1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443]
detected: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Video][Acceptable]
RISK: TLS (probably) Not Carrying HTTPS
detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Video][Acceptable]
RISK: TLS (probably) Not Carrying HTTPS
detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Video][Acceptable]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Video][Acceptable]
[min|max|avg|stddev]
[IAT(flow)...: 0.000| 0.199| 0.059| 0.083]
[IAT(c->s)...: 0.000| 0.182| 0.057| 0.080][IAT(s->c)...: 0.000| 0.199| 0.061| 0.086]
[PKTLEN(c->s): 66.000|1506.000| 243.400| 372.600][PKTLEN(s->c): 66.000|1506.000| 714.700| 603.300]
[BINS(c->s)..: 11,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0]
[BINS(s->c)..: 3,1,1,0,1,0,1,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,2,0,0,0,0,0,3,0,0]
new: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801]
analyse: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801]
[min|max|avg|stddev]
[IAT(flow)...: 0.000| 0.167| 0.025| 0.040]
[IAT(c->s)...: 0.012| 0.102| 0.072| 0.036][IAT(s->c)...: 0.000| 0.167| 0.018| 0.036]
[PKTLEN(c->s): 165.000| 170.000| 168.000| 2.400][PKTLEN(s->c): 60.000|1078.000| 820.700| 435.100]
[BINS(c->s)..: 0,0,0,2,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 2,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,20,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
guessed: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
detected: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
new: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801]
new: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801]
analyse: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801]
[min|max|avg|stddev]
[IAT(flow)...: 0.000| 0.176| 0.043| 0.049]
[IAT(c->s)...: 0.000| 0.168| 0.060| 0.053][IAT(s->c)...: 0.000| 0.176| 0.033| 0.044]
[PKTLEN(c->s): 130.000| 203.000| 166.200| 16.000][PKTLEN(s->c): 60.000| 178.000| 129.100| 37.100]
[BINS(c->s)..: 0,0,1,6,4,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 2,5,3,8,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
guessed: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
detected: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
analyse: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801]
[min|max|avg|stddev]
[IAT(flow)...: 0.000| 0.188| 0.047| 0.043]
[IAT(c->s)...: 0.000| 0.106| 0.052| 0.034][IAT(s->c)...: 0.000| 0.188| 0.042| 0.049]
[PKTLEN(c->s): 69.000| 185.000| 125.800| 53.300][PKTLEN(s->c): 60.000| 117.000| 86.900| 23.200]
[BINS(c->s)..: 7,0,0,2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 9,2,6,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
guessed: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
detected: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
new: [.....5] [ip4][.icmp] [..192.168.1.178] -> [.144.195.73.154]
detected: [.....5] [ip4][.icmp] [..192.168.1.178] -> [.144.195.73.154] [ICMP][Network][Acceptable]
idle: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
end: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Video][Acceptable]
RISK: TLS (probably) Not Carrying HTTPS
idle: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
idle: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] [Zoom][Video][Acceptable]
idle: [.....5] [ip4][.icmp] [..192.168.1.178] -> [.144.195.73.154] [ICMP][Network][Acceptable]
DAEMON-EVENT: shutdown
|