Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-09-07 03:12:3925-09-07 03:12:4400:00:050 → 5
Maintaining25-09-07 03:12:4425-09-07 03:17:4400:05:005
Decreasing25-09-07 03:17:4425-09-07 03:17:4500:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 140 (+75) 0 11.26 (+0.78) 2 (-1) 64 (+5) 0.47 (+0.25) 0.00 (+0.00)
GET get_analysis_latest_cpe 140 (+75) 0 121.93 (-15.64) 28 (-3) 381 (+73) 0.47 (+0.25) 0.00 (+0.00)
GET get_analysis_status 140 (+75) 0 6.02 (+0.84) 1 (0) 54 (+1) 0.47 (+0.25) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 140 (+75) 0 717.25 (-71.01) 153 (-64) 1929 (+219) 0.47 (+0.25) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 140 (+75) 0 796.29 (+22.71) 308 (-102) 1076 (+66) 0.47 (+0.25) 0.00 (+0.00)
GET list_advisory 140 (+75) 0 495.99 (+40.00) 217 (-4) 950 (+242) 0.47 (+0.25) 0.00 (+0.00)
GET list_advisory_paginated 140 (+75) 0 432.42 (-8.33) 138 (-50) 731 (-571) 0.47 (+0.25) 0.00 (+0.00)
GET list_importer 140 (+75) 0 5.42 (+0.68) 1 (0) 53 (+2) 0.47 (+0.25) 0.00 (+0.00)
GET list_organizations 140 (+75) 0 6.99 (-0.56) 1 (0) 51 (+3) 0.47 (+0.25) 0.00 (+0.00)
GET list_packages 140 (+75) 0 442.71 (+14.65) 77 (-123) 916 (+6) 0.47 (+0.25) 0.00 (+0.00)
GET list_packages_paginated 140 (+75) 0 365.89 (+8.23) 99 (+42) 683 (+82) 0.47 (+0.25) 0.00 (+0.00)
GET list_products 140 (+70) 0 6.95 (-0.08) 2 (-2) 57 (+44) 0.47 (+0.23) 0.00 (+0.00)
GET list_sboms 140 (+70) 0 1100.99 (-158.17) 578 (+57) 1681 (-184) 0.47 (+0.23) 0.00 (+0.00)
GET list_sboms_paginated 140 (+70) 0 1390.45 (-350.45) 472 (+11) 2801 (-305) 0.47 (+0.23) 0.00 (+0.00)
GET list_vulnerabilities 140 (+75) 0 228.40 (-23.17) 37 (-55) 386 (-91) 0.47 (+0.25) 0.00 (+0.00)
GET list_vulnerabilities_paginated 140 (+75) 0 181.00 (+11.66) 27 (-50) 363 (+92) 0.47 (+0.25) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 140 (+75) 0 49.44 (-27.01) 10 (+1) 181 (+3) 0.47 (+0.25) 0.00 (+0.00)
GET search_advisory 140 (+75) 0 952.91 (-32.70) 145 (-169) 2383 (+311) 0.47 (+0.25) 0.00 (+0.00)
GET search_exact_purl 140 (+70) 0 6.81 (-21.42) 2 (-18) 53 (+2) 0.47 (+0.23) 0.00 (+0.00)
GET search_purls 145 (+75) 0 2854.67 (-10727.20) 1501 (-4623) 5715 (-10433) 0.48 (+0.25) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 140 (+75) 0 536.69 (-19.64) 231 (-7) 979 (+66) 0.47 (+0.25) 0.00 (+0.00)
Aggregated 2945 (+1555) 0 514.00 (-577.65) 1 (0) 5715 (-10433) 9.82 (+5.18) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (+1) 7 (0) 8 (0) 9 (0) 43 (+11) 52 (+7) 57 (-1) 64 (+5)
GET get_analysis_latest_cpe 99 (-21) 120 (-20) 150 (-20) 190 (0) 210 (-10) 220 (-50) 310 (+30) 380 (+72)
GET get_analysis_status 2 (0) 3 (+1) 4 (+1) 5 (+1) 8 (+1) 46 (+12) 52 (0) 54 (+1)
GET get_sbom[sha256:720e4451…a939656247164447] 500 (-200) 600 (-100) 700 (-100) 1,000 (0) 1,000 (-710) 1,929 (+219) 1,929 (+219) 1,929 (+219)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (0) 900 (+100) 900 (0) 900 (0) 1,000 (+100) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 480 (+20) 490 (+30) 500 (+30) 500 (+10) 600 (+100) 800 (+200) 900 (+300) 950 (+250)
GET list_advisory_paginated 430 (+10) 460 (+10) 480 (0) 500 (0) 600 (+100) 600 (0) 700 (0) 700 (-300)
GET list_importer 2 (0) 3 (+1) 3 (0) 4 (0) 7 (0) 43 (+32) 49 (0) 53 (+2)
GET list_organizations 3 (0) 5 (+1) 6 (-1) 9 (-2) 14 (-3) 25 (-8) 45 (+2) 51 (+3)
GET list_packages 430 (+50) 450 (+60) 470 (+40) 500 (+10) 700 (-100) 800 (-100) 800 (-100) 900 (0)
GET list_packages_paginated 390 (0) 400 (-10) 430 (+10) 470 (0) 500 (+10) 500 (0) 600 (+100) 683 (+83)
GET list_products 5 (-2) 5 (-2) 6 (-2) 8 (0) 10 (0) 10 (-2) 54 (+42) 57 (+44)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-865) 1,000 (-865) 1,681 (-184) 1,681 (-184)
GET list_sboms_paginated 1,000 (-1,000) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (-1,000) 2,000 (-1,000) 2,801 (-199) 2,801 (-199)
GET list_vulnerabilities 220 (-40) 240 (-20) 270 (-10) 280 (-40) 300 (-60) 310 (-80) 350 (-100) 386 (-91)
GET list_vulnerabilities_paginated 180 (+10) 190 (+10) 200 (+10) 210 (+10) 260 (+50) 270 (+40) 300 (+30) 360 (+90)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 24 (-51) 47 (-38) 67 (-43) 89 (-21) 110 (-20) 130 (-30) 170 (0) 180 (+2)
GET search_advisory 700 (-200) 900 (-100) 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 4 (-23) 4 (-24) 5 (-23) 5 (-28) 7 (-29) 44 (-5) 50 (0) 53 (+2)
GET search_purls 2,000 (-12,000) 2,000 (-12,000) 3,000 (-12,000) 4,000 (-11,000) 5,000 (-10,000) 5,000 (-10,000) 5,715 (-9,285) 5,715 (-10,285)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 480 (-120) 500 (-100) 600 (0) 700 (+100) 800 (0) 800 (0) 979 (+79) 979 (+79)
Aggregated 300 (0) 430 (0) 500 (0) 800 (0) 1,000 (-1,000) 2,000 (-4,000) 4,000 (-11,000) 5,715 (-10,285)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 140 [200]
GET get_analysis_latest_cpe 140 [200]
GET get_analysis_status 140 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 140 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 140 [200]
GET list_advisory 140 [200]
GET list_advisory_paginated 140 [200]
GET list_importer 140 [200]
GET list_organizations 140 [200]
GET list_packages 140 [200]
GET list_packages_paginated 140 [200]
GET list_products 140 [200]
GET list_sboms 140 [200]
GET list_sboms_paginated 140 [200]
GET list_vulnerabilities 140 [200]
GET list_vulnerabilities_paginated 140 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 140 [200]
GET search_advisory 140 [200]
GET search_exact_purl 140 [200]
GET search_purls 145 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 140 [200]
Aggregated 2,945 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 140 (+75) 0 (0) 14.04 (+0.42) 8 (+1) 23 (0) 0.47 (+0.25) 0.00 (+0.00)
1.1 list_organizations 140 (+75) 0 (0) 7.17 (-0.51) 1 (0) 51 (+3) 0.47 (+0.25) 0.00 (+0.00)
1.2 list_advisory 140 (+75) 0 (0) 496.05 (+40.00) 217 (-4) 950 (+242) 0.47 (+0.25) 0.00 (+0.00)
1.3 list_advisory_paginated 140 (+75) 0 (0) 432.45 (-8.32) 138 (-50) 731 (-571) 0.47 (+0.25) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 140 (+75) 0 (0) 11.29 (+0.75) 2 (-1) 64 (+5) 0.47 (+0.25) 0.00 (+0.00)
1.5 search_advisory 140 (+75) 0 (0) 952.96 (-32.70) 145 (-169) 2383 (+311) 0.47 (+0.25) 0.00 (+0.00)
1.6 list_vulnerabilities 140 (+75) 0 (0) 228.50 (-23.13) 37 (-55) 386 (-91) 0.47 (+0.25) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 140 (+75) 0 (0) 181.04 (+11.64) 27 (-50) 363 (+92) 0.47 (+0.25) 0.00 (+0.00)
1.8 list_importer 140 (+75) 0 (0) 5.43 (+0.67) 1 (0) 53 (+2) 0.47 (+0.25) 0.00 (+0.00)
1.9 list_packages 140 (+75) 0 (0) 442.77 (+14.68) 77 (-123) 916 (+6) 0.47 (+0.25) 0.00 (+0.00)
1.10 list_packages_paginated 140 (+75) 0 (0) 365.98 (+8.29) 99 (+42) 684 (+83) 0.47 (+0.25) 0.00 (+0.00)
1.11 search_purls 145 (+75) 0 (0) 2854.72 (-10727.16) 1501 (-4623) 5715 (-10433) 0.48 (+0.25) 0.00 (+0.00)
1.12 search_exact_purl 140 (+70) 0 (0) 6.82 (-21.45) 2 (-18) 53 (+2) 0.47 (+0.23) 0.00 (+0.00)
1.13 list_products 140 (+70) 0 (0) 6.95 (-0.11) 2 (-2) 57 (+44) 0.47 (+0.23) 0.00 (+0.00)
1.14 list_sboms 140 (+70) 0 (0) 1101.05 (-158.18) 578 (+57) 1681 (-184) 0.47 (+0.23) 0.00 (+0.00)
1.15 list_sboms_paginated 140 (+70) 0 (0) 1390.52 (-350.39) 473 (+12) 2801 (-305) 0.47 (+0.23) 0.00 (+0.00)
1.16 get_analysis_status 140 (+75) 0 (0) 6.11 (+0.91) 1 (0) 54 (+1) 0.47 (+0.25) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 140 (+75) 0 (0) 121.97 (-15.71) 28 (-3) 381 (+73) 0.47 (+0.25) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 140 (+75) 0 (0) 717.31 (-70.97) 153 (-64) 1929 (+219) 0.47 (+0.25) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 140 (+75) 0 (0) 49.51 (-27.03) 10 (+1) 181 (+3) 0.47 (+0.25) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 140 (+75) 0 (0) 796.31 (+22.66) 308 (-102) 1076 (+65) 0.47 (+0.25) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 140 (+75) 0 (0) 536.73 (-19.64) 231 (-7) 979 (+66) 0.47 (+0.25) 0.00 (+0.00)
Aggregated 3,085 (+1,630) 0 (0) 490.68 (-552.21) 1 (0) 5715 (-10433) 10.28 (+5.43) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 140 (+75) 10682.40 (-11125.74) 5890 (-3921) 14984 (-10776) 0.47 (+0.25) 28.00 (+15.00)
Aggregated 5 (0) 140 (+75) 10682.40 (-11125.74) 5890 (-3921) 14984 (-10776) 0.47 (+0.25) 28.00 (+15.00)

User Metrics