aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/ocs.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/default/ocs.pcap.out')
-rw-r--r--test/results/flow-info/default/ocs.pcap.out35
1 files changed, 18 insertions, 17 deletions
diff --git a/test/results/flow-info/default/ocs.pcap.out b/test/results/flow-info/default/ocs.pcap.out
index 04ccfba59..2e525df7b 100644
--- a/test/results/flow-info/default/ocs.pcap.out
+++ b/test/results/flow-info/default/ocs.pcap.out
@@ -12,19 +12,18 @@
new: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443]
new: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80]
detected: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws]
- RISK: Unidirectional Traffic
detected: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable][api.eu01.capptain.com]
- RISK: HTTP Susp User-Agent, Unidirectional Traffic
+ RISK: HTTP Susp User-Agent
new: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80]
detected: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable][api.eu01.capptain.com]
- RISK: HTTP Susp User-Agent, Unidirectional Traffic
+ RISK: HTTP Susp User-Agent
new: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53]
detected: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][android.clients.google.com]
new: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443]
detected: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS][Google][Web][Safe][]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
detected: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][AmazonAWS][DataTransfer][Acceptable][settings.crashlytics.com]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
new: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53]
detected: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][xmpp.device06.eu01.capptain.com]
new: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122]
@@ -32,10 +31,11 @@
new: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53]
detected: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][ocs.labgency.ws]
detected: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws]
- RISK: Unidirectional Traffic
new: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443]
detected: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][OCS][Media][Fun][ocs.labgency.ws]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
+ detection-update: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws]
+ RISK: Unidirectional Traffic
analyse: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.929| 0.088| 0.173| 29794.175| 3.500]
@@ -48,12 +48,12 @@
[ENTROPIES...: 4.5,5.1,6.0,5.1,5.2,5.2,5.2,5.2,5.3,5.2,5.2,5.2,5.2,5.1,5.2,5.2,5.1,5.2,5.1,5.1,5.0,5.1,5.2,5.1,5.2,5.1,5.2,5.2,5.2,5.0,5.1,5.1]
new: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443]
detected: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com]
- RISK: TLS (probably) Not Carrying HTTPS, Unidirectional Traffic
+ RISK: TLS (probably) Not Carrying HTTPS
new: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53]
detected: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][play.googleapis.com]
new: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443]
detected: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS][Google][Web][Safe][]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
update: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
update: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
update: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
@@ -64,6 +64,8 @@
detected: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][www.ocs.fr]
new: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80]
detected: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun][www.ocs.fr]
+ RISK: HTTP Susp User-Agent
+ detection-update: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun][www.ocs.fr]
RISK: HTTP Susp User-Agent, Unidirectional Traffic
analyse: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun][www.ocs.fr]
min| max| avg| stddev| variance| entropy
@@ -77,14 +79,14 @@
[ENTROPIES...: 4.6,5.0,5.9,5.2,5.1,5.2,5.2,5.2,5.2,5.2,5.2,5.2,5.3,5.2,5.3,5.3,5.4,5.3,5.3,5.3,5.3,5.2,5.2,5.2,5.1,5.2,5.2,5.1,5.2,5.2,5.3,5.3]
update: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
end: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable]
- RISK: HTTP Susp User-Agent, Unidirectional Traffic
+ RISK: HTTP Susp User-Agent
end: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS][Google][Web][Safe]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
idle: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
idle: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Google][Web][Acceptable]
- RISK: TLS (probably) Not Carrying HTTPS, Unidirectional Traffic
+ RISK: TLS (probably) Not Carrying HTTPS
idle: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][OCS][Media][Fun]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
idle: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
idle: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
idle: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
@@ -93,14 +95,13 @@
RISK: HTTP Susp User-Agent, Unidirectional Traffic
idle: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
idle: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS][Google][Web][Safe]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
end: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][AmazonAWS][DataTransfer][Acceptable]
- RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic
+ RISK: Obsolete TLS (v1.1 or older)
idle: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun]
- RISK: Unidirectional Traffic
idle: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable]
end: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable]
- RISK: HTTP Susp User-Agent, Unidirectional Traffic
+ RISK: HTTP Susp User-Agent
guessed: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] [Google][Google][Web][Acceptable]
RISK: Unidirectional Traffic
idle: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228]