Goose Attack Report

Users: 7

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-11-04 02:19:4825-11-04 02:19:5500:00:070 → 7
Maintaining25-11-04 02:19:5525-11-04 02:24:5500:05:007
Decreasing25-11-04 02:24:5525-11-04 02:25:2000:00:250 ← 7

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 36 (0) 0 1495.06 (+99.56) 666 (+483) 2638 (-197) 0.12 (+0.00) 0.00 (+0.00)
GET get_analysis_latest_cpe 5 (-40) 0 210.80 (-29.76) 208 (+113) 213 (-262) 0.02 (-0.13) 0.00 (+0.00)
GET get_analysis_status 5 (-40) 0 13.00 (+1.76) 2 (+1) 51 (-6) 0.02 (-0.13) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 5 (-40) 0 619.00 (-1178.09) 616 (+118) 623 (-3694) 0.02 (-0.13) 0.00 (+0.00)
GET get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 5 0 284129.19 279997 288179 0.02 0.00
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 3 (-42) 0 6049.00 (-2248.78) 5313 (+2296) 6570 (-8248) 0.01 (-0.14) 0.00 (+0.00)
GET list_importer 1 (-45) 0 2.00 (-4.17) 2 (+1) 2 (-46) 0.00 (-0.15) 0.00 (+0.00)
GET list_packages 1 (-45) 0 294.00 (-103.63) 294 (+173) 294 (-460) 0.00 (-0.15) 0.00 (+0.00)
GET list_packages_paginated 1 (-45) 0 216.00 (-115.13) 216 (+93) 216 (-363) 0.00 (-0.15) 0.00 (+0.00)
GET list_products 5 (-43) 0 10.00 (-2.06) 4 (+1) 22 (-35) 0.02 (-0.14) 0.00 (+0.00)
GET list_sboms 5 (-43) 0 649.20 (-1021.51) 616 (+306) 665 (-2827) 0.02 (-0.14) 0.00 (+0.00)
GET list_sboms_paginated 5 (-40) 0 1207.80 (-3069.31) 1156 (+363) 1256 (-11354) 0.02 (-0.13) 0.00 (+0.00)
GET list_vulnerabilities 1 (-45) 0 330.00 (-22.09) 330 (+255) 330 (-438) 0.00 (-0.15) 0.00 (+0.00)
GET list_vulnerabilities_paginated 1 (-45) 0 180.00 (-8.26) 180 (+116) 180 (-216) 0.00 (-0.15) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 3 (-42) 0 101.33 (+73.40) 8 (+4) 288 (+33) 0.01 (-0.14) 0.00 (+0.00)
GET search_advisory 1 (-45) 0 399.00 (-601.37) 399 (+237) 399 (-2194) 0.00 (-0.15) 0.00 (+0.00)
GET search_exact_purl 5 (-43) 0 10.60 (-25.40) 5 (+1) 16 (-51) 0.02 (-0.14) 0.00 (+0.00)
GET search_licenses 1 (-1) 0 76521.00 (+26111.50) 76521 (+35570) 76521 (+16653) 0.00 (-0.00) 0.00 (+0.00)
GET search_purls 5 (-45) 0 15476.80 (+3711.08) 10807 (+8806) 17836 (-13665) 0.02 (-0.15) 0.00 (+0.00)
GET search_purls_by_license 1 (0) 0 159670.00 (-11226.00) 159670 (-11226) 159670 (-11226) 0.00 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 1 (0) 0 90665.00 (+29985.00) 90665 (+29985) 90665 (+29985) 0.00 (+0.00) 0.00 (+0.00)
Aggregated 96 (-999) 0 19918.56 (+18167.29) 2 (+1) 288179 (+117283) 0.32 (-3.33) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (-835) 2,000 (-835) 2,638 (-197) 2,638 (-197)
GET get_analysis_latest_cpe 210 (0) 210 (-20) 210 (-80) 210 (-110) 210 (-190) 210 (-210) 210 (-265) 210 (-265)
GET get_analysis_status 4 (0) 4 (0) 5 (0) 5 (-3) 51 (-1) 51 (-4) 51 (-6) 51 (-6)
GET get_sbom[sha256:720e4451…a939656247164447] 616 (-1,384) 616 (-1,384) 616 (-1,384) 616 (-1,384) 616 (-2,384) 616 (-2,384) 616 (-3,384) 616 (-3,384)
GET get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 283,000 283,000 288,000 288,000 288,000 288,000 288,000 288,000
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 6,000 (-1,000) 6,000 (-2,000) 6,000 (-3,000) 6,000 (-4,000) 6,570 (-6,430) 6,570 (-7,430) 6,570 (-8,248) 6,570 (-8,248)
GET list_importer 2 (-1) 2 (-1) 2 (-2) 2 (-3) 2 (-8) 2 (-36) 2 (-46) 2 (-46)
GET list_packages 294 (-116) 294 (-176) 294 (-196) 294 (-306) 294 (-306) 294 (-306) 294 (-460) 294 (-460)
GET list_packages_paginated 216 (-114) 216 (-174) 216 (-184) 216 (-204) 216 (-274) 216 (-284) 216 (-363) 216 (-363)
GET list_products 9 (+2) 9 (+1) 9 (-1) 9 (-3) 22 (+3) 22 (-32) 22 (-35) 22 (-35)
GET list_sboms 665 (-335) 665 (-1,335) 665 (-1,335) 665 (-2,335) 665 (-2,335) 665 (-2,335) 665 (-2,335) 665 (-2,335)
GET list_sboms_paginated 1,156 (-2,844) 1,156 (-3,844) 1,156 (-4,844) 1,156 (-4,844) 1,156 (-5,844) 1,156 (-9,844) 1,156 (-11,454) 1,156 (-11,454)
GET list_vulnerabilities 330 (+30) 330 (-60) 330 (-170) 330 (-170) 330 (-270) 330 (-370) 330 (-438) 330 (-438)
GET list_vulnerabilities_paginated 180 (-10) 180 (-30) 180 (-40) 180 (-70) 180 (-110) 180 (-130) 180 (-216) 180 (-216)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 8 (-5) 8 (-8) 8 (-18) 8 (-24) 288 (+221) 288 (+212) 288 (+33) 288 (+33)
GET search_advisory 399 (-501) 399 (-601) 399 (-601) 399 (-601) 399 (-1,601) 399 (-1,601) 399 (-2,194) 399 (-2,194)
GET search_exact_purl 11 (-40) 11 (-42) 14 (-40) 14 (-41) 16 (-43) 16 (-45) 16 (-51) 16 (-51)
GET search_licenses 76,521 (+35,521) 76,521 (+35,521) 76,521 (+35,521) 76,521 (+16,653) 76,521 (+16,653) 76,521 (+16,653) 76,521 (+16,653) 76,521 (+16,653)
GET search_purls 16,000 (+5,000) 16,000 (+4,000) 17,000 (+3,000) 17,000 (+1,000) 17,836 (-4,164) 17,836 (-6,164) 17,836 (-13,665) 17,836 (-13,665)
GET search_purls_by_license 159,670 (-11,226) 159,670 (-11,226) 159,670 (-11,226) 159,670 (-11,226) 159,670 (-11,226) 159,670 (-11,226) 159,670 (-11,226) 159,670 (-11,226)
GET search_sboms_by_license 90,665 (+29,985) 90,665 (+29,985) 90,665 (+29,985) 90,665 (+29,985) 90,665 (+29,985) 90,665 (+29,985) 90,665 (+29,985) 90,665 (+29,985)
Aggregated 1,000 (+700) 1,000 (+520) 2,000 (+1,300) 2,000 (+1,000) 16,000 (+11,000) 160,000 (+152,000) 288,000 (+270,000) 288,000 (+117,104)

Status Code Metrics

Method Name Status Codes
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 36 [200]
GET get_analysis_latest_cpe 5 [200]
GET get_analysis_status 5 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 5 [200]
GET get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 5 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 3 [200]
GET list_importer 1 [200]
GET list_packages 1 [200]
GET list_packages_paginated 1 [200]
GET list_products 5 [200]
GET list_sboms 5 [200]
GET list_sboms_paginated 5 [200]
GET list_vulnerabilities 1 [200]
GET list_vulnerabilities_paginated 1 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 3 [200]
GET search_advisory 1 [200]
GET search_exact_purl 5 [200]
GET search_licenses 1 [200]
GET search_purls 5 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [200]
Aggregated 96 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 0 (-45) 0 (0) 0.00 (-14.73) 0 (-6) 0 (-29) 0.00 (-0.15) 0.00 (+0.00)
1.1 list_organizations 0 (-45) 0 (0) 0.00 (-16.64) 0 (-1) 0 (-57) 0.00 (-0.15) 0.00 (+0.00)
1.2 list_advisory 0 (-45) 0 (0) 0.00 (-462.96) 0 (-105) 0 (-832) 0.00 (-0.15) 0.00 (+0.00)
1.3 list_advisory_paginated 0 (-45) 0 (0) 0.00 (-444.67) 0 (-107) 0 (-1053) 0.00 (-0.15) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 0 (-45) 0 (0) 0.00 (-20.69) 0 (-3) 0 (-67) 0.00 (-0.15) 0.00 (+0.00)
1.5 search_advisory 1 (-45) 0 (0) 399.00 (-601.48) 399 (+237) 399 (-2196) 0.00 (-0.15) 0.00 (+0.00)
1.6 list_vulnerabilities 1 (-45) 0 (0) 330.00 (-22.09) 330 (+255) 330 (-438) 0.00 (-0.15) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 1 (-45) 0 (0) 180.00 (-8.26) 180 (+116) 180 (-216) 0.00 (-0.15) 0.00 (+0.00)
1.8 list_importer 1 (-45) 0 (0) 2.00 (-4.20) 2 (+1) 2 (-46) 0.00 (-0.15) 0.00 (+0.00)
1.9 list_packages 1 (-45) 0 (0) 294.00 (-103.63) 294 (+173) 294 (-460) 0.00 (-0.15) 0.00 (+0.00)
1.10 list_packages_paginated 1 (-45) 0 (0) 216.00 (-115.24) 216 (+93) 216 (-363) 0.00 (-0.15) 0.00 (+0.00)
1.11 search_purls 5 (-45) 0 (0) 15477.00 (+3711.28) 10807 (+8806) 17837 (-13664) 0.02 (-0.15) 0.00 (+0.00)
1.12 search_exact_purl 5 (-43) 0 (0) 11.00 (-25.02) 6 (+2) 16 (-52) 0.02 (-0.14) 0.00 (+0.00)
1.13 list_products 5 (-43) 0 (0) 10.00 (-2.12) 4 (+1) 22 (-35) 0.02 (-0.14) 0.00 (+0.00)
1.14 list_sboms 5 (-43) 0 (0) 649.20 (-1021.55) 616 (+306) 665 (-2827) 0.02 (-0.14) 0.00 (+0.00)
1.15 list_sboms_paginated 5 (-40) 0 (0) 1208.00 (-3069.22) 1156 (+363) 1256 (-11354) 0.02 (-0.13) 0.00 (+0.00)
1.16 get_analysis_status 5 (-40) 0 (0) 13.00 (+1.67) 2 (+1) 51 (-6) 0.02 (-0.13) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 5 (-40) 0 (0) 210.80 (-29.84) 208 (+113) 213 (-262) 0.02 (-0.13) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 5 (-40) 0 (0) 619.00 (-1178.11) 616 (+118) 623 (-3694) 0.02 (-0.13) 0.00 (+0.00)
1.19 get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 5 0 284129.19 279997 288179 0.02 0.00
1.20 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 3 0 101.33 8 288 0.01 0.00
1.21 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 3 0 6049.00 5313 6570 0.01 0.00
1.22 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 0 0 0.00 0 0 0.00 0.00
1.23 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 0 0 0.00 0 0 0.00 0.00
1.24 get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 0 0 0.00 0 0 0.00 0.00
RestAPIUserSlow
2.0 logon 0 (-1) 0 (0) 0.00 (-13.00) 0 (-13) 0 (-13) 0.00 (-0.00) 0.00 (+0.00)
2.1 search_licenses 1 (-1) 0 (0) 76522.00 (+26112.00) 76522 (+35571) 76522 (+16653) 0.00 (-0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 1 (0) 0 (0) 90665.00 (+29985.00) 90665 (+29985) 90665 (+29985) 0.00 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (0) 0 (0) 159670.00 (-11226.00) 159670 (-11226) 159670 (-11226) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUserDelete
3.0 logon 35 (-1) 0 (0) 9.57 (-1.26) 6 (0) 17 (-7) 0.12 (-0.00) 0.00 (+0.00)
3.1 delete_sbom_from_pool_sequential[100 SBOMs] 36 (0) 0 (0) 1495.28 (+99.72) 666 (+483) 2638 (-198) 0.12 (+0.00) 0.00 (+0.00)
Aggregated 131 (-1,046) 0 (0) 14596.81 (+12967.54) 2 (+1) 288179 (+117283) 0.44 (-3.49) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 0 (-5) 0 (-45) 0.00 (-33104.29) 0 (-18361) 0 (-50842) 0.00 (-0.15) 0.00 (-9.00)
RestAPIUserSlow 0 (-1) 0 (-1) 0.00 (-291456.00) 0 (-291456) 0 (-291456) 0.00 (-0.00) 0.00 (-1.00)
RestAPIUserDelete 1 (0) 35 (-1) 8512.43 (+115.73) 7442 (+875) 9787 (-547) 0.12 (-0.00) 35.00 (-1.00)
Aggregated 1 (-6) 35 (-47) 8512.43 (-16895.25) 7442 (+875) 9787 (-281669) 0.12 (-0.16) 35.00 (-11.00)

User Metrics