aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/smtp-starttls.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/smtp-starttls.pcap.out')
-rw-r--r--test/results/flow-info/smtp-starttls.pcap.out18
1 files changed, 10 insertions, 8 deletions
diff --git a/test/results/flow-info/smtp-starttls.pcap.out b/test/results/flow-info/smtp-starttls.pcap.out
index 545966bd0..2c1fefa27 100644
--- a/test/results/flow-info/smtp-starttls.pcap.out
+++ b/test/results/flow-info/smtp-starttls.pcap.out
@@ -11,14 +11,15 @@
detection-update: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] [SMTPS.Google][Email][Acceptable]
RISK: Obsolete TLS (v1.1 or older)
analyse: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] [SMTPS.Google][Email][Acceptable]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.157| 0.030| 0.035| 1204.841| 0.000]
- [PKTLEN......: 66.000| 1484.000| 254.300| 368.100|135468.500| 4.100]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.157| 0.030| 0.035| 1204.841| 4.200]
+ [PKTLEN......: 52.000| 1470.000| 240.300| 368.100| 135468.500| 4.000]
[BINS(c->s)..: 9,3,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,1,3,1,1,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0]
[DIRECTIONS..: 0,1,0,1,0,0,1,1,0,1,0,1,1,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,1,0,0,1]
[IATS(ms)....: 11.2,11.2,11.9,11.8,0.1,11.2,39.2,67.1,28.2,11.5,12.2,0.3,12.3,0.0,24.8,37.9,13.5,11.9,11.6,11.6,11.8,51.4,103.7,157.0,13.6,11.5,11.1,16.4,67.3,42.9,94.1]
- [PKTLENS.....: 74,74,66,117,66,94,66,220,76,96,178,1484,1484,66,919,380,276,119,231,127,131,127,66,172,752,66,94,66,142,66,97,147]
+ [PKTLENS.....: 60,60,52,103,52,80,52,206,62,82,164,1470,1470,52,905,366,262,105,217,113,117,113,52,158,738,52,80,52,128,52,83,133]
+ [ENTROPIES...: 4.5,5.2,4.9,5.7,4.9,4.9,5.0,5.8,5.1,5.4,5.2,6.6,7.4,4.9,7.2,7.3,6.9,6.0,6.9,6.1,6.2,6.2,4.9,6.5,7.7,4.9,5.6,4.9,6.3,4.8,5.6,6.3]
DAEMON-EVENT: [Processed: 36 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 0]
new: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25]
@@ -28,14 +29,15 @@
detection-update: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] [SMTPS][Email][Safe]
RISK: Self-signed Cert, TLS (probably) Not Carrying HTTPS
analyse: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] [SMTPS][Email][Safe]
- min| max| avg| stddev| variance| entropy
- [IAT.........: 0.000| 0.203| 0.019| 0.049| 2372.381| 0.000]
- [PKTLEN......: 78.000| 1218.000| 198.500| 257.100|66086.800| 4.300]
+ min| max| avg| stddev| variance| entropy
+ [IAT.........: 0.000| 0.203| 0.019| 0.049| 2372.381| 2.800]
+ [PKTLEN......: 60.000| 1200.000| 180.500| 257.100| 66086.800| 4.200]
[BINS(c->s)..: 7,4,2,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 6,4,2,0,1,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,1,0,1,1,0,1,0,1,0,0,1,1,0,0,1,0,1,0,1,1,0,1,1,0,1,0,0,1,0]
[IATS(ms)....: 0.7,1.0,19.0,29.5,11.1,0.1,1.2,1.0,1.0,6.1,12.8,0.6,8.6,202.0,202.9,1.0,7.3,6.8,7.3,7.3,1.2,2.1,3.0,0.4,21.0,21.8,1.0,6.8,0.0,6.8,0.7]
- [PKTLENS.....: 90,90,78,136,128,78,230,88,108,260,1218,204,157,336,245,78,167,121,141,121,113,144,78,1112,78,143,113,122,109,78,109,78]
+ [PKTLENS.....: 72,72,60,118,110,60,212,70,90,242,1200,186,139,318,227,60,149,103,123,103,95,126,60,1094,60,125,95,104,91,60,91,60]
+ [ENTROPIES...: 4.3,5.0,4.6,5.6,5.4,4.8,5.6,4.9,5.2,5.4,7.6,6.2,5.9,7.2,6.9,4.7,6.1,5.7,5.6,5.7,5.2,6.1,4.8,7.8,4.8,6.1,5.1,5.8,5.0,4.6,5.5,4.4]
end: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] [SMTPS][Email][Safe]
RISK: Self-signed Cert, TLS (probably) Not Carrying HTTPS
end: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] [SMTPS.Google][Email][Acceptable]