diff options
Diffstat (limited to 'test/results/flow-info/default/wa_voice.pcap.out')
-rw-r--r-- | test/results/flow-info/default/wa_voice.pcap.out | 30 |
1 files changed, 15 insertions, 15 deletions
diff --git a/test/results/flow-info/default/wa_voice.pcap.out b/test/results/flow-info/default/wa_voice.pcap.out index 05d0b1b12..d014bfd75 100644 --- a/test/results/flow-info/default/wa_voice.pcap.out +++ b/test/results/flow-info/default/wa_voice.pcap.out @@ -14,9 +14,9 @@ new: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] detected: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] analyse: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.304| 0.044| 0.076| 5836.115| 3.200] - [PKTLEN......: 52.000| 1440.000| 295.400| 467.500| 218553.500| 3.800] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.304| 0.044| 0.076| 5836.115| 3.200] + [PKTLEN......: 52.000| 1440.000| 295.400| 467.500| 218553.500| 3.800] [BINS(c->s)..: 11,3,1,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 4,3,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,1,1,1,1,1,1,1,1,1,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,1,1] @@ -30,9 +30,9 @@ detected: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][media-mxp1-1.cdn.whatsapp.net] detection-update: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][media-mxp1-1.cdn.whatsapp.net] analyse: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.163| 0.020| 0.047| 2203.182| 2.500] - [PKTLEN......: 52.000| 1440.000| 343.600| 489.700| 239839.300| 3.900] + min| max| avg| stddev| variance| entropy + [IAT.........: 0.000| 0.163| 0.020| 0.047| 2203.182| 2.500] + [PKTLEN......: 52.000| 1440.000| 343.600| 489.700| 239839.300| 3.900] [BINS(c->s)..: 10,3,1,0,0,0,0,0,1,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 5,1,1,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,0,0,0,0,1,0,1,1,0] @@ -70,9 +70,9 @@ detected: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable][pps.whatsapp.net] detection-update: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable][pps.whatsapp.net] analyse: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 0.129| 0.020| 0.031| 949.768| 3.500] - [PKTLEN......: 52.000| 1440.000| 374.400| 526.300| 277041.400| 3.900] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 0.129| 0.020| 0.031| 949.768| 3.500] + [PKTLEN......: 52.000| 1440.000| 374.400| 526.300| 277041.400| 3.900] [BINS(c->s)..: 10,3,1,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 5,1,1,0,0,1,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,6,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,1,1,1,0,0,0,0,0,0,0,1,1,0,0,0,1,1,0,1,0,1,1,0,1,1,1,1] @@ -85,9 +85,9 @@ detected: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 12.196| 1.588| 3.050| 9304956.469| 3.200] - [PKTLEN......: 30.000| 306.000| 110.000| 87.200| 7598.900| 4.600] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 12.196| 1.588| 3.050| 9304956.469| 3.200] + [PKTLEN......: 30.000| 306.000| 110.000| 87.200| 7598.900| 4.600] [BINS(c->s)..: 6,0,0,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 7,6,0,1,0,0,3,1,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,0,1,1,0,1,0,0,1,1,0,1,0,1,0,1,0,1,1,1,1,1,1,1,1,1,1,0,1,0,0,1] @@ -98,9 +98,9 @@ detected: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 1.204| 0.182| 0.229| 52393.320| 4.200] - [PKTLEN......: 54.000| 301.000| 144.900| 51.700| 2672.500| 4.900] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 1.204| 0.182| 0.229| 52393.320| 4.200] + [PKTLEN......: 54.000| 301.000| 144.900| 51.700| 2672.500| 4.900] [BINS(c->s)..: 1,4,0,8,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 0,2,0,4,6,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,0,0,1,1,0,0,1,0,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,1,0,0,0,1,0,0,1] |