Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-09-23 02:18:3625-09-23 02:18:4100:00:050 → 5
Maintaining25-09-23 02:18:4125-09-23 02:23:4100:05:005
Decreasing25-09-23 02:23:4125-09-23 02:23:5000:00:090 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 85 (0) 0 12.01 (+2.28) 3 (0) 64 (+8) 0.28 (+0.00) 0.00 (+0.00)
GET get_analysis_latest_cpe 85 (-2) 0 140.81 (-21.00) 35 (-4) 271 (-116) 0.28 (-0.01) 0.00 (+0.00)
GET get_analysis_status 85 (-2) 0 6.72 (+0.74) 1 (0) 59 (+9) 0.28 (-0.01) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 85 (-2) 0 798.60 (-572.79) 197 (-113) 3118 (-723) 0.28 (-0.01) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 85 (-2) 0 842.65 (-87.11) 525 (-81) 1758 (+245) 0.28 (-0.01) 0.00 (+0.00)
GET list_advisory 85 (0) 0 500.21 (+64.80) 293 (+125) 1043 (+219) 0.28 (+0.00) 0.00 (+0.00)
GET list_advisory_paginated 85 (0) 0 421.99 (+43.06) 117 (+15) 883 (+166) 0.28 (+0.00) 0.00 (+0.00)
GET list_importer 85 (0) 0 3.65 (-0.41) 1 (0) 52 (+4) 0.28 (+0.00) 0.00 (+0.00)
GET list_organizations 85 (0) 0 7.68 (-6.32) 1 (0) 52 (-1) 0.28 (+0.00) 0.00 (+0.00)
GET list_packages 85 (0) 0 458.25 (+142.05) 101 (+26) 1232 (+441) 0.28 (+0.00) 0.00 (+0.00)
GET list_packages_paginated 85 (0) 0 411.67 (+113.28) 107 (-6) 1252 (+761) 0.28 (+0.00) 0.00 (+0.00)
GET list_products 85 (-5) 0 6.26 (-0.39) 3 (-1) 13 (+2) 0.28 (-0.02) 0.00 (+0.00)
GET list_sboms 85 (-5) 0 987.33 (-347.85) 579 (-26) 1605 (-798) 0.28 (-0.02) 0.00 (+0.00)
GET list_sboms_paginated 85 (-5) 0 1370.96 (-1342.38) 486 (+2) 4261 (-3854) 0.28 (-0.02) 0.00 (+0.00)
GET list_vulnerabilities 85 (0) 0 225.76 (+30.98) 55 (+9) 380 (+20) 0.28 (+0.00) 0.00 (+0.00)
GET list_vulnerabilities_paginated 85 (0) 0 177.95 (+28.34) 32 (-10) 359 (+97) 0.28 (+0.00) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 85 (-2) 0 58.16 (-15.08) 10 (-2) 185 (-4) 0.28 (-0.01) 0.00 (+0.00)
GET search_advisory 85 (0) 0 1029.52 (+269.79) 173 (+18) 2270 (-139) 0.28 (+0.00) 0.00 (+0.00)
GET search_exact_purl 85 (-5) 0 6.58 (-2.32) 4 (+1) 20 (-38) 0.28 (-0.02) 0.00 (+0.00)
GET search_purls 90 (0) 0 9674.09 (+2478.36) 4724 (+1508) 13746 (+2960) 0.30 (+0.00) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 85 (0) 0 579.92 (-167.51) 264 (-25) 974 (-425) 0.28 (+0.00) 0.00 (+0.00)
Aggregated 1790 (-30) 0 868.51 (+35.68) 1 (0) 13746 (+2960) 5.97 (-0.10) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (0) 7 (0) 7 (-1) 11 (+1) 42 (+26) 51 (+7) 61 (+7) 64 (+8)
GET get_analysis_latest_cpe 120 (-50) 170 (-10) 190 (0) 190 (-20) 210 (-20) 220 (-50) 260 (-90) 270 (-117)
GET get_analysis_status 2 (-1) 2 (-2) 3 (-1) 4 (-1) 10 (+2) 49 (0) 54 (+4) 59 (+9)
GET get_sbom[sha256:720e4451…a939656247164447] 700 (-200) 700 (-300) 800 (-200) 1,000 (-2,000) 2,000 (-1,000) 2,000 (-1,000) 2,000 (-1,841) 3,000 (-841)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (-100) 800 (-200) 900 (-100) 900 (-100) 1,000 (0) 1,000 (0) 1,758 (+758) 1,758 (+245)
GET list_advisory 470 (+40) 480 (+30) 500 (+10) 600 (+100) 700 (+100) 700 (0) 1,000 (+200) 1,000 (+200)
GET list_advisory_paginated 400 (0) 420 (+10) 460 (+30) 480 (+20) 500 (0) 600 (0) 883 (+183) 883 (+183)
GET list_importer 2 (0) 2 (0) 3 (0) 4 (0) 5 (-2) 10 (+2) 46 (+1) 52 (+4)
GET list_organizations 3 (-1) 4 (-3) 5 (-16) 8 (-26) 22 (-19) 31 (-14) 48 (-3) 52 (-1)
GET list_packages 410 (+90) 440 (+70) 480 (+90) 500 (+90) 800 (+350) 1,000 (+530) 1,000 (+400) 1,000 (+209)
GET list_packages_paginated 400 (+90) 410 (+60) 460 (+80) 490 (+100) 600 (+160) 1,000 (+530) 1,000 (+510) 1,000 (+510)
GET list_products 6 (0) 6 (-1) 8 (0) 8 (0) 9 (0) 10 (-1) 13 (+2) 13 (+2)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000) 1,605 (-395) 1,605 (-395)
GET list_sboms_paginated 1,000 (-2,000) 1,000 (-2,000) 2,000 (-2,000) 2,000 (-2,000) 2,000 (-3,000) 3,000 (-2,000) 4,000 (-2,000) 4,000 (-4,000)
GET list_vulnerabilities 220 (+20) 240 (+20) 260 (+30) 280 (+10) 310 (+20) 310 (-10) 380 (+40) 380 (+20)
GET list_vulnerabilities_paginated 180 (+20) 190 (+10) 200 (+10) 210 (+20) 250 (+40) 270 (+50) 300 (+40) 359 (+99)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 43 (-27) 65 (-11) 72 (-19) 83 (-27) 110 (-50) 160 (-20) 180 (0) 185 (-4)
GET search_advisory 900 (+200) 1,000 (+300) 1,000 (+200) 1,000 (0) 2,000 (+1,000) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 6 (0) 6 (0) 7 (0) 7 (0) 8 (-2) 9 (-45) 15 (-40) 20 (-38)
GET search_purls 10,000 (+3,000) 10,000 (+2,000) 10,000 (+2,000) 11,000 (+2,000) 11,000 (+1,000) 13,000 (+3,000) 13,746 (+2,960) 13,746 (+2,960)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (-100) 600 (-200) 700 (-200) 700 (-200) 800 (-200) 900 (-100) 900 (-100) 974 (-26)
Aggregated 310 (+50) 430 (+30) 600 (0) 800 (-100) 1,000 (-1,000) 5,000 (+1,000) 11,000 (+2,000) 13,746 (+2,960)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 85 [200]
GET get_analysis_latest_cpe 85 [200]
GET get_analysis_status 85 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 85 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 85 [200]
GET list_advisory 85 [200]
GET list_advisory_paginated 85 [200]
GET list_importer 85 [200]
GET list_organizations 85 [200]
GET list_packages 85 [200]
GET list_packages_paginated 85 [200]
GET list_products 85 [200]
GET list_sboms 85 [200]
GET list_sboms_paginated 85 [200]
GET list_vulnerabilities 85 [200]
GET list_vulnerabilities_paginated 85 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 85 [200]
GET search_advisory 85 [200]
GET search_exact_purl 85 [200]
GET search_purls 90 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 85 [200]
Aggregated 1,790 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 85 (0) 0 (0) 14.18 (+0.26) 7 (0) 27 (+2) 0.28 (+0.00) 0.00 (+0.00)
1.1 list_organizations 85 (0) 0 (0) 7.82 (-6.44) 1 (0) 52 (-1) 0.28 (+0.00) 0.00 (+0.00)
1.2 list_advisory 85 (0) 0 (0) 500.33 (+64.88) 295 (+126) 1043 (+219) 0.28 (+0.00) 0.00 (+0.00)
1.3 list_advisory_paginated 85 (0) 0 (0) 422.06 (+43.06) 117 (+15) 883 (+166) 0.28 (+0.00) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 85 (0) 0 (0) 12.08 (+2.32) 3 (0) 64 (+8) 0.28 (+0.00) 0.00 (+0.00)
1.5 search_advisory 85 (0) 0 (0) 1029.54 (+269.73) 173 (+18) 2270 (-139) 0.28 (+0.00) 0.00 (+0.00)
1.6 list_vulnerabilities 85 (0) 0 (0) 225.86 (+31.05) 55 (+9) 380 (+20) 0.28 (+0.00) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 85 (0) 0 (0) 178.04 (+28.32) 32 (-10) 359 (+97) 0.28 (+0.00) 0.00 (+0.00)
1.8 list_importer 85 (0) 0 (0) 3.67 (-0.46) 1 (0) 52 (+4) 0.28 (+0.00) 0.00 (+0.00)
1.9 list_packages 85 (0) 0 (0) 458.29 (+142.04) 101 (+26) 1232 (+441) 0.28 (+0.00) 0.00 (+0.00)
1.10 list_packages_paginated 85 (0) 0 (0) 411.72 (+113.31) 107 (-6) 1252 (+761) 0.28 (+0.00) 0.00 (+0.00)
1.11 search_purls 90 (0) 0 (0) 9674.13 (+2478.33) 4724 (+1508) 13746 (+2960) 0.30 (+0.00) 0.00 (+0.00)
1.12 search_exact_purl 85 (-5) 0 (0) 6.60 (-2.33) 4 (+1) 20 (-38) 0.28 (-0.02) 0.00 (+0.00)
1.13 list_products 85 (-5) 0 (0) 6.34 (-0.34) 3 (-1) 13 (+2) 0.28 (-0.02) 0.00 (+0.00)
1.14 list_sboms 85 (-5) 0 (0) 987.38 (-347.86) 580 (-25) 1605 (-798) 0.28 (-0.02) 0.00 (+0.00)
1.15 list_sboms_paginated 85 (-5) 0 (0) 1371.02 (-1342.45) 486 (+2) 4261 (-3854) 0.28 (-0.02) 0.00 (+0.00)
1.16 get_analysis_status 85 (-2) 0 (0) 6.75 (+0.70) 1 (0) 59 (+8) 0.28 (-0.01) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 85 (-2) 0 (0) 140.86 (-20.98) 35 (-4) 271 (-116) 0.28 (-0.01) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 85 (-2) 0 (0) 798.67 (-572.75) 197 (-114) 3118 (-723) 0.28 (-0.01) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 85 (-2) 0 (0) 58.22 (-15.16) 10 (-2) 185 (-6) 0.28 (-0.01) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 85 (-2) 0 (0) 842.72 (-87.09) 525 (-81) 1758 (+245) 0.28 (-0.01) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 85 (0) 0 (0) 580.01 (-167.46) 264 (-25) 974 (-425) 0.28 (+0.00) 0.00 (+0.00)
Aggregated 1,875 (-30) 0 (0) 829.14 (+33.47) 1 (0) 13746 (+2960) 6.25 (-0.10) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 85 (0) 17363.38 (+268.25) 8504 (+190) 26665 (+4560) 0.28 (+0.00) 17.00 (+0.00)
Aggregated 5 (0) 85 (0) 17363.38 (+268.25) 8504 (+190) 26665 (+4560) 0.28 (+0.00) 17.00 (+0.00)

User Metrics