1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [.192.168.63.100][.7718] -> [.192.168.63.253][..502]
detected: [.....1] [ip4][..tcp] [.192.168.63.100][.7718] -> [.192.168.63.253][..502] [Modbus.UMAS][Unknown][IoT-Scada][Acceptable]
analyse: [.....1] [ip4][..tcp] [.192.168.63.100][.7718] -> [.192.168.63.253][..502] [Modbus.UMAS][Unknown][IoT-Scada][Acceptable]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.007| 0.006| 0.002| 3.171| 4.900]
[PKTLEN......: 40.000| 301.000| 114.800| 89.300| 7972.700| 4.600]
[BINS(c->s)..: 14,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 4,2,3,3,0,1,0,0,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,0,1,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1]
[IATS(ms)....: 0.9,1.0,0.8,1.8,4.7,6.0,7.0,6.8,7.3,7.3,5.7,6.0,6.2,6.2,5.9,5.6,6.1,6.4,7.2,6.9,5.8,5.8,6.0,5.9,6.0,6.0,6.1,6.1,5.9,5.9,6.3]
[PKTLENS.....: 52,50,40,50,50,96,51,63,300,300,51,97,51,159,50,116,51,63,301,301,50,116,50,116,59,153,59,209,59,153,59,299]
[ENTROPIES...: 4.2,4.7,4.5,4.3,4.6,4.5,4.3,4.1,1.4,1.4,4.3,4.8,4.3,2.8,4.3,3.9,4.2,4.1,7.8,7.8,4.4,3.9,4.4,3.9,4.1,3.9,4.2,3.1,4.2,2.4,4.2,2.7]
end: [.....1] [ip4][..tcp] [.192.168.63.100][.7718] -> [.192.168.63.253][..502] [Modbus.UMAS][Unknown][IoT-Scada][Acceptable]
DAEMON-EVENT: shutdown
|