summaryrefslogtreecommitdiff
path: root/test/results/flow-info/bad-dns-traffic.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/bad-dns-traffic.pcap.out')
-rw-r--r--test/results/flow-info/bad-dns-traffic.pcap.out9
1 files changed, 5 insertions, 4 deletions
diff --git a/test/results/flow-info/bad-dns-traffic.pcap.out b/test/results/flow-info/bad-dns-traffic.pcap.out
index 22c646290..f17ace4dc 100644
--- a/test/results/flow-info/bad-dns-traffic.pcap.out
+++ b/test/results/flow-info/bad-dns-traffic.pcap.out
@@ -22,14 +22,15 @@
detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Network][Acceptable]
RISK: Suspicious DGA Domain name, Risky Domain Name
analyse: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Network][Acceptable]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.063| 4.102| 1.074| 0.689|474850.951| 0.000]
- [PKTLEN......: 95.000| 323.000| 129.200| 50.600| 2560.600| 4.900]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.063| 4.102| 1.074| 0.689| 474850.951| 4.700]
+ [PKTLEN......: 81.000| 309.000| 115.200| 50.600| 2560.600| 4.900]
[BINS(c->s)..: 0,13,5,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,0,10,1,1,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,0,0,0,1,0,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,0,1,0,1]
[IATS(ms)....: 1006.5,1005.8,1008.1,1008.5,4101.9,73.2,63.1,1023.9,1006.7,2080.9,1018.8,962.5,1014.1,1012.6,1013.6,1040.3,1038.2,1060.2,1011.7,991.1,1041.5,1066.6,1017.8,982.3,1029.5,1026.2,1027.8,1007.4,2080.4,166.4,305.9]
- [PKTLENS.....: 133,133,133,133,133,164,95,130,95,95,126,95,128,95,130,95,128,95,128,95,126,95,128,95,130,95,128,95,95,174,290,323]
+ [PKTLENS.....: 119,119,119,119,119,150,81,116,81,81,112,81,114,81,116,81,114,81,114,81,112,81,114,81,116,81,114,81,81,160,276,309]
+ [ENTROPIES...: 4.9,5.0,5.0,5.0,5.0,4.9,5.0,5.0,5.0,5.1,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,4.9,5.0,4.9,5.0,5.0,5.0,5.0,5.0,4.9,4.2,4.3]
update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Network][Acceptable]
RISK: Suspicious DGA Domain name, Risky Domain Name
update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Network][Acceptable]