DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] new: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] detected: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] [BeckhoffADS][Unknown][IoT-Scada][Acceptable] analyse: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] [BeckhoffADS][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: < 0.001| 25.812| 1.672| 6.314| 39862191.260| 1.100] [PKTLEN......: 40.000| 318.000| 100.400| 47.800| 2284.800| 4.900] [BINS(c->s)..: 3,5,7,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 1,13,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [DIRECTIONS..: 0,1,0,0,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1] [IATS(ms)....: 0.3,0.4,0.4,1.2,198.9,25613.3,25812.4,4.0,3.7,24.0,23.6,51.0,51.0,4.0,4.0,2.1,2.5,1.9,1.9,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0] [PKTLENS.....: 48,48,40,78,86,40,90,90,90,318,118,86,78,86,82,82,118,86,136,87,133,86,134,87,135,86,134,87,136,87,134,86] [ENTROPIES...: 4.1,4.5,4.3,4.1,4.1,4.5,3.9,3.9,3.9,3.6,3.4,4.0,4.1,4.1,4.0,4.1,3.3,4.0,4.9,4.1,4.9,4.1,4.9,4.1,5.0,4.1,4.9,4.1,5.0,4.1,4.9,4.1] idle: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] [BeckhoffADS][Unknown][IoT-Scada][Acceptable] DAEMON-EVENT: shutdown