1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881]
detected: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] [BitTorrent][Unknown][Download][Acceptable]
RISK: Known Proto on Non Std Port
analyse: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] [BitTorrent][Unknown][Download][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.065| 0.014| 0.017| 294.673| 3.800]
[PKTLEN......: 40.000| 1480.000| 782.200| 666.400| 444053.700| 4.400]
[BINS(c->s)..: 8,0,1,0,0,0,1,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 1,1,0,0,0,0,0,1,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,15,0,0]
[DIRECTIONS..: 0,1,0,0,1,0,0,1,0,1,0,1,1,1,1,1,1,1,1,1,1,1,0,0,1,1,1,1,1,0,0,0]
[IATS(ms)....: 18.7,26.9,29.9,65.0,29.3,33.9,54.9,20.6,19.6,22.0,21.0,6.9,0.3,0.2,0.2,0.2,0.2,0.3,0.6,0.1,0.5,33.9,0.0,24.5,0.4,0.1,0.4,0.4,18.5,0.0,0.0]
[PKTLENS.....: 60,52,40,238,464,40,511,280,108,419,328,90,1480,1480,1480,1480,1480,1480,1480,1480,1480,1480,40,40,1480,1480,1480,1480,1480,40,40,40]
[ENTROPIES...: 4.7,5.1,4.8,7.1,7.5,4.9,7.5,7.2,6.2,5.6,5.1,4.1,7.8,7.9,7.9,7.9,7.9,7.9,7.9,7.9,7.9,7.9,4.9,4.8,7.9,7.9,7.9,7.9,7.9,4.9,4.9,4.9]
idle: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] [BitTorrent][Unknown][Download][Acceptable]
RISK: Known Proto on Non Std Port
DAEMON-EVENT: shutdown
|