aboutsummaryrefslogtreecommitdiff
path: root/test/results/default/signal_audiocall.pcapng.out
blob: 18eee38d57c9c389bafc29f39cac935b3c4fb985 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
00623{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.13.0-5173-c49d126","ndpi_api_version":11990,"size_per_flow":1400,"max-flows-per-thread":32768,"max-idle-flows-per-thread":1024,"reader-thread-count":1,"flow-scan-interval":10000000,"generic-max-idle-time":600000000,"icmp-max-idle-time":120000000,"udp-max-idle-time":180000000,"tcp-max-idle-time":7560000000,"max-packets-per-flow-to-send":5,"max-packets-per-flow-to-process":32,"max-packets-per-flow-to-analyse":32,"global_ts_usec":0}
00844{"daemon_event_id":4,"daemon_event_name":"status","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.13.0-5173-c49d126","ndpi_api_version":11990,"size_per_flow":1400,"packets-captured":1,"packets-processed":0,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":0,"total-not-detected-flows":0,"total-guessed-flows":0,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":0,"total-idle-flows":0,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":2,"global_ts_usec":1732024252560352}
00789{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024252560352,"flow_src_last_pkt_time":1732024252560352,"flow_dst_last_pkt_time":1732024252560352,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":20,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":20,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024252560352,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.216.234.234","src_port":45419,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
00546{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_src_last_pkt_time":1732024252560352,"flow_dst_last_pkt_time":1732024252560352,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":62,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":62,"pkt_l4_len":28,"thread_ts_usec":1732024252560352,"pkt":"dNo47VMyYhO2esBpCABFAAAwRWRAAEARGavAqAxDI9jq6rFrDZYAHHVvAAEAACESpEJXWklqc1dDeWlGaWU="}
01017{"flow_event_id":7,"flow_event_name":"detected","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024252560352,"flow_src_last_pkt_time":1732024252560352,"flow_dst_last_pkt_time":1732024252560352,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":20,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":20,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024252560352,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.216.234.234","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"confidence": {"6":"DPI"},"proto":"STUN","proto_id":"78","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":14,"category":"Network","hostname":"","domainame":"","stun": {"multimedia_flow_types":"Unknown"}}}
00789{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":2,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024252560499,"flow_dst_last_pkt_time":1732024252560499,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":20,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":20,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024252560499,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
00546{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_src_last_pkt_time":1732024252560499,"flow_dst_last_pkt_time":1732024252560499,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":62,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":62,"pkt_l4_len":28,"thread_ts_usec":1732024252560499,"pkt":"dNo47VMyYhO2esBpCABFAAAwgmpAAEARyvnAqAxDI9v8krFrDZYAHMWVAAEAACESpEI1cThLK29Vb2Zyc2I="}
01017{"flow_event_id":7,"flow_event_name":"detected","thread_id":0,"packet_id":2,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024252560499,"flow_dst_last_pkt_time":1732024252560499,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":20,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":20,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024252560499,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"confidence": {"6":"DPI"},"proto":"STUN","proto_id":"78","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":14,"category":"Network","hostname":"","domainame":"","stun": {"multimedia_flow_types":"Unknown"}}}
00558{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":2,"flow_src_last_pkt_time":1732024252562178,"flow_dst_last_pkt_time":1732024252560499,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":70,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":70,"pkt_l4_len":36,"thread_ts_usec":1732024252562178,"pkt":"dNo47VMyYhO2esBpCABFAAA4gmtAAEARyvDAqAxDI9v8krFrDZYAJFMAAAMACCESpEJESWJQSTJoSnlpWE4AGQAEEQAAAA=="}
01150{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":3,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":2,"flow_dst_packets_processed":0,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024252562178,"flow_dst_last_pkt_time":1732024252560499,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":28,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":48,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024252562178,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"flow_risk": {"46": {"risk":"Unidirectional Traffic","severity":"Low","risk_score": {"total":500,"client":430,"server":70}}},"confidence": {"6":"DPI"},"proto":"STUN","proto_id":"78","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":14,"category":"Network","hostname":"","domainame":"","stun": {"multimedia_flow_types":"Unknown"}}}
00591{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":4,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":3,"flow_src_last_pkt_time":1732024252562178,"flow_dst_last_pkt_time":1732024252564159,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":94,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":94,"pkt_l4_len":60,"thread_ts_usec":1732024252564159,"pkt":"YhO2esBpdNo47VMyCABFAABQYexAADkR8lcj2\/ySwKgMQw2WsWsAPPYdAQEAICESpEI1cThLK29Vb2Zyc2IAIAAIAAGR0HwxDFwAAQAIAAGwwl0jqB6AKAAEaYMT0g=="}
01065{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":4,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":2,"flow_dst_packets_processed":1,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024252562178,"flow_dst_last_pkt_time":1732024252564159,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":28,"flow_dst_max_l4_payload_len":52,"flow_src_tot_l4_payload_len":48,"flow_dst_tot_l4_payload_len":52,"midstream":0,"thread_ts_usec":1732024252564159,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"confidence": {"6":"DPI"},"proto":"STUN","proto_id":"78","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":14,"category":"Network","hostname":"","domainame":"","stun": {"mapped_address":"93.35.168.30:45250","multimedia_flow_types":"Unknown"}}}
00633{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":5,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":4,"flow_src_last_pkt_time":1732024252562178,"flow_dst_last_pkt_time":1732024252565403,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":126,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":126,"pkt_l4_len":92,"thread_ts_usec":1732024252565403,"pkt":"YhO2esBpdNo47VMyCABFAABwYe1AADkR8jYj2\/ySwKgMQw2WsWsAXAy5ARMAQCESpEJESWJQSTJoSnlpWE4ACQAQAAAEAVVuYXV0aG9yaXplZAAVABAxNjM3ZDNmZDRkOWM5YjYxABQACnNpZ25hbC5vcmcAAIAoAATPjK59"}
01098{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":5,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":2,"flow_dst_packets_processed":2,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024252562178,"flow_dst_last_pkt_time":1732024252565403,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":28,"flow_dst_max_l4_payload_len":84,"flow_src_tot_l4_payload_len":48,"flow_dst_tot_l4_payload_len":136,"midstream":0,"thread_ts_usec":1732024252565403,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"confidence": {"6":"DPI"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"signal.org","domainame":"signal.org","stun": {"mapped_address":"93.35.168.30:45250","multimedia_flow_types":"Unknown"}}}
00591{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":6,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":2,"flow_src_last_pkt_time":1732024252560352,"flow_dst_last_pkt_time":1732024252568619,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":94,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":94,"pkt_l4_len":60,"thread_ts_usec":1732024252568619,"pkt":"YhO2esBpdNo47VMyCABFYABQjT9AADkR2E8j2OrqwKgMQw2WsWsAPDZGAQEAICESpEJXWklqc1dDeWlGaWUAIAAIAAGR0HwxDFwAAQAIAAGwwl0jqB6AKAAEuwkx\/Q=="}
01085{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":6,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":1,"flow_first_seen":1732024252560352,"flow_src_last_pkt_time":1732024252560352,"flow_dst_last_pkt_time":1732024252568619,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":20,"flow_dst_max_l4_payload_len":52,"flow_src_tot_l4_payload_len":20,"flow_dst_tot_l4_payload_len":52,"midstream":0,"thread_ts_usec":1732024252568619,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.216.234.234","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"","domainame":"","stun": {"mapped_address":"93.35.168.30:45250","multimedia_flow_types":"Unknown"}}}
00559{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":7,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":3,"flow_src_last_pkt_time":1732024252569169,"flow_dst_last_pkt_time":1732024252568619,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":70,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":70,"pkt_l4_len":36,"thread_ts_usec":1732024252569169,"pkt":"dNo47VMyYhO2esBpCABFAAA4RWVAAEARGaLAqAxDI9jq6rFrDZYAJFh\/AAMACCESpEJGS3FkT09uNFJVbnEAGQAEEQAAAA=="}
00677{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":8,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":5,"flow_src_last_pkt_time":1732024252572448,"flow_dst_last_pkt_time":1732024252565403,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":158,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":158,"pkt_l4_len":124,"thread_ts_usec":1732024252572448,"pkt":"dNo47VMyYhO2esBpCABFAACQgmxAAEARypfAqAxDI9v8krFrDZYAfJOdAAMAYCESpEJuUEl0Z1MxUnVQKzcAGQAEEQAAAAAGABcxNzMyMTEwNjUzOjE1NTA1NTA4NiMwMQAAFAAKc2lnbmFsLm9yZwAAABUAEDE2MzdkM2ZkNGQ5YzliNjEACAAU3JGQo9CczDHRimYdZNnsDs1bURk="}
00634{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":10,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":4,"flow_src_last_pkt_time":1732024252569169,"flow_dst_last_pkt_time":1732024252576656,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":126,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":126,"pkt_l4_len":92,"thread_ts_usec":1732024252576656,"pkt":"YhO2esBpdNo47VMyCABFYABwjUdAADkR2Ccj2OrqwKgMQw2WsWsAXCnWARMAQCESpEJGS3FkT09uNFJVbnEACQAQAAAEAVVuYXV0aG9yaXplZAAVABAxYTZhN2ZjMjE4MzU3YTg0ABQACnNpZ25hbC5vcmcAAIAoAATMhc\/o"}
01107{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":10,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":2,"flow_dst_packets_processed":2,"flow_first_seen":1732024252560352,"flow_src_last_pkt_time":1732024252569169,"flow_dst_last_pkt_time":1732024252576656,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":28,"flow_dst_max_l4_payload_len":84,"flow_src_tot_l4_payload_len":48,"flow_dst_tot_l4_payload_len":136,"midstream":0,"thread_ts_usec":1732024252576656,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.216.234.234","src_port":45419,"dst_port":3478,"l4_proto":"udp","ndpi": {"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"signal.org","domainame":"signal.org","stun": {"mapped_address":"93.35.168.30:45250","multimedia_flow_types":"Unknown"}}}
00679{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":11,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":5,"flow_src_last_pkt_time":1732024252581941,"flow_dst_last_pkt_time":1732024252576656,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":158,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":158,"pkt_l4_len":124,"thread_ts_usec":1732024252581941,"pkt":"dNo47VMyYhO2esBpCABFAACQRWZAAEARGUnAqAxDI9jq6rFrDZYAfNTyAAMAYCESpEJPQ2R3Q1gyR0YxNG4AGQAEEQAAAAAGABcxNzMyMTEwNjUzOjE1NTA1NTA4NiMwMQAAFAAKc2lnbmFsLm9yZwAAABUAEDFhNmE3ZmMyMTgzNTdhODQACAAUdnj5ozIQ14RJfPGflgWJ9TOV+\/s="}
00790{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":24,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024255310800,"flow_src_last_pkt_time":1732024255310800,"flow_dst_last_pkt_time":1732024255310800,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":96,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":96,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":96,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024255310800,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":12261,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
00651{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":24,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_src_last_pkt_time":1732024255310800,"flow_dst_last_pkt_time":1732024255310800,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"thread_ts_usec":1732024255310800,"pkt":"dNo47VMyYhO2esBpCABFAAB8Fd9AAEARUcDAqAxDI9viC7FrL+UAaMFUAAEATCESpEJOeGYzd003aEM0NlMABgAJazhrQTo0VDNxAAAAwFcABAADAAqAKgAI5xJMPuQQFBUAJAAEbn8e\/wAIABT68YL7vmQRS9HQZGiIeRD1SGtWiYAoAASjdTd6"}
01170{"flow_event_id":7,"flow_event_name":"detected","thread_id":0,"packet_id":24,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024255310800,"flow_src_last_pkt_time":1732024255310800,"flow_dst_last_pkt_time":1732024255310800,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":96,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":96,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":96,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024255310800,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":12261,"l4_proto":"udp","ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"","domainame":"","stun": {"multimedia_flow_types":"Unknown"}}}
00613{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":31,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":2,"flow_src_last_pkt_time":1732024255310800,"flow_dst_last_pkt_time":1732024255375430,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":106,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":106,"pkt_l4_len":72,"thread_ts_usec":1732024255375430,"pkt":"YhO2esBpdNo47VMyCABFAABceXNAADER\/Usj2+ILwKgMQy\/lsWsASMN1AQEALCESpEJOeGYzd003aEM0NlMAIAAIAAGR0XwxDFwACAAUnZDi6xiY73CNxpkvkJm\/4v\/vMgCAKAAEI0j0WQ=="}
00664{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":32,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":3,"flow_src_last_pkt_time":1732024255408164,"flow_dst_last_pkt_time":1732024255375430,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":146,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":146,"pkt_l4_len":112,"thread_ts_usec":1732024255408164,"pkt":"dNo47VMyYhO2esBpCABFAACEFeVAAEARUbLAqAxDI9viC7FrL+UAcJtXAAEAVCESpEJpQUE2cDZ4ODNaWU8ABgAJazhrQTo0VDNxAAAAwFcABAADAAqAKgAI5xJMPuQQFBXAAQAEAAAAAQAkAARufx7\/AAgAFI5RI5U78Kp13DMCmA7Leck\/6NW6gCgABO24t1c="}
00611{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":39,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":4,"flow_src_last_pkt_time":1732024255408164,"flow_dst_last_pkt_time":1732024255478382,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":106,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":106,"pkt_l4_len":72,"thread_ts_usec":1732024255478382,"pkt":"YhO2esBpdNo47VMyCABFAABceaxAADER\/RIj2+ILwKgMQy\/lsWsASLnsAQEALCESpEJpQUE2cDZ4ODNaWU8AIAAIAAGR0XwxDFwACAAUb93PFiaRbp51W72Lo4W8+vqpJJCAKAAEhXIENA=="}
00654{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":40,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":5,"flow_src_last_pkt_time":1732024255408164,"flow_dst_last_pkt_time":1732024255504818,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"thread_ts_usec":1732024255504818,"pkt":"YhO2esBpdNo47VMyCABFAAB8ea9AADER\/O8j2+ILwKgMQy\/lsWsAaKWbAAEATCESpEIwUGVvRDJtRTdqaXQABgAJNFQzcTprOGtBAAAAwFcABAADA4SAKQAIDLe2oNQ22wcAJAAEbn8r\/wAIABTMgM4WmvIXuVnGMvf\/8DTFYb2Fd4AoAARIK8xL"}
00790{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":46,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024255554100,"flow_src_last_pkt_time":1732024255554100,"flow_dst_last_pkt_time":1732024255554100,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":96,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":96,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":96,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024255554100,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":54116,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
00651{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":46,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_packet_id":1,"flow_src_last_pkt_time":1732024255554100,"flow_dst_last_pkt_time":1732024255554100,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"thread_ts_usec":1732024255554100,"pkt":"dNo47VMyYhO2esBpCABFAAB8Fe9AAEARUbDAqAxDI9viC7Fr02QAaCf8AAEATCESpEIrN09mWUNLWHJaaVQABgAJazhrQTo0VDNxAAAAwFcABAADAAqAKgAI5xJMPuQQFBUAJAAEbn8e\/wAIABSFh95GlbVTlHrpRlUg3UgrYXJ00oAoAASZD4hP"}
01170{"flow_event_id":7,"flow_event_name":"detected","thread_id":0,"packet_id":46,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1732024255554100,"flow_src_last_pkt_time":1732024255554100,"flow_dst_last_pkt_time":1732024255554100,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":96,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":96,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":96,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024255554100,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":54116,"l4_proto":"udp","ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"","domainame":"","stun": {"multimedia_flow_types":"Unknown"}}}
02257{"flow_event_id":5,"flow_event_name":"analyse","thread_id":0,"packet_id":47,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"finished","flow_src_packets_processed":16,"flow_dst_packets_processed":16,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024255506282,"flow_dst_last_pkt_time":1732024255591142,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":140,"flow_dst_max_l4_payload_len":140,"flow_src_tot_l4_payload_len":1348,"flow_dst_tot_l4_payload_len":1440,"midstream":0,"thread_ts_usec":1732024255591142,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5,"data_analysis": {"iat": {"min":34,"avg":192787.9,"max":1009305,"stddev":328853.4,"var":108144574464.0,"ent":3.4,"data": [1679,3660,1244,10270,10180,26749,26618,250237,250253,501155,501113,1004003,1009305,956070,950707,3808,8981,1122,5251,38927,115928,34,84920,11595,28824,12973,35886,1216,42468,17725,63525]},"pktlen": {"min":48,"avg":115.1,"max":168,"stddev":39.1,"var":1531.7,"ent":4.9,"data": [48,56,80,112,144,112,56,108,56,108,56,108,56,108,148,80,168,148,128,80,160,168,136,128,168,168,128,168,148,80,136,136]},"bins": {"c_to_s": [6,0,0,7,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"s_to_c": [0,4,6,3,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]},"directions": [0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,1,0,0,1,0,1,1,0,0,1,0,0,0,1,1,1],"entropies": [5.092222691,4.896289825,5.489066124,5.744682789,5.768844128,5.706256866,4.913536072,5.656898022,4.877822399,5.693010330,4.913536072,5.644444466,4.877821922,5.674491882,5.815627575,5.871930599,6.136301041,5.839058876,5.921264172,5.746930122,5.986515999,6.205406189,5.953484058,5.819549084,5.906489849,6.141389370,5.824335575,5.926788807,5.885375023,5.921932697,5.977344990,5.910892010]},"ndpi": {"confidence": {"6":"DPI"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"signal.org"}}
00653{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":48,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_packet_id":2,"flow_src_last_pkt_time":1732024255603277,"flow_dst_last_pkt_time":1732024255554100,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"thread_ts_usec":1732024255603277,"pkt":"dNo47VMyYhO2esBpCABFAAB8FfFAAEARUa7AqAxDI9viC7Fr02QAaGVCAAEATCESpEIvV3hJemdRQ2V4OFQABgAJazhrQTo0VDNxAAAAwFcABAADAAqAKgAI5xJMPuQQFBUAJAAEbn8e\/wAIABQYYyyDTy\/jE1\/Nd7a1vmyLdnoNJYAoAAQy+vP7"}
01289{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":48,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_state":"info","flow_src_packets_processed":2,"flow_dst_packets_processed":0,"flow_first_seen":1732024255554100,"flow_src_last_pkt_time":1732024255603277,"flow_dst_last_pkt_time":1732024255554100,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":96,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":96,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":192,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1732024255603277,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":54116,"l4_proto":"udp","ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}},"46": {"risk":"Unidirectional Traffic","severity":"Low","risk_score": {"total":500,"client":430,"server":70}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"","domainame":"","stun": {"multimedia_flow_types":"Unknown"}}}
00609{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":49,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_packet_id":3,"flow_src_last_pkt_time":1732024255603277,"flow_dst_last_pkt_time":1732024255617924,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":106,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":106,"pkt_l4_len":72,"thread_ts_usec":1732024255617924,"pkt":"YhO2esBpdNo47VMyCABFYABcedJAADoR84wj2+ILwKgMQ9NksWsASGZUAQEALCESpEIrN09mWUNLWHJaaVQAIAAIAAGR0XwxDFwACAAUV6fjCSR3JzdWauCIks3ZoPOQt6yAKAAE1l85zg=="}
01219{"flow_event_id":8,"flow_event_name":"detection-update","thread_id":0,"packet_id":49,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_state":"info","flow_src_packets_processed":2,"flow_dst_packets_processed":1,"flow_first_seen":1732024255554100,"flow_src_last_pkt_time":1732024255603277,"flow_dst_last_pkt_time":1732024255617924,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":96,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":96,"flow_dst_max_l4_payload_len":64,"flow_src_tot_l4_payload_len":192,"flow_dst_tot_l4_payload_len":64,"midstream":0,"thread_ts_usec":1732024255617924,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":54116,"l4_proto":"udp","ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"","domainame":"","stun": {"mapped_address":"93.35.168.30:45251","multimedia_flow_types":"Unknown"}}}
00665{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":50,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_packet_id":4,"flow_src_last_pkt_time":1732024255651938,"flow_dst_last_pkt_time":1732024255617924,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":146,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":146,"pkt_l4_len":112,"thread_ts_usec":1732024255651938,"pkt":"dNo47VMyYhO2esBpCABFAACEFfRAAEARUaPAqAxDI9viC7Fr02QAcC1KAAEAVCESpEJsNGpWVkczUWZNMFgABgAJazhrQTo0VDNxAAAAwFcABAADAAqAKgAI5xJMPuQQFBXAAQAEAAAAAwAkAARufx7\/AAgAFLx4XCVdI\/2uyx6lx8OrrNXNQyE\/gCgABDOgNrg="}
00651{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":51,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_packet_id":5,"flow_src_last_pkt_time":1732024255651938,"flow_dst_last_pkt_time":1732024255657241,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"thread_ts_usec":1732024255657241,"pkt":"YhO2esBpdNo47VMyCABFYAB8eeVAADoR81kj2+ILwKgMQ9NksWsAaHX9AAEATCESpEJqV2p5emF6aUd3Z0kABgAJNFQzcTprOGtBAAAAwFcABAADA4SAKQAIDLe2oNQ22wcAJAAEbn8q\/wAIABSES8PnIh8Hi99anNPE0CgU3ijLmoAoAASQYvIj"}
02383{"flow_event_id":5,"flow_event_name":"analyse","thread_id":0,"packet_id":106,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_state":"finished","flow_src_packets_processed":17,"flow_dst_packets_processed":15,"flow_first_seen":1732024255554100,"flow_src_last_pkt_time":1732024262728582,"flow_dst_last_pkt_time":1732024262809079,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":28,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":104,"flow_dst_max_l4_payload_len":96,"flow_src_tot_l4_payload_len":1240,"flow_dst_tot_l4_payload_len":1108,"midstream":0,"thread_ts_usec":1732024262809079,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":54116,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5,"data_analysis": {"iat": {"min":7975,"avg":465466.5,"max":2229214,"stddev":655102.9,"var":429159809024.0,"ent":3.8,"data": [49177,63824,48661,39317,8988,7975,43088,49998,8002,41078,51322,943432,1038291,262155,354976,260389,75745,606181,10918,31204,394466,279938,364276,2145789,28790,2221167,290330,345130,931089,1204551,2229214]},"pktlen": {"min":56,"avg":101.4,"max":132,"stddev":22.2,"var":491.6,"ent":5.0,"data": [124,124,92,132,124,92,92,124,92,92,124,92,132,92,124,92,56,84,84,56,124,92,124,92,124,56,92,124,92,84,124,92]},"bins": {"c_to_s": [2,2,6,7,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"s_to_c": [1,1,7,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]},"directions": [0,0,1,0,1,0,1,1,0,1,1,0,0,1,1,0,1,1,0,0,0,1,1,0,0,0,1,1,0,0,0,1],"entropies": [5.954615116,5.890099049,5.936881542,5.799671173,5.975784302,5.832649708,5.819981575,5.872922421,5.789170742,5.862594128,5.872116566,5.802706242,5.723914146,5.759228230,5.937438488,5.737487316,5.186729908,5.916122437,5.723992348,5.190757751,5.819494724,5.923347950,5.943526745,5.780966759,5.877923489,5.155044079,5.841721058,5.969696999,5.737488747,5.781786919,5.896186829,5.789172649]},"ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP"}}
01149{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":268,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":4,"flow_state":"finished","flow_src_packets_processed":91,"flow_dst_packets_processed":87,"flow_first_seen":1732024255554100,"flow_src_last_pkt_time":1732024271658206,"flow_dst_last_pkt_time":1732024271623847,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":28,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":295,"flow_dst_max_l4_payload_len":295,"flow_src_tot_l4_payload_len":16436,"flow_dst_tot_l4_payload_len":15122,"midstream":0,"thread_ts_usec":1732024271658206,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":54116,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP"}}
01034{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":268,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"finished","flow_src_packets_processed":5,"flow_dst_packets_processed":5,"flow_first_seen":1732024252560352,"flow_src_last_pkt_time":1732024262578771,"flow_dst_last_pkt_time":1732024262586393,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":116,"flow_dst_max_l4_payload_len":84,"flow_src_tot_l4_payload_len":300,"flow_dst_tot_l4_payload_len":332,"midstream":0,"thread_ts_usec":1732024271658206,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.216.234.234","src_port":45419,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"signal.org"}}
01031{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":268,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"finished","flow_src_packets_processed":29,"flow_dst_packets_processed":29,"flow_first_seen":1732024252560499,"flow_src_last_pkt_time":1732024271632164,"flow_dst_last_pkt_time":1732024271627708,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":20,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":140,"flow_dst_max_l4_payload_len":140,"flow_src_tot_l4_payload_len":2352,"flow_dst_tot_l4_payload_len":2992,"midstream":0,"thread_ts_usec":1732024271658206,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.252.146","src_port":45419,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"confidence": {"6":"DPI"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP","hostname":"signal.org"}}
01144{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":268,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"finished","flow_src_packets_processed":11,"flow_dst_packets_processed":11,"flow_first_seen":1732024255310800,"flow_src_last_pkt_time":1732024270121601,"flow_dst_last_pkt_time":1732024270117593,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":64,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":104,"flow_dst_max_l4_payload_len":96,"flow_src_tot_l4_payload_len":776,"flow_dst_tot_l4_payload_len":992,"midstream":0,"thread_ts_usec":1732024271658206,"l3_proto":"ip4","src_ip":"192.168.12.67","dst_ip":"35.219.226.11","src_port":45419,"dst_port":12261,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"flow_risk": {"5": {"risk":"Known Proto on Non Std Port","severity":"Medium","risk_score": {"total":160,"client":140,"server":20}}},"confidence": {"5":"DPI (cache)"},"proto":"STUN.SignalVoip","proto_id":"78.269","proto_by_ip":"GoogleCloud","proto_by_ip_id":284,"encrypted":0,"breed":"Acceptable","category_id":10,"category":"VoIP"}}
00857{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":268,"source":"cfgs\/default\/pcap\/signal_audiocall.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.13.0-5173-c49d126","ndpi_api_version":11990,"size_per_flow":1400,"packets-captured":268,"packets-processed":268,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":39302,"total-not-detected-flows":0,"total-guessed-flows":0,"total-detected-flows":4,"total-detection-updates":7,"total-updates":0,"current-active-flows":0,"total-active-flows":4,"total-idle-flows":4,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":44,"global_ts_usec":1732024271658206}
~~~~~~~~~~~~~~~~~~~~ SUMMARY ~~~~~~~~~~~~~~~~~~~~
~~ packets captured/processed: 268/268
~~ skipped flows.............: 0
~~ total layer4 data length..: 39302 bytes
~~ total detected protocols..: 4
~~ total active/idle flows...: 4/4
~~ total timeout flows.......: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ total memory allocated....: 8437492 bytes
~~ total memory freed........: 8437492 bytes
~~ total allocations/frees...: 145035/145035
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ json message min len.......: 551 chars
~~ json message max len.......: 2388 chars
~~ json message avg len.......: 1467 chars