Goose Attack Report

Users: 7

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-11-01 02:20:2325-11-01 02:20:3000:00:070 → 7
Maintaining25-11-01 02:20:3025-11-01 02:25:3000:05:007
Decreasing25-11-01 02:25:3025-11-01 02:25:3100:00:010 ← 7

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 35 0 1693.00 313 4637 0.12 0.00
GET get_advisory_by_doc_id 45 (+1) 0 19.69 (-0.13) 3 (0) 110 (-60) 0.15 (+0.00) 0.00 (+0.00)
GET get_analysis_latest_cpe 50 (+4) 0 268.56 (+45.76) 35 (-49) 1754 (+1192) 0.17 (+0.01) 0.00 (+0.00)
GET get_analysis_status 50 (+4) 0 14.72 (+5.59) 1 (0) 363 (+310) 0.17 (+0.01) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 48 (+4) 0 1034.33 (+406.95) 153 (-19) 2748 (+1224) 0.16 (+0.01) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 50 (+4) 0 1839.54 (-174.46) 264 (+67) 6580 (+219) 0.17 (+0.01) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 50 (+4) 0 8472.02 (+3026.61) 3361 (-345) 14313 (+3136) 0.17 (+0.01) 0.00 (+0.00)
GET list_advisory 48 (+4) 0 600.88 (+157.69) 93 (-37) 1703 (+526) 0.16 (+0.01) 0.00 (+0.00)
GET list_advisory_paginated 48 (+4) 0 467.40 (+53.42) 180 (+24) 1025 (+123) 0.16 (+0.01) 0.00 (+0.00)
GET list_importer 46 (+3) 0 7.91 (-1.46) 1 (0) 72 (+18) 0.15 (+0.01) 0.00 (+0.00)
GET list_organizations 48 (+4) 0 20.15 (+9.87) 2 (+1) 369 (+322) 0.16 (+0.01) 0.00 (+0.00)
GET list_packages 46 (+3) 0 460.15 (+60.57) 99 (-47) 1241 (+162) 0.15 (+0.01) 0.00 (+0.00)
GET list_packages_paginated 46 (+3) 0 366.28 (+5.45) 98 (-32) 582 (-19) 0.15 (+0.01) 0.00 (+0.00)
GET list_products 50 (+4) 0 11.04 (-2.24) 5 (+2) 74 (-20) 0.17 (+0.01) 0.00 (+0.00)
GET list_sboms 50 (+4) 0 1554.74 (+272.46) 492 (+253) 3692 (+83) 0.17 (+0.01) 0.00 (+0.00)
GET list_sboms_paginated 50 (+4) 0 4650.18 (+149.38) 509 (+194) 13812 (+1806) 0.17 (+0.01) 0.00 (+0.00)
GET list_vulnerabilities 45 (+2) 0 398.04 (+125.28) 41 (-3) 715 (+87) 0.15 (+0.01) 0.00 (+0.00)
GET list_vulnerabilities_paginated 45 (+2) 0 225.27 (+42.55) 28 (-6) 400 (+74) 0.15 (+0.01) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 50 (+4) 0 59.96 (-25.78) 6 (-7) 611 (+357) 0.17 (+0.01) 0.00 (+0.00)
GET search_advisory 45 (+1) 0 917.51 (-168.78) 128 (-49) 1880 (-2439) 0.15 (+0.00) 0.00 (+0.00)
GET search_exact_purl 50 (+4) 0 8.86 (-12.55) 4 (0) 55 (-13) 0.17 (+0.01) 0.00 (+0.00)
GET search_licenses 1 (-1) 0 86996.00 (+35793.00) 86996 (+44837) 86996 (+26749) 0.00 (-0.00) 0.00 (+0.00)
GET search_purls 50 (+4) 0 8743.02 (-185.50) 4489 (+2258) 12789 (-4886) 0.17 (+0.01) 0.00 (+0.00)
GET search_purls_by_license 1 (0) 0 154872.00 (-27864.00) 154872 (-27864) 154872 (-27864) 0.00 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 1 (0) 0 60893.00 (+16129.00) 60893 (+16129) 60893 (+16129) 0.00 (+0.00) 0.00 (+0.00)
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 48 (+4) 0 37.85 (+22.54) 3 (+1) 496 (+440) 0.16 (+0.01) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 48 (+4) 0 577.69 (+258.35) 68 (-3) 1738 (+855) 0.16 (+0.01) 0.00 (+0.00)
Aggregated 1144 (+113) 0 1646.14 (+144.85) 1 (0) 154872 (-27864) 3.81 (+0.38) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 1,000 2,000 2,000 2,000 3,000 3,000 4,637 4,637
GET get_advisory_by_doc_id 8 (+1) 10 (+2) 12 (+3) 19 (-24) 60 (+2) 80 (+18) 110 (-60) 110 (-60)
GET get_analysis_latest_cpe 220 (+20) 220 (0) 280 (+20) 310 (+20) 380 (+50) 500 (+110) 1,754 (+1,192) 1,754 (+1,192)
GET get_analysis_status 3 (-1) 5 (+1) 6 (+1) 7 (0) 12 (-7) 51 (0) 360 (+307) 360 (+307)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 1,000 (+400) 1,000 (+400) 1,000 (+300) 1,000 (+200) 2,000 (+1,000) 2,000 (+1,000) 2,748 (+1,224) 2,748 (+1,224)
GET get_sbom[sha256:720e4451…a939656247164447] 2,000 (+1,100) 2,000 (+1,000) 2,000 (-1,000) 3,000 (-1,000) 3,000 (-2,000) 3,000 (-2,000) 6,580 (+580) 6,580 (+580)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (+3,000) 9,000 (+3,000) 9,000 (+3,000) 10,000 (+4,000) 11,000 (+4,000) 13,000 (+6,000) 14,000 (+3,000) 14,000 (+3,000)
GET list_advisory 600 (+190) 600 (+150) 600 (+120) 700 (+200) 900 (+300) 1,703 (+1,103) 1,703 (+703) 1,703 (+703)
GET list_advisory_paginated 490 (+90) 500 (+70) 500 (+20) 600 (+100) 600 (0) 800 (+200) 1,000 (+100) 1,000 (+100)
GET list_importer 3 (0) 3 (0) 4 (0) 6 (0) 23 (-20) 36 (-16) 72 (+18) 72 (+18)
GET list_organizations 6 (+1) 7 (+2) 9 (+3) 17 (+10) 43 (+1) 47 (+3) 369 (+322) 369 (+322)
GET list_packages 470 (+80) 500 (+90) 500 (+80) 600 (+120) 700 (+200) 900 (+300) 1,000 (0) 1,000 (0)
GET list_packages_paginated 410 (+30) 420 (+30) 470 (+70) 490 (+70) 500 (+10) 582 (+82) 582 (-18) 582 (-18)
GET list_products 9 (+2) 11 (+3) 12 (+2) 14 (+2) 15 (-3) 17 (-44) 74 (-20) 74 (-20)
GET list_sboms 1,000 (+300) 1,000 (+100) 2,000 (+1,000) 2,000 (0) 3,000 (0) 3,000 (0) 3,692 (+83) 3,692 (+83)
GET list_sboms_paginated 4,000 (+3,200) 4,000 (+2,000) 6,000 (-3,000) 8,000 (-2,000) 8,000 (-3,000) 9,000 (-3,000) 13,812 (+1,812) 13,812 (+1,812)
GET list_vulnerabilities 390 (+120) 420 (+130) 600 (+300) 600 (+280) 600 (+110) 700 (+210) 700 (+100) 700 (+100)
GET list_vulnerabilities_paginated 220 (+30) 230 (+30) 280 (+70) 310 (+90) 380 (+90) 390 (+80) 400 (+74) 400 (+74)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 19 (-54) 36 (-50) 61 (-31) 76 (-54) 130 (-60) 210 (+10) 600 (+350) 600 (+350)
GET search_advisory 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,880 (-120) 1,880 (-120) 1,880 (-2,120) 1,880 (-2,120)
GET search_exact_purl 6 (-2) 6 (-4) 7 (-9) 8 (-42) 9 (-45) 41 (-19) 55 (-13) 55 (-13)
GET search_licenses 86,996 (+44,837) 86,996 (+44,837) 86,996 (+44,837) 86,996 (+26,996) 86,996 (+26,996) 86,996 (+26,996) 86,996 (+26,996) 86,996 (+26,996)
GET search_purls 8,000 (+3,000) 9,000 (-3,000) 10,000 (-4,000) 11,000 (-5,000) 12,000 (-5,000) 12,789 (-4,886) 12,789 (-4,886) 12,789 (-4,886)
GET search_purls_by_license 154,872 (-27,864) 154,872 (-27,864) 154,872 (-27,864) 154,872 (-27,864) 154,872 (-27,864) 154,872 (-27,864) 154,872 (-27,864) 154,872 (-27,864)
GET search_sboms_by_license 60,893 (+16,129) 60,893 (+16,129) 60,893 (+16,129) 60,893 (+16,129) 60,893 (+16,129) 60,893 (+16,129) 60,893 (+16,129) 60,893 (+16,129)
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 10 (+3) 11 (+4) 14 (+5) 17 (+2) 30 (-23) 300 (+247) 496 (+440) 496 (+440)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 400 (+110) 600 (+300) 900 (+590) 900 (+510) 1,000 (+400) 1,738 (+938) 1,738 (+855) 1,738 (+855)
Aggregated 370 (+80) 500 (+110) 700 (+200) 1,000 (+200) 6,000 (+2,000) 8,000 (+1,000) 12,000 (-4,000) 154,872 (-27,864)

Status Code Metrics

Method Name Status Codes
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 35 [200]
GET get_advisory_by_doc_id 45 [200]
GET get_analysis_latest_cpe 50 [200]
GET get_analysis_status 50 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 48 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 50 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 50 [200]
GET list_advisory 48 [200]
GET list_advisory_paginated 48 [200]
GET list_importer 46 [200]
GET list_organizations 48 [200]
GET list_packages 46 [200]
GET list_packages_paginated 46 [200]
GET list_products 50 [200]
GET list_sboms 50 [200]
GET list_sboms_paginated 50 [200]
GET list_vulnerabilities 45 [200]
GET list_vulnerabilities_paginated 45 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 50 [200]
GET search_advisory 45 [200]
GET search_exact_purl 50 [200]
GET search_licenses 1 [200]
GET search_purls 50 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [200]
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 48 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 48 [200]
Aggregated 1,144 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 48 (+4) 0 (0) 14.62 (-0.49) 6 (-1) 26 (-4) 0.16 (+0.01) 0.00 (+0.00)
1.1 list_organizations 48 (+4) 0 (0) 20.38 (+9.90) 2 (0) 369 (+322) 0.16 (+0.01) 0.00 (+0.00)
1.2 list_advisory 48 (+4) 0 (0) 600.92 (+157.71) 93 (-37) 1703 (+526) 0.16 (+0.01) 0.00 (+0.00)
1.3 list_advisory_paginated 48 (+4) 0 (0) 467.42 (+53.37) 180 (+24) 1025 (+123) 0.16 (+0.01) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 45 (+1) 0 (0) 19.78 (-0.06) 3 (0) 110 (-60) 0.15 (+0.00) 0.00 (+0.00)
1.5 search_advisory 45 (+1) 0 (0) 917.53 (-168.83) 128 (-49) 1880 (-2439) 0.15 (+0.00) 0.00 (+0.00)
1.6 list_vulnerabilities 45 (+2) 0 (0) 398.09 (+125.27) 41 (-3) 715 (+87) 0.15 (+0.01) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 45 (+2) 0 (0) 225.29 (+42.54) 28 (-6) 400 (+74) 0.15 (+0.01) 0.00 (+0.00)
1.8 list_importer 46 (+3) 0 (0) 7.96 (-1.62) 1 (0) 72 (+17) 0.15 (+0.01) 0.00 (+0.00)
1.9 list_packages 46 (+3) 0 (0) 460.22 (+60.47) 100 (-46) 1241 (+162) 0.15 (+0.01) 0.00 (+0.00)
1.10 list_packages_paginated 46 (+3) 0 (0) 366.37 (+5.53) 99 (-31) 582 (-19) 0.15 (+0.01) 0.00 (+0.00)
1.11 search_purls 50 (+4) 0 (0) 8743.06 (-185.51) 4489 (+2258) 12789 (-4886) 0.17 (+0.01) 0.00 (+0.00)
1.12 search_exact_purl 50 (+4) 0 (0) 8.88 (-12.55) 4 (0) 55 (-13) 0.17 (+0.01) 0.00 (+0.00)
1.13 list_products 50 (+4) 0 (0) 11.06 (-2.27) 5 (+2) 74 (-21) 0.17 (+0.01) 0.00 (+0.00)
1.14 list_sboms 50 (+4) 0 (0) 1554.78 (+272.35) 492 (+253) 3692 (+83) 0.17 (+0.01) 0.00 (+0.00)
1.15 list_sboms_paginated 50 (+4) 0 (0) 4650.22 (+149.35) 509 (+194) 13812 (+1806) 0.17 (+0.01) 0.00 (+0.00)
1.16 get_analysis_status 50 (+4) 0 (0) 14.78 (+5.65) 1 (0) 363 (+310) 0.17 (+0.01) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 50 (+4) 0 (0) 268.64 (+45.73) 36 (-48) 1754 (+1192) 0.17 (+0.01) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 50 (+4) 0 (0) 1839.58 (-174.51) 264 (+67) 6580 (+219) 0.17 (+0.01) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 50 (+4) 0 (0) 60.00 (-25.78) 6 (-7) 611 (+357) 0.17 (+0.01) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 50 (+4) 0 (0) 8472.10 (+3026.69) 3361 (-345) 14313 (+3136) 0.17 (+0.01) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 48 (+4) 0 (0) 577.81 (+258.38) 68 (-3) 1738 (+854) 0.16 (+0.01) 0.00 (+0.00)
1.22 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 48 (+4) 0 (0) 1034.38 (+406.90) 153 (-19) 2748 (+1224) 0.16 (+0.01) 0.00 (+0.00)
1.23 get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 48 (+4) 0 (0) 37.92 (+22.51) 3 (+1) 496 (+440) 0.16 (+0.01) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 0 (-1) 0 (0) 0.00 (-15.00) 0 (-15) 0 (-15) 0.00 (-0.00) 0.00 (+0.00)
2.1 search_licenses 1 (-1) 0 (0) 86996.00 (+35793.00) 86996 (+44837) 86996 (+26749) 0.00 (-0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 1 (0) 0 (0) 60893.00 (+16129.00) 60893 (+16129) 60893 (+16129) 0.00 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (0) 0 (0) 154872.00 (-27864.00) 154872 (-27864) 154872 (-27864) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUserDelete
3.0 logon 34 (-52) 0 (0) 11.38 (+0.82) 6 (0) 19 (-2) 0.11 (-0.17) 0.00 (+0.00)
3.1 delete_sbom_from_pool_sequential[100 SBOMs] 35 0 1693.14 313 4637 0.12 0.00
Aggregated 1,226 (+64) 0 (0) 1536.04 (+204.00) 1 (0) 154872 (-27864) 4.09 (+0.21) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (+1) 48 (+4) 30411.48 (+3959.57) 18089 (+5809) 44207 (-32) 0.16 (+0.01) 9.60 (-1.40)
RestAPIUserSlow 0 (-1) 0 (-1) 0.00 (-287759.00) 0 (-287759) 0 (-287759) 0.00 (-0.00) 0.00 (-1.00)
RestAPIUserDelete 1 (0) 34 (-52) 8693.94 (+5170.34) 7077 (+4047) 12528 (+8520) 0.11 (-0.17) 34.00 (-52.00)
Aggregated 6 (0) 82 (-49) 21406.65 (+8012.20) 7077 (+4047) 44207 (-243552) 0.27 (-0.16) 43.60 (-54.40)

User Metrics