aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-analyse/default/tplink_shp.pcap.out
blob: 1f736ad1c1c963a7b26e4c0744f02453c076990c (plain)
1
2
3
4
5
6
flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks
1,ip4,192.168.242.41,255.255.255.255,udp,9999,9999,finished,32,0,1671480246580620,1671482107022461,1671480246580620,29,0,29,0,928,0,0,59941020,60014252.0,60058740,28832.0,831283968.0,5.0,"59981502,60026902,60033545,60025983,60019439,60029060,60007918,59960596,60018542,60041575,60007787,60058740,60009897,59988150,60032816,60027954,59999029,60019785,59971862,60037098,60038357,59969686,60047493,60049617,59970507,60028097,60020936,60058290,59941020,60019156,60000502",57,57.0,57,0.0,0.0,5.0,"57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57","32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971,4.992990971",TPLINK_SHP,332,0,Acceptable,IoT-Scada,6,DPI,""
1,ip4,192.168.242.40,255.255.255.255,udp,9999,9999,finished,32,0,1671480252766159,1671482113211224,1671480252766159,29,0,29,0,928,0,0,58157868,60014356.0,62682126,761550.5,579959128064.0,5.0,"60006889,59992234,59988113,60055878,62042393,58480216,59528957,59979179,60022444,59995841,60040145,60020835,60008844,60011011,60032284,59945925,60060707,59962350,60043922,60010468,60018299,62682126,59182323,58157868,60047220,60012353,60002512,60045750,59979486,60038815,60049678",57,57.0,57,0.0,0.0,5.0,"57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57","32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556,5.028078556",TPLINK_SHP,332,0,Acceptable,IoT-Scada,6,DPI,""
1,ip4,192.168.242.99,255.255.255.255,udp,9999,9999,finished,32,0,1671480255663786,1671482115665844,1671480255663786,29,0,29,0,928,0,0,59882007,60000068.0,60106251,33292.3,1108378624.0,5.0,"59993154,60020440,59990979,59994518,60003706,60005058,59991379,60018870,59983291,60003671,59994527,59997085,60003675,59991507,60013334,59999380,60003136,59995803,59988169,60000198,60004205,60003135,60004033,59996922,60008027,60106251,59882007,60006816,59993721,60005230,59999831",57,57.0,57,0.0,0.0,5.0,"57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57,57","32,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","5.159829617,5.194917202,5.194917202,5.194917679,5.159829617,5.194917679,5.194917679,5.194917679,5.194917679,5.091405869,5.159829140,5.159829140,5.194917202,5.194917679,5.194917679,5.194917679,5.146585464,5.124742031,5.159829140,5.159829617,5.159829617,5.146585464,5.194917679,5.194917202,5.194917679,5.159829617,5.194917202,5.194917202,5.124741554,5.159829617,5.194917679,5.194917202",TPLINK_SHP,332,0,Acceptable,IoT-Scada,6,DPI,""
timestamp,json_lines,json_bytes,flow_src_total_bytes,flow_dst_total_bytes,flow_new_count,flow_end_count,flow_idle_count,flow_update_count,flow_analyse_count,flow_guessed_count,flow_detected_count,flow_detection_update_count,flow_not_detected_count,flow_risky_count,packet_count,packet_flow_count,init_count,reconnect_count,shutdown_count,status_count,error_unknown_datalink,error_unknown_l3_protocol,error_unsupported_datalink,error_packet_too_short,error_packet_type_unknown,error_packet_header_invalid,error_ip4_packet_too_short,error_ip4_size_smaller_than_header,error_ip4_l4_payload_detection,error_ip6_packet_too_short,error_ip6_size_smaller_than_header,error_ip6_l4_payload_detection,error_tcp_packet_too_short,error_udp_packet_too_short,error_capture_size_smaller_than_packet,error_max_flows_to_track,error_flow_memory_alloc,flow_state_info,flow_state_finished,flow_breed_safe_count,flow_breed_acceptable_count,flow_breed_fun_count,flow_breed_unsafe_count,flow_breed_potentially_dangerous_count,flow_breed_tracker_ads_count,flow_breed_dangerous_count,flow_breed_unrated_count,flow_breed_unknown_count,flow_category_unspecified_count,flow_category_media_count,flow_category_vpn_count,flow_category_email_count,flow_category_data_transfer_count,flow_category_web_count,flow_category_social_network_count,flow_category_download_count,flow_category_game_count,flow_category_chat_count,flow_category_voip_count,flow_category_database_count,flow_category_remote_access_count,flow_category_cloud_count,flow_category_network_count,flow_category_collaborative_count,flow_category_rpc_count,flow_category_streaming_count,flow_category_system_count,flow_category_software_update_count,flow_category_music_count,flow_category_video_count,flow_category_shopping_count,flow_category_productivity_count,flow_category_file_sharing_count,flow_category_conn_check_count,flow_category_iot_scada_count,flow_category_virt_assistant_count,flow_category_cybersecurity_count,flow_category_adult_content_count,flow_category_mining_count,flow_category_malware_count,flow_category_advertisment_count,flow_category_banned_site_count,flow_category_site_unavail_count,flow_category_allowed_site_count,flow_category_antimalware_count,flow_category_crypto_currency_count,flow_category_gambling_count,flow_category_unknown_count,flow_confidence_by_port,flow_confidence_dpi_partial,flow_confidence_dpi_partial_cache,flow_confidence_dpi_cache,flow_confidence_dpi,flow_confidence_nbpf,flow_confidence_by_ip,flow_confidence_dpi_aggressive,flow_confidence_custom_rule,flow_confidence_unknown,flow_severity_low,flow_severity_medium,flow_severity_high,flow_severity_severe,flow_severity_critical,flow_severity_emergency,flow_severity_unknown,flow_l3_ip4_count,flow_l3_ip6_count,flow_l3_other_count,flow_l4_tcp_count,flow_l4_udp_count,flow_l4_icmp_count,flow_l4_other_count,flow_active_count,flow_detected_count,flow_guessed_count,flow_not_detected_count,flow_risk_1_count,flow_risk_2_count,flow_risk_3_count,flow_risk_4_count,flow_risk_5_count,flow_risk_6_count,flow_risk_7_count,flow_risk_8_count,flow_risk_9_count,flow_risk_10_count,flow_risk_11_count,flow_risk_12_count,flow_risk_13_count,flow_risk_14_count,flow_risk_15_count,flow_risk_16_count,flow_risk_17_count,flow_risk_18_count,flow_risk_19_count,flow_risk_20_count,flow_risk_21_count,flow_risk_22_count,flow_risk_23_count,flow_risk_24_count,flow_risk_25_count,flow_risk_26_count,flow_risk_27_count,flow_risk_28_count,flow_risk_29_count,flow_risk_30_count,flow_risk_31_count,flow_risk_32_count,flow_risk_33_count,flow_risk_34_count,flow_risk_35_count,flow_risk_36_count,flow_risk_37_count,flow_risk_38_count,flow_risk_39_count,flow_risk_40_count,flow_risk_41_count,flow_risk_42_count,flow_risk_43_count,flow_risk_44_count,flow_risk_45_count,flow_risk_46_count,flow_risk_47_count,flow_risk_48_count,flow_risk_49_count,flow_risk_50_count,flow_risk_51_count,flow_risk_52_count,flow_risk_53_count,flow_risk_54_count,flow_risk_55_count,flow_risk_56_count,flow_risk_unknown_count
0,314,296383,7279,0,8,0,8,241,3,0,8,0,0,0,0,40,1,0,1,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,0,0,0,0,0,0,0,0,0,8,0,0,0,8,0,0,8,8,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0