nDPI/tests/cfgs/default/result/tristation.pcap.out
2025-10-22 20:34:29 +02:00

46 lines
6.8 KiB
Text

DPI Packets (UDP): 11 (1.00 pkts/flow)
Confidence DPI : 11 (flows)
Num dissector calls: 11 (1.00 diss/flow)
LRU cache ookla: 0/0/0 (insert/search/found)
LRU cache bittorrent: 0/0/0 (insert/search/found)
LRU cache stun: 0/0/0 (insert/search/found)
LRU cache tls_cert: 0/0/0 (insert/search/found)
LRU cache mining: 0/0/0 (insert/search/found)
LRU cache msteams: 0/0/0 (insert/search/found)
LRU cache fpc_dns: 0/0/0 (insert/search/found)
Automa host: 0/0 (search/found)
Automa domain: 0/0 (search/found)
Automa tls cert: 0/0 (search/found)
Automa risk mask: 0/0 (search/found)
Automa common alpns: 0/0 (search/found)
Patricia risk mask: 0/0 (search/found)
Patricia risk mask IPv6: 0/0 (search/found)
Patricia risk: 0/0 (search/found)
Patricia risk IPv6: 0/0 (search/found)
Patricia protocols: 22/0 (search/found)
Patricia protocols IPv6: 0/0 (search/found)
Hash malicious ja4: 0/0 (search/found)
Hash malicious sha1: 0/0 (search/found)
Hash TCP fingerprints: 0/0 (search/found)
Hash public domain suffix: 0/0 (search/found)
Hash ja4 custom protos: 0/0 (search/found)
Hash fp custom protos: 0/0 (search/found)
Hash url custom protos: 0/0 (search/found)
TriStation 896 144336 11
Acceptable 896 144336 11
IoT-Scada 896 144336 11
1 UDP 192.168.1.88:33279 <-> 192.168.1.2:1502 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][443 pkts/26698 bytes <-> 443 pkts/115368 bytes][Goodput ratio: 30/84][435.39 sec][bytes ratio: -0.624 (Download)][IAT c2s/s2c min/avg/max/stddev: 134/11 981/980 5225/5230 1809/1810][Pkt Len c2s/s2c min/avg/max/stddev: 48/64 60/260 164/1092 7/167][PLAIN TEXT (NOZOMI)][Plen Bins: 60,3,1,5,0,3,25,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
2 UDP 192.168.1.11:1502 -> 192.168.1.88:33279 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/1092 bytes -> 0 pkts/0 bytes][Goodput ratio: 96/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
3 UDP 192.168.1.7:1502 -> 192.168.1.88:33279 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/380 bytes -> 0 pkts/0 bytes][Goodput ratio: 89/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 0,0,0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
4 UDP 192.168.1.5:1502 -> 192.168.1.88:33279 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/244 bytes -> 0 pkts/0 bytes][Goodput ratio: 82/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][PLAIN TEXT (NOZOMI)][Plen Bins: 0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
5 UDP 192.168.1.9:1502 -> 192.168.1.88:33279 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/168 bytes -> 0 pkts/0 bytes][Goodput ratio: 75/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
6 UDP 192.168.1.88:33279 -> 192.168.1.6:1502 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/66 bytes -> 0 pkts/0 bytes][Goodput ratio: 36/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
7 UDP 192.168.1.88:33279 -> 192.168.1.8:1502 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/66 bytes -> 0 pkts/0 bytes][Goodput ratio: 36/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
8 UDP 192.168.1.88:33279 -> 192.168.1.10:1502 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/66 bytes -> 0 pkts/0 bytes][Goodput ratio: 36/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
9 UDP 192.168.1.88:33279 -> 192.168.1.12:1502 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/66 bytes -> 0 pkts/0 bytes][Goodput ratio: 36/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
10 UDP 192.168.1.3:1502 -> 192.168.1.88:33279 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/64 bytes -> 0 pkts/0 bytes][Goodput ratio: 9/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
11 UDP 192.168.1.88:33279 -> 192.168.1.4:1502 [proto: 455/TriStation][Stack: TriStation][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 455/TriStation, Confidence: DPI][DPI packets: 1][cat: IoT-Scada/31][Breed: Acceptable][1 pkts/58 bytes -> 0 pkts/0 bytes][Goodput ratio: 27/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]