1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [...192.168.0.20][36835] -> [..192.168.0.241][.4712]
detected: [.....1] [ip4][..tcp] [...192.168.0.20][36835] -> [..192.168.0.241][.4712] [IEEE-C37118][Unknown][IoT-Scada][Acceptable]
analyse: [.....1] [ip4][..tcp] [...192.168.0.20][36835] -> [..192.168.0.241][.4712] [IEEE-C37118][Unknown][IoT-Scada][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.040| 0.018| 0.013| 176.295| 4.500]
[PKTLEN......: 52.000| 186.000| 81.600| 31.500| 989.700| 4.900]
[BINS(c->s)..: 14,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 3,14,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,1,1,1,0,1,0,1,0,1,0,1,1,0,1,1,0,1,0,1,1,0,1,1,0]
[IATS(ms)....: 1.2,1.3,0.2,1.8,0.7,2.3,1.0,1.8,1.0,20.1,39.0,19.9,2.8,19.9,19.9,20.0,39.1,20.0,20.2,38.0,20.0,20.0,40.0,19.9,22.6,20.2,20.1,37.5,19.9,20.0,40.0]
[PKTLENS.....: 60,64,52,70,52,186,52,70,52,106,106,52,106,52,106,52,106,52,106,106,52,106,106,52,106,52,106,106,52,106,106,52]
[ENTROPIES...: 4.5,5.0,4.9,4.7,5.0,4.4,4.9,4.7,5.0,5.7,5.6,5.0,5.6,5.0,5.7,5.0,5.7,5.0,5.7,5.6,4.9,5.6,5.6,4.9,5.6,4.9,5.7,5.6,5.0,5.6,5.6,5.0]
DAEMON-EVENT: [Processed: 417 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....2] [ip4][..udp] [...192.168.0.10][.4712] -> [...192.168.0.60][.4713]
detected: [.....2] [ip4][..udp] [...192.168.0.10][.4712] -> [...192.168.0.60][.4713] [IEEE-C37118][Unknown][IoT-Scada][Acceptable]
analyse: [.....2] [ip4][..udp] [...192.168.0.10][.4712] -> [...192.168.0.60][.4713] [IEEE-C37118][Unknown][IoT-Scada][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: 0.020| 0.318| 0.042| 0.073| 5330.315| 3.900]
[PKTLEN......: 46.000| 402.000| 83.400| 57.900| 3351.100| 4.800]
[BINS(c->s)..: 3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,28,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,1,0,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1]
[IATS(ms)....: 316.8,318.0,54.4,59.6,20.2,20.0,19.8,20.0,20.0,20.2,19.8,20.0,20.2,19.8,20.2,19.8,20.0,20.0,20.0,20.2,19.8,20.0,20.0,20.0,20.2,19.8,20.0,20.0,20.0,20.2,19.8]
[PKTLENS.....: 46,46,402,46,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76,76]
[ENTROPIES...: 4.4,4.2,4.1,4.4,4.9,4.9,5.0,4.8,4.9,4.9,5.0,5.0,5.0,4.9,5.0,4.9,4.9,4.9,5.0,5.0,5.0,4.8,5.0,4.9,5.1,4.8,4.8,4.9,4.9,4.9,4.9,4.9]
end: [.....1] [ip4][..tcp] [...192.168.0.20][36835] -> [..192.168.0.241][.4712] [IEEE-C37118][Unknown][IoT-Scada][Acceptable]
idle: [.....2] [ip4][..udp] [...192.168.0.10][.4712] -> [...192.168.0.60][.4713] [IEEE-C37118][Unknown][IoT-Scada][Acceptable]
DAEMON-EVENT: shutdown
|