aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/openvpn_heuristic_enabled/openvpn_obfuscated.pcapng.out
blob: d7b5b13070561ca3f6546532abe894df53c3e374 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
     DAEMON-EVENT: init
     DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
     DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
              new: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465]
          analyse: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465]
                                         min|       max|       avg|    stddev|         variance|  entropy
                   [IAT.........: <    0.001|     1.020|     0.080|     0.242|        58469.183|    2.300]
                   [PKTLEN......:     52.000|  1500.000|   308.700|   431.500|       186180.000|    4.000]
                   [BINS(c->s)..: 7,0,1,3,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 7,0,0,4,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0]
                   [DIRECTIONS..: 0,1,0,0,1,1,0,0,1,1,1,1,0,0,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,1]
                   [IATS(ms)....: 20.0,22.1,6.2,28.1,0.0,21.2,1.0,26.3,0.0,0.0,0.0,28.0,0.1,0.2,23.6,57.5,41.8,4.8,15.8,16.4,4.9,7.9,24.7,0.5,24.0,23.3,24.7,66.8,1019.8,977.6,0.7]
                   [PKTLENS.....: 60,60,52,140,52,152,52,429,148,1500,1500,1500,52,52,152,164,52,52,376,873,52,52,801,52,310,172,395,176,52,199,52,148]
                   [ENTROPIES...: 4.7,5.2,5.1,6.5,5.1,6.6,5.1,7.3,6.6,7.9,7.9,7.9,5.0,5.1,6.5,6.7,5.1,5.1,7.3,7.8,5.1,5.1,7.7,5.2,7.3,6.7,7.5,6.5,5.1,6.9,5.1,6.5]
          guessed: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465] [SMTPS][NordVPN][Email][Safe]
                   RISK: Fully Encrypted Flow
              new: [.....2] [ip4][..udp] [.192.168.12.156][47128] -> [149.102.238.108][.1214]
     DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0]
     DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 0]
              new: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072]
          analyse: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072]
                                         min|       max|       avg|    stddev|         variance|  entropy
                   [IAT.........: <    0.001|     0.303|     0.045|     0.076|         5806.697|    3.500]
                   [PKTLEN......:     52.000|   152.000|    67.300|    23.700|          562.800|    4.900]
                   [BINS(c->s)..: 9,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 19,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,1,1,1,1,1,1,1,1,1,1,1,0,1,1,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,0]
                   [IATS(ms)....: 102.1,4.8,6.5,5.5,5.4,5.3,5.7,5.4,5.2,5.6,5.1,255.6,100.3,15.6,143.0,32.7,143.0,0.0,303.0,27.7,1.3,5.4,5.4,5.7,6.7,5.0,142.9,27.8,1.2,5.5,5.5]
                   [PKTLENS.....: 60,52,61,61,61,61,61,61,61,61,61,59,64,88,58,80,80,52,152,98,52,59,59,59,59,59,59,52,148,52,52,52]
                   [ENTROPIES...: 5.3,5.2,5.4,5.5,5.4,5.4,5.5,5.4,5.5,5.4,5.2,5.1,5.2,5.9,5.3,5.2,5.1,5.2,6.3,5.7,5.2,5.3,5.3,5.4,5.3,5.4,5.3,5.2,6.4,5.1,5.2,5.3]
          guessed: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072] [TLS][Unknown][Web][Safe]
             idle: [.....3] [ip4][..tcp] [.107.161.86.131][..443] -> [.192.168.12.156][48072] [TLS][Unknown][Web][Safe]
             idle: [.....1] [ip4][..tcp] [.192.168.12.156][37976] -> [..185.128.25.99][..465] [SMTPS][NordVPN][Email][Safe]
                   RISK: Fully Encrypted Flow
          guessed: [.....2] [ip4][..udp] [.192.168.12.156][47128] -> [149.102.238.108][.1214] [NordVPN][NordVPN][VPN][Acceptable]
                   RISK: Susp Entropy
             idle: [.....2] [ip4][..udp] [.192.168.12.156][47128] -> [149.102.238.108][.1214]
     DAEMON-EVENT: shutdown