Goose Attack Report

Users: 6

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-10-30 02:16:4425-10-30 02:16:5000:00:060 → 6
Maintaining25-10-30 02:16:5025-10-30 02:21:5000:05:006
Decreasing25-10-30 02:21:5025-10-30 02:21:5200:00:020 ← 6

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 51 (-2) 0 15.61 (+4.08) 3 (0) 65 (+4) 0.17 (-0.01) 0.00 (+0.00)
GET get_analysis_latest_cpe 55 (0) 0 208.04 (-45.84) 37 (-46) 589 (+59) 0.18 (+0.00) 0.00 (+0.00)
GET get_analysis_status 55 (0) 0 11.24 (+6.20) 1 (0) 57 (+2) 0.18 (+0.00) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 52 (-3) 0 986.88 (+125.76) 281 (+132) 1920 (-171) 0.17 (-0.01) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 55 (0) 0 1245.45 (-877.82) 302 (-136) 4067 (-2731) 0.18 (+0.00) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 54 (-1) 0 8397.26 (+877.20) 4499 (-179) 14715 (+1492) 0.18 (-0.00) 0.00 (+0.00)
GET list_advisory 52 (-2) 0 666.10 (+47.06) 273 (+153) 1361 (+1) 0.17 (-0.01) 0.00 (+0.00)
GET list_advisory_paginated 52 (-1) 0 563.58 (+30.88) 163 (-5) 1616 (+302) 0.17 (-0.00) 0.00 (+0.00)
GET list_importer 51 (-2) 0 5.22 (-1.14) 1 (0) 53 (-1) 0.17 (-0.01) 0.00 (+0.00)
GET list_organizations 52 (-3) 0 19.94 (+1.42) 1 (0) 52 (0) 0.17 (-0.01) 0.00 (+0.00)
GET list_packages 51 (-2) 0 440.25 (+21.69) 64 (-34) 973 (-176) 0.17 (-0.01) 0.00 (+0.00)
GET list_packages_paginated 51 (-2) 0 375.33 (+38.28) 112 (-4) 784 (+214) 0.17 (-0.01) 0.00 (+0.00)
GET list_products 55 (-2) 0 17.11 (+3.78) 3 (0) 73 (-12) 0.18 (-0.01) 0.00 (+0.00)
GET list_sboms 55 (-2) 0 1379.53 (-95.75) 798 (+93) 2790 (+610) 0.18 (-0.01) 0.00 (+0.00)
GET list_sboms_paginated 55 (-1) 0 1740.55 (-2728.12) 445 (-58) 4078 (-8921) 0.18 (-0.00) 0.00 (+0.00)
GET list_vulnerabilities 51 (-2) 0 257.59 (-75.81) 114 (+27) 449 (-274) 0.17 (-0.01) 0.00 (+0.00)
GET list_vulnerabilities_paginated 51 (-2) 0 196.61 (+16.04) 41 (+12) 324 (+26) 0.17 (-0.01) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 54 (-1) 0 82.98 (-9.00) 16 (-3) 402 (+82) 0.18 (-0.00) 0.00 (+0.00)
GET search_advisory 51 (-2) 0 992.80 (-377.74) 238 (+43) 2396 (-1300) 0.17 (-0.01) 0.00 (+0.00)
GET search_exact_purl 55 (-2) 0 16.33 (+9.41) 3 (+1) 73 (+43) 0.18 (-0.01) 0.00 (+0.00)
GET search_licenses 1 (0) 0 67646.00 (-28671.00) 67646 (-28671) 67646 (-28671) 0.00 (+0.00) 0.00 (+0.00)
GET search_purls 55 (-2) 0 9534.13 (+3636.09) 2823 (+2117) 19327 (+6854) 0.18 (-0.01) 0.00 (+0.00)
GET search_purls_by_license 1 (0) 0 195223.00 (+56746.00) 195223 (+56746) 195223 (+56746) 0.00 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 1 (0) 0 41217.00 (-39919.00) 41217 (-39919) 41217 (-39919) 0.00 (+0.00) 0.00 (+0.00)
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 52 0 15.98 4 64 0.17 0.00
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 52 (-3) 0 957.38 (+141.53) 586 (+354) 1570 (+59) 0.17 (-0.01) 0.00 (+0.00)
Aggregated 1220 (+15) 0 1494.89 (-26.34) 1 (0) 195223 (+56746) 4.07 (+0.05) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 9 (+3) 11 (+4) 12 (+3) 12 (+2) 53 (+25) 57 (+5) 58 (-1) 65 (+4)
GET get_analysis_latest_cpe 200 (-50) 210 (-60) 240 (-50) 280 (-20) 350 (-30) 380 (-40) 589 (+119) 589 (+89)
GET get_analysis_status 3 (0) 3 (0) 4 (0) 8 (+3) 47 (+38) 49 (+39) 52 (0) 57 (+2)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 800 (+100) 1,000 (+200) 1,000 (0) 1,000 (0) 1,920 (-80) 1,920 (-80) 1,920 (-80) 1,920 (-80)
GET get_sbom[sha256:720e4451…a939656247164447] 800 (-100) 900 (-100) 1,000 (-1,000) 2,000 (-3,000) 3,000 (-2,000) 3,000 (-3,798) 4,000 (-2,798) 4,000 (-2,798)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 7,000 (0) 8,000 (+1,000) 9,000 (+1,000) 12,000 (+3,000) 13,000 (+1,000) 13,000 (+1,000) 14,000 (+1,000) 14,715 (+1,715)
GET list_advisory 600 (+100) 700 (+100) 700 (+100) 800 (0) 900 (-100) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory_paginated 500 (+10) 500 (0) 600 (0) 700 (0) 800 (0) 900 (0) 1,616 (+616) 1,616 (+616)
GET list_importer 2 (0) 3 (0) 3 (-1) 5 (0) 6 (0) 8 (-41) 51 (-3) 53 (-1)
GET list_organizations 8 (+4) 15 (+5) 37 (-2) 42 (-1) 48 (+1) 49 (-1) 49 (-1) 52 (0)
GET list_packages 410 (-40) 430 (-50) 480 (-10) 500 (0) 700 (+100) 800 (+100) 900 (+100) 973 (-27)
GET list_packages_paginated 380 (+50) 390 (+20) 410 (-10) 480 (+50) 500 (+10) 600 (+100) 600 (+100) 784 (+214)
GET list_products 9 (+2) 12 (+4) 13 (+1) 16 (+2) 57 (+34) 68 (+4) 69 (-13) 73 (-12)
GET list_sboms 1,000 (-1,000) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,790 (+790) 2,790 (+790)
GET list_sboms_paginated 2,000 (-2,000) 2,000 (-3,000) 2,000 (-3,000) 2,000 (-5,000) 3,000 (-5,000) 4,000 (-5,000) 4,000 (-5,000) 4,000 (-8,999)
GET list_vulnerabilities 270 (0) 290 (-20) 310 (-70) 310 (-290) 370 (-330) 380 (-320) 380 (-320) 449 (-251)
GET list_vulnerabilities_paginated 200 (0) 220 (+10) 230 (+20) 270 (+50) 280 (0) 300 (+20) 320 (+30) 320 (+22)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 73 (-14) 77 (-15) 83 (-17) 93 (-37) 150 (-30) 230 (+40) 290 (+90) 400 (+80)
GET search_advisory 900 (-100) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-2,000) 2,000 (-1,000) 2,000 (-1,696) 2,000 (-1,696)
GET search_exact_purl 8 (+3) 9 (+3) 12 (+5) 13 (+5) 54 (+42) 61 (+46) 64 (+34) 73 (+43)
GET search_licenses 67,646 (-28,671) 67,646 (-28,671) 67,646 (-28,671) 67,646 (-28,671) 67,646 (-28,671) 67,646 (-28,671) 67,646 (-28,671) 67,646 (-28,671)
GET search_purls 10,000 (+4,000) 13,000 (+7,000) 14,000 (+6,000) 16,000 (+8,000) 17,000 (+6,000) 18,000 (+6,000) 19,000 (+7,000) 19,000 (+7,000)
GET search_purls_by_license 195,223 (+56,746) 195,223 (+56,746) 195,223 (+56,746) 195,223 (+56,746) 195,223 (+56,746) 195,223 (+56,746) 195,223 (+56,746) 195,223 (+56,746)
GET search_sboms_by_license 41,217 (-39,919) 41,217 (-39,919) 41,217 (-39,919) 41,217 (-39,919) 41,217 (-39,919) 41,217 (-39,919) 41,217 (-39,919) 41,217 (-39,919)
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 8 9 12 21 53 55 62 64
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 900 (+100) 1,000 (+200) 1,000 (+100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-511) 1,570 (+59)
Aggregated 320 (-50) 500 (0) 800 (0) 1,000 (0) 3,000 (-2,000) 7,000 (0) 16,000 (+4,000) 195,000 (+57,000)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 51 [200]
GET get_analysis_latest_cpe 55 [200]
GET get_analysis_status 55 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 52 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 55 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 54 [200]
GET list_advisory 52 [200]
GET list_advisory_paginated 52 [200]
GET list_importer 51 [200]
GET list_organizations 52 [200]
GET list_packages 51 [200]
GET list_packages_paginated 51 [200]
GET list_products 55 [200]
GET list_sboms 55 [200]
GET list_sboms_paginated 55 [200]
GET list_vulnerabilities 51 [200]
GET list_vulnerabilities_paginated 51 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 54 [200]
GET search_advisory 51 [200]
GET search_exact_purl 55 [200]
GET search_licenses 1 [200]
GET search_purls 55 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [200]
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 52 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 52 [200]
Aggregated 1,220 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 52 (-3) 0 (0) 15.96 (+0.43) 7 (0) 34 (-2) 0.17 (-0.01) 0.00 (+0.00)
1.1 list_organizations 52 (-3) 0 (0) 20.19 (+1.48) 1 (0) 52 (0) 0.17 (-0.01) 0.00 (+0.00)
1.2 list_advisory 52 (-2) 0 (0) 666.25 (+47.06) 273 (+153) 1361 (+1) 0.17 (-0.01) 0.00 (+0.00)
1.3 list_advisory_paginated 52 (-1) 0 (0) 563.62 (+30.90) 163 (-5) 1616 (+302) 0.17 (-0.00) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 51 (-2) 0 (0) 15.67 (+4.08) 3 (0) 65 (+4) 0.17 (-0.01) 0.00 (+0.00)
1.5 search_advisory 51 (-2) 0 (0) 992.84 (-377.80) 238 (+43) 2396 (-1300) 0.17 (-0.01) 0.00 (+0.00)
1.6 list_vulnerabilities 51 (-2) 0 (0) 257.67 (-75.75) 114 (+27) 449 (-274) 0.17 (-0.01) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 51 (-2) 0 (0) 196.65 (+16.04) 41 (+12) 324 (+26) 0.17 (-0.01) 0.00 (+0.00)
1.8 list_importer 51 (-2) 0 (0) 5.25 (-1.10) 1 (0) 53 (-1) 0.17 (-0.01) 0.00 (+0.00)
1.9 list_packages 51 (-2) 0 (0) 440.31 (+21.71) 64 (-34) 973 (-176) 0.17 (-0.01) 0.00 (+0.00)
1.10 list_packages_paginated 51 (-2) 0 (0) 375.45 (+38.32) 112 (-4) 784 (+214) 0.17 (-0.01) 0.00 (+0.00)
1.11 search_purls 55 (-2) 0 (0) 9534.15 (+3636.04) 2823 (+2116) 19327 (+6854) 0.18 (-0.01) 0.00 (+0.00)
1.12 search_exact_purl 55 (-2) 0 (0) 16.44 (+9.47) 3 (+1) 74 (+44) 0.18 (-0.01) 0.00 (+0.00)
1.13 list_products 55 (-2) 0 (0) 17.15 (+3.76) 3 (0) 74 (-11) 0.18 (-0.01) 0.00 (+0.00)
1.14 list_sboms 55 (-2) 0 (0) 1379.56 (-95.75) 798 (+93) 2790 (+610) 0.18 (-0.01) 0.00 (+0.00)
1.15 list_sboms_paginated 55 (-1) 0 (0) 1740.56 (-2728.22) 445 (-58) 4078 (-8921) 0.18 (-0.00) 0.00 (+0.00)
1.16 get_analysis_status 55 (0) 0 (0) 11.27 (+6.22) 1 (0) 57 (+2) 0.18 (+0.00) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 55 (0) 0 (0) 208.07 (-45.82) 37 (-46) 589 (+59) 0.18 (+0.00) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 55 (0) 0 (0) 1245.56 (-877.84) 302 (-136) 4067 (-2731) 0.18 (+0.00) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 54 (-1) 0 (0) 83.02 (-9.09) 16 (-3) 402 (+82) 0.18 (-0.00) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 54 (-1) 0 (0) 8397.31 (+877.19) 4499 (-179) 14715 (+1492) 0.18 (-0.00) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 52 (-3) 0 (0) 957.48 (+141.55) 587 (+355) 1570 (+59) 0.17 (-0.01) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 52 (-3) 0 (0) 987.04 (+125.80) 281 (+132) 1923 (-168) 0.17 (-0.01) 0.00 (+0.00)
1.23 get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 52 0 16.00 4 64 0.17 0.00
RestAPIUserSlow
2.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 1 (0) 0 (0) 67646.00 (-28671.00) 67646 (-28671) 67646 (-28671) 0.00 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 1 (0) 0 (0) 41217.00 (-39919.00) 41217 (-39919) 41217 (-39919) 0.00 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (0) 0 (0) 195223.00 (+56746.00) 195223 (+56746) 195223 (+56746) 0.00 (+0.00) 0.00 (+0.00)
Aggregated 1,272 (+12) 0 (0) 1433.78 (-21.05) 1 (0) 195223 (+56746) 4.24 (+0.04) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 52 (-3) 28120.75 (+857.40) 18290 (+1714) 43217 (+5098) 0.17 (-0.01) 10.40 (-0.60)
RestAPIUserSlow 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
Aggregated 5 (0) 52 (-3) 28120.75 (+857.40) 18290 (+1714) 43217 (+5098) 0.17 (-0.01) 10.40 (-0.60)

User Metrics