From 8ebaccc27d779e981b500e80b69f62396dcaa0ca Mon Sep 17 00:00:00 2001 From: Toni Uhlig Date: Thu, 9 Nov 2023 23:18:55 +0100 Subject: py-flow-info: Improved analyse result printing. Signed-off-by: Toni Uhlig --- test/results/flow-info/default/imap-starttls.pcap.out | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) (limited to 'test/results/flow-info/default/imap-starttls.pcap.out') diff --git a/test/results/flow-info/default/imap-starttls.pcap.out b/test/results/flow-info/default/imap-starttls.pcap.out index 63fa7a136..4ab4f6cfd 100644 --- a/test/results/flow-info/default/imap-starttls.pcap.out +++ b/test/results/flow-info/default/imap-starttls.pcap.out @@ -11,9 +11,9 @@ detection-update: [.....1] [ip4][..tcp] [..192.168.17.53][49640] -> [.212.227.17.186][..143] [IMAPS][Unknown][Email][Safe] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn analyse: [.....1] [ip4][..tcp] [..192.168.17.53][49640] -> [.212.227.17.186][..143] [IMAPS][Unknown][Email][Safe] - min| max| avg| stddev| variance| entropy - [IAT.........: 0.000| 1.678| 0.188| 0.378| 143010.873| 3.300] - [PKTLEN......: 40.000| 1500.000| 235.200| 424.600| 180326.200| 3.600] + min| max| avg| stddev| variance| entropy + [IAT.........: < 0.001| 1.678| 0.188| 0.378| 143010.873| 3.300] + [PKTLEN......: 40.000| 1500.000| 235.200| 424.600| 180326.200| 3.600] [BINS(c->s)..: 15,1,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 5,2,1,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0] [DIRECTIONS..: 0,1,0,1,0,0,1,1,0,0,1,1,0,0,1,1,0,1,1,0,0,0,1,0,0,1,1,0,0,0,0,1] -- cgit v1.2.3