diff options
Diffstat (limited to 'test/results/flow-info/ocs.pcap.out')
-rw-r--r-- | test/results/flow-info/ocs.pcap.out | 58 |
1 files changed, 29 insertions, 29 deletions
diff --git a/test/results/flow-info/ocs.pcap.out b/test/results/flow-info/ocs.pcap.out index 23cc2b7ba..7904ec310 100644 --- a/test/results/flow-info/ocs.pcap.out +++ b/test/results/flow-info/ocs.pcap.out @@ -3,36 +3,36 @@ DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] new: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] new: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] - detected: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] [DNS.OCS][Media][Fun][ocu03.labgency.ws] + detected: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun][ocu03.labgency.ws] new: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] - detected: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] [DNS.Crashlytics][DataTransfer][Acceptable][settings.crashlytics.com] + detected: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] [DNS.Crashlytics][Google][Network][Acceptable][settings.crashlytics.com] new: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] - detected: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] [DNS.Google][Web][Acceptable][api.eu01.capptain.com] + detected: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][api.eu01.capptain.com] new: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] new: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] new: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] - detected: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] [HTTP.OCS][Media][Fun][ocu03.labgency.ws] - detected: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] [HTTP.Azure][Cloud][Acceptable][api.eu01.capptain.com] + detected: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws] + detected: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable][api.eu01.capptain.com] new: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] - detected: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] [HTTP.Azure][Cloud][Acceptable][api.eu01.capptain.com] + detected: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable][api.eu01.capptain.com] new: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] - detected: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] [DNS.PlayStore][SoftwareUpdate][Safe][android.clients.google.com] + detected: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] [DNS.PlayStore][Google][Network][Safe][android.clients.google.com] new: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] - detected: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS.Google][Web][Acceptable][] + detected: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - detected: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][DataTransfer][Acceptable][settings.crashlytics.com] + detected: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][AmazonAWS][DataTransfer][Acceptable][settings.crashlytics.com] RISK: Obsolete TLS (v1.1 or older) new: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] - detected: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS.Google][Web][Acceptable][xmpp.device06.eu01.capptain.com] + detected: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][xmpp.device06.eu01.capptain.com] new: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] new: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] new: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] - detected: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS.OCS][Media][Fun][ocs.labgency.ws] - detected: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][Media][Fun][ocu03.labgency.ws] + detected: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun][ocs.labgency.ws] + detected: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws] new: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] - detected: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][Media][Fun][ocs.labgency.ws] + detected: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][OCS][Media][Fun][ocs.labgency.ws] RISK: Obsolete TLS (v1.1 or older) - analyse: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][Media][Fun] + analyse: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.929| 0.088| 0.173| 29794.175| 3.500] [PKTLEN......: 52.000| 715.000| 83.100| 113.800| 12942.200| 4.500] @@ -43,12 +43,12 @@ [PKTLENS.....: 60,52,715,64,72,72,80,72,72,72,72,72,64,52,64,64,64,52,52,52,52,64,64,64,64,52,52,64,64,52,64,64] [ENTROPIES...: 4.5,5.1,6.0,5.1,5.2,5.2,5.2,5.2,5.3,5.2,5.2,5.2,5.2,5.1,5.2,5.2,5.1,5.2,5.1,5.1,5.0,5.1,5.2,5.1,5.2,5.1,5.2,5.2,5.2,5.0,5.1,5.1] new: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] - detected: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Web][Acceptable][mtalk.google.com] + detected: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com] RISK: TLS (probably) Not Carrying HTTPS new: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] - detected: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] [DNS.GoogleServices][Web][Acceptable][play.googleapis.com] + detected: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] [DNS.GoogleServices][Google][Network][Acceptable][play.googleapis.com] new: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] - detected: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS.Google][Web][Acceptable][] + detected: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) update: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] update: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] @@ -57,10 +57,10 @@ update: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] update: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] new: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] - detected: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] [DNS.OCS][Media][Fun][www.ocs.fr] + detected: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun][www.ocs.fr] new: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] - detected: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][Media][Fun][www.ocs.fr] - analyse: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][Media][Fun] + detected: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun][www.ocs.fr] + analyse: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.079| 0.027| 0.030| 875.550| 4.000] [PKTLEN......: 52.000| 204.000| 63.900| 26.300| 690.500| 4.900] @@ -71,27 +71,27 @@ [PKTLENS.....: 60,52,204,52,52,52,52,52,64,64,64,64,72,64,64,72,72,72,64,64,64,52,52,52,52,52,52,52,52,52,64,72] [ENTROPIES...: 4.6,5.0,5.9,5.2,5.1,5.2,5.2,5.2,5.2,5.2,5.2,5.2,5.3,5.2,5.3,5.3,5.4,5.3,5.3,5.3,5.3,5.2,5.2,5.2,5.1,5.2,5.2,5.1,5.2,5.2,5.3,5.3] update: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] - idle: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][Media][Fun] + idle: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun] end: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] - guessed: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] [Azure][Cloud][Acceptable] + not-detected: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] [Unknown][Azure][Unrated] idle: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] - guessed: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] [Google][Web][Acceptable] + not-detected: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] [Unknown][Google][Unrated] idle: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] - end: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][DataTransfer][Acceptable] + end: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][AmazonAWS][DataTransfer][Acceptable] RISK: Obsolete TLS (v1.1 or older) end: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] - idle: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][Media][Fun] + idle: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][OCS][Media][Fun] RISK: Obsolete TLS (v1.1 or older) idle: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] - idle: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Web][Acceptable] + idle: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Google][Web][Acceptable] RISK: TLS (probably) Not Carrying HTTPS - end: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][Media][Fun] + end: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun] idle: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] idle: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] idle: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] - end: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS.Google][Web][Acceptable] + end: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS][Google][Web][Safe] RISK: Obsolete TLS (v1.1 or older) - idle: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS.Google][Web][Acceptable] + idle: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS][Google][Web][Safe] RISK: Obsolete TLS (v1.1 or older) idle: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] idle: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] |