Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-27 02:16:2625-10-27 02:16:3200:00:060 → 6
Maintaining25-10-27 02:16:3225-10-27 02:21:3200:05:006
Decreasing25-10-27 02:21:3225-10-27 02:21:5100:00:190 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 45 (+10) 0 11.13 (-3.07) 3 (0) 58 (0) 0.15 (+0.03) 0.00 (+0.00)
GET get_analysis_latest_cpe 45 (+10) 0 167.07 (-74.10) 33 (+1) 389 (-306) 0.15 (+0.03) 0.00 (+0.00)
GET get_analysis_status 45 (+10) 0 8.11 (-2.83) 1 (0) 50 (-5) 0.15 (+0.03) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 45 (+10) 0 769.73 (-116.41) 138 (-16) 1472 (-435) 0.15 (+0.03) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 45 (+10) 0 902.40 (-457.09) 213 (-101) 4117 (-68) 0.15 (+0.03) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 45 (+10) 0 8546.13 (-303.64) 2618 (-1092) 13731 (-457) 0.15 (+0.03) 0.00 (+0.00)
GET list_advisory 45 (+10) 0 505.56 (-68.27) 135 (-22) 934 (-142) 0.15 (+0.03) 0.00 (+0.00)
GET list_advisory_paginated 45 (+10) 0 441.38 (+1.63) 120 (-2) 931 (+133) 0.15 (+0.03) 0.00 (+0.00)
GET list_importer 46 (+10) 0 4.13 (+1.41) 1 (0) 48 (+41) 0.15 (+0.03) 0.00 (+0.00)
GET list_organizations 45 (+10) 0 12.11 (-7.26) 1 (0) 57 (-110) 0.15 (+0.03) 0.00 (+0.00)
GET list_packages 46 (+10) 0 411.74 (-35.29) 118 (+8) 782 (-11) 0.15 (+0.03) 0.00 (+0.00)
GET list_packages_paginated 46 (+10) 0 332.04 (-53.62) 128 (-4) 599 (-415) 0.15 (+0.03) 0.00 (+0.00)
GET list_products 45 (+10) 0 10.44 (+1.50) 2 (-1) 67 (+47) 0.15 (+0.03) 0.00 (+0.00)
GET list_sboms 45 (+10) 0 1057.98 (-35.17) 657 (-7) 1654 (-33) 0.15 (+0.03) 0.00 (+0.00)
GET list_sboms_paginated 45 (+10) 0 1626.07 (-99.56) 346 (-257) 5195 (+903) 0.15 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities 46 (+10) 0 374.65 (+30.68) 61 (+18) 826 (+141) 0.15 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities_paginated 46 (+10) 0 188.89 (-28.97) 32 (-3) 295 (-120) 0.15 (+0.03) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 45 (+10) 0 73.29 (-7.97) 15 (-7) 257 (+65) 0.15 (+0.03) 0.00 (+0.00)
GET search_advisory 45 (+9) 0 1008.29 (-81.66) 196 (+36) 3002 (+681) 0.15 (+0.03) 0.00 (+0.00)
GET search_exact_purl 45 (+10) 0 15.27 (-32.39) 2 (0) 65 (-71) 0.15 (+0.03) 0.00 (+0.00)
GET search_licenses 2 (0) 0 66422.00 (+20659.50) 65575 (+19883) 67269 (+21436) 0.01 (+0.00) 0.00 (+0.00)
GET search_purls 50 (+10) 0 15116.62 (-7888.93) 5020 (-4233) 24619 (-5728) 0.17 (+0.03) 0.00 (+0.00)
GET search_purls_by_license 1 (-1) 0 126729.00 (+40171.00) 126729 (+49302) 126729 (+31040) 0.00 (-0.00) 0.00 (+0.00)
GET search_sboms_by_license 2 (0) 0 30477.50 (-5840.00) 22260 (-12456) 38695 (+776) 0.01 (+0.00) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 45 (+10) 0 814.11 (+118.11) 132 (-24) 1585 (+207) 0.15 (+0.03) 0.00 (+0.00)
Aggregated 1005 (+218) 0 1846.06 (-579.21) 1 (0) 126729 (+31040) 3.35 (+0.73) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (0) 8 (0) 9 (-6) 10 (-6) 12 (-29) 54 (0) 58 (0) 58 (0)
GET get_analysis_latest_cpe 170 (-40) 180 (-50) 190 (-100) 210 (-90) 290 (-100) 330 (-70) 389 (-306) 389 (-306)
GET get_analysis_status 3 (0) 4 (+1) 4 (0) 5 (0) 45 (-4) 49 (0) 50 (-5) 50 (-5)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 700 (-200) 900 (-100) 1,000 (0) 1,000 (0) 1,000 (-907) 1,000 (-907) 1,000 (-907) 1,000 (-907)
GET get_sbom[sha256:720e4451…a939656247164447] 700 (-100) 800 (-100) 900 (-1,100) 900 (-1,100) 2,000 (-1,000) 2,000 (-1,000) 4,000 (0) 4,000 (0)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (0) 8,000 (-1,000) 11,000 (+1,000) 11,000 (-1,000) 12,000 (0) 12,000 (0) 13,731 (-269) 13,731 (-269)
GET list_advisory 500 (-100) 600 (0) 600 (-100) 600 (-100) 700 (-200) 800 (-100) 900 (-100) 900 (-100)
GET list_advisory_paginated 480 (0) 490 (0) 500 (0) 500 (-100) 600 (-100) 600 (-100) 900 (+102) 900 (+102)
GET list_importer 2 (0) 3 (0) 4 (+1) 5 (+1) 6 (+2) 7 (+2) 48 (+41) 48 (+41)
GET list_organizations 4 (-2) 5 (-3) 6 (-15) 27 (-10) 42 (-2) 45 (-5) 57 (-110) 57 (-110)
GET list_packages 490 (+10) 500 (0) 500 (-100) 600 (0) 600 (0) 700 (0) 782 (-11) 782 (-11)
GET list_packages_paginated 320 (-10) 390 (-10) 400 (-70) 460 (-40) 490 (-110) 500 (-100) 599 (-401) 599 (-401)
GET list_products 8 (0) 8 (-1) 10 (0) 12 (+1) 14 (0) 16 (+1) 67 (+47) 67 (+47)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-687) 1,654 (-33) 1,654 (-33)
GET list_sboms_paginated 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 3,000 (0) 4,000 (+1,000) 5,000 (+1,000) 5,000 (+1,000)
GET list_vulnerabilities 350 (+20) 420 (+30) 500 (+100) 500 (0) 700 (+100) 800 (+115) 800 (+115) 800 (+115)
GET list_vulnerabilities_paginated 200 (0) 220 (0) 260 (-30) 270 (-30) 270 (-110) 290 (-110) 295 (-120) 295 (-120)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 70 (-8) 76 (-4) 84 (0) 89 (+2) 140 (-30) 190 (+20) 257 (+67) 257 (+67)
GET search_advisory 800 (0) 800 (-200) 900 (-1,100) 1,000 (-1,000) 2,000 (0) 3,000 (+1,000) 3,000 (+1,000) 3,000 (+1,000)
GET search_exact_purl 7 (-30) 8 (-50) 10 (-49) 11 (-49) 53 (-83) 53 (-83) 65 (-71) 65 (-71)
GET search_licenses 66,000 (+20,167) 66,000 (+20,167) 66,000 (+20,167) 67,000 (+21,167) 67,000 (+21,167) 67,000 (+21,167) 67,000 (+21,167) 67,000 (+21,167)
GET search_purls 14,000 (-9,000) 16,000 (-8,000) 17,000 (-8,000) 19,000 (-7,000) 20,000 (-10,000) 22,000 (-8,000) 24,619 (-5,381) 24,619 (-5,381)
GET search_purls_by_license 126,729 (+49,302) 126,729 (+49,302) 126,729 (+49,302) 126,729 (+31,040) 126,729 (+31,040) 126,729 (+31,040) 126,729 (+31,040) 126,729 (+31,040)
GET search_sboms_by_license 22,260 (-12,740) 22,260 (-12,740) 22,260 (-12,740) 38,695 (+776) 38,695 (+776) 38,695 (+776) 38,695 (+776) 38,695 (+776)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 800 (+200) 800 (+100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,585 (+585) 1,585 (+585)
Aggregated 320 (-40) 500 (0) 700 (0) 1,000 (0) 4,000 (-2,000) 12,000 (-8,000) 20,000 (-10,000) 126,729 (+31,040)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 45 [200]
GET get_analysis_latest_cpe 45 [200]
GET get_analysis_status 45 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 45 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 45 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 45 [200]
GET list_advisory 45 [200]
GET list_advisory_paginated 45 [200]
GET list_importer 46 [200]
GET list_organizations 45 [200]
GET list_packages 46 [200]
GET list_packages_paginated 46 [200]
GET list_products 45 [200]
GET list_sboms 45 [200]
GET list_sboms_paginated 45 [200]
GET list_vulnerabilities 46 [200]
GET list_vulnerabilities_paginated 46 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 45 [200]
GET search_advisory 45 [200]
GET search_exact_purl 45 [200]
GET search_licenses 2 [200]
GET search_purls 50 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 2 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 45 [200]
Aggregated 1,005 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 45 (+10) 0 (0) 15.11 (-0.60) 6 (0) 30 (+4) 0.15 (+0.03) 0.00 (+0.00)
1.1 list_organizations 45 (+10) 0 (0) 12.33 (-7.10) 1 (0) 57 (-110) 0.15 (+0.03) 0.00 (+0.00)
1.2 list_advisory 45 (+10) 0 (0) 505.67 (-68.45) 135 (-22) 934 (-142) 0.15 (+0.03) 0.00 (+0.00)
1.3 list_advisory_paginated 45 (+10) 0 (0) 441.42 (+1.54) 120 (-2) 931 (+132) 0.15 (+0.03) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 45 (+10) 0 (0) 11.20 (-3.00) 3 (0) 58 (0) 0.15 (+0.03) 0.00 (+0.00)
1.5 search_advisory 45 (+9) 0 (0) 1008.31 (-81.77) 196 (+36) 3002 (+680) 0.15 (+0.03) 0.00 (+0.00)
1.6 list_vulnerabilities 46 (+10) 0 (0) 374.72 (+30.61) 61 (+18) 826 (+141) 0.15 (+0.03) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 46 (+10) 0 (0) 188.93 (-28.98) 32 (-3) 296 (-119) 0.15 (+0.03) 0.00 (+0.00)
1.8 list_importer 46 (+10) 0 (0) 4.17 (+1.42) 1 (0) 48 (+41) 0.15 (+0.03) 0.00 (+0.00)
1.9 list_packages 46 (+10) 0 (0) 411.85 (-35.35) 118 (+8) 782 (-12) 0.15 (+0.03) 0.00 (+0.00)
1.10 list_packages_paginated 46 (+10) 0 (0) 332.09 (-53.75) 128 (-4) 599 (-415) 0.15 (+0.03) 0.00 (+0.00)
1.11 search_purls 50 (+10) 0 (0) 15116.64 (-7888.96) 5020 (-4234) 24619 (-5728) 0.17 (+0.03) 0.00 (+0.00)
1.12 search_exact_purl 45 (+10) 0 (0) 15.27 (-32.42) 2 (0) 65 (-71) 0.15 (+0.03) 0.00 (+0.00)
1.13 list_products 45 (+10) 0 (0) 10.49 (+1.46) 2 (-1) 67 (+47) 0.15 (+0.03) 0.00 (+0.00)
1.14 list_sboms 45 (+10) 0 (0) 1058.00 (-35.20) 657 (-7) 1654 (-33) 0.15 (+0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 45 (+10) 0 (0) 1626.09 (-99.60) 346 (-257) 5195 (+903) 0.15 (+0.03) 0.00 (+0.00)
1.16 get_analysis_status 45 (+10) 0 (0) 8.13 (-2.87) 1 (0) 50 (-5) 0.15 (+0.03) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 45 (+10) 0 (0) 167.09 (-74.17) 33 (+1) 389 (-306) 0.15 (+0.03) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 45 (+10) 0 (0) 902.51 (-456.97) 213 (-101) 4117 (-68) 0.15 (+0.03) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 45 (+10) 0 (0) 73.42 (-7.92) 15 (-7) 257 (+65) 0.15 (+0.03) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 45 (+10) 0 (0) 8546.18 (-303.59) 2618 (-1092) 13731 (-457) 0.15 (+0.03) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 45 (+10) 0 (0) 814.11 (+118.11) 132 (-24) 1585 (+207) 0.15 (+0.03) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 45 (+10) 0 (0) 769.78 (-116.37) 139 (-15) 1472 (-435) 0.15 (+0.03) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 1 (0) 0 (0) 11.00 (+4.00) 11 (+4) 11 (+4) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 2 (0) 0 (0) 66422.50 (+20660.00) 65575 (+19883) 67270 (+21437) 0.01 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 2 (0) 0 (0) 30477.50 (-5840.00) 22260 (-12456) 38695 (+776) 0.01 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (-1) 0 (0) 126729.00 (+40171.00) 126729 (+49302) 126729 (+31040) 0.00 (-0.00) 0.00 (+0.00)
Aggregated 1,051 (+228) 0 (0) 1765.27 (-553.92) 1 (0) 126729 (+31040) 3.50 (+0.76) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 45 (+10) 32507.53 (-8154.90) 19116 (-4490) 40775 (-12911) 0.15 (+0.03) 9.00 (+2.00)
RestAPIUserSlow 1 (0) 1 (0) 231010.00 (+54764.00) 231010 (+54764) 231010 (+54764) 0.00 (+0.00) 1.00 (+0.00)
Aggregated 6 (0) 46 (+10) 36822.80 (-7605.84) 19116 (-4490) 231010 (+54764) 0.15 (+0.03) 10.00 (+2.00)

User Metrics