aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/no_sni.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/default/no_sni.pcap.out')
-rw-r--r--test/results/flow-info/default/no_sni.pcap.out27
1 files changed, 12 insertions, 15 deletions
diff --git a/test/results/flow-info/default/no_sni.pcap.out b/test/results/flow-info/default/no_sni.pcap.out
index 27b10647a..dfdcea5d7 100644
--- a/test/results/flow-info/default/no_sni.pcap.out
+++ b/test/results/flow-info/default/no_sni.pcap.out
@@ -3,10 +3,7 @@
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [MIDSTREAM]
detected: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe]
- detection-update: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe]
- RISK: Unidirectional Traffic
new: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443]
- detection-update: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe]
detected: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com]
detection-update: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com]
new: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443]
@@ -21,9 +18,9 @@
[PKTLENS.....: 64,52,40,656,46,210,46,722,40,102,46,40,124,46,71,40,191,126,100,132,71,46,46,46,366,71,40,40,46,293,71,40]
[ENTROPIES...: 4.4,4.9,4.5,7.1,4.6,7.0,4.4,7.7,4.6,6.1,4.5,4.6,6.3,4.4,5.6,4.5,6.8,6.4,6.2,6.4,5.5,4.4,4.4,4.4,7.3,5.7,4.6,4.6,4.5,7.3,5.6,4.6]
detected: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
detection-update: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
analyse: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS][Cloudflare][Web][Safe]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.473| 0.050| 0.107| 11455.737| 3.000]
@@ -42,19 +39,19 @@
detected: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe][951c558a-5e07-47ca-a0c0-225da1b33163.is-cf.help.every1dns.net]
detected: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe][951c558a-5e07-47ca-a0c0-225da1b33163.is-doh.help.every1dns.net]
detected: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
detected: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
detected: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
detection-update: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe][951c558a-5e07-47ca-a0c0-225da1b33163.is-cf.help.every1dns.net]
detection-update: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe][951c558a-5e07-47ca-a0c0-225da1b33163.is-doh.help.every1dns.net]
detection-update: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
detection-update: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
detection-update: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
analyse: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.144| 0.032| 0.043| 1852.691| 3.800]
@@ -68,13 +65,13 @@
end: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe]
idle: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com]
idle: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] [TLS][Cloudflare][Web][Safe]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
idle: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe]
idle: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe]
idle: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
end: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
end: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe]
- RISK: TLS Susp ESNI Usage, Missing SNI TLS Extn, ALPN/SNI Mismatch
+ RISK: Missing SNI TLS Extn, TLS Susp Extn, ALPN/SNI Mismatch
DAEMON-EVENT: shutdown