Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-09-09 03:09:5625-09-09 03:10:0100:00:050 → 5
Maintaining25-09-09 03:10:0125-09-09 03:15:0100:05:005
Decreasing25-09-09 03:15:0125-09-09 03:15:0100:00:000 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 140 (+10) 0 10.95 (-0.41) 2 (-1) 62 (-13) 0.47 (+0.03) 0.00 (+0.00)
GET get_analysis_latest_cpe 141 (+6) 0 107.42 (+5.60) 35 (0) 217 (-214) 0.47 (+0.02) 0.00 (+0.00)
GET get_analysis_status 141 (+6) 0 7.21 (+0.59) 1 (0) 55 (0) 0.47 (+0.02) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 141 (+6) 0 601.55 (-36.54) 150 (-10) 1692 (-128) 0.47 (+0.02) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 141 (+8) 0 830.57 (+3.21) 496 (+135) 1207 (-76) 0.47 (+0.03) 0.00 (+0.00)
GET list_advisory 141 (+11) 0 477.30 (+6.38) 296 (+146) 1316 (+288) 0.47 (+0.04) 0.00 (+0.00)
GET list_advisory_paginated 140 (+10) 0 429.60 (+30.70) 237 (+58) 783 (+31) 0.47 (+0.03) 0.00 (+0.00)
GET list_importer 140 (+10) 0 4.78 (+1.88) 1 (0) 51 (+4) 0.47 (+0.03) 0.00 (+0.00)
GET list_organizations 141 (+11) 0 9.08 (+2.01) 1 (0) 50 (+6) 0.47 (+0.04) 0.00 (+0.00)
GET list_packages 140 (+10) 0 384.32 (-14.76) 95 (+2) 896 (-63) 0.47 (+0.03) 0.00 (+0.00)
GET list_packages_paginated 140 (+10) 0 351.66 (+18.23) 97 (-8) 603 (+10) 0.47 (+0.03) 0.00 (+0.00)
GET list_products 144 (+9) 0 7.11 (+0.47) 2 (-2) 58 (-17) 0.48 (+0.03) 0.00 (+0.00)
GET list_sboms 144 (+9) 0 1100.18 (+124.89) 477 (+8) 1606 (+274) 0.48 (+0.03) 0.00 (+0.00)
GET list_sboms_paginated 143 (+8) 0 1445.74 (+217.41) 409 (+25) 3084 (+208) 0.48 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities 140 (+10) 0 227.29 (-40.95) 57 (0) 385 (-185) 0.47 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities_paginated 140 (+10) 0 188.69 (+9.62) 44 (+16) 301 (-4) 0.47 (+0.03) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 141 (+8) 0 53.55 (+7.23) 10 (+1) 182 (+16) 0.47 (+0.03) 0.00 (+0.00)
GET search_advisory 140 (+10) 0 1014.73 (+78.16) 389 (+253) 2322 (+208) 0.47 (+0.03) 0.00 (+0.00)
GET search_exact_purl 144 (+9) 0 6.94 (+2.92) 2 (0) 56 (+47) 0.48 (+0.03) 0.00 (+0.00)
GET search_purls 145 (+10) 0 2709.31 (-1228.40) 579 (-29) 8004 (+2208) 0.48 (+0.03) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 141 (+11) 0 636.11 (+88.45) 238 (-15) 1103 (+180) 0.47 (+0.04) 0.00 (+0.00)
Aggregated 2968 (+192) 0 508.64 (-35.19) 1 (0) 8004 (+2208) 9.89 (+0.64) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (0) 7 (0) 9 (+1) 13 (+2) 21 (-7) 49 (-3) 57 (-8) 62 (-13)
GET get_analysis_latest_cpe 99 (+9) 110 (+13) 110 (0) 140 (+20) 170 (0) 180 (0) 210 (0) 217 (-213)
GET get_analysis_status 3 (+1) 3 (+1) 4 (+1) 5 (+1) 9 (0) 47 (0) 54 (+1) 55 (0)
GET get_sbom[sha256:720e4451…a939656247164447] 370 (-40) 410 (-80) 430 (-270) 1,000 (0) 1,000 (0) 1,692 (-128) 1,692 (-128) 1,692 (-128)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (0) 900 (0) 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 460 (0) 480 (+10) 490 (0) 500 (0) 600 (0) 600 (-200) 1,000 (0) 1,000 (0)
GET list_advisory_paginated 420 (+30) 440 (+30) 470 (+40) 480 (0) 500 (0) 600 (0) 700 (+100) 783 (+31)
GET list_importer 2 (0) 3 (+1) 3 (+1) 4 (+1) 7 (+2) 9 (+3) 51 (+10) 51 (+4)
GET list_organizations 3 (0) 5 (+2) 6 (+2) 9 (+2) 37 (+14) 43 (+4) 47 (+3) 50 (+6)
GET list_packages 380 (-40) 400 (-40) 410 (-60) 430 (-50) 480 (-20) 700 (+100) 896 (+96) 896 (-63)
GET list_packages_paginated 360 (-10) 380 (-10) 390 (-10) 410 (-10) 470 (0) 500 (+10) 600 (+100) 600 (+7)
GET list_products 5 (0) 6 (0) 7 (+1) 8 (+1) 10 (+2) 13 (+4) 54 (-14) 58 (-17)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,606 (+606) 1,606 (+606)
GET list_sboms_paginated 1,000 (0) 2,000 (+1,000) 2,000 (+1,000) 2,000 (0) 2,000 (0) 2,000 (0) 3,000 (+124) 3,000 (+124)
GET list_vulnerabilities 220 (-60) 230 (-70) 260 (-60) 280 (-90) 290 (-120) 310 (-140) 350 (-150) 385 (-185)
GET list_vulnerabilities_paginated 190 (0) 200 (0) 200 (-10) 210 (-10) 260 (0) 270 (0) 290 (+10) 300 (-5)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 54 (+30) 64 (+6) 70 (+6) 80 (+8) 110 (+29) 150 (+40) 170 (+10) 180 (+14)
GET search_advisory 800 (0) 1,000 (+100) 1,000 (0) 1,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 4 (0) 4 (0) 5 (+1) 6 (+1) 9 (+4) 42 (+36) 55 (+47) 56 (+47)
GET search_purls 3,000 (-1,000) 3,000 (-1,000) 3,000 (-2,000) 4,000 (-1,000) 4,000 (-1,000) 5,000 (0) 7,000 (+2,000) 8,000 (+2,204)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (+100) 700 (+100) 700 (+100) 800 (+100) 900 (+100) 1,000 (+200) 1,000 (+100) 1,000 (+100)
Aggregated 290 (-10) 400 (0) 500 (0) 800 (0) 1,000 (0) 2,000 (0) 4,000 (-1,000) 8,000 (+2,204)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 140 [200]
GET get_analysis_latest_cpe 141 [200]
GET get_analysis_status 141 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 141 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 141 [200]
GET list_advisory 141 [200]
GET list_advisory_paginated 140 [200]
GET list_importer 140 [200]
GET list_organizations 141 [200]
GET list_packages 140 [200]
GET list_packages_paginated 140 [200]
GET list_products 144 [200]
GET list_sboms 144 [200]
GET list_sboms_paginated 143 [200]
GET list_vulnerabilities 140 [200]
GET list_vulnerabilities_paginated 140 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 141 [200]
GET search_advisory 140 [200]
GET search_exact_purl 144 [200]
GET search_purls 145 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 141 [200]
Aggregated 2,968 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 141 (+11) 0 (0) 14.07 (-0.28) 7 (0) 23 (-2) 0.47 (+0.04) 0.00 (+0.00)
1.1 list_organizations 141 (+11) 0 (0) 9.26 (+1.99) 1 (0) 50 (+6) 0.47 (+0.04) 0.00 (+0.00)
1.2 list_advisory 141 (+11) 0 (0) 477.39 (+6.39) 296 (+146) 1316 (+288) 0.47 (+0.04) 0.00 (+0.00)
1.3 list_advisory_paginated 140 (+10) 0 (0) 429.66 (+30.71) 237 (+58) 783 (+31) 0.47 (+0.03) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 140 (+10) 0 (0) 11.00 (-0.44) 2 (-1) 62 (-14) 0.47 (+0.03) 0.00 (+0.00)
1.5 search_advisory 140 (+10) 0 (0) 1014.76 (+78.12) 389 (+253) 2322 (+208) 0.47 (+0.03) 0.00 (+0.00)
1.6 list_vulnerabilities 140 (+10) 0 (0) 227.35 (-40.97) 57 (0) 386 (-184) 0.47 (+0.03) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 140 (+10) 0 (0) 188.80 (+9.68) 44 (+16) 302 (-3) 0.47 (+0.03) 0.00 (+0.00)
1.8 list_importer 140 (+10) 0 (0) 4.80 (+1.87) 1 (0) 51 (+4) 0.47 (+0.03) 0.00 (+0.00)
1.9 list_packages 140 (+10) 0 (0) 384.36 (-14.77) 95 (+2) 896 (-64) 0.47 (+0.03) 0.00 (+0.00)
1.10 list_packages_paginated 140 (+10) 0 (0) 351.69 (+18.20) 97 (-8) 603 (+10) 0.47 (+0.03) 0.00 (+0.00)
1.11 search_purls 145 (+10) 0 (0) 2709.34 (-1228.42) 579 (-29) 8004 (+2208) 0.48 (+0.03) 0.00 (+0.00)
1.12 search_exact_purl 144 (+9) 0 (0) 6.99 (+2.93) 2 (0) 56 (+47) 0.48 (+0.03) 0.00 (+0.00)
1.13 list_products 144 (+9) 0 (0) 7.12 (+0.41) 2 (-2) 58 (-17) 0.48 (+0.03) 0.00 (+0.00)
1.14 list_sboms 144 (+9) 0 (0) 1100.24 (+124.90) 477 (+8) 1606 (+274) 0.48 (+0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 143 (+8) 0 (0) 1445.81 (+217.44) 409 (+25) 3084 (+208) 0.48 (+0.03) 0.00 (+0.00)
1.16 get_analysis_status 141 (+6) 0 (0) 7.25 (+0.57) 1 (0) 55 (0) 0.47 (+0.02) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 141 (+6) 0 (0) 107.50 (+5.64) 35 (0) 217 (-214) 0.47 (+0.02) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 141 (+6) 0 (0) 601.64 (-36.55) 150 (-10) 1692 (-128) 0.47 (+0.02) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 141 (+8) 0 (0) 53.61 (+7.24) 10 (0) 182 (+16) 0.47 (+0.03) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 141 (+8) 0 (0) 830.65 (+3.18) 496 (+135) 1207 (-76) 0.47 (+0.03) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 141 (+11) 0 (0) 636.16 (+88.46) 238 (-15) 1103 (+180) 0.47 (+0.04) 0.00 (+0.00)
Aggregated 3,109 (+203) 0 (0) 485.57 (-33.93) 1 (0) 8004 (+2208) 10.36 (+0.68) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 141 (+11) 10580.80 (-734.03) 7121 (+438) 12916 (-2279) 0.47 (+0.04) 28.20 (+2.20)
Aggregated 5 (0) 141 (+11) 10580.80 (-734.03) 7121 (+438) 12916 (-2279) 0.47 (+0.04) 28.20 (+2.20)

User Metrics