summaryrefslogtreecommitdiff
path: root/test/results/flow-info/gnutella.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/gnutella.pcap.out')
-rw-r--r--test/results/flow-info/gnutella.pcap.out72
1 files changed, 40 insertions, 32 deletions
diff --git a/test/results/flow-info/gnutella.pcap.out b/test/results/flow-info/gnutella.pcap.out
index 46a647992..b3f592cc9 100644
--- a/test/results/flow-info/gnutella.pcap.out
+++ b/test/results/flow-info/gnutella.pcap.out
@@ -575,32 +575,35 @@
detected: [...327] [ip4][..udp] [......10.0.2.15][28681] -> [...84.28.53.225][44859] [Gnutella][Download][Potentially Dangerous]
RISK: Unsafe Protocol
analyse: [...239] [ip4][..tcp] [......10.0.2.15][50285] -> [..75.133.101.93][52367] [Gnutella][Download][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 8.796| 0.767| 2.113|4465727.373| 0.000]
- [PKTLEN......: 54.000| 1514.000| 423.200| 491.700|241767.600| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 8.796| 0.767| 2.113| 4465727.373| 2.600]
+ [PKTLEN......: 40.000| 1500.000| 409.200| 491.700| 241767.600| 4.100]
[BINS(c->s)..: 9,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,0,0,0,1,0,0,0,0,0,0,1,1,0,0,0,0,0,4,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,1,1,0,0,1,1,0,0,1,1,1,0,1,1,0,1,1,0,1,1,0,1]
[IATS(ms)....: 111.8,112.0,0.2,0.6,122.2,123.8,1.7,510.2,510.3,125.4,7.0,133.1,508.5,509.1,643.4,701.9,8737.9,8796.5,643.9,0.1,644.7,118.6,3.0,121.6,121.6,0.1,121.5,120.9,0.1,121.0,117.5]
- [PKTLENS.....: 66,58,54,653,54,666,104,54,367,54,196,437,54,82,54,463,54,100,54,1514,1066,54,654,1502,54,1514,642,54,1514,642,54,654]
+ [PKTLENS.....: 52,44,40,639,40,652,90,40,353,40,182,423,40,68,40,449,40,86,40,1500,1052,40,640,1488,40,1500,628,40,1500,628,40,640]
+ [ENTROPIES...: 4.6,4.8,4.7,5.8,4.6,5.7,5.6,4.7,7.1,4.6,6.7,7.4,4.7,5.3,4.6,7.4,4.8,5.6,4.6,7.8,7.8,4.7,7.6,7.9,4.7,7.9,7.6,4.7,7.9,7.6,4.7,7.7]
analyse: [...238] [ip4][..tcp] [......10.0.2.15][50284] -> [.104.156.226.72][53258] [Gnutella][Download][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 8.218| 0.797| 1.971|3884024.594| 0.000]
- [PKTLEN......: 54.000| 1078.000| 296.600| 381.800|145784.600| 4.000]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 8.218| 0.797| 1.971| 3884024.594| 2.900]
+ [PKTLEN......: 40.000| 1064.000| 282.600| 381.800| 145784.600| 3.900]
[BINS(c->s)..: 12,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 8,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,1,0,0,1,1,0,0,1,1,0,1,0,1,0,1,0,1,0,0,1,0,1]
[IATS(ms)....: 128.3,128.7,0.4,0.9,178.6,178.8,0.0,501.2,501.5,98.4,140.7,469.4,511.6,1191.0,1233.5,8175.8,8218.5,772.3,828.1,95.7,89.5,96.9,110.1,405.4,409.6,95.4,89.1,2.8,63.4,0.6,0.6]
- [PKTLENS.....: 66,58,54,654,54,682,104,54,367,54,588,54,82,54,456,54,100,54,1078,54,1078,54,1078,54,1078,54,1078,54,69,54,64,54]
+ [PKTLENS.....: 52,44,40,640,40,668,90,40,353,40,574,40,68,40,442,40,86,40,1064,40,1064,40,1064,40,1064,40,1064,40,55,40,50,40]
+ [ENTROPIES...: 4.7,4.7,4.6,5.8,4.5,5.7,5.6,4.6,7.2,4.6,7.5,4.7,5.4,4.6,7.3,4.7,5.7,4.6,7.8,4.7,7.8,4.7,7.8,4.7,7.8,4.7,7.8,4.7,4.9,4.6,4.9,4.6]
analyse: [...288] [ip4][..tcp] [......10.0.2.15][50312] -> [104.238.172.250][23548] [Gnutella][Download][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 8.692| 0.666| 2.111|4456211.546| 0.000]
- [PKTLEN......: 54.000| 682.000| 135.800| 170.000|28912.700| 4.200]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 8.692| 0.666| 2.111| 4456211.546| 1.900]
+ [PKTLEN......: 40.000| 668.000| 121.800| 170.000| 28912.700| 4.100]
[BINS(c->s)..: 12,2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 12,0,0,0,1,0,0,0,0,0,1,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,1,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0]
[IATS(ms)....: 30.9,31.2,0.4,0.8,29.2,31.6,2.5,501.7,502.0,17.1,17.4,35.1,479.7,480.4,544.2,592.6,8643.7,8692.0,0.6,0.6,0.6,0.6,0.4,0.4,0.5,0.4,0.3,0.4,0.4,0.4,0.4]
- [PKTLENS.....: 66,58,54,655,54,682,104,54,367,54,196,384,54,81,54,441,54,108,54,64,54,64,54,64,54,64,54,64,54,64,54,64]
+ [PKTLENS.....: 52,44,40,641,40,668,90,40,353,40,182,370,40,67,40,427,40,94,40,50,40,50,40,50,40,50,40,50,40,50,40,50]
+ [ENTROPIES...: 4.5,4.7,4.5,5.8,4.5,5.8,5.6,4.6,7.1,4.4,6.7,7.3,4.7,5.3,4.6,7.4,4.6,5.8,4.5,4.7,4.5,4.7,4.5,4.7,4.5,4.7,4.4,4.7,4.5,4.7,4.5,4.6]
new: [...328] [ip4][..udp] [......10.0.2.15][28681] -> [.203.220.105.27][19260]
detected: [...328] [ip4][..udp] [......10.0.2.15][28681] -> [.203.220.105.27][19260] [Gnutella][Download][Potentially Dangerous]
RISK: Unsafe Protocol
@@ -643,23 +646,25 @@
detected: [...336] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][.6888] [Gnutella][Download][Potentially Dangerous]
RISK: Unsafe Protocol
analyse: [...333] [ip4][..tcp] [......10.0.2.15][50327] -> [.69.118.162.229][46906] [HTTP.Gnutella][Media][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 1.139| 0.307| 0.464|214847.930| 0.000]
- [PKTLEN......: 54.000| 1514.000| 862.800| 665.400|442787.600| 4.400]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 1.139| 0.307| 0.464| 214847.930| 3.300]
+ [PKTLEN......: 40.000| 1500.000| 848.800| 665.400| 442787.600| 4.400]
[BINS(c->s)..: 9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 2,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,15,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,0,1,1,1,0,1,1,1,1,0,0,1,1,1,0,1,0,1,1,1,1,0,1,1,1]
[IATS(ms)....: 109.0,109.5,0.8,1.6,1123.2,14.9,1138.7,0.5,4.1,0.0,4.4,993.4,0.2,0.0,0.3,993.8,0.1,988.9,0.2,0.0,989.1,4.8,4.8,1004.1,0.1,0.0,0.1,1004.3,1027.6,5.2,0.1]
- [PKTLENS.....: 66,58,54,587,54,848,1514,54,1514,1514,118,54,1514,1514,1514,912,54,54,1514,1514,1514,54,912,54,1514,1514,1514,912,54,1514,1514,1514]
+ [PKTLENS.....: 52,44,40,573,40,834,1500,40,1500,1500,104,40,1500,1500,1500,898,40,40,1500,1500,1500,40,898,40,1500,1500,1500,898,40,1500,1500,1500]
+ [ENTROPIES...: 4.6,4.6,4.6,5.9,4.5,6.0,0.6,4.8,0.3,0.3,2.4,4.7,0.6,0.5,0.6,5.6,4.7,4.8,7.8,7.8,7.7,4.6,7.7,4.7,7.7,7.8,7.8,7.7,4.8,7.8,7.7,7.8]
analyse: [...276] [ip4][..tcp] [......10.0.2.15][50300] -> [..188.61.52.183][11852] [Gnutella][Download][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 13.802| 1.828| 3.934|15478358.540| 0.000]
- [PKTLEN......: 54.000| 1514.000| 212.900| 294.000|86413.100| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 13.802| 1.828| 3.934| 15478358.540| 2.800]
+ [PKTLEN......: 40.000| 1500.000| 198.900| 294.000| 86413.100| 4.000]
[BINS(c->s)..: 8,1,2,1,1,0,0,0,1,0,0,1,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 8,1,1,0,1,1,0,0,0,0,1,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,1,1,0,0,1,1,0,1,0,0,1,1,0,1,0,0,1,1,0,0,1,0]
[IATS(ms)....: 17.2,17.4,3.5,3.9,14.2,15.0,0.7,2.8,2.9,25.8,0.0,26.1,9.0,9.3,15.9,71.8,495.6,483.5,221.2,265.2,15.6,77.3,487.6,467.7,9469.0,9510.7,13761.0,13801.6,1593.6,1634.0,4141.0]
- [PKTLENS.....: 66,58,54,653,54,713,125,54,318,54,1514,194,54,180,54,105,54,233,54,418,54,401,54,521,54,129,54,125,54,190,54,115]
+ [PKTLENS.....: 52,44,40,639,40,699,111,40,304,40,1500,180,40,166,40,91,40,219,40,404,40,387,40,507,40,115,40,111,40,176,40,101]
+ [ENTROPIES...: 4.6,4.8,4.8,5.8,4.6,5.7,5.6,4.7,5.3,4.7,7.7,6.7,4.7,6.3,4.6,5.2,4.8,6.9,4.8,7.5,4.7,7.4,4.7,7.5,4.8,6.0,4.6,5.8,4.8,6.7,4.6,5.9]
update: [...134] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346]
update: [...128] [ip4][..udp] [......10.0.2.15][28681] -> [..77.141.219.27][37580]
update: [...114] [ip4][..udp] [......10.0.2.15][28681] -> [....86.23.75.69][.6346]
@@ -746,14 +751,15 @@
detected: [...344] [ip4][..udp] [......10.0.2.15][28681] -> [.207.38.163.228][.6778] [Gnutella][Download][Potentially Dangerous]
RISK: Unsafe Protocol
analyse: [...334] [ip4][..tcp] [......10.0.2.15][50328] -> [..189.147.72.83][26108] [HTTP.Gnutella][Media][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 1.215| 0.581| 0.506|255907.955| 0.000]
- [PKTLEN......: 54.000| 1514.000| 789.100| 623.900|389219.000| 4.400]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 1.215| 0.581| 0.506| 255907.955| 4.200]
+ [PKTLEN......: 40.000| 1500.000| 775.100| 623.900| 389219.000| 4.400]
[BINS(c->s)..: 10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 2,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,9,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1,0,1,1]
[IATS(ms)....: 193.6,195.3,1.8,3.7,1208.8,5.6,0.1,1214.8,993.3,0.1,993.5,1040.3,0.1,1040.5,1001.3,0.1,1001.5,998.2,0.1,998.2,1008.3,0.2,1008.5,1046.8,0.1,1046.9,1000.2,0.1,1000.3,1013.4,0.0]
- [PKTLENS.....: 66,58,54,592,54,860,1514,340,54,1514,1146,54,1514,1146,54,1514,1146,54,1514,1146,54,1514,1146,54,1514,1146,54,1514,1146,54,1514,1146]
+ [PKTLENS.....: 52,44,40,578,40,846,1500,326,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132,40,1500,1132]
+ [ENTROPIES...: 4.6,4.8,4.7,5.9,4.6,5.9,7.8,7.3,4.7,7.8,7.8,4.8,7.8,7.8,4.8,7.9,7.8,4.7,7.9,7.8,4.8,7.8,7.8,4.7,7.9,7.8,4.8,7.9,7.8,4.8,7.8,7.8]
new: [...345] [ip4][..tcp] [......10.0.2.15][50330] -> [.69.118.162.229][46906]
detected: [...345] [ip4][..tcp] [......10.0.2.15][50330] -> [.69.118.162.229][46906] [HTTP.Gnutella][Download][Potentially Dangerous]
RISK: Known Proto on Non Std Port, HTTP Numeric IP Address, Unsafe Protocol
@@ -843,14 +849,15 @@
new: [...351] [ip4][..udp] [......10.0.2.15][28681] -> [..187.37.87.189][.6346]
new: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346]
analyse: [....93] [ip4][..tcp] [......10.0.2.15][50248] -> [109.214.154.216][.6346] [Gnutella][Download][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.001| 22.685| 3.465| 6.256|39132462.055| 0.000]
- [PKTLEN......: 54.000| 1078.000| 152.200| 217.400|47264.800| 4.200]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.001| 22.685| 3.465| 6.256| 39132462.055| 3.300]
+ [PKTLEN......: 40.000| 1064.000| 138.200| 217.400| 47264.800| 4.000]
[BINS(c->s)..: 9,0,2,2,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 12,0,2,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,1,1,0,1,1,0,0,1,0,1,1,1,0,1,0,0,1,1,0,0,1,0,1,1]
[IATS(ms)....: 399.9,400.2,2.6,3.1,879.2,880.3,1.1,343.3,15.8,359.6,3.0,2.2,5.1,145.1,145.6,10048.7,10048.7,469.5,2.7,472.7,3557.8,3604.1,6175.3,6222.2,413.8,464.5,22633.8,22684.6,605.3,605.0,15818.9]
- [PKTLENS.....: 66,58,54,358,54,337,157,54,132,776,54,67,72,54,163,54,118,54,1078,59,54,136,54,84,54,227,54,66,54,137,54,76]
+ [PKTLENS.....: 52,44,40,344,40,323,143,40,118,762,40,53,58,40,149,40,104,40,1064,45,40,122,40,70,40,213,40,52,40,123,40,62]
+ [ENTROPIES...: 4.6,4.8,4.6,5.8,4.5,5.6,5.6,4.6,5.6,7.7,4.7,4.7,4.9,4.6,6.3,4.5,5.9,4.5,7.8,4.3,4.8,6.2,4.8,5.5,4.6,6.6,4.7,4.8,4.6,6.2,4.6,4.9]
new: [...353] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][25282]
new: [...354] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][.1032]
new: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998]
@@ -1171,14 +1178,15 @@
update: [...204] [ip4][..udp] [......10.0.2.15][28681] -> [..84.126.240.32][45313]
update: [...202] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346]
analyse: [....94] [ip4][..tcp] [......10.0.2.15][50249] -> [.86.208.180.181][45883] [Gnutella][Download][Potentially Dangerous]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 55.455| 7.491| 14.262|203411798.622| 0.000]
- [PKTLEN......: 54.000| 1119.000| 170.900| 244.600|59812.500| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 55.455| 7.491| 14.262| 203411798.622| 3.200]
+ [PKTLEN......: 40.000| 1105.000| 156.900| 244.600| 59812.500| 4.000]
[BINS(c->s)..: 11,0,2,2,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 10,0,0,0,1,1,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,1,0,0,1,0,1,1,0,1,0,0,1,1,0,0,1,0,1,1,1,0,1,0,0]
[IATS(ms)....: 107.0,107.3,0.3,0.8,178.4,179.8,1.4,41.0,98.0,375.7,432.9,10046.8,10046.8,42.3,94.5,6595.0,6594.8,3591.9,3643.9,39.2,93.5,24009.1,24063.3,605.1,604.8,14641.1,23.8,14665.3,55396.9,55455.4,453.2]
- [PKTLENS.....: 66,58,54,357,54,337,157,54,926,54,163,54,118,54,1119,54,214,54,84,54,203,54,66,54,137,54,78,503,54,64,54,63]
+ [PKTLENS.....: 52,44,40,343,40,323,143,40,912,40,149,40,104,40,1105,40,200,40,70,40,189,40,52,40,123,40,64,489,40,50,40,49]
+ [ENTROPIES...: 4.6,4.6,4.7,5.8,4.6,5.6,5.7,4.6,7.7,4.8,6.3,4.5,6.0,4.6,7.8,4.8,6.7,4.7,5.5,4.6,6.6,4.8,4.9,4.7,6.3,4.7,5.1,7.5,4.8,4.6,4.8,4.6]
end: [....35] [ip4][..tcp] [......10.0.2.15][50196] -> [...218.250.6.59][12556] [Gnutella][Download][Potentially Dangerous]
RISK: Unsafe Protocol
end: [....46] [ip4][..tcp] [......10.0.2.15][50206] -> [175.181.156.244][.8255] [Gnutella][Download][Potentially Dangerous]