aboutsummaryrefslogtreecommitdiff
path: root/test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out
diff options
context:
space:
mode:
Diffstat (limited to 'test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out')
-rw-r--r--test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out10
1 files changed, 5 insertions, 5 deletions
diff --git a/test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out b/test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out
index f086fda49..fc0930548 100644
--- a/test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out
+++ b/test/results/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out
@@ -1,4 +1,4 @@
-00640{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","ndpi_api_version":11619,"size_per_flow":1408,"max-flows-per-thread":2048,"max-idle-flows-per-thread":64,"reader-thread-count":1,"flow-scan-interval":10000000,"generic-max-idle-time":600000000,"icmp-max-idle-time":120000000,"udp-max-idle-time":180000000,"tcp-max-idle-time":7560000000,"max-packets-per-flow-to-send":5,"max-packets-per-flow-to-process":32,"max-packets-per-flow-to-analyse":32,"global_ts_usec":0}
+00643{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","ndpi_api_version":11619,"size_per_flow":1408,"max-flows-per-thread":32768,"max-idle-flows-per-thread":1024,"reader-thread-count":1,"flow-scan-interval":10000000,"generic-max-idle-time":600000000,"icmp-max-idle-time":120000000,"udp-max-idle-time":180000000,"tcp-max-idle-time":7560000000,"max-packets-per-flow-to-send":5,"max-packets-per-flow-to-process":32,"max-packets-per-flow-to-analyse":32,"global_ts_usec":0}
00864{"daemon_event_id":4,"daemon_event_name":"status","thread_id":0,"packet_id":1,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","ndpi_api_version":11619,"size_per_flow":1408,"packets-captured":1,"packets-processed":0,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":0,"total-not-detected-flows":0,"total-guessed-flows":0,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":0,"total-idle-flows":0,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":2,"global_ts_usec":1722427237865123}
00806{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427237865123,"flow_dst_last_pkt_time":1722427237865123,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":0,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":0,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1722427237865123,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5}
00585{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_src_last_pkt_time":1722427237865123,"flow_dst_last_pkt_time":1722427237865123,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"thread_ts_usec":1722427237865123,"pkt":"CL6sCxduJjb1W8R1CABFAAA8G7tAAEAGftnAqAycuYAZY5RYAdHRRTx5AAAAAKAC\/\/8WmQAAAgQFtAQCCApRg5vRAAAAAAEDAwk="}
@@ -23,10 +23,10 @@
00585{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":95,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":5,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590873564,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":75,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":75,"pkt_l4_len":41,"thread_ts_usec":1722705590873564,"pkt":"CL6sCxduJjb1W8R1CABFAAA9Ke9AAEAGgWPAqAyca6FWg7vIAbsz4mKOJW6rfoAYAKyd\/QAAAQEICsoN5qpqqi2UOno3Y591U252"}
02005{"flow_event_id":5,"flow_event_name":"analyse","thread_id":0,"packet_id":122,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":11,"flow_dst_packets_processed":21,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705591511972,"flow_dst_last_pkt_time":1722705591387622,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":100,"flow_dst_max_l4_payload_len":46,"flow_src_tot_l4_payload_len":196,"flow_dst_tot_l4_payload_len":218,"midstream":0,"thread_ts_usec":1722705591511972,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"data_analysis": {"iat": {"min":26,"avg":44847.8,"max":303035,"stddev":76201.7,"var":5806696960.0,"ent":3.5,"data": [102069,4840,6500,5499,5384,5348,5717,5375,5168,5616,5148,255594,100325,15640,143042,32722,143022,26,303035,27745,1278,5419,5419,5738,6677,5026,142895,27779,1244,5483,5509]},"pktlen": {"min":52,"avg":67.3,"max":152,"stddev":23.7,"var":562.8,"ent":4.9,"data": [60,52,61,61,61,61,61,61,61,61,61,59,64,88,58,80,80,52,152,98,52,59,59,59,59,59,59,52,148,52,52,52]},"bins": {"c_to_s": [9,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"s_to_c": [19,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]},"directions": [0,1,1,1,1,1,1,1,1,1,1,1,0,1,1,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,0],"entropies": [5.300120831,5.233812809,5.399485111,5.467381954,5.434595108,5.401808262,5.500168800,5.401808262,5.455006599,5.377057552,5.233534813,5.055375576,5.207358360,5.946230888,5.336176872,5.165400982,5.130965233,5.231892586,6.316833973,5.691545963,5.156889915,5.259676456,5.280779839,5.403578281,5.333379745,5.369679928,5.299482346,5.193430901,6.433825016,5.140452385,5.193430901,5.270354271]}}
00964{"flow_event_id":6,"flow_event_name":"guessed","thread_id":0,"packet_id":122,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":11,"flow_dst_packets_processed":21,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705591511972,"flow_dst_last_pkt_time":1722705591387622,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":100,"flow_dst_max_l4_payload_len":46,"flow_src_tot_l4_payload_len":196,"flow_dst_tot_l4_payload_len":218,"midstream":0,"thread_ts_usec":1722705591511972,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","ndpi": {"confidence": {"1":"Match by port"},"proto":"TLS","proto_id":"91","proto_by_ip":"Unknown","proto_by_ip_id":0,"encrypted":1,"breed":"Safe","category_id":5,"category":"Web"}}
+01010{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"finished","flow_src_packets_processed":40,"flow_dst_packets_processed":47,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705593900158,"flow_dst_last_pkt_time":1722705593880142,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":1448,"flow_dst_max_l4_payload_len":1024,"flow_src_tot_l4_payload_len":6532,"flow_dst_tot_l4_payload_len":13095,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"confidence": {"1":"Match by port"},"proto":"TLS","proto_id":"91","proto_by_ip":"Unknown","proto_by_ip_id":0,"encrypted":1,"breed":"Safe","category_id":5,"category":"Web"}}
+01141{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"finished","flow_src_packets_processed":29,"flow_dst_packets_processed":31,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427239577895,"flow_dst_last_pkt_time":1722427239598141,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":1024,"flow_dst_max_l4_payload_len":1448,"flow_src_tot_l4_payload_len":5488,"flow_dst_tot_l4_payload_len":7758,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"flow_risk": {"51": {"risk":"Fully Encrypted Flow","severity":"Medium","risk_score": {"total":360,"client":240,"server":120}}},"confidence": {"1":"Match by port"},"proto":"SMTPS","proto_id":"29","proto_by_ip":"NordVPN","proto_by_ip_id":426,"encrypted":1,"breed":"Safe","category_id":3,"category":"Email"}}
01096{"flow_event_id":6,"flow_event_name":"guessed","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":19,"flow_dst_packets_processed":11,"flow_first_seen":1722427401914491,"flow_src_last_pkt_time":1722427403179824,"flow_dst_last_pkt_time":1722427403133860,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":73,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":740,"flow_dst_max_l4_payload_len":1116,"flow_src_tot_l4_payload_len":2831,"flow_dst_tot_l4_payload_len":6507,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"149.102.238.108","src_port":47128,"dst_port":1214,"l4_proto":"udp","ndpi": {"flow_risk": {"35": {"risk":"Susp Entropy","severity":"Low","risk_score": {"total":210,"client":165,"server":45}}},"confidence": {"7":"Match by IP"},"proto":"NordVPN","proto_id":"426","proto_by_ip":"NordVPN","proto_by_ip_id":426,"encrypted":1,"breed":"Acceptable","category_id":2,"category":"VPN"}}
00825{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":19,"flow_dst_packets_processed":11,"flow_first_seen":1722427401914491,"flow_src_last_pkt_time":1722427403179824,"flow_dst_last_pkt_time":1722427403133860,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":73,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":740,"flow_dst_max_l4_payload_len":1116,"flow_src_tot_l4_payload_len":2831,"flow_dst_tot_l4_payload_len":6507,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"149.102.238.108","src_port":47128,"dst_port":1214,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
-01141{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"finished","flow_src_packets_processed":29,"flow_dst_packets_processed":31,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427239577895,"flow_dst_last_pkt_time":1722427239598141,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":1024,"flow_dst_max_l4_payload_len":1448,"flow_src_tot_l4_payload_len":5488,"flow_dst_tot_l4_payload_len":7758,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"flow_risk": {"51": {"risk":"Fully Encrypted Flow","severity":"Medium","risk_score": {"total":360,"client":240,"server":120}}},"confidence": {"1":"Match by port"},"proto":"SMTPS","proto_id":"29","proto_by_ip":"NordVPN","proto_by_ip_id":426,"encrypted":1,"breed":"Safe","category_id":3,"category":"Email"}}
-01010{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"finished","flow_src_packets_processed":40,"flow_dst_packets_processed":47,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705593900158,"flow_dst_last_pkt_time":1722705593880142,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":1448,"flow_dst_max_l4_payload_len":1024,"flow_src_tot_l4_payload_len":6532,"flow_dst_tot_l4_payload_len":13095,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"confidence": {"1":"Match by port"},"proto":"TLS","proto_id":"91","proto_by_ip":"Unknown","proto_by_ip_id":0,"encrypted":1,"breed":"Safe","category_id":5,"category":"Web"}}
00877{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":177,"source":"cfgs\/openvpn_heuristic_enabled\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","ndpi_api_version":11619,"size_per_flow":1408,"packets-captured":177,"packets-processed":177,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":42211,"total-not-detected-flows":0,"total-guessed-flows":3,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":3,"total-idle-flows":3,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":30,"global_ts_usec":1722705593900158}
~~~~~~~~~~~~~~~~~~~~ SUMMARY ~~~~~~~~~~~~~~~~~~~~
~~ packets captured/processed: 177/177
@@ -36,8 +36,8 @@
~~ total active/idle flows...: 3/3
~~ total timeout flows.......: 1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-~~ total memory allocated....: 6668215 bytes
-~~ total memory freed........: 6668215 bytes
+~~ total memory allocated....: 6921655 bytes
+~~ total memory freed........: 6921655 bytes
~~ total allocations/frees...: 114340/114340
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ json message min len.......: 576 chars