summaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/rtsp.pcap.out
blob: 7c6e4915fc9e93494f80df83211bec1722e9fb11 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
     DAEMON-EVENT: init
     DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
     DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
              new: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [MIDSTREAM] 
         detected: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port, Unidirectional Traffic
              new: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] 
         detected: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
          analyse: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                                        min|      max|      avg|   stddev|       variance| entropy
                   [IAT.........:     0.000|    0.021|    0.002|    0.006|         34.529|   2.200]
                   [PKTLEN......:    40.000|  182.000|   92.600|   58.600|       3438.900|   4.700]
                   [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,1,1,1,1]
                   [IATS(ms)....: 0.0,0.0,0.1,0.2,0.1,0.0,0.0,0.2,0.0,0.0,0.1,13.1,0.0,0.0,0.1,13.5,0.0,0.0,0.0,20.6,0.0,0.0,0.0,21.1,0.0,0.0,0.1,0.5,0.0,0.0,0.0]
                   [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,40,46,46,165,165,165,165,182,182,182,182,46,40,46,46]
                   [ENTROPIES...: 4.4,4.4,4.5,4.5,4.7,4.7,4.7,4.7,4.4,4.4,4.7,4.4,5.7,5.7,5.7,5.7,4.3,4.6,4.3,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.3,4.7,4.4,4.3]
              new: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] 
         detected: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
          analyse: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                                        min|      max|      avg|   stddev|       variance| entropy
                   [IAT.........:     0.000|    0.021|    0.002|    0.005|         29.923|   2.200]
                   [PKTLEN......:    40.000|  182.000|   92.600|   58.600|       3438.900|   4.700]
                   [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,1,1,1,1]
                   [IATS(ms)....: 0.0,0.0,0.1,0.3,0.0,0.0,0.0,0.6,0.0,0.0,0.1,9.3,0.0,0.0,0.1,10.1,0.0,0.0,0.0,20.5,0.0,0.0,0.0,21.2,0.0,0.0,0.4,0.9,0.1,0.0,0.0]
                   [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,40,46,46,165,165,165,165,182,182,182,182,46,46,40,46]
                   [ENTROPIES...: 4.4,4.4,4.4,4.4,4.6,4.7,4.7,4.6,4.4,4.4,4.7,4.4,5.8,5.8,5.8,5.8,4.3,4.7,4.4,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.3,4.3,4.6,4.3]
              new: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] 
         detected: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
          analyse: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                                        min|      max|      avg|   stddev|       variance| entropy
                   [IAT.........:     0.000|    0.021|    0.002|    0.005|         26.106|   2.200]
                   [PKTLEN......:    40.000|  182.000|   92.600|   58.600|       3438.900|   4.700]
                   [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,1,1,1,1]
                   [IATS(ms)....: 0.0,0.0,0.3,0.3,0.1,0.0,0.1,0.8,0.1,0.0,0.2,4.8,0.0,0.0,0.4,6.2,0.1,0.0,0.1,20.1,0.0,0.1,0.0,21.0,0.0,0.0,0.1,0.9,0.0,0.0,0.1]
                   [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,46,40,46,165,165,165,165,182,182,182,182,46,40,46,46]
                   [ENTROPIES...: 4.3,4.3,4.4,4.4,4.6,4.6,4.6,4.6,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.2,4.5,4.2,4.3]
              new: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] 
         detected: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
          analyse: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                                        min|      max|      avg|   stddev|       variance| entropy
                   [IAT.........:     0.000|    0.505|    0.033|    0.124|      15344.430|   1.200]
                   [PKTLEN......:    40.000|  165.000|   76.300|   48.800|       2380.700|   4.700]
                   [BINS(c->s)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,0,0,0,1,1,1,1,0,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1]
                   [IATS(ms)....: 0.0,0.0,0.1,1.3,0.0,0.0,0.3,505.2,0.0,0.0,0.1,504.5,0.0,0.0,0.1,1.0,0.0,0.0,0.1,0.1,0.0,0.0,0.0,0.6,0.1,0.0,0.0,20.4,0.0,0.0,0.1]
                   [PKTLENS.....: 52,52,52,52,46,40,46,46,52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,46,40,46,165,165,165,165]
                   [ENTROPIES...: 4.4,4.4,4.4,4.4,3.5,3.8,3.5,3.5,4.4,4.4,4.4,4.4,4.6,4.7,4.6,4.7,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7]
              end: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
              new: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] 
         detected: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
          analyse: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                                        min|      max|      avg|   stddev|       variance| entropy
                   [IAT.........:     0.000|    0.024|    0.002|    0.006|         34.195|   2.400]
                   [PKTLEN......:    40.000|  182.000|   92.600|   58.600|       3438.900|   4.700]
                   [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,0,0,0,1,1,1,1,0,0,0,0,0,0,0,1,1,0,1,1,1,1,1,1,0,0,0,0,1,1,1,1]
                   [IATS(ms)....: 0.0,0.0,0.1,0.4,0.0,0.0,0.1,0.6,0.0,0.0,0.1,10.3,0.0,0.0,11.4,0.0,0.8,0.0,0.1,20.3,0.0,0.0,0.1,23.8,0.0,0.0,0.1,3.5,0.0,0.0,0.1]
                   [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,46,40,156,46,46,165,165,165,165,182,182,182,182,46,40,46,46]
                   [ENTROPIES...: 4.3,4.3,4.4,4.4,4.6,4.6,4.6,4.6,4.3,4.3,4.6,4.3,5.7,5.7,5.7,4.2,4.6,5.7,4.2,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.2,4.6,4.2,4.3]
              end: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
              new: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] 
         detected: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
          analyse: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                                        min|      max|      avg|   stddev|       variance| entropy
                   [IAT.........:     0.000|    0.021|    0.002|    0.005|         26.978|   2.200]
                   [PKTLEN......:    40.000|  182.000|   92.600|   58.600|       3438.900|   4.700]
                   [BINS(c->s)..: 8,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,0,0,0,1,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,1,1,1,1]
                   [IATS(ms)....: 0.0,0.0,0.1,0.4,0.0,0.0,0.1,0.6,0.0,0.0,0.1,6.6,0.0,0.0,0.1,7.5,0.0,0.1,0.1,20.0,0.0,0.1,0.1,21.0,0.0,0.0,0.1,0.8,0.0,0.0,0.1]
                   [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,40,46,46,165,165,165,165,182,182,182,182,46,40,46,46]
                   [ENTROPIES...: 4.3,4.3,4.3,4.3,4.4,4.5,4.4,4.5,4.3,4.3,4.5,4.3,5.7,5.7,5.7,5.7,4.2,4.5,4.2,4.3,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,4.3,4.6,4.3,4.3]
              end: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
              end: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
              end: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
              end: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
             idle: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun]
                   RISK: Known Proto on Non Std Port
     DAEMON-EVENT: shutdown