diff options
Diffstat (limited to 'test/results/flow-info/rtsp.pcap.out')
-rw-r--r-- | test/results/flow-info/rtsp.pcap.out | 81 |
1 files changed, 81 insertions, 0 deletions
diff --git a/test/results/flow-info/rtsp.pcap.out b/test/results/flow-info/rtsp.pcap.out new file mode 100644 index 000000000..45e4fb47f --- /dev/null +++ b/test/results/flow-info/rtsp.pcap.out @@ -0,0 +1,81 @@ + DAEMON-EVENT: init + DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] + new: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [MIDSTREAM] + detected: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + new: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] + detected: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + analyse: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + [min|max|avg|stddev] + [IAT(flow)...: 0.000| 0.021| 0.002| 0.006] + [IAT(c->s)...: 0.000| 0.021| 0.002| 0.006][IAT(s->c)...: 0.000| 0.021| 0.002| 0.006] + [PKTLEN(c->s): 56.000| 198.000| 124.600| 61.100][PKTLEN(s->c): 56.000| 181.000| 92.500| 51.200] + [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + new: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] + detected: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + analyse: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + [min|max|avg|stddev] + [IAT(flow)...: 0.000| 0.021| 0.002| 0.005] + [IAT(c->s)...: 0.000| 0.021| 0.002| 0.006][IAT(s->c)...: 0.000| 0.020| 0.002| 0.005] + [PKTLEN(c->s): 56.000| 198.000| 124.600| 61.100][PKTLEN(s->c): 56.000| 181.000| 92.500| 51.200] + [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + new: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] + detected: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + analyse: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + [min|max|avg|stddev] + [IAT(flow)...: 0.000| 0.021| 0.002| 0.005] + [IAT(c->s)...: 0.000| 0.021| 0.002| 0.005][IAT(s->c)...: 0.000| 0.020| 0.002| 0.005] + [PKTLEN(c->s): 56.000| 198.000| 124.600| 61.100][PKTLEN(s->c): 56.000| 181.000| 92.500| 51.200] + [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + new: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] + detected: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + analyse: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + [min|max|avg|stddev] + [IAT(flow)...: 0.000| 0.505| 0.033| 0.124] + [IAT(c->s)...: 0.000| 0.505| 0.034| 0.126][IAT(s->c)...: 0.000| 0.505| 0.033| 0.122] + [PKTLEN(c->s): 56.000| 172.000| 92.100| 46.200][PKTLEN(s->c): 56.000| 181.000| 92.500| 51.200] + [BINS(c->s)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + end: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + new: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] + detected: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + analyse: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + [min|max|avg|stddev] + [IAT(flow)...: 0.000| 0.024| 0.002| 0.006] + [IAT(c->s)...: 0.000| 0.024| 0.002| 0.006][IAT(s->c)...: 0.000| 0.020| 0.002| 0.005] + [PKTLEN(c->s): 56.000| 198.000| 124.600| 61.100][PKTLEN(s->c): 56.000| 181.000| 92.500| 51.200] + [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + end: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + new: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] + detected: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + analyse: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + [min|max|avg|stddev] + [IAT(flow)...: 0.000| 0.021| 0.002| 0.005] + [IAT(c->s)...: 0.000| 0.021| 0.002| 0.005][IAT(s->c)...: 0.000| 0.020| 0.002| 0.005] + [PKTLEN(c->s): 56.000| 198.000| 124.600| 61.100][PKTLEN(s->c): 56.000| 181.000| 92.500| 51.200] + [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] + end: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + end: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + end: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + end: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + idle: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Media][Fun] + RISK: Known Proto on Non Std Port + DAEMON-EVENT: shutdown |