nDPI/tests/cfgs/default/result/false_positives2.pcapng.out
Luca Deri 851703b8bb Exteded Slowloris detection to TLS/QUIC
DoS latency reported in sec (used to be ms)
2026-01-18 11:44:39 +01:00

41 lines
3.2 KiB
Text

DPI Packets (TCP): 61 (20.33 pkts/flow)
Confidence Unknown : 3 (flows)
Num dissector calls: 703 (234.33 diss/flow)
LRU cache ookla: 0/0/0 (insert/search/found)
LRU cache bittorrent: 0/9/0 (insert/search/found)
LRU cache stun: 0/0/0 (insert/search/found)
LRU cache tls_cert: 0/0/0 (insert/search/found)
LRU cache mining: 0/3/0 (insert/search/found)
LRU cache msteams: 0/0/0 (insert/search/found)
LRU cache fpc_dns: 0/3/0 (insert/search/found)
Automa host: 0/0 (search/found)
Automa domain: 0/0 (search/found)
Automa tls cert: 0/0 (search/found)
Automa risk mask: 0/0 (search/found)
Automa common alpns: 0/0 (search/found)
Patricia risk mask: 0/0 (search/found)
Patricia risk mask IPv6: 0/0 (search/found)
Patricia risk: 0/0 (search/found)
Patricia risk IPv6: 0/0 (search/found)
Patricia protocols: 6/0 (search/found)
Patricia protocols IPv6: 0/0 (search/found)
Hash malicious ja4: 0/0 (search/found)
Hash malicious sha1: 0/0 (search/found)
Hash TCP fingerprints: 3/0 (search/found)
Hash public domain suffix: 0/0 (search/found)
Hash ja4 custom protos: 0/0 (search/found)
Hash fp custom protos: 0/0 (search/found)
Hash url custom protos: 0/0 (search/found)
Unknown 82 58035 3
Unrated 82 58035 3
Unspecified 82 58035 3
Undetected flows:
1 TCP 127.0.0.1:54900 <-> 127.0.0.1:1234 [proto: 0/Unknown][Stack: Unknown][IP: 0/Unknown][ClearText][Confidence: Unknown][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 27][Breed: Unrated][23 pkts/4536 bytes <-> 25 pkts/36959 bytes][Goodput ratio: 65/95][140.47 sec][bytes ratio: -0.781 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 7803/22 139814/295 32017/65][Pkt Len c2s/s2c min/avg/max/stddev: 68/68 197/1478 866/9429 234/2245][Risk: ** (Possible) Slow DoS **][Risk Score: 100][Risk Info: Slow TCP 3WH (ACK): 140.1 sec][TCP Fingerprint: 2_64_65495_db1b9381215d/Unknown][PLAIN TEXT (StFJbE.l)][Plen Bins: 0,0,0,13,4,0,13,0,0,0,8,0,0,4,0,0,0,0,4,0,0,0,0,0,8,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,34]
2 TCP 127.0.0.1:49996 <-> 127.0.0.1:1234 [proto: 0/Unknown][Stack: Unknown][IP: 0/Unknown][ClearText][Confidence: Unknown][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 19][Breed: Unrated][10 pkts/2323 bytes <-> 9 pkts/7085 bytes][Goodput ratio: 70/91][0.11 sec][bytes ratio: -0.506 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 13/14 79/79 25/27][Pkt Len c2s/s2c min/avg/max/stddev: 68/68 232/787 856/2116 289/942][TCP Fingerprint: 2_64_65495_db1b9381215d/Unknown][Plen Bins: 0,0,11,22,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,33]
3 TCP 127.0.0.1:33550 <-> 127.0.0.1:1234 [proto: 0/Unknown][Stack: Unknown][IP: 0/Unknown][ClearText][Confidence: Unknown][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 15][Breed: Unrated][8 pkts/1346 bytes <-> 7 pkts/5786 bytes][Goodput ratio: 59/92][2.18 sec][bytes ratio: -0.623 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 363/12 1127/43 497/18][Pkt Len c2s/s2c min/avg/max/stddev: 68/68 168/827 862/2116 262/911][TCP Fingerprint: 2_64_65495_db1b9381215d/Unknown][Plen Bins: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,25,0,0,0,0,0,0,0,0,0,0,0,0,25,0,0,0,0,0,0,0,0,0,50]