1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [.192.168.88.231][48084] -> [.192.168.88.208][.4000]
detected: [.....1] [ip4][..tcp] [.192.168.88.231][48084] -> [.192.168.88.208][.4000] [NoMachine][Unknown][RemoteAccess][Acceptable]
RISK: Desktop/File Sharing
analyse: [.....1] [ip4][..tcp] [.192.168.88.231][48084] -> [.192.168.88.208][.4000] [NoMachine][Unknown][RemoteAccess][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 1.638| 0.177| 0.449| 201543.221| 2.300]
[PKTLEN......: 40.000| 1281.000| 114.500| 213.600| 45617.600| 4.000]
[BINS(c->s)..: 13,0,1,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 3,8,2,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,0,1,0,0,1,0,1,0,1,0,0,1,0,1,0,1,0,1,0,1,0,1,1,0,1]
[IATS(ms)....: 0.2,0.2,0.3,43.9,970.9,1014.5,2.7,11.4,49.9,1596.3,1638.1,0.6,0.8,0.8,0.1,0.1,0.1,0.8,42.2,71.3,29.8,0.0,0.0,0.1,0.1,0.6,0.6,0.2,0.1,0.3,0.2]
[PKTLENS.....: 60,52,40,52,40,51,40,170,1281,40,166,91,40,113,40,77,40,162,162,40,103,40,109,40,77,119,91,40,77,93,40,77]
[ENTROPIES...: 4.8,5.0,4.7,5.2,4.9,5.2,4.7,5.3,7.6,4.8,6.5,5.9,4.8,6.2,4.8,5.7,4.8,6.7,6.7,4.7,6.0,4.6,6.2,4.7,5.7,6.4,6.0,4.7,5.7,6.0,4.7,5.7]
new: [.....2] [ip4][..udp] [.192.168.88.231][56019] -> [.192.168.88.208][.4000]
detected: [.....2] [ip4][..udp] [.192.168.88.231][56019] -> [.192.168.88.208][.4000] [NoMachine][Unknown][RemoteAccess][Acceptable]
RISK: Desktop/File Sharing
end: [.....1] [ip4][..tcp] [.192.168.88.231][48084] -> [.192.168.88.208][.4000] [NoMachine][Unknown][RemoteAccess][Acceptable]
RISK: Desktop/File Sharing
idle: [.....2] [ip4][..udp] [.192.168.88.231][56019] -> [.192.168.88.208][.4000] [NoMachine][Unknown][RemoteAccess][Acceptable]
RISK: Desktop/File Sharing
DAEMON-EVENT: shutdown
|