1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443]
detected: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][]
RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch
detection-update: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][]
RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch
analyse: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe]
min| max| avg| stddev| variance| entropy
[IAT.........: 0.000| 3.088| 0.311| 0.823| 676677.157| 2.200]
[PKTLEN......: 40.000| 1628.000| 193.500| 364.600| 132965.600| 3.700]
[BINS(c->s)..: 9,0,2,2,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 11,0,1,0,0,0,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,0,0,0,1,1,1,0,1,0,1,1,0,0,1,1,1,1,0,0,1,1,1,0]
[IATS(ms)....: 15.2,15.2,0.4,15.3,1.8,16.7,0.1,0.1,90.4,0.1,0.1,105.3,0.0,0.1,14.9,0.0,0.1,6.0,0.0,6.0,0.4,8.9,6.4,1568.6,0.0,1583.6,0.7,15.6,3073.2,0.0,3088.2]
[PKTLENS.....: 60,52,40,301,46,1500,40,1628,40,104,126,164,46,46,111,40,46,71,311,71,40,144,46,46,259,71,40,202,46,344,71,40]
[ENTROPIES...: 4.7,4.7,4.5,6.0,4.2,7.8,4.5,7.9,4.5,6.0,6.3,6.7,4.2,4.1,6.1,4.5,4.2,5.5,7.2,5.5,4.4,6.4,4.2,4.2,7.2,5.4,4.5,6.8,4.2,7.3,5.5,4.5]
idle: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe]
RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch
DAEMON-EVENT: shutdown
|