Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-23 02:16:5825-10-23 02:17:0400:00:060 → 6
Maintaining25-10-23 02:17:0425-10-23 02:22:0400:05:006
Decreasing25-10-23 02:22:0425-10-23 02:23:0700:01:030 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 40 (-11) 0 18.12 (+0.32) 3 (0) 70 (+2) 0.13 (-0.04) 0.00 (+0.00)
GET get_analysis_latest_cpe 45 (-8) 0 199.16 (-25.32) 35 (-55) 547 (+37) 0.15 (-0.03) 0.00 (+0.00)
GET get_analysis_status 45 (-8) 0 6.16 (-4.88) 1 (0) 52 (-6) 0.15 (-0.03) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 40 (-11) 0 869.25 (-78.61) 209 (-13) 2074 (+141) 0.13 (-0.04) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 45 (-8) 0 1172.51 (-9.64) 333 (-70) 3982 (+260) 0.15 (-0.03) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 45 (-7) 0 8064.80 (+428.53) 2426 (-1179) 13506 (-1183) 0.15 (-0.02) 0.00 (+0.00)
GET list_advisory 40 (-11) 0 564.47 (-155.66) 256 (+92) 1113 (-540) 0.13 (-0.04) 0.00 (+0.00)
GET list_advisory_paginated 40 (-11) 0 470.98 (-75.36) 182 (+38) 1287 (+356) 0.13 (-0.04) 0.00 (+0.00)
GET list_importer 41 (-11) 0 5.07 (-1.79) 1 (0) 52 (-4) 0.14 (-0.04) 0.00 (+0.00)
GET list_organizations 40 (-11) 0 15.80 (-0.22) 1 (0) 51 (-4) 0.13 (-0.04) 0.00 (+0.00)
GET list_packages 41 (-11) 0 401.02 (-47.71) 179 (+28) 853 (-264) 0.14 (-0.04) 0.00 (+0.00)
GET list_packages_paginated 41 (-11) 0 331.51 (-69.99) 121 (-7) 525 (-752) 0.14 (-0.04) 0.00 (+0.00)
GET list_products 45 (-10) 0 12.67 (-8.26) 3 (+1) 65 (-72) 0.15 (-0.03) 0.00 (+0.00)
GET list_sboms 45 (-10) 0 1262.44 (-32.50) 948 (+144) 2180 (-34) 0.15 (-0.03) 0.00 (+0.00)
GET list_sboms_paginated 45 (-10) 0 2319.80 (+87.13) 668 (+29) 6494 (+75) 0.15 (-0.03) 0.00 (+0.00)
GET list_vulnerabilities 41 (-11) 0 365.37 (+42.73) 73 (+3) 821 (+209) 0.14 (-0.04) 0.00 (+0.00)
GET list_vulnerabilities_paginated 41 (-11) 0 224.15 (+2.26) 90 (+59) 481 (+93) 0.14 (-0.04) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 45 (-7) 0 69.44 (-1.36) 11 (-5) 202 (-15) 0.15 (-0.02) 0.00 (+0.00)
GET search_advisory 41 (-11) 0 1286.00 (+184.77) 257 (+58) 3315 (+614) 0.14 (-0.04) 0.00 (+0.00)
GET search_exact_purl 45 (-10) 0 42.64 (+9.86) 2 (-1) 179 (-27) 0.15 (-0.03) 0.00 (+0.00)
GET search_licenses 2 (0) 0 57486.50 (-3030.00) 47835 (-3957) 67138 (-2103) 0.01 (+0.00) 0.00 (+0.00)
GET search_purls 45 (-11) 0 15825.62 (+5917.85) 2038 (-83) 35197 (+8091) 0.15 (-0.04) 0.00 (+0.00)
GET search_purls_by_license 2 (+1) 0 83990.00 (-91498.00) 64025 (-111463) 103955 (-71533) 0.01 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 2 (+1) 2 40940.50 (+6289.50) 18622 (-16029) 63259 (+28608) 0.01 (+0.00) 0.01 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 40 (-11) 0 879.22 (-30.40) 234 (+46) 2003 (+107) 0.13 (-0.04) 0.00 (+0.00)
Aggregated 942 (-219) 2 2004.85 (+411.33) 1 (0) 103955 (-71533) 3.14 (-0.73) 0.01 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (-3) 11 (0) 13 (-1) 45 (+29) 52 (-3) 52 (-5) 70 (+8) 70 (+2)
GET get_analysis_latest_cpe 180 (-30) 200 (-30) 230 (-30) 270 (-20) 380 (-10) 460 (+50) 500 (0) 500 (0)
GET get_analysis_status 3 (0) 3 (-1) 4 (0) 5 (-2) 7 (-43) 46 (-7) 52 (-3) 52 (-6)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 600 (-100) 700 (-300) 1,000 (0) 1,000 (-933) 2,000 (+67) 2,000 (+67) 2,000 (+67) 2,000 (+67)
GET get_sbom[sha256:720e4451…a939656247164447] 600 (-200) 800 (-100) 1,000 (0) 1,000 (-1,000) 3,982 (+1,982) 3,982 (+982) 3,982 (+982) 3,982 (+260)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (+1,000) 8,000 (+1,000) 9,000 (+1,000) 10,000 (+1,000) 12,000 (0) 12,000 (0) 13,506 (+1,506) 13,506 (-1,183)
GET list_advisory 500 (-200) 600 (-100) 600 (-200) 700 (-300) 700 (-300) 800 (-200) 1,000 (-653) 1,000 (-653)
GET list_advisory_paginated 450 (-50) 460 (-140) 490 (-110) 500 (-200) 600 (-100) 700 (-100) 1,000 (+100) 1,000 (+100)
GET list_importer 2 (0) 3 (0) 4 (0) 4 (-3) 6 (-7) 7 (-35) 52 (+5) 52 (-4)
GET list_organizations 6 (+1) 10 (+3) 14 (+3) 38 (-1) 44 (-4) 45 (-4) 51 (-2) 51 (-4)
GET list_packages 410 (0) 450 (+10) 470 (-30) 500 (-100) 600 (0) 600 (-200) 853 (-47) 853 (-147)
GET list_packages_paginated 330 (-60) 350 (-60) 380 (-40) 420 (-50) 450 (-150) 490 (-110) 500 (-100) 500 (-500)
GET list_products 9 (+1) 12 (+3) 13 (0) 21 (+5) 24 (-49) 26 (-63) 65 (-65) 65 (-72)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET list_sboms_paginated 2,000 (0) 2,000 (0) 3,000 (0) 4,000 (+1,000) 5,000 (+1,000) 5,000 (+1,000) 6,000 (0) 6,000 (0)
GET list_vulnerabilities 270 (-30) 330 (-20) 450 (+60) 600 (+150) 700 (+200) 800 (+300) 800 (+200) 800 (+200)
GET list_vulnerabilities_paginated 230 (0) 240 (-20) 250 (-20) 290 (+10) 310 (+10) 350 (+50) 480 (+110) 480 (+92)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 70 (-2) 73 (-3) 80 (-1) 85 (-10) 170 (+50) 190 (+10) 200 (0) 200 (-17)
GET search_advisory 1,000 (0) 1,000 (0) 1,000 (0) 2,000 (+1,000) 3,000 (+1,000) 3,000 (+1,000) 3,000 (+299) 3,000 (+299)
GET search_exact_purl 10 (+2) 13 (+3) 98 (+46) 100 (+44) 110 (+48) 110 (-60) 179 (+9) 179 (-27)
GET search_licenses 48,000 (-4,000) 48,000 (-4,000) 48,000 (-4,000) 67,000 (-2,000) 67,000 (-2,000) 67,000 (-2,000) 67,000 (-2,000) 67,000 (-2,000)
GET search_purls 13,000 (+9,000) 15,000 (+10,000) 22,000 (+5,000) 26,000 (+5,000) 35,000 (+12,000) 35,000 (+8,000) 35,000 (+8,000) 35,000 (+8,000)
GET search_purls_by_license 64,025 (-111,463) 64,025 (-111,463) 64,025 (-111,463) 103,955 (-71,533) 103,955 (-71,533) 103,955 (-71,533) 103,955 (-71,533) 103,955 (-71,533)
GET search_sboms_by_license 19,000 (-15,651) 19,000 (-15,651) 19,000 (-15,651) 63,000 (+28,349) 63,000 (+28,349) 63,000 (+28,349) 63,000 (+28,349) 63,000 (+28,349)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 700 (-100) 800 (-100) 800 (-200) 1,000 (0) 1,000 (0) 2,000 (+104) 2,000 (+104) 2,000 (+104)
Aggregated 360 (-50) 500 (-100) 700 (-100) 1,000 (0) 5,000 (+2,000) 9,000 (+2,000) 35,000 (+13,000) 103,955 (-71,045)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 40 [200]
GET get_analysis_latest_cpe 45 [200]
GET get_analysis_status 45 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 40 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 45 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 45 [200]
GET list_advisory 40 [200]
GET list_advisory_paginated 40 [200]
GET list_importer 41 [200]
GET list_organizations 40 [200]
GET list_packages 41 [200]
GET list_packages_paginated 41 [200]
GET list_products 45 [200]
GET list_sboms 45 [200]
GET list_sboms_paginated 45 [200]
GET list_vulnerabilities 41 [200]
GET list_vulnerabilities_paginated 41 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 45 [200]
GET search_advisory 41 [200]
GET search_exact_purl 45 [200]
GET search_licenses 2 [200]
GET search_purls 45 [200]
GET search_purls_by_license 2 [200]
GET search_sboms_by_license 2 [500]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 40 [200]
Aggregated 940 [200], 2 [500]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 40 (-11) 0 (0) 15.75 (-0.05) 8 (0) 36 (+2) 0.13 (-0.04) 0.00 (+0.00)
1.1 list_organizations 40 (-11) 0 (0) 16.05 (-0.13) 2 (0) 51 (-4) 0.13 (-0.04) 0.00 (+0.00)
1.2 list_advisory 40 (-11) 0 (0) 564.55 (-155.61) 256 (+92) 1113 (-540) 0.13 (-0.04) 0.00 (+0.00)
1.3 list_advisory_paginated 40 (-11) 0 (0) 471.10 (-75.31) 182 (+38) 1287 (+355) 0.13 (-0.04) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 40 (-11) 0 (0) 18.20 (+0.30) 3 (0) 71 (+3) 0.13 (-0.04) 0.00 (+0.00)
1.5 search_advisory 41 (-11) 0 (0) 1286.05 (+184.72) 257 (+58) 3315 (+614) 0.14 (-0.04) 0.00 (+0.00)
1.6 list_vulnerabilities 41 (-11) 0 (0) 365.44 (+42.73) 73 (+3) 821 (+209) 0.14 (-0.04) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 41 (-11) 0 (0) 224.20 (+2.23) 90 (+59) 481 (+93) 0.14 (-0.04) 0.00 (+0.00)
1.8 list_importer 41 (-11) 0 (0) 5.10 (-1.77) 1 (0) 52 (-4) 0.14 (-0.04) 0.00 (+0.00)
1.9 list_packages 41 (-11) 0 (0) 401.05 (-47.82) 179 (+28) 853 (-264) 0.14 (-0.04) 0.00 (+0.00)
1.10 list_packages_paginated 41 (-11) 0 (0) 331.56 (-69.98) 121 (-7) 525 (-752) 0.14 (-0.04) 0.00 (+0.00)
1.11 search_purls 45 (-11) 0 (0) 15825.71 (+5917.92) 2038 (-83) 35197 (+8091) 0.15 (-0.04) 0.00 (+0.00)
1.12 search_exact_purl 45 (-10) 0 (0) 42.69 (+9.87) 2 (-1) 179 (-27) 0.15 (-0.03) 0.00 (+0.00)
1.13 list_products 45 (-10) 0 (0) 12.71 (-8.29) 3 (+1) 65 (-72) 0.15 (-0.03) 0.00 (+0.00)
1.14 list_sboms 45 (-10) 0 (0) 1262.47 (-32.53) 948 (+144) 2180 (-34) 0.15 (-0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 45 (-10) 0 (0) 2319.82 (+87.13) 668 (+29) 6494 (+75) 0.15 (-0.03) 0.00 (+0.00)
1.16 get_analysis_status 45 (-8) 0 (0) 6.20 (-4.88) 1 (0) 52 (-6) 0.15 (-0.03) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 45 (-8) 0 (0) 199.20 (-25.27) 35 (-55) 547 (+37) 0.15 (-0.03) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 45 (-8) 0 (0) 1172.58 (-9.67) 333 (-70) 3982 (+260) 0.15 (-0.03) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 45 (-7) 0 (0) 69.56 (-1.35) 11 (-6) 202 (-15) 0.15 (-0.02) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 45 (-7) 0 (0) 8064.87 (+428.48) 2426 (-1179) 13506 (-1183) 0.15 (-0.02) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 40 (-11) 0 (0) 879.25 (-30.42) 234 (+46) 2003 (+107) 0.13 (-0.04) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 40 (-11) 0 (0) 869.25 (-78.81) 209 (-14) 2074 (+141) 0.13 (-0.04) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 1 (0) 0 (0) 7.00 (-6.00) 7 (-6) 7 (-6) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 2 (0) 0 (0) 57486.50 (-3030.00) 47835 (-3957) 67138 (-2103) 0.01 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 2 (+1) 0 (0) 40940.50 (+6289.50) 18622 (-16029) 63259 (+28608) 0.01 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 2 (+1) 0 (0) 83990.00 (-91498.00) 64025 (-111463) 103955 (-71533) 0.01 (+0.00) 0.00 (+0.00)
Aggregated 983 (-230) 0 (0) 1921.23 (+396.02) 1 (0) 103955 (-71533) 3.28 (-0.77) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 40 (-11) 35636.95 (+7003.26) 17936 (+34) 57609 (+6811) 0.13 (-0.04) 8.00 (-2.20)
RestAPIUserSlow 1 (0) 1 (0) 170427.00 (-91514.00) 170427 (-91514) 170427 (-91514) 0.00 (+0.00) 1.00 (+0.00)
Aggregated 6 (0) 41 (-11) 38924.51 (+5804.14) 17936 (+34) 170427 (-91514) 0.14 (-0.04) 9.00 (-2.20)

User Metrics

Errors

# Error
2 (+1) 500 Internal Server Error: search_sboms_by_license