Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-26 02:14:5025-10-26 02:14:5600:00:060 → 6
Maintaining25-10-26 02:14:5625-10-26 02:19:5600:05:006
Decreasing25-10-26 02:19:5625-10-26 02:20:3100:00:350 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 35 (-10) 0 14.20 (-0.29) 3 (0) 58 (-4) 0.12 (-0.03) 0.00 (+0.00)
GET get_analysis_latest_cpe 35 (-15) 0 241.17 (+49.37) 32 (-19) 695 (+319) 0.12 (-0.05) 0.00 (+0.00)
GET get_analysis_status 35 (-15) 0 10.94 (+2.74) 1 (0) 55 (+2) 0.12 (-0.05) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 35 (-10) 0 886.14 (+23.92) 154 (-36) 1907 (+213) 0.12 (-0.03) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 35 (-15) 0 1359.49 (+23.69) 314 (-15) 4185 (+93) 0.12 (-0.05) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 35 (-14) 0 8849.77 (-187.66) 3710 (-2192) 14188 (-695) 0.12 (-0.05) 0.00 (+0.00)
GET list_advisory 35 (-10) 0 573.83 (-18.37) 157 (-8) 1076 (-23) 0.12 (-0.03) 0.00 (+0.00)
GET list_advisory_paginated 35 (-10) 0 439.74 (-64.86) 122 (-66) 798 (-108) 0.12 (-0.03) 0.00 (+0.00)
GET list_importer 36 (-10) 0 2.72 (-7.71) 1 (0) 7 (-51) 0.12 (-0.03) 0.00 (+0.00)
GET list_organizations 35 (-10) 0 19.37 (+4.77) 1 (0) 167 (+104) 0.12 (-0.03) 0.00 (+0.00)
GET list_packages 36 (-10) 0 447.03 (+49.75) 110 (+3) 793 (+108) 0.12 (-0.03) 0.00 (+0.00)
GET list_packages_paginated 36 (-10) 0 385.67 (-13.68) 132 (-18) 1014 (+238) 0.12 (-0.03) 0.00 (+0.00)
GET list_products 35 (-15) 0 8.94 (-2.72) 3 (0) 20 (-36) 0.12 (-0.05) 0.00 (+0.00)
GET list_sboms 35 (-15) 0 1093.14 (+49.72) 664 (-81) 1687 (+196) 0.12 (-0.05) 0.00 (+0.00)
GET list_sboms_paginated 35 (-15) 0 1725.63 (-374.29) 603 (-71) 4292 (-1618) 0.12 (-0.05) 0.00 (+0.00)
GET list_vulnerabilities 36 (-10) 0 343.97 (+59.84) 43 (+9) 685 (+169) 0.12 (-0.03) 0.00 (+0.00)
GET list_vulnerabilities_paginated 36 (-10) 0 217.86 (+38.97) 35 (+9) 415 (+107) 0.12 (-0.03) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 35 (-14) 0 81.26 (+11.16) 22 (+13) 192 (-83) 0.12 (-0.05) 0.00 (+0.00)
GET search_advisory 36 (-9) 0 1089.94 (-73.39) 160 (-50) 2321 (-823) 0.12 (-0.03) 0.00 (+0.00)
GET search_exact_purl 35 (-15) 0 47.66 (+33.90) 2 (0) 136 (+67) 0.12 (-0.05) 0.00 (+0.00)
GET search_licenses 2 (0) 0 45762.50 (-22720.50) 45692 (-15591) 45833 (-29850) 0.01 (+0.00) 0.00 (+0.00)
GET search_purls 40 (-10) 0 23005.55 (+10600.57) 9253 (+6139) 30347 (+7182) 0.13 (-0.03) 0.00 (+0.00)
GET search_purls_by_license 2 (+1) 0 86558.00 (-47228.00) 77427 (-56359) 95689 (-38097) 0.01 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 2 (+1) 0 36317.50 (-3465.50) 34716 (-5067) 37919 (-1864) 0.01 (+0.00) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 35 (-10) 0 696.00 (-99.00) 156 (0) 1378 (-232) 0.12 (-0.03) 0.00 (+0.00)
Aggregated 787 (-260) 0 2425.28 (+659.95) 1 (0) 95689 (-38097) 2.62 (-0.87) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (0) 8 (0) 15 (+6) 16 (+1) 41 (-15) 54 (-6) 58 (-4) 58 (-4)
GET get_analysis_latest_cpe 210 (+20) 230 (+30) 290 (+80) 300 (+70) 390 (+110) 400 (+90) 695 (+319) 695 (+319)
GET get_analysis_status 3 (+1) 3 (0) 4 (-1) 5 (-2) 49 (+35) 49 (-3) 55 (+2) 55 (+2)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 900 (+300) 1,000 (0) 1,000 (0) 1,000 (0) 1,907 (+907) 1,907 (+213) 1,907 (+213) 1,907 (+213)
GET get_sbom[sha256:720e4451…a939656247164447] 800 (0) 900 (0) 2,000 (0) 2,000 (0) 3,000 (0) 3,000 (-1,000) 4,000 (0) 4,000 (0)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (0) 9,000 (+1,000) 10,000 (+1,000) 12,000 (+1,000) 12,000 (-1,000) 12,000 (-2,000) 14,000 (-883) 14,000 (-883)
GET list_advisory 600 (0) 600 (0) 700 (0) 700 (-100) 900 (+100) 900 (-100) 1,000 (0) 1,000 (0)
GET list_advisory_paginated 480 (-20) 490 (-110) 500 (-100) 600 (0) 700 (0) 700 (0) 798 (-102) 798 (-102)
GET list_importer 2 (0) 3 (-1) 3 (-2) 4 (-4) 4 (-42) 5 (-46) 7 (-51) 7 (-51)
GET list_organizations 6 (+2) 8 (+2) 21 (+9) 37 (+1) 44 (+2) 50 (+5) 167 (+104) 167 (+104)
GET list_packages 480 (+50) 500 (+20) 600 (+100) 600 (+100) 600 (0) 700 (+100) 793 (+108) 793 (+108)
GET list_packages_paginated 330 (-50) 400 (-70) 470 (-20) 500 (0) 600 (0) 600 (0) 1,000 (+224) 1,000 (+224)
GET list_products 8 (0) 9 (+1) 10 (+1) 11 (0) 14 (-3) 15 (-39) 20 (-36) 20 (-36)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,687 (+687) 1,687 (+687) 1,687 (+687)
GET list_sboms_paginated 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (-1,000) 3,000 (0) 3,000 (-1,000) 4,000 (-1,910) 4,000 (-1,910)
GET list_vulnerabilities 330 (+10) 390 (+50) 400 (+50) 500 (+120) 600 (+190) 685 (+195) 685 (+185) 685 (+185)
GET list_vulnerabilities_paginated 200 (+20) 220 (+10) 290 (+80) 300 (+30) 380 (+100) 400 (+100) 415 (+107) 415 (+107)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 78 (+4) 80 (-1) 84 (+1) 87 (-5) 170 (+70) 170 (-20) 190 (-85) 190 (-85)
GET search_advisory 800 (-200) 1,000 (0) 2,000 (+1,000) 2,000 (0) 2,000 (0) 2,000 (-1,000) 2,000 (-1,000) 2,000 (-1,000)
GET search_exact_purl 37 (+30) 58 (+50) 59 (+51) 60 (+51) 136 (+84) 136 (+81) 136 (+67) 136 (+67)
GET search_licenses 45,833 (-15,450) 45,833 (-15,450) 45,833 (-15,450) 45,833 (-29,850) 45,833 (-29,850) 45,833 (-29,850) 45,833 (-29,850) 45,833 (-29,850)
GET search_purls 23,000 (+11,000) 24,000 (+10,000) 25,000 (+10,000) 26,000 (+10,000) 30,000 (+8,000) 30,000 (+7,000) 30,000 (+7,000) 30,000 (+7,000)
GET search_purls_by_license 77,427 (-56,359) 77,427 (-56,359) 77,427 (-56,359) 95,689 (-38,097) 95,689 (-38,097) 95,689 (-38,097) 95,689 (-38,097) 95,689 (-38,097)
GET search_sboms_by_license 35,000 (-4,783) 35,000 (-4,783) 35,000 (-4,783) 37,919 (-1,864) 37,919 (-1,864) 37,919 (-1,864) 37,919 (-1,864) 37,919 (-1,864)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (-200) 700 (-100) 1,000 (+100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-610) 1,000 (-610)
Aggregated 360 (+10) 500 (0) 700 (0) 1,000 (0) 6,000 (+2,000) 20,000 (+11,000) 30,000 (+8,000) 95,689 (-38,097)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 35 [200]
GET get_analysis_latest_cpe 35 [200]
GET get_analysis_status 35 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 35 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 35 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 35 [200]
GET list_advisory 35 [200]
GET list_advisory_paginated 35 [200]
GET list_importer 36 [200]
GET list_organizations 35 [200]
GET list_packages 36 [200]
GET list_packages_paginated 36 [200]
GET list_products 35 [200]
GET list_sboms 35 [200]
GET list_sboms_paginated 35 [200]
GET list_vulnerabilities 36 [200]
GET list_vulnerabilities_paginated 36 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 35 [200]
GET search_advisory 36 [200]
GET search_exact_purl 35 [200]
GET search_licenses 2 [200]
GET search_purls 40 [200]
GET search_purls_by_license 2 [200]
GET search_sboms_by_license 2 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 35 [200]
Aggregated 787 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 35 (-10) 0 (0) 15.71 (+0.96) 6 (-1) 26 (-9) 0.12 (-0.03) 0.00 (+0.00)
1.1 list_organizations 35 (-10) 0 (0) 19.43 (+4.63) 1 (0) 167 (+104) 0.12 (-0.03) 0.00 (+0.00)
1.2 list_advisory 35 (-10) 0 (0) 574.11 (-18.15) 157 (-8) 1076 (-23) 0.12 (-0.03) 0.00 (+0.00)
1.3 list_advisory_paginated 35 (-10) 0 (0) 439.89 (-64.76) 122 (-66) 799 (-107) 0.12 (-0.03) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 35 (-10) 0 (0) 14.20 (-0.40) 3 (0) 58 (-4) 0.12 (-0.03) 0.00 (+0.00)
1.5 search_advisory 36 (-9) 0 (0) 1090.08 (-73.32) 160 (-50) 2322 (-822) 0.12 (-0.03) 0.00 (+0.00)
1.6 list_vulnerabilities 36 (-10) 0 (0) 344.11 (+59.89) 43 (+9) 685 (+169) 0.12 (-0.03) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 36 (-10) 0 (0) 217.92 (+38.98) 35 (+9) 415 (+107) 0.12 (-0.03) 0.00 (+0.00)
1.8 list_importer 36 (-10) 0 (0) 2.75 (-7.73) 1 (0) 7 (-51) 0.12 (-0.03) 0.00 (+0.00)
1.9 list_packages 36 (-10) 0 (0) 447.19 (+49.87) 110 (+3) 794 (+109) 0.12 (-0.03) 0.00 (+0.00)
1.10 list_packages_paginated 36 (-10) 0 (0) 385.83 (-13.56) 132 (-18) 1014 (+238) 0.12 (-0.03) 0.00 (+0.00)
1.11 search_purls 40 (-10) 0 (0) 23005.60 (+10600.58) 9254 (+6140) 30347 (+7182) 0.13 (-0.03) 0.00 (+0.00)
1.12 search_exact_purl 35 (-15) 0 (0) 47.69 (+33.89) 2 (0) 136 (+67) 0.12 (-0.05) 0.00 (+0.00)
1.13 list_products 35 (-15) 0 (0) 9.03 (-2.63) 3 (0) 20 (-36) 0.12 (-0.05) 0.00 (+0.00)
1.14 list_sboms 35 (-15) 0 (0) 1093.20 (+49.74) 664 (-81) 1687 (+196) 0.12 (-0.05) 0.00 (+0.00)
1.15 list_sboms_paginated 35 (-15) 0 (0) 1725.69 (-374.29) 603 (-71) 4292 (-1618) 0.12 (-0.05) 0.00 (+0.00)
1.16 get_analysis_status 35 (-15) 0 (0) 11.00 (+2.76) 1 (0) 55 (+2) 0.12 (-0.05) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 35 (-15) 0 (0) 241.26 (+49.36) 32 (-19) 695 (+319) 0.12 (-0.05) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 35 (-15) 0 (0) 1359.49 (+23.63) 314 (-15) 4185 (+93) 0.12 (-0.05) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 35 (-14) 0 (0) 81.34 (+11.14) 22 (+13) 192 (-83) 0.12 (-0.05) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 35 (-14) 0 (0) 8849.77 (-187.76) 3710 (-2192) 14188 (-695) 0.12 (-0.05) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 35 (-10) 0 (0) 696.00 (-99.07) 156 (0) 1378 (-232) 0.12 (-0.03) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 35 (-10) 0 (0) 886.14 (+23.79) 154 (-36) 1907 (+213) 0.12 (-0.03) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 1 (0) 0 (0) 7.00 (+0.00) 7 (0) 7 (0) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 2 (0) 0 (0) 45762.50 (-22720.50) 45692 (-15591) 45833 (-29850) 0.01 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 2 (+1) 0 (0) 36317.50 (-3465.50) 34716 (-5067) 37919 (-1864) 0.01 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 2 (+1) 0 (0) 86558.00 (-47228.00) 77427 (-56359) 95689 (-38097) 0.01 (+0.00) 0.00 (+0.00)
Aggregated 823 (-270) 0 (0) 2319.19 (+628.16) 1 (0) 95689 (-38097) 2.74 (-0.90) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 35 (-10) 40662.43 (+8539.70) 23606 (+2754) 53686 (+8615) 0.12 (-0.03) 7.00 (-2.00)
RestAPIUserSlow 1 (0) 1 (0) 176246.00 (-58615.00) 176246 (-58615) 176246 (-58615) 0.00 (+0.00) 1.00 (+0.00)
Aggregated 6 (0) 36 (-10) 44428.64 (+7898.55) 23606 (+2754) 176246 (-58615) 0.12 (-0.03) 8.00 (-2.00)

User Metrics