Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-25 02:17:4225-10-25 02:17:4800:00:060 → 6
Maintaining25-10-25 02:17:4825-10-25 02:22:4800:05:006
Decreasing25-10-25 02:22:4825-10-25 02:22:5700:00:090 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 45 (-4) 0 14.49 (+1.88) 3 (+1) 62 (+6) 0.15 (-0.01) 0.00 (+0.00)
GET get_analysis_latest_cpe 50 (-3) 0 191.80 (-32.39) 51 (+10) 376 (-37) 0.17 (-0.01) 0.00 (+0.00)
GET get_analysis_status 50 (-3) 0 8.20 (-2.82) 1 (0) 53 (-2) 0.17 (-0.01) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 45 (-4) 0 862.22 (-17.70) 190 (-84) 1694 (-302) 0.15 (-0.01) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 50 (-3) 0 1335.80 (+22.31) 329 (-38) 4092 (+676) 0.17 (-0.01) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 49 (-4) 0 9037.43 (+794.75) 5902 (+701) 14883 (+73) 0.16 (-0.01) 0.00 (+0.00)
GET list_advisory 45 (-4) 0 592.20 (+12.24) 165 (-107) 1099 (-350) 0.15 (-0.01) 0.00 (+0.00)
GET list_advisory_paginated 45 (-4) 0 504.60 (-6.79) 188 (+78) 906 (-386) 0.15 (-0.01) 0.00 (+0.00)
GET list_importer 46 (-4) 0 10.43 (+4.17) 1 (0) 58 (-34) 0.15 (-0.01) 0.00 (+0.00)
GET list_organizations 45 (-4) 0 14.60 (-4.52) 1 (-1) 63 (+14) 0.15 (-0.01) 0.00 (+0.00)
GET list_packages 46 (-4) 0 397.28 (-18.08) 107 (-50) 685 (-105) 0.15 (-0.01) 0.00 (+0.00)
GET list_packages_paginated 46 (-4) 0 399.35 (+40.25) 150 (-22) 776 (+251) 0.15 (-0.01) 0.00 (+0.00)
GET list_products 50 (-3) 0 11.66 (-2.15) 3 (0) 56 (-9) 0.17 (-0.01) 0.00 (+0.00)
GET list_sboms 50 (-3) 0 1043.42 (-244.45) 745 (+179) 1491 (-589) 0.17 (-0.01) 0.00 (+0.00)
GET list_sboms_paginated 50 (-3) 0 2099.92 (-212.08) 674 (+150) 5910 (+290) 0.17 (-0.01) 0.00 (+0.00)
GET list_vulnerabilities 46 (-4) 0 284.13 (-38.43) 34 (-36) 516 (-141) 0.15 (-0.01) 0.00 (+0.00)
GET list_vulnerabilities_paginated 46 (-4) 0 178.89 (-27.87) 26 (-15) 308 (-71) 0.15 (-0.01) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 49 (-4) 0 70.10 (-20.12) 9 (-8) 275 (-26) 0.16 (-0.01) 0.00 (+0.00)
GET search_advisory 45 (-4) 0 1163.33 (-157.28) 210 (+2) 3144 (+175) 0.15 (-0.01) 0.00 (+0.00)
GET search_exact_purl 50 (-3) 0 13.76 (-12.35) 2 (-1) 69 (-33) 0.17 (-0.01) 0.00 (+0.00)
GET search_licenses 2 (0) 0 68483.00 (+22167.50) 61283 (+26979) 75683 (+17356) 0.01 (+0.00) 0.00 (+0.00)
GET search_purls 50 (-4) 0 12404.98 (+2536.50) 3114 (+991) 23165 (+695) 0.17 (-0.01) 0.00 (+0.00)
GET search_purls_by_license 1 (0) 0 133786.00 (-55926.00) 133786 (-55926) 133786 (-55926) 0.00 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 1 (0) 0 39783.00 (-11282.00) 39783 (-11282) 39783 (-11282) 0.00 (+0.00) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 45 (-5) 0 795.00 (-106.28) 156 (-132) 1610 (+143) 0.15 (-0.02) 0.00 (+0.00)
Aggregated 1047 (-82) 0 1765.32 (+121.07) 1 (0) 133786 (-55926) 3.49 (-0.27) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (-1) 8 (-1) 9 (-1) 15 (+3) 56 (+38) 60 (+5) 62 (+6) 62 (+6)
GET get_analysis_latest_cpe 190 (-30) 200 (-50) 210 (-50) 230 (-70) 280 (-80) 310 (-90) 376 (-24) 376 (-34)
GET get_analysis_status 2 (-1) 3 (-1) 5 (+1) 7 (+1) 14 (-36) 52 (0) 53 (0) 53 (-2)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 600 (-100) 1,000 (+200) 1,000 (+200) 1,000 (0) 1,000 (0) 1,694 (-302) 1,694 (-302) 1,694 (-302)
GET get_sbom[sha256:720e4451…a939656247164447] 800 (0) 900 (-100) 2,000 (0) 2,000 (0) 3,000 (0) 4,000 (+1,000) 4,000 (+1,000) 4,000 (+1,000)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (+1,000) 8,000 (0) 9,000 (0) 11,000 (0) 13,000 (+1,000) 14,000 (+1,000) 14,883 (+883) 14,883 (+73)
GET list_advisory 600 (+100) 600 (0) 700 (+100) 800 (+100) 800 (0) 1,000 (+100) 1,000 (0) 1,000 (0)
GET list_advisory_paginated 500 (0) 600 (+100) 600 (+100) 600 (0) 700 (0) 700 (-100) 900 (-100) 900 (-100)
GET list_importer 2 (0) 4 (+1) 5 (+2) 8 (+4) 46 (+39) 51 (+6) 58 (-34) 58 (-34)
GET list_organizations 4 (-4) 6 (-4) 12 (-25) 36 (-6) 42 (-3) 45 (-2) 63 (+14) 63 (+14)
GET list_packages 430 (+30) 480 (+60) 500 (+30) 500 (0) 600 (0) 600 (-100) 685 (-105) 685 (-105)
GET list_packages_paginated 380 (+40) 470 (+70) 490 (+70) 500 (+30) 600 (+110) 600 (+100) 776 (+276) 776 (+276)
GET list_products 8 (-2) 8 (-3) 9 (-2) 11 (-2) 17 (-2) 54 (-5) 56 (-8) 56 (-9)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000)
GET list_sboms_paginated 2,000 (0) 2,000 (0) 2,000 (-1,000) 3,000 (0) 3,000 (-1,000) 4,000 (0) 5,910 (+910) 5,910 (+290)
GET list_vulnerabilities 320 (+10) 340 (0) 350 (-10) 380 (-40) 410 (-90) 490 (-110) 500 (-157) 500 (-157)
GET list_vulnerabilities_paginated 180 (-20) 210 (0) 210 (-30) 270 (+10) 280 (-20) 300 (-30) 308 (-71) 308 (-71)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 74 (-4) 81 (-2) 83 (-8) 92 (-8) 100 (-90) 190 (-10) 275 (-25) 275 (-25)
GET search_advisory 1,000 (0) 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 3,000 (+31) 3,000 (+31) 3,000 (+31)
GET search_exact_purl 7 (-2) 8 (-3) 8 (-11) 9 (-44) 52 (-9) 55 (-45) 69 (-31) 69 (-31)
GET search_licenses 61,283 (+26,979) 61,283 (+26,979) 61,283 (+26,979) 75,683 (+17,683) 75,683 (+17,683) 75,683 (+17,683) 75,683 (+17,683) 75,683 (+17,683)
GET search_purls 12,000 (+3,000) 14,000 (+3,000) 15,000 (-1,000) 16,000 (-2,000) 22,000 (+3,000) 23,000 (+1,000) 23,000 (+1,000) 23,000 (+1,000)
GET search_purls_by_license 133,786 (-55,926) 133,786 (-55,926) 133,786 (-55,926) 133,786 (-55,926) 133,786 (-55,926) 133,786 (-55,926) 133,786 (-55,926) 133,786 (-55,926)
GET search_sboms_by_license 39,783 (-11,282) 39,783 (-11,282) 39,783 (-11,282) 39,783 (-11,282) 39,783 (-11,282) 39,783 (-11,282) 39,783 (-11,282) 39,783 (-11,282)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 800 (-100) 800 (-200) 900 (-100) 1,000 (0) 1,000 (0) 1,000 (0) 1,610 (+610) 1,610 (+610)
Aggregated 350 (-40) 500 (0) 700 (-100) 1,000 (0) 4,000 (+1,000) 9,000 (+2,000) 22,000 (+3,000) 133,786 (-55,926)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 45 [200]
GET get_analysis_latest_cpe 50 [200]
GET get_analysis_status 50 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 45 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 50 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 49 [200]
GET list_advisory 45 [200]
GET list_advisory_paginated 45 [200]
GET list_importer 46 [200]
GET list_organizations 45 [200]
GET list_packages 46 [200]
GET list_packages_paginated 46 [200]
GET list_products 50 [200]
GET list_sboms 50 [200]
GET list_sboms_paginated 50 [200]
GET list_vulnerabilities 46 [200]
GET list_vulnerabilities_paginated 46 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 49 [200]
GET search_advisory 45 [200]
GET search_exact_purl 50 [200]
GET search_licenses 2 [200]
GET search_purls 50 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 45 [200]
Aggregated 1,047 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 45 (-4) 0 (0) 14.76 (+0.06) 7 (-1) 35 (+11) 0.15 (-0.01) 0.00 (+0.00)
1.1 list_organizations 45 (-4) 0 (0) 14.80 (-4.47) 1 (-1) 63 (+14) 0.15 (-0.01) 0.00 (+0.00)
1.2 list_advisory 45 (-4) 0 (0) 592.27 (+12.29) 165 (-107) 1099 (-350) 0.15 (-0.01) 0.00 (+0.00)
1.3 list_advisory_paginated 45 (-4) 0 (0) 504.64 (-6.78) 188 (+78) 906 (-386) 0.15 (-0.01) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 45 (-4) 0 (0) 14.60 (+1.87) 3 (+1) 62 (+6) 0.15 (-0.01) 0.00 (+0.00)
1.5 search_advisory 45 (-4) 0 (0) 1163.40 (-157.36) 210 (+2) 3144 (+175) 0.15 (-0.01) 0.00 (+0.00)
1.6 list_vulnerabilities 46 (-4) 0 (0) 284.22 (-38.42) 34 (-36) 516 (-142) 0.15 (-0.01) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 46 (-4) 0 (0) 178.93 (-27.93) 26 (-15) 308 (-71) 0.15 (-0.01) 0.00 (+0.00)
1.8 list_importer 46 (-4) 0 (0) 10.48 (+4.14) 1 (0) 58 (-34) 0.15 (-0.01) 0.00 (+0.00)
1.9 list_packages 46 (-4) 0 (0) 397.33 (-18.15) 107 (-50) 685 (-105) 0.15 (-0.01) 0.00 (+0.00)
1.10 list_packages_paginated 46 (-4) 0 (0) 399.39 (+40.17) 150 (-22) 776 (+251) 0.15 (-0.01) 0.00 (+0.00)
1.11 search_purls 50 (-4) 0 (0) 12405.02 (+2536.46) 3114 (+991) 23165 (+695) 0.17 (-0.01) 0.00 (+0.00)
1.12 search_exact_purl 50 (-3) 0 (0) 13.80 (-12.37) 2 (-1) 69 (-33) 0.17 (-0.01) 0.00 (+0.00)
1.13 list_products 50 (-3) 0 (0) 11.66 (-2.25) 3 (0) 56 (-9) 0.17 (-0.01) 0.00 (+0.00)
1.14 list_sboms 50 (-3) 0 (0) 1043.46 (-244.52) 745 (+179) 1491 (-589) 0.17 (-0.01) 0.00 (+0.00)
1.15 list_sboms_paginated 50 (-3) 0 (0) 2099.98 (-212.13) 674 (+150) 5910 (+290) 0.17 (-0.01) 0.00 (+0.00)
1.16 get_analysis_status 50 (-3) 0 (0) 8.24 (-2.82) 1 (0) 53 (-2) 0.17 (-0.01) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 50 (-3) 0 (0) 191.90 (-32.38) 51 (+10) 376 (-37) 0.17 (-0.01) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 50 (-3) 0 (0) 1335.86 (+22.35) 329 (-38) 4092 (+676) 0.17 (-0.01) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 49 (-4) 0 (0) 70.20 (-20.10) 9 (-8) 275 (-26) 0.16 (-0.01) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 49 (-4) 0 (0) 9037.53 (+794.70) 5902 (+701) 14883 (+73) 0.16 (-0.01) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 45 (-5) 0 (0) 795.07 (-106.25) 156 (-132) 1610 (+143) 0.15 (-0.02) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 45 (-4) 0 (0) 862.36 (-17.66) 190 (-84) 1694 (-303) 0.15 (-0.01) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 1 (0) 0 (0) 7.00 (-9.00) 7 (-9) 7 (-9) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 2 (0) 0 (0) 68483.00 (+22167.50) 61283 (+26979) 75683 (+17356) 0.01 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 1 (0) 0 (0) 39783.00 (-11282.00) 39783 (-11282) 39783 (-11282) 0.00 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (0) 0 (0) 133786.00 (-55926.00) 133786 (-55926) 133786 (-55926) 0.00 (+0.00) 0.00 (+0.00)
Aggregated 1,093 (-86) 0 (0) 1691.03 (+116.51) 1 (0) 133786 (-55926) 3.64 (-0.29) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 45 (-4) 32122.73 (+2844.10) 20852 (+3126) 45071 (-1698) 0.15 (-0.01) 9.00 (-0.80)
RestAPIUserSlow 1 (0) 1 (0) 234861.00 (-64255.00) 234861 (-64255) 234861 (-64255) 0.00 (+0.00) 1.00 (+0.00)
Aggregated 6 (0) 46 (-4) 36530.09 (+1854.71) 20852 (+3126) 234861 (-64255) 0.15 (-0.01) 10.00 (-0.80)

User Metrics