aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/viber.pcap.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/flow-info/viber.pcap.out')
-rw-r--r--test/results/flow-info/viber.pcap.out150
1 files changed, 150 insertions, 0 deletions
diff --git a/test/results/flow-info/viber.pcap.out b/test/results/flow-info/viber.pcap.out
new file mode 100644
index 000000000..698ddeb71
--- /dev/null
+++ b/test/results/flow-info/viber.pcap.out
@@ -0,0 +1,150 @@
+ DAEMON-EVENT: init
+ DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
+ DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
+ new: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [MIDSTREAM]
+ new: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53]
+ detected: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][SocialNetwork][Fun]
+ detection-update: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][SocialNetwork][Fun]
+ new: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53]
+ detected: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS][Advertisement][Acceptable]
+ detection-update: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS][Advertisement][Acceptable]
+ new: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53]
+ detected: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ detection-update: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ new: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443]
+ detected: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ detection-update: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ detection-update: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ new: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443]
+ detected: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ detection-update: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ new: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53]
+ detected: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] [DNS.Viber][Chat][Acceptable]
+ detection-update: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] [DNS.Viber][Chat][Acceptable]
+ new: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443]
+ detected: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][Chat][Acceptable]
+ detection-update: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][Chat][Acceptable]
+ detection-update: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][Chat][Acceptable]
+ new: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53]
+ detected: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] [DNS.Viber][Chat][Acceptable]
+ detection-update: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] [DNS.Viber][Chat][Acceptable]
+ new: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443]
+ detected: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][Chat][Acceptable]
+ detection-update: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][Chat][Acceptable]
+ detection-update: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][Chat][Acceptable]
+ analyse: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443]
+ [min|max|avg|stddev]
+ [IAT(flow)...: 0.000| 0.048| 0.009| 0.015]
+ [IAT(c->s)...: 0.000| 0.041| 0.011| 0.015][IAT(s->c)...: 0.000| 0.048| 0.008| 0.015]
+ [PKTLEN(c->s): 66.000| 774.000| 139.200| 184.300][PKTLEN(s->c): 66.000|1514.000|1186.100| 547.900]
+ [BINS(c->s)..: 11,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [BINS(s->c)..: 2,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,13,0,0]
+ detection-update: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][Chat][Acceptable]
+ new: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443]
+ new: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53]
+ detected: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ detection-update: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ new: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443]
+ detected: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] [TLS.Google][Web][Acceptable]
+ detection-update: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] [TLS.Google][Web][Acceptable]
+ new: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353]
+ detected: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353] [MDNS][Network][Acceptable]
+ new: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2]
+ detected: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] [ICMPV6][Network][Acceptable]
+ new: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53]
+ detected: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ detection-update: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ new: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443]
+ detected: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] [TLS][Web][Safe]
+ detection-update: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] [TLS][Web][Safe]
+ analyse: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244]
+ [min|max|avg|stddev]
+ [IAT(flow)...: 0.000| 10.702| 1.934| 2.902]
+ [IAT(c->s)...: 0.000| 10.564| 2.006| 2.878][IAT(s->c)...: 0.000| 10.702| 1.858| 2.926]
+ [PKTLEN(c->s): 66.000| 596.000| 211.100| 159.700][PKTLEN(s->c): 66.000| 164.000| 92.900| 39.000]
+ [BINS(c->s)..: 4,1,6,2,0,0,0,0,0,0,1,1,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [BINS(s->c)..: 10,0,3,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ guessed: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [Viber][VoIP][Acceptable]
+ detected: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [Viber][VoIP][Acceptable]
+ new: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443]
+ new: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985]
+ detected: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] [Viber][VoIP][Acceptable]
+ new: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987]
+ detected: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987] [Viber][VoIP][Acceptable]
+ new: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443]
+ detected: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ detection-update: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ detection-update: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ analyse: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] [Viber][VoIP][Acceptable]
+ [min|max|avg|stddev]
+ [IAT(flow)...: 0.000| 0.525| 0.329| 0.210]
+ [IAT(c->s)...: 0.000| 0.525| 0.321| 0.212][IAT(s->c)...: 0.015| 0.525| 0.337| 0.208]
+ [PKTLEN(c->s): 62.000| 299.000| 215.400| 113.300][PKTLEN(s->c): 76.000| 118.000| 104.000| 19.800]
+ [BINS(c->s)..: 6,0,0,0,0,0,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [BINS(s->c)..: 0,5,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ new: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443]
+ new: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985]
+ detected: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] [Viber][VoIP][Acceptable]
+ new: [....24] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7987]
+ detected: [....24] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7987] [Viber][VoIP][Acceptable]
+ update: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] [ICMPV6][Network][Acceptable]
+ analyse: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] [Viber][VoIP][Acceptable]
+ [min|max|avg|stddev]
+ [IAT(flow)...: 0.000| 0.531| 0.262| 0.245]
+ [IAT(c->s)...: 0.000| 0.531| 0.226| 0.244][IAT(s->c)...: 0.000| 0.531| 0.311| 0.237]
+ [PKTLEN(c->s): 54.000| 299.000| 172.500| 120.100][PKTLEN(s->c): 76.000| 118.000| 101.800| 20.400]
+ [BINS(c->s)..: 10,0,0,0,0,0,0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ [BINS(s->c)..: 0,5,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
+ new: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53]
+ detected: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] [DNS.Google][Web][Acceptable]
+ detection-update: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] [DNS.Google][Web][Acceptable]
+ new: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15]
+ detected: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15] [ICMP][Network][Acceptable]
+ update: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS][Advertisement][Acceptable]
+ update: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][SocialNetwork][Fun]
+ update: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ DAEMON-EVENT: [Processed: 420 pkts][ZLib][compressions: 0|diff: 0 / 0]
+ DAEMON-EVENT: [Flows][active: 26 / 26|skipped: 0|!detected: 0|guessed: 1|detection-updates: 20|updates: 4]
+ new: [....27] [ip4][..tcp] [..192.168.2.100][48690] -> [...52.0.252.145][.4244]
+ detected: [....27] [ip4][..tcp] [..192.168.2.100][48690] -> [...52.0.252.145][.4244] [Viber][VoIP][Acceptable]
+ end: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443]
+ end: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ guessed: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443] [Google][Web][Acceptable]
+ idle: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443]
+ idle: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] [Viber][VoIP][Acceptable]
+ idle: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987] [Viber][VoIP][Acceptable]
+ idle: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443]
+ idle: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15] [ICMP][Network][Acceptable]
+ idle: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] [TLS][Web][Safe]
+ idle: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [Viber][VoIP][Acceptable]
+ idle: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][Chat][Acceptable]
+ idle: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] [ICMPV6][Network][Acceptable]
+ idle: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353]
+ idle: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS][Advertisement][Acceptable]
+ idle: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ idle: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] [DNS.Viber][Chat][Acceptable]
+ idle: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][SocialNetwork][Fun]
+ guessed: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ end: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443]
+ end: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443]
+ idle: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] [DNS.Google][Web][Acceptable]
+ idle: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] [Viber][VoIP][Acceptable]
+ idle: [....24] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7987] [Viber][VoIP][Acceptable]
+ idle: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] [TLS.Google][Web][Acceptable]
+ idle: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ idle: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Network][Acceptable]
+ guessed: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443] [TLS.AmazonAWS][Cloud][Acceptable]
+ end: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443]
+ idle: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] [DNS.Viber][Chat][Acceptable]
+ DAEMON-EVENT: [Processed: 435 pkts][ZLib][compressions: 0|diff: 0 / 0]
+ DAEMON-EVENT: [Flows][active: 1 / 27|skipped: 0|!detected: 0|guessed: 4|detection-updates: 20|updates: 4]
+ new: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242]
+ detected: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242] [Viber][VoIP][Acceptable]
+ DAEMON-EVENT: [Processed: 446 pkts][ZLib][compressions: 0|diff: 0 / 0]
+ DAEMON-EVENT: [Flows][active: 2 / 28|skipped: 0|!detected: 0|guessed: 4|detection-updates: 20|updates: 4]
+ new: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [MIDSTREAM]
+ detected: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [Viber][VoIP][Acceptable]
+ idle: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [Viber][VoIP][Acceptable]
+ end: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242] [Viber][VoIP][Acceptable]
+ idle: [....27] [ip4][..tcp] [..192.168.2.100][48690] -> [...52.0.252.145][.4244] [Viber][VoIP][Acceptable]
+ DAEMON-EVENT: shutdown