1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898]
detected: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] [BeckhoffADS][Unknown][IoT-Scada][Acceptable]
analyse: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] [BeckhoffADS][Unknown][IoT-Scada][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 25.812| 1.672| 6.314| 39862191.260| 1.100]
[PKTLEN......: 40.000| 318.000| 100.400| 47.800| 2284.800| 4.900]
[BINS(c->s)..: 3,5,7,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 1,13,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,0,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1]
[IATS(ms)....: 0.3,0.4,0.4,1.2,198.9,25613.3,25812.4,4.0,3.7,24.0,23.6,51.0,51.0,4.0,4.0,2.1,2.5,1.9,1.9,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0,2.0]
[PKTLENS.....: 48,48,40,78,86,40,90,90,90,318,118,86,78,86,82,82,118,86,136,87,133,86,134,87,135,86,134,87,136,87,134,86]
[ENTROPIES...: 4.1,4.5,4.3,4.1,4.1,4.5,3.9,3.9,3.9,3.6,3.4,4.0,4.1,4.1,4.0,4.1,3.3,4.0,4.9,4.1,4.9,4.1,4.9,4.1,5.0,4.1,4.9,4.1,5.0,4.1,4.9,4.1]
idle: [.....1] [ip4][..tcp] [...192.168.1.99][49201] -> [....192.168.1.8][48898] [BeckhoffADS][Unknown][IoT-Scada][Acceptable]
DAEMON-EVENT: shutdown
|