Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-24 02:20:1125-10-24 02:20:1700:00:060 → 6
Maintaining25-10-24 02:20:1725-10-24 02:25:1700:05:006
Decreasing25-10-24 02:25:1725-10-24 02:25:4800:00:310 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 49 (+9) 0 12.61 (-5.51) 2 (-1) 56 (-14) 0.16 (+0.03) 0.00 (+0.00)
GET get_analysis_latest_cpe 53 (+8) 0 224.19 (+25.03) 41 (+6) 413 (-134) 0.18 (+0.03) 0.00 (+0.00)
GET get_analysis_status 53 (+8) 0 11.02 (+4.86) 1 (0) 55 (+3) 0.18 (+0.03) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 49 (+9) 0 879.92 (+10.67) 274 (+65) 1996 (-78) 0.16 (+0.03) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 53 (+8) 0 1313.49 (+140.98) 367 (+34) 3416 (-566) 0.18 (+0.03) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 53 (+8) 0 8242.68 (+177.88) 5201 (+2775) 14810 (+1304) 0.18 (+0.03) 0.00 (+0.00)
GET list_advisory 49 (+9) 0 579.96 (+15.48) 272 (+16) 1449 (+336) 0.16 (+0.03) 0.00 (+0.00)
GET list_advisory_paginated 49 (+9) 0 511.39 (+40.41) 110 (-72) 1292 (+5) 0.16 (+0.03) 0.00 (+0.00)
GET list_importer 50 (+9) 0 6.26 (+1.19) 1 (0) 92 (+40) 0.17 (+0.03) 0.00 (+0.00)
GET list_organizations 49 (+9) 0 19.12 (+3.32) 2 (+1) 49 (-2) 0.16 (+0.03) 0.00 (+0.00)
GET list_packages 50 (+9) 0 415.36 (+14.34) 157 (-22) 790 (-63) 0.17 (+0.03) 0.00 (+0.00)
GET list_packages_paginated 50 (+9) 0 359.10 (+27.59) 172 (+51) 525 (0) 0.17 (+0.03) 0.00 (+0.00)
GET list_products 53 (+8) 0 13.81 (+1.14) 3 (0) 65 (0) 0.18 (+0.03) 0.00 (+0.00)
GET list_sboms 53 (+8) 0 1287.87 (+25.42) 566 (-382) 2080 (-100) 0.18 (+0.03) 0.00 (+0.00)
GET list_sboms_paginated 53 (+8) 0 2312.00 (-7.80) 524 (-144) 5620 (-874) 0.18 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities 50 (+9) 0 322.56 (-42.81) 70 (-3) 657 (-164) 0.17 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities_paginated 50 (+9) 0 206.76 (-17.39) 41 (-49) 379 (-102) 0.17 (+0.03) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 53 (+8) 0 90.23 (+20.78) 17 (+6) 301 (+99) 0.18 (+0.03) 0.00 (+0.00)
GET search_advisory 49 (+8) 0 1320.61 (+34.61) 208 (-49) 2969 (-346) 0.16 (+0.03) 0.00 (+0.00)
GET search_exact_purl 53 (+8) 0 26.11 (-16.53) 3 (+1) 102 (-77) 0.18 (+0.03) 0.00 (+0.00)
GET search_licenses 2 (0) 0 46315.50 (-11171.00) 34304 (-13531) 58327 (-8811) 0.01 (+0.00) 0.00 (+0.00)
GET search_purls 54 (+9) 0 9868.48 (-5957.14) 2123 (+85) 22470 (-12727) 0.18 (+0.03) 0.00 (+0.00)
GET search_purls_by_license 1 (-1) 0 189712.00 (+105722.00) 189712 (+125687) 189712 (+85757) 0.00 (-0.00) 0.00 (+0.00)
GET search_sboms_by_license 1 (-1) 0 51065.00 (+10124.50) 51065 (+32443) 51065 (-12194) 0.00 (-0.00) 0.00 (-0.01)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 50 (+10) 0 901.28 (+22.06) 288 (+54) 1467 (-536) 0.17 (+0.03) 0.00 (+0.00)
Aggregated 1129 (+187) 0 1644.25 (-360.60) 1 (0) 189712 (+85757) 3.76 (+0.62) 0.00 (-0.01)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 8 (+1) 9 (-2) 10 (-3) 12 (-33) 18 (-34) 55 (+3) 56 (-14) 56 (-14)
GET get_analysis_latest_cpe 220 (+40) 250 (+50) 260 (+30) 300 (+30) 360 (-20) 400 (-60) 400 (-100) 410 (-90)
GET get_analysis_status 3 (0) 4 (+1) 4 (0) 6 (+1) 50 (+43) 52 (+6) 53 (+1) 55 (+3)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 700 (+100) 800 (+100) 800 (-200) 1,000 (0) 1,000 (-1,000) 1,996 (-4) 1,996 (-4) 1,996 (-4)
GET get_sbom[sha256:720e4451…a939656247164447] 800 (+200) 1,000 (+200) 2,000 (+1,000) 2,000 (+1,000) 3,000 (-982) 3,000 (-982) 3,000 (-982) 3,000 (-982)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 7,000 (-1,000) 8,000 (0) 9,000 (0) 11,000 (+1,000) 12,000 (0) 13,000 (+1,000) 14,000 (+494) 14,810 (+1,304)
GET list_advisory 500 (0) 600 (0) 600 (0) 700 (0) 800 (+100) 900 (+100) 1,000 (0) 1,000 (0)
GET list_advisory_paginated 500 (+50) 500 (+40) 500 (+10) 600 (+100) 700 (+100) 800 (+100) 1,000 (0) 1,000 (0)
GET list_importer 2 (0) 3 (0) 3 (-1) 4 (0) 7 (+1) 45 (+38) 92 (+40) 92 (+40)
GET list_organizations 8 (+2) 10 (0) 37 (+23) 42 (+4) 45 (+1) 47 (+2) 49 (-2) 49 (-2)
GET list_packages 400 (-10) 420 (-30) 470 (0) 500 (0) 600 (0) 700 (+100) 790 (-63) 790 (-63)
GET list_packages_paginated 340 (+10) 400 (+50) 420 (+40) 470 (+50) 490 (+40) 500 (+10) 500 (0) 500 (0)
GET list_products 10 (+1) 11 (-1) 11 (-2) 13 (-8) 19 (-5) 59 (+33) 64 (-1) 65 (0)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 2,000 (+1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET list_sboms_paginated 2,000 (0) 2,000 (0) 3,000 (0) 3,000 (-1,000) 4,000 (-1,000) 4,000 (-1,000) 5,000 (-1,000) 5,620 (-380)
GET list_vulnerabilities 310 (+40) 340 (+10) 360 (-90) 420 (-180) 500 (-200) 600 (-200) 657 (-143) 657 (-143)
GET list_vulnerabilities_paginated 200 (-30) 210 (-30) 240 (-10) 260 (-30) 300 (-10) 330 (-20) 379 (-101) 379 (-101)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 78 (+8) 83 (+10) 91 (+11) 100 (+15) 190 (+20) 200 (+10) 300 (+100) 300 (+100)
GET search_advisory 1,000 (0) 1,000 (0) 2,000 (+1,000) 2,000 (0) 2,000 (-1,000) 2,969 (-31) 2,969 (-31) 2,969 (-31)
GET search_exact_purl 9 (-1) 11 (-2) 19 (-79) 53 (-47) 61 (-49) 100 (-10) 100 (-79) 100 (-79)
GET search_licenses 34,304 (-13,696) 34,304 (-13,696) 34,304 (-13,696) 58,000 (-9,000) 58,000 (-9,000) 58,000 (-9,000) 58,000 (-9,000) 58,000 (-9,000)
GET search_purls 9,000 (-4,000) 11,000 (-4,000) 16,000 (-6,000) 18,000 (-8,000) 19,000 (-16,000) 22,000 (-13,000) 22,000 (-13,000) 22,000 (-13,000)
GET search_purls_by_license 189,712 (+125,687) 189,712 (+125,687) 189,712 (+125,687) 189,712 (+85,757) 189,712 (+85,757) 189,712 (+85,757) 189,712 (+85,757) 189,712 (+85,757)
GET search_sboms_by_license 51,065 (+32,065) 51,065 (+32,065) 51,065 (+32,065) 51,065 (-11,935) 51,065 (-11,935) 51,065 (-11,935) 51,065 (-11,935) 51,065 (-11,935)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 900 (+200) 1,000 (+200) 1,000 (+200) 1,000 (0) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000)
Aggregated 390 (+30) 500 (0) 800 (+100) 1,000 (0) 3,000 (-2,000) 7,000 (-2,000) 19,000 (-16,000) 189,712 (+85,757)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 49 [200]
GET get_analysis_latest_cpe 53 [200]
GET get_analysis_status 53 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 49 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 53 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 53 [200]
GET list_advisory 49 [200]
GET list_advisory_paginated 49 [200]
GET list_importer 50 [200]
GET list_organizations 49 [200]
GET list_packages 50 [200]
GET list_packages_paginated 50 [200]
GET list_products 53 [200]
GET list_sboms 53 [200]
GET list_sboms_paginated 53 [200]
GET list_vulnerabilities 50 [200]
GET list_vulnerabilities_paginated 50 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 53 [200]
GET search_advisory 49 [200]
GET search_exact_purl 53 [200]
GET search_licenses 2 [200]
GET search_purls 54 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 50 [200]
Aggregated 1,129 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 49 (+9) 0 (0) 14.69 (-1.06) 8 (0) 24 (-12) 0.16 (+0.03) 0.00 (+0.00)
1.1 list_organizations 49 (+9) 0 (0) 19.27 (+3.22) 2 (0) 49 (-2) 0.16 (+0.03) 0.00 (+0.00)
1.2 list_advisory 49 (+9) 0 (0) 579.98 (+15.43) 272 (+16) 1449 (+336) 0.16 (+0.03) 0.00 (+0.00)
1.3 list_advisory_paginated 49 (+9) 0 (0) 511.43 (+40.33) 110 (-72) 1292 (+5) 0.16 (+0.03) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 49 (+9) 0 (0) 12.73 (-5.47) 2 (-1) 56 (-15) 0.16 (+0.03) 0.00 (+0.00)
1.5 search_advisory 49 (+8) 0 (0) 1320.76 (+34.71) 208 (-49) 2969 (-346) 0.16 (+0.03) 0.00 (+0.00)
1.6 list_vulnerabilities 50 (+9) 0 (0) 322.64 (-42.80) 70 (-3) 658 (-163) 0.17 (+0.03) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 50 (+9) 0 (0) 206.86 (-17.34) 41 (-49) 379 (-102) 0.17 (+0.03) 0.00 (+0.00)
1.8 list_importer 50 (+9) 0 (0) 6.34 (+1.24) 1 (0) 92 (+40) 0.17 (+0.03) 0.00 (+0.00)
1.9 list_packages 50 (+9) 0 (0) 415.48 (+14.43) 157 (-22) 790 (-63) 0.17 (+0.03) 0.00 (+0.00)
1.10 list_packages_paginated 50 (+9) 0 (0) 359.22 (+27.66) 172 (+51) 525 (0) 0.17 (+0.03) 0.00 (+0.00)
1.11 search_purls 54 (+9) 0 (0) 9868.56 (-5957.16) 2123 (+85) 22470 (-12727) 0.18 (+0.03) 0.00 (+0.00)
1.12 search_exact_purl 53 (+8) 0 (0) 26.17 (-16.52) 3 (+1) 102 (-77) 0.18 (+0.03) 0.00 (+0.00)
1.13 list_products 53 (+8) 0 (0) 13.91 (+1.19) 3 (0) 65 (0) 0.18 (+0.03) 0.00 (+0.00)
1.14 list_sboms 53 (+8) 0 (0) 1287.98 (+25.51) 566 (-382) 2080 (-100) 0.18 (+0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 53 (+8) 0 (0) 2312.11 (-7.71) 524 (-144) 5620 (-874) 0.18 (+0.03) 0.00 (+0.00)
1.16 get_analysis_status 53 (+8) 0 (0) 11.06 (+4.86) 1 (0) 55 (+3) 0.18 (+0.03) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 53 (+8) 0 (0) 224.28 (+25.08) 41 (+6) 413 (-134) 0.18 (+0.03) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 53 (+8) 0 (0) 1313.51 (+140.93) 367 (+34) 3416 (-566) 0.18 (+0.03) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 53 (+8) 0 (0) 90.30 (+20.75) 17 (+6) 301 (+99) 0.18 (+0.03) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 53 (+8) 0 (0) 8242.83 (+177.96) 5201 (+2775) 14810 (+1304) 0.18 (+0.03) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 50 (+10) 0 (0) 901.32 (+22.07) 288 (+54) 1467 (-536) 0.17 (+0.03) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 49 (+9) 0 (0) 880.02 (+10.77) 274 (+65) 1997 (-77) 0.16 (+0.03) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 1 (0) 0 (0) 16.00 (+9.00) 16 (+9) 16 (+9) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 2 (0) 0 (0) 46315.50 (-11171.00) 34304 (-13531) 58327 (-8811) 0.01 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 1 (-1) 0 (0) 51065.00 (+10124.50) 51065 (+32443) 51065 (-12194) 0.00 (-0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (-1) 0 (0) 189712.00 (+105722.00) 189712 (+125687) 189712 (+85757) 0.00 (-0.00) 0.00 (+0.00)
Aggregated 1,179 (+196) 0 (0) 1574.52 (-346.71) 1 (0) 189712 (+85757) 3.93 (+0.65) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 49 (+9) 29278.63 (-6358.32) 17726 (-210) 46769 (-10840) 0.16 (+0.03) 9.80 (+1.80)
RestAPIUserSlow 1 (0) 1 (0) 299116.00 (+128689.00) 299116 (+128689) 299116 (+128689) 0.00 (+0.00) 1.00 (+0.00)
Aggregated 6 (0) 50 (+9) 34675.38 (-4249.13) 17726 (-210) 299116 (+128689) 0.17 (+0.03) 10.80 (+1.80)

User Metrics