Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-09-12 02:15:0325-09-12 02:15:0800:00:050 → 5
Maintaining25-09-12 02:15:0825-09-12 02:20:0800:05:005
Decreasing25-09-12 02:20:0825-09-12 02:20:0900:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 70 (+5) 0 12.71 (-0.44) 3 (0) 71 (+10) 0.23 (+0.02) 0.00 (+0.00)
GET get_analysis_latest_cpe 70 (+5) 0 117.03 (-30.96) 33 (+4) 209 (-189) 0.23 (+0.02) 0.00 (+0.00)
GET get_analysis_status 70 (+5) 0 5.13 (-1.09) 1 (0) 50 (-3) 0.23 (+0.02) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 70 (+5) 0 666.46 (-99.76) 203 (-1) 1967 (-49) 0.23 (+0.02) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 70 (+5) 0 828.47 (+11.33) 333 (-89) 1210 (-370) 0.23 (+0.02) 0.00 (+0.00)
GET list_advisory 70 (+5) 0 489.04 (-2.03) 207 (-56) 811 (-240) 0.23 (+0.02) 0.00 (+0.00)
GET list_advisory_paginated 70 (+5) 0 410.29 (-17.58) 141 (-52) 684 (+81) 0.23 (+0.02) 0.00 (+0.00)
GET list_importer 70 (+5) 0 4.83 (+2.44) 1 (0) 56 (+47) 0.23 (+0.02) 0.00 (+0.00)
GET list_organizations 70 (+5) 0 4.33 (-3.13) 1 (0) 39 (-13) 0.23 (+0.02) 0.00 (+0.00)
GET list_packages 70 (+5) 0 484.16 (-74.23) 98 (-281) 972 (-1116) 0.23 (+0.02) 0.00 (+0.00)
GET list_packages_paginated 70 (+5) 0 443.20 (-12.54) 113 (-91) 983 (-75) 0.23 (+0.02) 0.00 (+0.00)
GET list_products 75 (+10) 0 6.88 (-0.86) 3 (0) 42 (+25) 0.25 (+0.03) 0.00 (+0.00)
GET list_sboms 75 (+10) 0 1090.20 (-1.78) 606 (+35) 1823 (-129) 0.25 (+0.03) 0.00 (+0.00)
GET list_sboms_paginated 70 (+5) 0 1322.33 (-98.98) 478 (-18) 3580 (+694) 0.23 (+0.02) 0.00 (+0.00)
GET list_vulnerabilities 70 (+5) 0 288.49 (-5.64) 51 (-18) 578 (+149) 0.23 (+0.02) 0.00 (+0.00)
GET list_vulnerabilities_paginated 70 (+5) 0 170.96 (-25.83) 39 (-75) 311 (+34) 0.23 (+0.02) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 70 (+5) 0 56.16 (+0.86) 9 (0) 210 (+19) 0.23 (+0.02) 0.00 (+0.00)
GET search_advisory 70 (+5) 0 836.79 (-142.45) 131 (-152) 1692 (-529) 0.23 (+0.02) 0.00 (+0.00)
GET search_exact_purl 75 (+10) 0 7.15 (+0.36) 5 (+1) 54 (+41) 0.25 (+0.03) 0.00 (+0.00)
GET search_purls 75 (+5) 0 12872.52 (-1656.21) 6293 (-651) 24512 (+6123) 0.25 (+0.02) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 70 (+5) 0 531.73 (-59.07) 297 (+19) 913 (-1) 0.23 (+0.02) 0.00 (+0.00)
Aggregated 1490 (+120) 0 1016.98 (-120.95) 1 (0) 24512 (+6123) 4.97 (+0.40) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (-1) 7 (-2) 9 (-2) 13 (-3) 46 (+3) 55 (-1) 56 (-4) 71 (+10)
GET get_analysis_latest_cpe 98 (-42) 110 (-60) 160 (-30) 180 (-30) 190 (-80) 200 (-90) 209 (-181) 209 (-189)
GET get_analysis_status 2 (0) 2 (-1) 3 (-1) 4 (0) 6 (-4) 42 (-4) 49 (-2) 50 (-3)
GET get_sbom[sha256:720e4451…a939656247164447] 480 (-220) 600 (-200) 700 (-200) 800 (-200) 1,000 (-1,000) 1,967 (-33) 1,967 (-33) 1,967 (-33)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 900 (+100) 900 (0) 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-580)
GET list_advisory 480 (+30) 500 (+30) 500 (+10) 600 (+100) 600 (-100) 700 (-300) 800 (-200) 800 (-200)
GET list_advisory_paginated 430 (+10) 450 (0) 470 (0) 490 (-10) 500 (-100) 600 (0) 684 (+84) 684 (+84)
GET list_importer 2 (0) 3 (+1) 4 (+1) 5 (+2) 8 (+4) 9 (+4) 45 (+38) 56 (+47)
GET list_organizations 3 (0) 3 (-1) 3 (-3) 5 (-2) 9 (-15) 14 (-22) 17 (-25) 39 (-13)
GET list_packages 470 (+20) 480 (+30) 490 (-10) 500 (-200) 600 (-300) 972 (-28) 972 (-28) 972 (-1,028)
GET list_packages_paginated 430 (+10) 440 (-30) 470 (-10) 490 (-10) 500 (-100) 900 (-100) 983 (-17) 983 (-17)
GET list_products 6 (-1) 7 (-1) 8 (-1) 8 (-2) 9 (-2) 10 (-3) 13 (-3) 42 (+25)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-952) 1,823 (-129) 1,823 (-129)
GET list_sboms_paginated 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 3,000 (+114) 3,580 (+694)
GET list_vulnerabilities 280 (-30) 290 (-40) 310 (-60) 340 (-50) 390 (-10) 440 (+20) 578 (+149) 578 (+149)
GET list_vulnerabilities_paginated 170 (-20) 180 (-10) 180 (-20) 190 (-30) 220 (-40) 270 (0) 310 (+40) 310 (+33)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 36 (0) 53 (-8) 63 (-10) 79 (-7) 140 (+20) 170 (+40) 210 (+40) 210 (+20)
GET search_advisory 800 (0) 900 (-100) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,692 (-308) 1,692 (-308) 1,692 (-308)
GET search_exact_purl 6 (0) 7 (0) 7 (0) 7 (-1) 8 (-1) 8 (-2) 10 (0) 54 (+41)
GET search_purls 13,000 (-2,000) 14,000 (-2,000) 14,000 (-2,000) 14,000 (-2,000) 16,000 (-1,000) 24,000 (+6,000) 24,000 (+6,000) 24,512 (+6,512)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 500 (-100) 600 (0) 600 (0) 600 (-100) 700 (-100) 800 (0) 900 (0) 900 (0)
Aggregated 330 (-40) 440 (0) 500 (-100) 800 (-100) 1,000 (0) 6,000 (-2,000) 14,000 (-2,000) 24,512 (+6,512)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 70 [200]
GET get_analysis_latest_cpe 70 [200]
GET get_analysis_status 70 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 70 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 70 [200]
GET list_advisory 70 [200]
GET list_advisory_paginated 70 [200]
GET list_importer 70 [200]
GET list_organizations 70 [200]
GET list_packages 70 [200]
GET list_packages_paginated 70 [200]
GET list_products 75 [200]
GET list_sboms 75 [200]
GET list_sboms_paginated 70 [200]
GET list_vulnerabilities 70 [200]
GET list_vulnerabilities_paginated 70 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 70 [200]
GET search_advisory 70 [200]
GET search_exact_purl 75 [200]
GET search_purls 75 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 70 [200]
Aggregated 1,490 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 70 (+5) 0 (0) 14.17 (-0.04) 8 (+1) 26 (+4) 0.23 (+0.02) 0.00 (+0.00)
1.1 list_organizations 70 (+5) 0 (0) 4.60 (-3.06) 1 (0) 39 (-13) 0.23 (+0.02) 0.00 (+0.00)
1.2 list_advisory 70 (+5) 0 (0) 489.10 (-2.01) 207 (-56) 811 (-240) 0.23 (+0.02) 0.00 (+0.00)
1.3 list_advisory_paginated 70 (+5) 0 (0) 410.36 (-17.57) 141 (-52) 684 (+81) 0.23 (+0.02) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 70 (+5) 0 (0) 12.76 (-0.46) 3 (0) 71 (+10) 0.23 (+0.02) 0.00 (+0.00)
1.5 search_advisory 70 (+5) 0 (0) 836.80 (-142.51) 131 (-152) 1692 (-529) 0.23 (+0.02) 0.00 (+0.00)
1.6 list_vulnerabilities 70 (+5) 0 (0) 288.54 (-5.63) 51 (-18) 578 (+149) 0.23 (+0.02) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 70 (+5) 0 (0) 171.06 (-25.74) 40 (-74) 311 (+34) 0.23 (+0.02) 0.00 (+0.00)
1.8 list_importer 70 (+5) 0 (0) 4.84 (+2.41) 1 (0) 56 (+47) 0.23 (+0.02) 0.00 (+0.00)
1.9 list_packages 70 (+5) 0 (0) 484.20 (-74.22) 98 (-281) 972 (-1116) 0.23 (+0.02) 0.00 (+0.00)
1.10 list_packages_paginated 70 (+5) 0 (0) 443.27 (-12.56) 113 (-92) 983 (-75) 0.23 (+0.02) 0.00 (+0.00)
1.11 search_purls 75 (+5) 0 (0) 12872.57 (-1656.18) 6293 (-651) 24512 (+6123) 0.25 (+0.02) 0.00 (+0.00)
1.12 search_exact_purl 75 (+10) 0 (0) 7.23 (+0.43) 5 (+1) 54 (+41) 0.25 (+0.03) 0.00 (+0.00)
1.13 list_products 75 (+10) 0 (0) 6.92 (-0.88) 3 (0) 42 (+25) 0.25 (+0.03) 0.00 (+0.00)
1.14 list_sboms 75 (+10) 0 (0) 1090.21 (-1.83) 606 (+35) 1823 (-129) 0.25 (+0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 70 (+5) 0 (0) 1322.37 (-98.95) 478 (-18) 3580 (+694) 0.23 (+0.02) 0.00 (+0.00)
1.16 get_analysis_status 70 (+5) 0 (0) 5.16 (-1.14) 1 (0) 50 (-4) 0.23 (+0.02) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 70 (+5) 0 (0) 117.03 (-31.08) 33 (+4) 209 (-189) 0.23 (+0.02) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 70 (+5) 0 (0) 666.53 (-99.73) 203 (-1) 1967 (-49) 0.23 (+0.02) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 70 (+5) 0 (0) 56.20 (+0.82) 9 (0) 210 (+19) 0.23 (+0.02) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 70 (+5) 0 (0) 828.54 (+11.28) 333 (-89) 1210 (-370) 0.23 (+0.02) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 70 (+5) 0 (0) 531.77 (-59.06) 297 (+19) 913 (-1) 0.23 (+0.02) 0.00 (+0.00)
Aggregated 1,560 (+125) 0 (0) 971.35 (-115.04) 1 (0) 24512 (+6123) 5.20 (+0.42) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 70 (+5) 20181.84 (-2620.62) 10070 (-599) 34609 (+6833) 0.23 (+0.02) 14.00 (+1.00)
Aggregated 5 (0) 70 (+5) 20181.84 (-2620.62) 10070 (-599) 34609 (+6833) 0.23 (+0.02) 14.00 (+1.00)

User Metrics