520,6.548796177,5.785968304,4.855899334,6.773957253,6.347529888,5.014834881,7.875683308,7.723464012,5.132945061,7.879707336,7.463565826,4.976374149,6.741343498,5.014835358,5.970962524,7.852532387,5.014835358,7.852782249,6.910366535",TLS.Zoom,91.189,1,Acceptable,Video,6,DPI,"15" -1,ip4,192.168.1.178,144.195.73.154,udp,60653,8801,finished,5,27,1642965459595620,1642965459884168,1642965460094905,123,0,128,1036,630,21016,0,21,25414.0,166585,40490.2,1639456256.0,3.6,"101379,166585,27,72990,12330,100439,29,101849,72959,11921,4860,10860,10480,10129,246,9160,10351,10320,11352,21,292,9440,8565,5418,4862,82,10799,10006,10476,9401,205",46,704.7,1064,464.6,215864.3,4.6,"151,151,72,46,156,156,72,46,156,88,88,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,88,1064,1064,1064,1064,1064,1064,1064","0,0,0,2,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,20,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.840515137,5.848702431,4.861306667,4.234366894,5.447824001,5.554306984,4.833528996,4.321323395,5.629264832,4.681292534,4.672410965,0.559972763,0.556576610,0.564253807,0.560080409,0.590531707,0.561960101,0.563839793,0.561959982,0.563839793,0.597341061,0.588497758,0.561959982,0.561959982,4.750781059,0.551231861,0.590992451,0.553111553,0.553111553,0.561959982,0.561959982,0.599220753",RTP.Zoom,87.189,0,Acceptable,Video,6,DPI,"" -1,ip4,192.168.1.178,144.195.73.154,udp,58117,8801,finished,12,20,1642965460219455,1642965460877104,1642965460887928,88,0,161,136,1490,1734,0,12,42778.1,176446,48878.6,2389121792.0,4.1,"98469,176446,124,85491,9538,94754,12,99878,94166,12337,1946,12440,20627,16992,20131,168367,18000,3631,10879,10252,19350,32137,20903,115345,15,17844,18745,20098,20216,21487,85502",46,129.0,189,35.8,1279.8,4.9,"151,151,72,46,156,156,72,46,156,88,88,161,164,154,149,145,116,88,149,92,143,144,134,135,166,189,116,150,148,143,144,116","0,0,1,6,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,5,3,8,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,0,0,1,0,0,0,0,1","5.774950981,5.795780182,4.871791363,4.390829086,5.589504242,5.647461891,4.816236019,4.390829086,5.513776779,4.672714233,4.717865467,5.984676361,5.988471985,5.890224934,5.750802994,5.721282959,5.103803158,4.742203236,5.809841633,4.711098671,5.716365814,5.704583168,5.625706196,5.615069389,6.022024632,6.167570114,5.279437542,5.717482567,5.684329510,5.700431347,5.688298225,5.216770172",RTP.Zoom,87.189,0,Acceptable,Video,6,DPI,"" -1,ip4,192.168.1.178,144.195.73.154,udp,57953,8801,finished,15,17,1642965460359314,1642965461085374,1642965461081424,27,0,143,75,1257,755,0,8,46715.2,187597,42950.9,1844783744.0,4.3,"102087,187597,15,105625,59,93505,28,87640,70667,56,105994,30,21517,32815,58979,18,48377,5541,49496,50209,26,8,55223,45719,56325,52361,22,59786,52118,47745,58582",46,91.1,171,44.6,1993.4,4.8,"153,153,72,46,163,163,72,46,163,163,163,103,103,55,55,171,55,55,103,55,103,103,55,55,55,55,103,55,55,55,55,55","7,0,0,2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,0,0,1,1,0,1,0,0,1,1,0,1,1,1,0,1,0,1,1,0,1,1,0","5.810314178,5.912507057,4.833528996,4.303872585,5.517835140,5.506913185,4.805751324,4.390829086,5.576398373,5.539088726,5.561493397,4.442456245,4.487634182,3.597789288,3.852133274,5.482311726,3.597789288,3.888496876,4.520360470,3.744285822,4.494622231,4.547106743,3.853325367,3.707922220,3.961224079,3.671558619,4.547106743,3.924860477,3.671558380,3.888496876,3.924860477,3.707922220",RTP.Zoom,87.189,0,Acceptable,Video,6,DPI,"" +1,ip4,192.168.1.178,144.195.73.154,udp,60653,8801,finished,5,27,1642965459595620,1642965459884168,1642965460094905,123,0,128,1036,630,21016,0,21,25414.0,166585,40490.2,1639456256.0,3.6,"101379,166585,27,72990,12330,100439,29,101849,72959,11921,4860,10860,10480,10129,246,9160,10351,10320,11352,21,292,9440,8565,5418,4862,82,10799,10006,10476,9401,205",46,704.7,1064,464.6,215864.3,4.6,"151,151,72,46,156,156,72,46,156,88,88,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,88,1064,1064,1064,1064,1064,1064,1064","0,0,0,2,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,20,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","5.840515137,5.848702431,4.861306667,4.234366894,5.447824001,5.554306984,4.833528996,4.321323395,5.629264832,4.681292534,4.672410965,0.559972763,0.556576610,0.564253807,0.560080409,0.590531707,0.561960101,0.563839793,0.561959982,0.563839793,0.597341061,0.588497758,0.561959982,0.561959982,4.750781059,0.551231861,0.590992451,0.553111553,0.553111553,0.561959982,0.561959982,0.599220753",SRTP.Zoom,338.189,1,Acceptable,Video,6,DPI,"" +1,ip4,192.168.1.178,144.195.73.154,udp,58117,8801,finished,12,20,1642965460219455,1642965460877104,1642965460887928,88,0,161,136,1490,1734,0,12,42778.1,176446,48878.6,2389121792.0,4.1,"98469,176446,124,85491,9538,94754,12,99878,94166,12337,1946,12440,20627,16992,20131,168367,18000,3631,10879,10252,19350,32137,20903,115345,15,17844,18745,20098,20216,21487,85502",46,129.0,189,35.8,1279.8,4.9,"151,151,72,46,156,156,72,46,156,88,88,161,164,154,149,145,116,88,149,92,143,144,134,135,166,189,116,150,148,143,144,116","0,0,1,6,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","2,5,3,8,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,1,1,1,1,1,1,1,0,1,1,1,1,1,1,1,0,0,1,0,0,0,0,1","5.774950981,5.795780182,4.871791363,4.390829086,5.589504242,5.647461891,4.816236019,4.390829086,5.513776779,4.672714233,4.717865467,5.984676361,5.988471985,5.890224934,5.750802994,5.721282959,5.103803158,4.742203236,5.809841633,4.711098671,5.716365814,5.704583168,5.625706196,5.615069389,6.022024632,6.167570114,5.279437542,5.717482567,5.684329510,5.700431347,5.688298225,5.216770172",SRTP.Zoom,338.189,1,Acceptable,Video,6,DPI,"" +1,ip4,192.168.1.178,144.195.73.154,udp,57953,8801,finished,15,17,1642965460359314,1642965461085374,1642965461081424,27,0,143,75,1257,755,0,8,46715.2,187597,42950.9,1844783744.0,4.3,"102087,187597,15,105625,59,93505,28,87640,70667,56,105994,30,21517,32815,58979,18,48377,5541,49496,50209,26,8,55223,45719,56325,52361,22,59786,52118,47745,58582",46,91.1,171,44.6,1993.4,4.8,"153,153,72,46,163,163,72,46,163,163,163,103,103,55,55,171,55,55,103,55,103,103,55,55,55,55,103,55,55,55,55,55","7,0,0,2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","9,2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,1,1,0,0,0,1,1,0,1,0,0,1,1,0,1,1,1,0,1,0,1,1,0,1,1,0","5.810314178,5.912507057,4.833528996,4.303872585,5.517835140,5.506913185,4.805751324,4.390829086,5.576398373,5.539088726,5.561493397,4.442456245,4.487634182,3.597789288,3.852133274,5.482311726,3.597789288,3.888496876,4.520360470,3.744285822,4.494622231,4.547106743,3.853325367,3.707922220,3.961224079,3.671558619,4.547106743,3.924860477,3.671558380,3.888496876,3.924860477,3.707922220",SRTP.Zoom,338.189,1,Acceptable,Video,6,DPI,"" diff --git a/test/results/flow-analyse/zoom_p2p.pcapng.out b/test/results/flow-analyse/default/zoom_p2p.pcapng.out index ca3ebdf5e..78fdeebc9 100644 --- a/test/results/flow-analyse/zoom_p2p.pcapng.out +++ b/test/results/flow-analyse/default/zoom_p2p.pcapng.out @@ -1,5 +1,5 @@ flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks 1,ip4,192.168.12.156,192.168.1.226,udp,39065,46757,info,16,16,1666892675237560,1666892675646012,1666892675643750,85,0,1028,1249,10188,10473,0,50,26278.8,88605,20740.6,430173408.0,4.5,"8394,10159,12038,53,14255,4983,17542,37266,28360,52475,28978,88605,223,71337,10758,22416,50,28514,48671,32496,39006,13417,192,30154,24517,22794,31770,53366,31819,40077,9957",113,673.7,1277,485.6,235788.4,4.5,"113,113,113,113,113,113,113,113,113,113,113,1246,1056,1056,1246,800,1245,119,1245,800,800,1245,800,799,118,831,1245,1277,1043,1043,1257,1043","0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,1,0,0,0,0,0,3,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,7,1,0,0,0,0,0,0,0,0","0,1,0,1,1,0,1,0,1,1,0,1,0,0,1,0,1,1,1,0,0,1,0,0,1,0,1,1,0,0,1,0","4.879871845,4.806567192,4.780356884,4.859664917,4.859664917,4.837792873,4.824266434,4.879871845,4.824266434,4.806567192,4.815755367,7.809407711,0.496801347,0.516033888,7.832608223,7.657176495,7.832114697,5.751297951,7.815535069,7.718434811,7.700232506,7.835743904,7.666582108,7.693008900,5.751585960,7.688401699,7.843828678,7.832822323,7.774564743,7.788288593,7.829477787,7.789775848",,,,,,,,"" -1,ip4,206.247.10.253,192.168.12.156,icmp,,,finished,32,0,1666892883560468,1666892913745701,1666892883560468,80,0,80,0,2560,0,0,12,973717.2,2030871,1005257.0,1010541658112.0,3.9,"41,2023261,44,2021544,37,2008437,21,2013453,36,1994813,23,2022454,40,1990669,67,2022201,30,2021984,58,1995365,12,2020200,29,2002242,3110,1996909,3099,2014147,17,2030871,19",100,100.0,100,0.0,0.0,5.0,"100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100","0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.350244999,5.278791904,5.243694782,5.287598610,5.377793789,5.326340675,5.377793789,5.318793297,5.397793770,5.262695789,5.298792839,5.370244980,5.291243553,5.322695732,5.318792820,5.350244999,5.318792820,5.377793789,5.278791904,5.330244541,5.317793369,5.286341190,5.271244049,5.322696686,5.377794266,5.326341152,5.318791866,5.357794285,5.377793789,5.326341152,5.397794247,5.346340656",ICMP,81,0,Acceptable,Network,6,DPI,"" +1,ip4,206.247.10.253,192.168.12.156,icmp,,,finished,32,0,1666892883560468,1666892913745701,1666892883560468,80,0,80,0,2560,0,0,12,973717.2,2030871,1005257.0,1010541658112.0,3.9,"41,2023261,44,2021544,37,2008437,21,2013453,36,1994813,23,2022454,40,1990669,67,2022201,30,2021984,58,1995365,12,2020200,29,2002242,3110,1996909,3099,2014147,17,2030871,19",100,100.0,100,0.0,0.0,5.0,"100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100","0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.350244999,5.278791904,5.243694782,5.287598610,5.377793789,5.326340675,5.377793789,5.318793297,5.397793770,5.262695789,5.298792839,5.370244980,5.291243553,5.322695732,5.318792820,5.350244999,5.318792820,5.377793789,5.278791904,5.330244541,5.317793369,5.286341190,5.271244049,5.322696686,5.377794266,5.326341152,5.318791866,5.357794285,5.377793789,5.326341152,5.397794247,5.346340656",ICMP,81,0,Acceptable,Network,6,DPI,"46" 1,ip4,192.168.12.156,10.78.14.178,udp,42208,47312,info,32,0,1666892923321165,1666892923731059,1666892923321165,84,0,84,0,2688,0,0,149,13222.4,52278,15933.9,253890336.0,4.0,"206,27265,11246,7707,6831,1534,149,13289,6864,1707,40450,203,15506,643,33328,247,50821,420,5857,5665,52278,379,7223,2326,22718,234,30994,178,40889,183,22554",112,112.0,112,0.0,0.0,5.0,"112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112","0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.994051456,4.951597214,4.994051933,4.994051456,4.976194382,4.976194382,4.994051456,4.958336830,4.976194382,4.994051456,4.958336830,4.994051456,4.958336830,4.994051456,4.976194382,4.994051456,4.976194382,4.994051456,4.951597214,4.994051456,4.976194382,4.994051456,4.958336830,4.994051456,4.976194382,4.994051456,4.976194382,4.994051456,4.958336830,4.994051456,4.976194382,4.994051456",,,,,,,,"" 1,ip4,192.168.12.156,10.78.14.178,udp,49579,49586,info,32,0,1666892923611662,1666892924448503,1666892923611662,84,0,84,0,2688,0,0,338,26994.9,54779,14468.3,209331424.0,4.7,"23783,338,29801,1565,40495,506,22699,46435,8735,38102,43592,20546,19277,34040,24361,41537,21146,25008,31087,47211,23803,22874,54779,5988,45050,14923,26821,31551,48347,23766,18675",112,112.0,112,0.0,0.0,5.0,"112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112","0,0,32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.927000046,4.944857121,4.909142494,4.902402878,4.927000046,4.912628174,4.927000046,4.927000046,4.909142494,4.927000046,4.909142494,4.927000046,4.927000046,4.927000046,4.927000046,4.898025990,4.927000046,4.927000046,4.927000046,4.927000046,4.927000046,4.902402401,4.909142494,4.927000046,4.927000046,4.909142494,4.927000046,4.894771099,4.902402401,4.927000046,4.909142494,4.909142494",,,,,,,,"" diff --git a/test/results/flow-analyse/disable_aggressiveness/ookla.pcap.out b/test/results/flow-analyse/disable_aggressiveness/ookla.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/disable_aggressiveness/ookla.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/disable_protocols/dns_long_domainname.pcap.out b/test/results/flow-analyse/disable_protocols/dns_long_domainname.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/disable_protocols/dns_long_domainname.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/disable_protocols/pluralsight.pcap.out b/test/results/flow-analyse/disable_protocols/pluralsight.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/disable_protocols/pluralsight.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/disable_protocols/quic-mvfst-27.pcapng.out b/test/results/flow-analyse/disable_protocols/quic-mvfst-27.pcapng.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/disable_protocols/quic-mvfst-27.pcapng.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/disable_protocols/soap.pcap.out b/test/results/flow-analyse/disable_protocols/soap.pcap.out new file mode 100644 index 000000000..bab73746f --- /dev/null +++ b/test/results/flow-analyse/disable_protocols/soap.pcap.out @@ -0,0 +1 @@ +flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks diff --git a/test/results/flow-analyse/firefox.pcap.out b/test/results/flow-analyse/firefox.pcap.out deleted file mode 100644 index 8377b570f..000000000 --- a/test/results/flow-analyse/firefox.pcap.out +++ /dev/null @@ -1,7 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.178,146.48.58.18,tcp,51577,443,finished,14,18,1620927997754367,1620927998776498,1620927998804931,0,0,517,1440,1348,15691,0,3,66861.1,576607,148076.5,21926651904.0,2.8,"26706,26798,1311,27344,5752,45,31822,499,455,210977,313,236002,29,1309,26,26092,3,575380,1218,576607,259,117,346,122,123,243,1357,145807,171406,2874,1353",52,585.1,1492,633.0,400627.7,4.1,"64,60,52,569,52,1492,1492,52,758,52,132,438,52,52,355,355,52,52,1492,1492,52,1492,1492,52,1492,1471,52,52,417,52,1492,1492","10,0,1,0,0,0,0,0,0,0,0,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,9,0,0","0,1,0,0,1,1,1,0,1,0,0,0,1,1,1,1,0,0,1,1,0,1,1,0,1,1,0,0,0,1,1,1","4.428027153,5.266787052,5.014835358,5.174138069,5.162476063,7.842608452,7.864985943,5.014834881,7.695538521,5.053296566,6.283938885,7.435882092,5.085552692,5.008629799,7.300004005,7.376957893,5.014835358,4.976373672,7.887156010,7.855851173,4.976373672,7.868392467,7.877747059,5.014835358,7.872129440,7.861151218,4.961856842,5.014835358,7.429141998,5.124014378,7.843397617,7.882917881",TLS,91,1,Safe,Web,6,DPI,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,51583,443,finished,13,19,1620927998782772,1620927999138109,1620927999138090,0,0,680,1440,1491,17379,0,9,22924.4,231008,52648.8,2771896832.0,3.0,"34406,34489,3261,32258,1506,30479,4158,18595,31638,14,8894,18473,2988,120,21557,203508,231008,997,180,13,28684,187,199,924,71,1013,133,374,19,9,500",52,642.3,1492,649.7,422101.6,4.2,"64,60,52,732,52,312,52,132,402,52,355,52,52,1492,1028,52,433,52,1492,1492,1492,52,1492,52,1492,1492,52,1492,1492,1492,1492,52","9,0,1,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,0,1,1,1,0,0,1,1,1,1,0,1,0,1,1,0,1,1,1,1,0","4.459277153,5.233453751,5.014835358,7.202944279,5.085553169,7.007672310,4.961856842,6.264141560,7.328972340,5.032574654,7.353322983,5.014835358,5.124014854,7.879932404,7.808946609,4.961856365,7.467625618,5.047091484,7.873059750,7.873151302,7.887775421,4.976373672,7.877523422,5.014835358,7.875070572,7.887982368,4.976373672,7.869130135,7.859514236,7.867089272,7.877560139,5.014835358",TLS,91,1,Safe,Web,6,DPI,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,51588,443,info,14,18,1620927998806443,1620927999167352,1620927999167300,0,0,680,1440,1497,16303,0,19,23282.8,221390,50495.5,2549799168.0,3.1,"27372,27441,16192,42139,1225,27152,10064,34749,19,24715,195798,221390,1843,27432,3443,28677,1090,241,26560,1009,109,1111,130,120,236,127,123,253,261,233,512",52,608.9,1492,649.7,422127.9,4.1,"64,60,52,732,52,312,52,132,52,355,52,419,52,1392,52,422,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52","10,0,1,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,10,0,0","0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0","4.459277153,5.146034718,4.976373672,7.228655815,5.010550499,6.920869827,4.976373672,6.311110497,5.008629799,7.354775429,4.976373672,7.419640064,4.972088814,7.854094028,4.860989094,7.443080425,5.008629799,7.863340855,7.851551056,4.976373672,7.864044666,7.884602547,4.976373672,7.881500721,7.891372204,4.976373672,7.871342182,7.873107433,4.976373672,7.874297619,7.860782623,4.976373672",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,51600,443,info,15,17,1620927999111334,1620927999226479,1620927999226567,0,0,680,1440,1130,16403,0,2,7431.5,29597,10227.7,104605344.0,3.7,"26761,26832,3278,29208,2415,28362,2863,12850,29597,2,13859,11433,1695,114,13236,128,293,994,822,122,164,127,63,168,80,256,81,263,11998,12186,128",52,600.5,1492,660.2,435829.6,4.1,"64,60,52,732,52,312,52,132,422,52,355,52,52,1492,1492,52,1492,52,1492,52,1492,52,1492,52,1492,1492,52,52,1492,1492,52,1492","12,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,0,1,1,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1,1,0,1","4.377322197,5.220872402,5.014835358,7.213215351,5.008629799,6.968000412,5.014835358,6.313750267,7.425912857,5.085553169,7.267926216,5.014835358,5.008629799,7.858884811,7.871315002,4.976373672,7.877995014,4.931210041,7.875296116,5.053297043,7.839466572,4.931210041,7.867573261,4.976373672,7.859172344,7.851386070,5.014835358,4.892748356,7.876949787,7.858725071,4.976373672,7.891367435",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,51599,443,info,15,17,1620927999109976,1620927999243663,1620927999243600,0,0,680,1440,1130,15696,0,26,8622.9,45603,12422.0,154305440.0,3.6,"28117,28187,5501,31657,1076,27239,20259,3957,45603,1275,22621,2846,3133,147,6125,104,193,162,80,94,95,129,121,148,217,366,254,1527,18636,26,17416",52,578.4,1492,641.5,411570.0,4.1,"64,60,52,732,52,312,52,132,422,52,355,52,52,1492,1492,52,1492,52,1492,52,1492,52,1492,52,1492,1492,52,1492,52,1492,785,52","12,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,0,0,0,1,1,0,1,1,1,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,1,0","4.428027153,5.200119972,4.976374149,7.195712090,5.085553169,6.972116470,5.014835835,6.221041679,7.470200539,5.008629799,7.370405674,5.014835358,5.124014854,7.847041607,7.873993397,4.976373672,7.857460022,4.854287148,7.870365620,5.053297043,7.837957382,4.931210041,7.879583359,5.053297043,7.881470203,7.859474659,5.014835358,7.886620045,4.892748356,7.869515896,7.724751472,5.014835358",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,51601,443,info,15,17,1620927999112216,1620927999264777,1620927999264937,0,0,680,1440,1509,13869,0,2,9847.8,37388,13420.2,180101408.0,3.6,"28631,28716,7742,37388,1480,31124,2184,12981,31005,84,15910,15394,488,119,15971,252,383,635,139,236,17,375,2,151,475,36484,124,120,36112,183,377",52,533.2,1492,619.5,383804.7,4.0,"64,60,52,732,52,312,52,132,422,52,355,52,52,1492,1492,52,1492,1492,52,1492,1492,398,52,52,52,431,52,1492,1492,52,52,1492","11,0,1,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0","0,1,0,0,1,1,0,0,0,1,1,0,1,1,1,0,1,1,0,1,1,1,0,0,0,0,1,1,1,0,0,1","4.459277153,5.220872402,5.014835358,7.209626675,5.085553169,7.008624077,5.014835358,6.200282097,7.566779613,5.085553646,7.353106976,5.014835358,5.124014854,7.878056049,7.889544964,5.014835358,7.892714977,7.877523899,5.014835358,7.856287479,7.859073639,7.445496559,4.961856842,4.945419312,4.892748833,7.390010357,5.047091484,7.860656738,7.870811462,5.014835358,4.892748833,7.870283127",,,,,,,,"" diff --git a/test/results/flow-analyse/http-manipulated.pcap.out b/test/results/flow-analyse/http-manipulated.pcap.out deleted file mode 100644 index 73600a96d..000000000 --- a/test/results/flow-analyse/http-manipulated.pcap.out +++ /dev/null @@ -1,2 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.0.20,192.168.0.7,tcp,33684,8080,finished,16,16,946729142063151,946729142137590,946729142137635,0,0,386,5840,721,44377,0,7,4804.0,73065,17898.4,320351264.0,1.2,"227,236,111,336,193,414,72850,73065,187,402,51,53,13,9,38,39,116,116,52,52,10,8,43,47,49,47,9,7,46,48,49",40,1450.4,5880,1938.5,3757919.5,3.7,"52,52,40,426,46,617,40,375,46,2960,40,4420,40,2960,40,4420,40,1500,40,4420,40,2960,40,4420,40,1500,40,5880,40,5880,40,2960","14,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,10","0,1,0,0,1,1,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1","4.593450069,4.752667427,4.730641365,5.668842793,4.347350597,5.745784283,4.730641365,5.579823494,4.347351074,7.830016136,4.680641174,7.888666153,4.730641365,7.823786259,4.621928692,7.852690220,4.680641174,7.708244801,4.730641842,7.858263493,4.730641365,7.790898323,4.730641842,7.845959663,4.630641460,7.734711647,4.630641460,7.881909370,4.680641651,7.903243542,4.680641174,7.864356995",HTTP,7,0,Acceptable,Web,6,DPI,"5" diff --git a/test/results/flow-analyse/ookla.pcap.out b/test/results/flow-analyse/ookla.pcap.out deleted file mode 100644 index 2ab8039a0..000000000 --- a/test/results/flow-analyse/ookla.pcap.out +++ /dev/null @@ -1,2 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.7,46.44.253.187,tcp,51215,8080,finished,21,11,1491069115107460,1491069116003131,1491069115908957,0,0,19,34,174,186,0,72,54747.4,137734,32631.2,1064798016.0,4.7,"36785,36897,27990,64017,72,36059,38392,72665,34304,27134,61863,34745,97665,133205,35538,27694,63063,35336,68477,103729,35275,26006,61113,35107,103239,137734,34506,32637,67251,34614,94056",52,63.9,86,9.7,93.7,5.0,"64,60,52,55,52,86,52,71,71,52,71,71,52,71,71,52,71,71,52,71,71,52,71,71,52,71,71,52,71,71,52,71","21,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","10,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,0","4.484427452,5.279368877,5.115703106,5.192151546,5.207948208,5.516513824,5.077241421,5.383457661,5.524891853,5.024262905,5.400994301,5.542428493,5.077241421,5.485500813,5.524891853,5.077241421,5.439795971,5.648200035,5.077241421,5.411627769,5.609398842,5.115703106,5.485501289,5.524892330,4.961856365,5.485501289,5.648200035,5.115703106,5.496133804,5.530390263,5.000318050,5.390362263",Ookla,191,0,Safe,Network,5,DPI (cache),"" diff --git a/test/results/flow-analyse/quic-mvfst-22_decryption_error.pcap.out b/test/results/flow-analyse/quic-mvfst-22_decryption_error.pcap.out deleted file mode 100644 index 8c8f4b1cc..000000000 --- a/test/results/flow-analyse/quic-mvfst-22_decryption_error.pcap.out +++ /dev/null @@ -1,2 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -12,ip4,10.230.40.168,94.97.225.146,udp,62196,443,finished,10,22,1593498296832000,1593498296833000,1593498296836000,32,0,1232,1252,3572,18205,0,0,161.3,3000,573.4,328824.1,1.4,"1000,0,0,0,0,0,0,0,0,3000,0,0,0,0,0,1000,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0",60,708.5,1280,531.1,282057.0,4.5,"1260,106,106,106,698,698,698,60,60,60,66,66,66,261,261,261,400,400,400,1280,1280,1280,1280,1280,1280,1280,1280,1280,1280,1280,1280,1280","0,3,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0","0,3,0,0,0,0,0,3,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,13,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1","7.860296249,6.126270771,6.126270771,6.163064480,7.718494892,7.718494892,7.717700005,5.480065823,5.480065823,5.506893158,5.413313866,5.413313866,5.536673069,7.175638199,7.175638199,7.187689304,7.409482956,7.409482956,7.414732456,7.811549187,7.811549187,7.811690331,7.844969273,7.844969273,7.846896648,7.838176727,7.838176727,7.839562893,7.844841957,7.844841957,7.846801758,7.857825279",QUIC,188,1,Acceptable,Web,6,DPI,"" diff --git a/test/results/flow-analyse/safari.pcap.out b/test/results/flow-analyse/safari.pcap.out deleted file mode 100644 index 2a8328afc..000000000 --- a/test/results/flow-analyse/safari.pcap.out +++ /dev/null @@ -1,7 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.1.178,146.48.58.18,tcp,55262,443,info,15,17,1620898024056646,1620898025244024,1620898025243976,0,0,379,1440,1066,15026,0,3,76603.5,579033,166832.5,27833075712.0,2.8,"28338,28438,576,28670,6985,69,14,35105,3,52717,81952,29,29304,948,28144,550635,1230,579033,248,252,138,105,115,138,126,100,428094,455026,4375,1236,32565",52,555.5,1492,644.5,415419.9,4.0,"64,60,52,287,52,1492,1492,627,52,52,145,52,103,52,411,52,1492,1492,52,1492,52,1492,52,1492,52,1492,52,431,52,1492,1492,52","11,0,1,0,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,10,0,0","0,1,0,0,1,1,1,1,0,0,0,1,1,0,0,1,1,1,0,1,0,1,0,1,0,1,0,0,1,1,1,0","4.396777153,5.300120831,5.014835358,5.627039909,5.023147106,7.096756935,7.334726810,7.588644505,4.961856365,4.853978634,6.075397491,4.986606121,5.885092735,4.983880520,7.377478600,4.983880997,7.862138748,7.865662575,4.937912464,7.882334709,4.815825462,7.869226933,4.976374149,7.871172428,4.854287148,7.892846584,5.014835358,7.391702652,5.061608791,7.860088825,7.873157978,5.053297043",,,,,,,,"" -1,ip4,192.168.1.178,146.48.58.18,tcp,55267,443,finished,14,18,1620898025216866,1620898025482937,1620898025510399,0,0,442,1440,1135,16958,0,2,18051.7,118862,28694.5,823374080.0,3.5,"29610,29665,2362,30524,2,28159,51917,8877,77853,8496,625,1248,27408,129,120,247,131,125,259,123,123,248,503,122,637,24023,24010,84464,7818,118862,914",52,618.0,1492,660.5,436248.1,4.1,"64,60,52,263,52,193,52,103,494,52,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1029,52,52,483,52,1492","10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,0,0,0,1,1","4.365527153,5.154205322,4.884933472,5.833237171,5.047091484,6.387271881,4.923395157,5.485030651,7.478204250,4.994112968,4.772770882,7.875178814,7.866140842,4.961856842,7.872851372,7.874671459,4.961856842,7.876760006,7.864192009,4.884933472,7.871975422,7.883419514,4.961856842,7.874213696,7.878833771,4.923395157,7.820206165,4.961856842,4.839769840,7.462142944,5.085553646,7.865268230",TLS,91,1,Safe,Web,6,DPI,"15" -1,ip4,192.168.1.178,146.48.58.18,tcp,55265,443,finished,14,18,1620898025216193,1620898025515519,1620898025515861,0,0,434,1440,1102,16480,0,3,19322.4,140358,32968.3,1086907520.0,3.4,"30407,30442,2425,30749,1690,30065,50340,8582,78328,9234,5001,125,33713,130,749,881,125,129,16,259,3,103964,6593,140358,1494,509,31816,122,126,243,376",52,602.1,1492,656.6,431150.1,4.1,"64,60,52,263,52,193,52,103,458,52,52,1492,1492,52,1492,1492,52,1492,1492,551,52,52,52,486,52,1492,1492,52,1492,1492,52,1492","10,1,0,0,0,0,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,1,1,0,0,0,0,1,1,1,0,1,1,0,1","4.396777153,5.200120449,4.854287148,5.825632572,5.100070000,6.466464043,4.937912464,5.504448891,7.429816246,5.008629799,5.047091484,7.873772621,7.867330074,4.976373672,7.875112534,7.878286839,5.014835358,7.858428001,7.863643646,7.549911976,4.945418835,4.976373672,4.892748356,7.471665859,5.100070477,7.873035431,7.880444050,4.892748356,7.872234821,7.868445873,4.854287148,7.863982677",TLS,91,1,Safe,Web,6,DPI,"15" -1,ip4,192.168.1.178,146.48.58.18,tcp,55266,443,finished,14,18,1620898025216511,1620898025519635,1620898025519733,0,0,437,1440,1130,16706,0,9,19559.5,144002,33697.1,1135492736.0,3.4,"31343,31380,1377,32375,996,31994,49530,8158,77501,8373,630,1247,30061,122,9,127,127,136,106790,7135,144002,5758,108,35937,131,121,250,128,122,249,129",52,610.0,1492,657.1,431734.9,4.1,"64,60,52,263,52,193,52,103,489,52,52,1492,1492,52,1492,1492,52,777,52,52,483,52,1492,1492,52,1492,1492,52,1492,1492,52,1492","10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,1,0,0,0,1,1,1,0,1,1,0,1,1,0,1","4.314822197,5.233453751,4.923395157,5.828969955,5.023147106,6.406717777,4.808010101,5.437491417,7.501916409,5.023147106,4.970168114,7.863673210,7.870786667,4.923395157,7.876905441,7.877601147,4.961856842,7.763181210,4.923395157,4.762846470,7.385672092,5.061608791,7.861380100,7.878694057,4.839769363,7.892414093,7.876000881,4.916692734,7.865588188,7.858906269,4.930902004,7.889223099",TLS,91,1,Safe,Web,6,DPI,"15" -1,ip4,192.168.1.178,146.48.58.18,tcp,55269,443,finished,14,18,1620898025217638,1620898025521891,1620898025521857,0,0,434,1440,1125,16096,0,3,19628.1,147007,34082.4,1161612032.0,3.3,"33594,33644,1195,33573,9,32379,46938,8284,78165,6257,993,261,30448,865,3,877,105414,6486,147007,2135,111,37341,124,122,246,129,624,757,125,122,244",52,590.8,1492,660.8,436665.8,4.1,"64,60,52,263,52,193,52,103,481,52,52,1492,1492,52,1492,167,52,52,486,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52","10,1,0,0,0,0,1,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0","0,1,0,0,1,1,0,0,0,1,1,1,1,0,1,1,0,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0","4.428027153,5.266787052,5.014835835,5.842227459,5.023147106,6.438008308,4.937912464,5.659790039,7.505598068,5.008629799,5.138532162,7.874384403,7.853630066,5.053297043,7.871713161,6.760118008,4.937911987,4.854287148,7.518191338,5.025067806,7.867798328,7.843288898,5.053297043,7.860529423,7.873259544,5.014835358,7.870237827,7.866991520,4.976373672,7.854802608,7.868881702,5.053297043",TLS,91,1,Safe,Web,6,DPI,"15" -1,ip4,192.168.1.178,146.48.58.18,tcp,55268,443,finished,15,17,1620898025217296,1620898025552151,1620898025552116,0,0,437,1440,1558,13367,0,2,21602.4,146010,34561.6,1194505728.0,3.5,"30429,30474,1424,31291,132,29986,50740,8293,78244,9210,246,28671,116212,146010,494,137,30426,114,380,498,130,113,14,250,2,896,5501,36248,1496,132,31482",52,519.0,1492,616.9,380607.3,4.0,"64,60,52,263,52,193,52,103,480,52,52,1399,52,483,52,1492,1492,52,1492,1492,52,1492,1492,411,52,52,52,489,52,1492,1492,52","10,1,0,0,0,0,1,0,0,0,0,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","6,0,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,8,0,0","0,1,0,0,1,1,0,0,0,1,1,1,0,0,1,1,1,0,1,1,0,1,1,1,0,0,0,0,1,1,1,0","4.365527153,5.212701797,4.906957626,5.866992474,4.948143959,6.471822739,4.777055740,5.588072777,7.508736134,5.010550499,4.972089291,7.876531601,4.976373672,7.413162708,4.945419312,7.858516216,7.873053551,4.770353794,7.876352787,7.853984356,4.861793518,7.863806248,7.873053074,7.450196266,4.900255680,4.900255203,4.774691582,7.458786488,5.100070000,7.869789600,7.864884853,5.053297043",TLS,91,1,Safe,Web,6,DPI,"15" diff --git a/test/results/flow-analyse/softether.pcap.out b/test/results/flow-analyse/softether.pcap.out deleted file mode 100644 index a8278803d..000000000 --- a/test/results/flow-analyse/softether.pcap.out +++ /dev/null @@ -1,2 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,192.168.2.100,130.158.6.113,udp,51381,5004,finished,17,15,1657762868392000,1657907318692000,1657907318946000,1,0,480,328,975,1020,0,257000,36711136.0,1566080232,451865472.0,204182401654456320.0,2.7,"257000,27676000,27674000,26195000,26194000,26159000,26161000,10299000,10301000,14858000,14853000,27814000,27815000,25788000,1540291232,1566080232,18689000,18689000,5427000,5426000,27856000,27856000,26072000,26072000,26524000,26524000,24993000,24993000,25093000,862645000,887738000",29,90.3,508,132.5,17556.2,4.1,"29,56,29,56,29,56,29,56,508,356,29,56,29,56,29,29,56,508,356,29,56,29,56,29,56,29,56,29,56,29,29,56","15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1","4.513154984,5.059597492,4.582120895,5.059597492,4.582120895,4.988168716,4.582120895,5.059597492,5.016859055,4.526149750,4.582120895,5.059597492,4.513154984,5.010403156,4.582120895,4.582120895,5.001649380,5.023393631,4.521674156,4.582120895,5.001649380,4.582120895,5.059597492,4.513154984,5.059597492,4.582120895,5.059597492,4.582120895,5.059597492,4.582120895,4.582120895,4.988168716",Softether,290,1,Acceptable,VPN,6,DPI,"" diff --git a/test/results/flow-analyse/wireguard.pcap.out b/test/results/flow-analyse/wireguard.pcap.out deleted file mode 100644 index fc658c048..000000000 --- a/test/results/flow-analyse/wireguard.pcap.out +++ /dev/null @@ -1,2 +0,0 @@ -flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks -1,ip4,139.162.192.157,192.168.0.14,udp,51820,36116,finished,19,13,1563973554628757,1563973564026392,1563973564026499,96,0,800,272,4816,2160,0,23,606302.4,5525882,1489465.9,2218508681216.0,2.5,"23,158,13304,82421,23440,98,92806,699,114421,124480,180,238536,14265,86010,36434,91,108248,778,113616,3087006,3060616,97488,183654,5525873,24,5525882,16499,87990,44371,59,115907",124,246.0,828,181.0,32764.0,4.7,"828,172,124,300,124,316,172,124,284,124,652,172,124,300,124,348,172,124,284,124,172,140,172,140,684,172,124,300,124,556,172,124","0,0,0,6,7,0,0,0,0,1,1,0,0,0,0,0,1,0,0,1,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,7,1,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,1,1,0,0,0,1,1,0,0,0,1,1,0,0,0,1,1,0,1,0,0,1,0,0,1,1,0,0,0,1","7.721926689,6.520606995,6.064967632,7.277743816,6.125530243,7.157748699,6.507213116,6.119441986,7.162059307,6.042750835,7.643404961,6.557894707,6.103312969,7.165712357,6.014130592,7.252914429,6.580285549,6.200272083,7.152356148,6.059064388,6.527978897,6.293422222,6.622408867,6.284528732,7.697811604,6.593225002,6.135756016,7.191918850,6.052976608,7.621836662,6.581598282,6.206175327",WireGuard,206,1,Acceptable,VPN,6,DPI,"" |