1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..udp] [....10.4.14.102][58722] -> [.10.130.130.130][.9600]
detected: [.....1] [ip4][..udp] [....10.4.14.102][58722] -> [.10.130.130.130][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
analyse: [.....1] [ip4][..udp] [....10.4.14.102][58722] -> [.10.130.130.130][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001|< 0.001|< 0.001|< 0.001|< 0.001| 5.000]
[PKTLEN......: 44.000| 65.000| 47.200| 3.500| 12.600| 5.000]
[BINS(c->s)..: 31,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[IATS(ms)....: 0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0]
[PKTLENS.....: 46,46,46,46,46,46,46,46,46,46,46,46,46,46,46,46,46,46,46,52,48,44,48,50,46,46,46,46,46,50,48,65]
[ENTROPIES...: 4.0,4.0,4.0,4.1,4.0,4.1,4.0,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.2,4.0,4.0,4.0,4.3,3.9,3.9,3.9,3.9,3.8,4.1,3.9,3.7]
DAEMON-EVENT: [Processed: 245 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
ERROR-EVENT: Captured packet size is smaller than expected packet size [1/16]
new: [.....2] [ip4][..tcp] [.....10.1.1.173][17134] -> [.....10.1.1.164][.9600]
ERROR-EVENT: Captured packet size is smaller than expected packet size [2/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [3/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [4/16]
detected: [.....2] [ip4][..tcp] [.....10.1.1.173][17134] -> [.....10.1.1.164][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
ERROR-EVENT: Captured packet size is smaller than expected packet size [5/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [6/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [7/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [8/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [9/16]
ERROR-EVENT: Captured packet size is smaller than expected packet size [10/16]
idle: [.....1] [ip4][..udp] [....10.4.14.102][58722] -> [.10.130.130.130][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
ERROR-EVENT: Captured packet size is smaller than expected packet size [1/16]
new: [.....3] [ip4][..udp] [.....10.1.1.173][54855] -> [.....10.1.1.164][.9600]
detected: [.....3] [ip4][..udp] [.....10.1.1.173][54855] -> [.....10.1.1.164][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
ERROR-EVENT: Captured packet size is smaller than expected packet size [2/16]
end: [.....2] [ip4][..tcp] [.....10.1.1.173][17134] -> [.....10.1.1.164][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
idle: [.....3] [ip4][..udp] [.....10.1.1.173][54855] -> [.....10.1.1.164][.9600] [FINS][Unknown][IoT-Scada][Acceptable]
DAEMON-EVENT: shutdown
|