Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-20 14:38:5625-10-20 14:39:0200:00:060 → 6
Maintaining25-10-20 14:39:0225-10-20 14:44:0200:05:006
Decreasing25-10-20 14:44:0225-10-20 14:44:1100:00:090 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 59 (+56) 0 19.29 (-7.38) 3 (-23) 375 (+348) 0.20 (+0.19) 0.00 (+0.00)
GET get_analysis_latest_cpe 60 (+55) 0 244.58 (+69.18) 80 (-93) 706 (+529) 0.20 (+0.18) 0.00 (+0.00)
GET get_analysis_status 60 (+55) 0 5.45 (+3.05) 1 (0) 54 (+50) 0.20 (+0.18) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 59 (+56) 0 783.64 (-768.36) 201 (-1350) 1419 (-134) 0.20 (+0.19) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 60 (+57) 0 1324.38 (-135.95) 310 (-1147) 4009 (+2547) 0.20 (+0.19) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (+57) 0 8656.18 (+2541.18) 3487 (-2580) 14403 (+8223) 0.20 (+0.19) 0.00 (+0.00)
GET list_advisory 59 (+56) 0 484.78 (-30.89) 128 (-386) 927 (+409) 0.20 (+0.19) 0.00 (+0.00)
GET list_advisory_paginated 59 (+56) 0 427.05 (+81.05) 117 (-229) 698 (+352) 0.20 (+0.19) 0.00 (+0.00)
GET list_importer 60 (+57) 0 4.33 (+1.00) 1 (0) 55 (+48) 0.20 (+0.19) 0.00 (+0.00)
GET list_organizations 59 (+56) 0 12.66 (+10.66) 1 (-1) 48 (+46) 0.20 (+0.19) 0.00 (+0.00)
GET list_packages 60 (+57) 0 389.35 (+141.02) 123 (-120) 879 (+628) 0.20 (+0.19) 0.00 (+0.00)
GET list_packages_paginated 56 (+53) 0 332.09 (+37.09) 120 (-166) 573 (+268) 0.19 (+0.18) 0.00 (+0.00)
GET list_products 60 (+55) 0 17.68 (-17.52) 2 (-8) 107 (+54) 0.20 (+0.18) 0.00 (+0.00)
GET list_sboms 60 (+55) 0 1330.18 (+678.58) 749 (+104) 2616 (+1957) 0.20 (+0.18) 0.00 (+0.00)
GET list_sboms_paginated 60 (+55) 0 2024.13 (+1531.93) 628 (+143) 5890 (+5393) 0.20 (+0.18) 0.00 (+0.00)
GET list_vulnerabilities 60 (+57) 0 366.13 (+60.47) 79 (-226) 1067 (+760) 0.20 (+0.19) 0.00 (+0.00)
GET list_vulnerabilities_paginated 60 (+57) 0 190.08 (+69.42) 34 (-86) 311 (+190) 0.20 (+0.19) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (+57) 0 94.32 (-39.35) 21 (-98) 298 (+156) 0.20 (+0.19) 0.00 (+0.00)
GET search_advisory 60 (+57) 0 873.42 (-1371.92) 150 (-2095) 2050 (-196) 0.20 (+0.19) 0.00 (+0.00)
GET search_exact_purl 60 (+55) 0 16.67 (-7.73) 2 (-3) 102 (+51) 0.20 (+0.18) 0.00 (+0.00)
GET search_licenses 1 (-4) 0 98585.00 (-54246.80) 98585 (-37904) 98585 (-97882) 0.00 (-0.01) 0.00 (+0.00)
GET search_purls 60 (+52) 0 6969.20 (-14857.42) 2525 (-5790) 13733 (-27588) 0.20 (+0.17) 0.00 (+0.00)
GET search_purls_by_license 1 (-4) 0 162151.00 (+75745.40) 162151 (+133815) 162151 (+15364) 0.00 (-0.01) 0.00 (-0.01)
GET search_sboms_by_license 1 (-4) 1 50282.00 (-15988.20) 50282 (+1074) 50282 (-23958) 0.00 (-0.01) 0.00 (-0.01)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 59 (+56) 0 768.92 (-20.08) 285 (-430) 1356 (+525) 0.20 (+0.19) 0.00 (+0.00)
Aggregated 1313 (+1215) 1 1391.67 (-16481.11) 1 (0) 162151 (-34316) 4.38 (+4.05) 0.00 (-0.02)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (-21) 8 (-19) 9 (-18) 11 (-16) 51 (+24) 64 (+37) 70 (+43) 375 (+348)
GET get_analysis_latest_cpe 220 (+43) 230 (+53) 280 (+103) 310 (+133) 410 (+233) 470 (+293) 600 (+423) 700 (+523)
GET get_analysis_status 2 (0) 2 (0) 3 (0) 4 (+1) 6 (+2) 31 (+27) 54 (+50) 54 (+50)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 700 (-853) 900 (-653) 1,000 (-553) 1,000 (-553) 1,000 (-553) 1,000 (-553) 1,000 (-553) 1,000 (-553)
GET get_sbom[sha256:720e4451…a939656247164447] 900 (-557) 1,000 (-457) 1,000 (-457) 3,000 (+1,543) 3,000 (+1,543) 4,000 (+2,543) 4,000 (+2,543) 4,000 (+2,543)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (+1,933) 8,000 (+1,933) 9,000 (+2,933) 12,000 (+5,933) 13,000 (+6,933) 13,000 (+6,933) 14,000 (+7,933) 14,000 (+7,933)
GET list_advisory 500 (-14) 500 (-14) 600 (+86) 600 (+86) 700 (+186) 800 (+286) 900 (+386) 900 (+386)
GET list_advisory_paginated 470 (+124) 490 (+144) 500 (+154) 600 (+254) 600 (+254) 600 (+254) 698 (+352) 698 (+352)
GET list_importer 2 (0) 3 (+1) 3 (+1) 4 (+2) 6 (-1) 9 (+2) 47 (+40) 55 (+48)
GET list_organizations 4 (+2) 5 (+3) 9 (+7) 29 (+27) 39 (+37) 46 (+44) 47 (+45) 48 (+46)
GET list_packages 400 (+150) 470 (+220) 500 (+250) 500 (+250) 500 (+250) 600 (+350) 700 (+450) 879 (+629)
GET list_packages_paginated 310 (+20) 350 (+60) 400 (+110) 420 (+130) 500 (+195) 500 (+195) 573 (+268) 573 (+268)
GET list_products 8 (-43) 9 (-42) 14 (-38) 22 (-30) 55 (+2) 62 (+9) 72 (+19) 107 (+54)
GET list_sboms 1,000 (+341) 1,000 (+341) 1,000 (+341) 2,000 (+1,341) 2,000 (+1,341) 2,000 (+1,341) 2,000 (+1,341) 2,616 (+1,957)
GET list_sboms_paginated 2,000 (+1,510) 2,000 (+1,510) 2,000 (+1,503) 2,000 (+1,503) 4,000 (+3,503) 4,000 (+3,503) 4,000 (+3,503) 5,890 (+5,393)
GET list_vulnerabilities 320 (+13) 410 (+103) 440 (+133) 480 (+173) 500 (+193) 1,000 (+693) 1,000 (+693) 1,000 (+693)
GET list_vulnerabilities_paginated 210 (+90) 210 (+90) 220 (+100) 240 (+120) 290 (+170) 300 (+180) 310 (+190) 310 (+190)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 81 (-59) 86 (-54) 91 (-49) 100 (-40) 180 (+40) 260 (+120) 280 (+140) 298 (+158)
GET search_advisory 800 (-1,445) 900 (-1,345) 1,000 (-1,245) 1,000 (-1,245) 2,000 (-245) 2,000 (-245) 2,000 (-245) 2,000 (-245)
GET search_exact_purl 6 (-3) 7 (-2) 8 (-42) 13 (-37) 51 (0) 85 (+34) 100 (+49) 100 (+49)
GET search_licenses 98,585 (-39,415) 98,585 (-39,415) 98,585 (-57,415) 98,585 (-57,415) 98,585 (-97,415) 98,585 (-97,415) 98,585 (-97,415) 98,585 (-97,415)
GET search_purls 7,000 (-4,000) 7,000 (-5,000) 8,000 (-33,000) 9,000 (-32,000) 10,000 (-31,000) 11,000 (-30,000) 12,000 (-29,000) 13,733 (-27,267)
GET search_purls_by_license 162,151 (+101,151) 162,151 (+101,151) 162,151 (+15,364) 162,151 (+15,364) 162,151 (+15,364) 162,151 (+15,364) 162,151 (+15,364) 162,151 (+15,364)
GET search_sboms_by_license 50,282 (-18,718) 50,282 (-18,718) 50,282 (-19,718) 50,282 (-19,718) 50,282 (-23,718) 50,282 (-23,718) 50,282 (-23,718) 50,282 (-23,718)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 700 (-100) 800 (0) 900 (+100) 1,000 (+200) 1,000 (+200) 1,000 (+200) 1,000 (+200) 1,000 (+200)
Aggregated 320 (-170) 490 (-210) 700 (-1,300) 1,000 (-9,000) 3,000 (-66,000) 7,000 (-130,000) 12,000 (-144,000) 162,000 (-34,000)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 59 [200]
GET get_analysis_latest_cpe 60 [200]
GET get_analysis_status 60 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 59 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 60 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 [200]
GET list_advisory 59 [200]
GET list_advisory_paginated 59 [200]
GET list_importer 60 [200]
GET list_organizations 59 [200]
GET list_packages 60 [200]
GET list_packages_paginated 56 [200]
GET list_products 60 [200]
GET list_sboms 60 [200]
GET list_sboms_paginated 60 [200]
GET list_vulnerabilities 60 [200]
GET list_vulnerabilities_paginated 60 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 [200]
GET search_advisory 60 [200]
GET search_exact_purl 60 [200]
GET search_licenses 1 [200]
GET search_purls 60 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [500]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 59 [200]
Aggregated 1 [500], 1,312 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 59 (+56) 0 (0) 14.05 (+2.72) 8 (-1) 26 (+13) 0.20 (+0.19) 0.00 (+0.00)
1.1 list_organizations 59 (+56) 0 (0) 12.78 (+10.78) 1 (-1) 48 (+46) 0.20 (+0.19) 0.00 (+0.00)
1.2 list_advisory 59 (+56) 0 (0) 484.83 (-30.84) 128 (-386) 927 (+409) 0.20 (+0.19) 0.00 (+0.00)
1.3 list_advisory_paginated 59 (+56) 0 (0) 427.15 (+81.15) 118 (-228) 698 (+352) 0.20 (+0.19) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 59 (+56) 0 (0) 19.39 (-7.28) 3 (-23) 375 (+348) 0.20 (+0.19) 0.00 (+0.00)
1.5 search_advisory 60 (+57) 0 (0) 873.48 (-1371.85) 150 (-2095) 2050 (-196) 0.20 (+0.19) 0.00 (+0.00)
1.6 list_vulnerabilities 60 (+57) 0 (0) 366.18 (+60.52) 79 (-226) 1067 (+760) 0.20 (+0.19) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 60 (+57) 0 (0) 190.15 (+69.15) 34 (-86) 311 (+189) 0.20 (+0.19) 0.00 (+0.00)
1.8 list_importer 60 (+57) 0 (0) 4.37 (+1.03) 1 (0) 55 (+48) 0.20 (+0.19) 0.00 (+0.00)
1.9 list_packages 60 (+57) 0 (0) 389.42 (+141.08) 123 (-120) 879 (+628) 0.20 (+0.19) 0.00 (+0.00)
1.10 list_packages_paginated 56 (+53) 0 (0) 332.20 (+36.86) 120 (-166) 573 (+267) 0.19 (+0.18) 0.00 (+0.00)
1.11 search_purls 60 (+52) 0 (0) 6969.22 (-14857.41) 2525 (-5790) 13733 (-27588) 0.20 (+0.17) 0.00 (+0.00)
1.12 search_exact_purl 60 (+55) 0 (0) 16.77 (-7.63) 2 (-3) 103 (+52) 0.20 (+0.18) 0.00 (+0.00)
1.13 list_products 60 (+55) 0 (0) 17.80 (-17.40) 2 (-8) 107 (+54) 0.20 (+0.18) 0.00 (+0.00)
1.14 list_sboms 60 (+55) 0 (0) 1330.22 (+678.42) 749 (+103) 2616 (+1957) 0.20 (+0.18) 0.00 (+0.00)
1.15 list_sboms_paginated 60 (+55) 0 (0) 2024.20 (+1532.00) 628 (+143) 5890 (+5393) 0.20 (+0.18) 0.00 (+0.00)
1.16 get_analysis_status 60 (+55) 0 (0) 5.67 (+3.27) 1 (0) 54 (+50) 0.20 (+0.18) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 60 (+55) 0 (0) 244.63 (+69.03) 81 (-93) 706 (+529) 0.20 (+0.18) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 60 0 1324.48 310 4010 0.20 0.00
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 0 94.35 21 298 0.20 0.00
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 0 8656.25 3487 14403 0.20 0.00
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 59 0 768.98 285 1356 0.20 0.00
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 59 0 783.75 201 1419 0.20 0.00
RestAPIUserSlow
2.0 logon 0 0 0.00 0 0 0.00 0.00
2.1 search_licenses 1 0 98585.00 98585 98585 0.00 0.00
2.2 search_sboms_by_license 1 0 50282.00 50282 50282 0.00 0.00
2.3 search_purls_by_license 1 0 162151.00 162151 162151 0.00 0.00
Aggregated 1,372 (+1,271) 0 (0) 1331.83 (-16010.08) 1 (0) 162151 (-34316) 4.57 (+4.24) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (+2) 59 (+56) 25145.08 (-271559.56) 16013 (-278354) 35657 (-262718) 0.20 (+0.19) 11.80 (+10.80)
RestAPIUserSlow 0 0 0.00 0 0 0.00 0.00
Aggregated 5 (+2) 59 (+56) 25145.08 (-271559.56) 16013 (-278354) 35657 (-262718) 0.20 (+0.19) 11.80 (+10.80)

User Metrics

Errors

# Error
1 (-4) 500 Internal Server Error: search_sboms_by_license