1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [.192.168.25.177][53162] -> [.192.168.25.131][..102]
detected: [.....1] [ip4][..tcp] [.192.168.25.177][53162] -> [.192.168.25.131][..102] [S7CommPlus][Unknown][IoT-Scada][Acceptable]
analyse: [.....1] [ip4][..tcp] [.192.168.25.177][53162] -> [.192.168.25.131][..102] [S7CommPlus][Unknown][IoT-Scada][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.996| 0.038| 0.175| 30656.291| 1.200]
[PKTLEN......: 40.000| 337.000| 100.300| 73.000| 5323.400| 4.700]
[BINS(c->s)..: 12,2,6,2,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 4,2,0,0,1,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,1,0,0,0,0,1,0,0,1,1,0,0,0,0,1,0,0,0,0,1,0,0,0,0,1,0,0,1,0,0]
[IATS(ms)....: 0.0,0.7,0.9,0.0,0.4,0.0,1.7,2.5,0.0,13.8,4.3,17.7,0.0,12.3,0.0,17.8,4.8,0.0,1.5,0.0,7.2,5.7,0.0,28.6,0.0,33.3,4.7,0.0,36.3,995.8,0.0]
[PKTLENS.....: 52,52,46,40,40,76,76,76,257,257,46,177,47,47,162,162,71,47,47,123,123,84,47,47,133,133,337,47,47,46,133,133]
[ENTROPIES...: 4.6,4.6,4.5,4.7,4.7,5.3,5.3,5.2,5.5,5.5,4.1,5.2,4.6,4.6,4.7,4.7,4.2,4.6,4.6,4.6,4.6,4.3,4.5,4.5,4.9,4.9,1.6,4.5,4.5,4.1,4.9,4.9]
idle: [.....1] [ip4][..tcp] [.192.168.25.177][53162] -> [.192.168.25.131][..102] [S7CommPlus][Unknown][IoT-Scada][Acceptable]
DAEMON-EVENT: shutdown
|