diff options
Diffstat (limited to 'test/results/flow-info/default/ipsec_isakmp_esp.pcap.out')
-rw-r--r-- | test/results/flow-info/default/ipsec_isakmp_esp.pcap.out | 59 |
1 files changed, 3 insertions, 56 deletions
diff --git a/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out b/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out index a6f1e1985..5ab34ac01 100644 --- a/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out +++ b/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out @@ -8,15 +8,11 @@ detected: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 23 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic analyse: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 662.067| 70.207| 185.660|34469670203.425| 2.000] @@ -28,33 +24,24 @@ [PKTLENS.....: 844,236,140,108,124,444,1360,1360,928,1360,160,160,160,928,160,844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236] [ENTROPIES...: 7.7,7.0,6.1,5.8,6.1,7.4,7.9,7.9,7.8,7.9,6.6,6.7,6.6,7.8,6.6,7.8,6.9,6.2,5.8,6.0,7.4,7.9,7.9,7.8,6.6,6.5,6.8,7.8,6.7,5.7,7.8,6.8] update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 61 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] idle: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic new: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] detected: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 84 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] idle: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic new: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] detected: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic update: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic new: [.....5] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] detected: [.....5] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic @@ -62,17 +49,12 @@ detected: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic idle: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 126 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 12] idle: [.....5] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 145 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] new: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] @@ -82,19 +64,13 @@ detected: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic idle: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 164 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] update: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 187 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 18] new: [.....9] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] @@ -104,9 +80,7 @@ detected: [....10] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] [IPSec][Unknown][VPN][Safe] RISK: Malformed Packet, Unidirectional Traffic idle: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic new: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] detected: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] RISK: Malformed Packet, Unidirectional Traffic @@ -114,15 +88,13 @@ detected: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic idle: [....10] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Malformed Packet, Unidirectional Traffic + RISK: Malformed Packet idle: [.....9] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 225 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 18] update: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic update: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] - RISK: Malformed Packet, Unidirectional Traffic + RISK: Malformed Packet DAEMON-EVENT: [Processed: 244 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] new: [....13] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][.4500] @@ -132,9 +104,8 @@ detected: [....14] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic idle: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] - RISK: Malformed Packet, Unidirectional Traffic + RISK: Malformed Packet DAEMON-EVENT: [Processed: 267 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 14|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] new: [....15] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.129][..500] @@ -144,9 +115,7 @@ detected: [....16] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.129][.4500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic idle: [....13] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....14] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic new: [....17] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] detected: [....17] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic @@ -258,47 +227,25 @@ [PKTLENS.....: 844,236,140,108,124,444,1360,1360,928,160,160,160,1056,160,108,844,236,140,108,124,444,1360,1360,912,160,160,160,1056,160,1360,844,236] [ENTROPIES...: 7.7,6.9,6.3,5.8,6.2,7.5,7.8,7.8,7.8,6.7,6.6,6.6,7.8,6.6,5.7,7.8,7.0,6.2,5.9,6.2,7.5,7.9,7.9,7.8,6.7,6.6,6.6,7.8,6.6,7.8,7.7,6.9] idle: [....28] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.130][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....20] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....26] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.226][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....24] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.227][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....34] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....32] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....22] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....18] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....16] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.129][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....27] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.130][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....19] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....25] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.226][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....23] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.227][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....36] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....31] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....21] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....17] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....15] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.129][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....33] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....35] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....29] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic idle: [....30] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - RISK: Unidirectional Traffic DAEMON-EVENT: shutdown |