Goose Attack Report

Users: 7

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-11-23 02:17:0525-11-23 02:17:1200:00:070 → 7
Maintaining25-11-23 02:17:1225-11-23 02:22:1200:05:007
Decreasing25-11-23 02:22:1225-11-23 02:22:2500:00:130 ← 7

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 38 (+6) 0 1006.29 (-1441.99) 177 (-441) 2662 (-2290) 0.13 (+0.02) 0.00 (+0.00)
GET download_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 10 (-4) 10 10.00 (-13.21) 2 (0) 33 (-55) 0.03 (-0.01) 0.03 (-0.01)
GET get_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 10 (-4) 10 8.30 (-7.13) 1 (0) 26 (-30) 0.03 (-0.01) 0.03 (-0.01)
GET get_advisory_by_doc_id 10 (-5) 0 16.10 (-4.97) 3 (-2) 52 (-40) 0.03 (-0.02) 0.00 (+0.00)
GET get_analysis_latest_cpe 15 (+4) 0 248.20 (-26.53) 127 (-6) 484 (+20) 0.05 (+0.01) 0.00 (+0.00)
GET get_analysis_status 15 (+4) 0 7.27 (-20.37) 2 (0) 61 (-55) 0.05 (+0.01) 0.00 (+0.00)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 10 (-4) 0 737.50 (+46.07) 82 (-37) 1305 (+243) 0.03 (-0.01) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 15 (0) 0 1494.13 (+66.47) 362 (-50) 4016 (+383) 0.05 (+0.00) 0.00 (+0.00)
GET get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 15 (0) 0 56350.73 (-5172.80) 47821 (-3758) 62926 (-7695) 0.05 (+0.00) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 10 (-4) 0 8613.10 (+335.10) 7591 (+394) 11275 (-528) 0.03 (-0.01) 0.00 (+0.00)
GET list_advisory 10 (-4) 0 849.40 (+206.61) 165 (-144) 1170 (+131) 0.03 (-0.01) 0.00 (+0.00)
GET list_advisory_labels 15 (0) 0 13901.80 (+730.93) 8439 (+2937) 19915 (-2380) 0.05 (+0.00) 0.00 (+0.00)
GET list_advisory_paginated 10 (-5) 0 516.00 (-23.67) 175 (-43) 883 (-128) 0.03 (-0.02) 0.00 (+0.00)
GET list_importer 11 (0) 0 3.64 (-2.36) 1 (0) 8 (-18) 0.04 (+0.00) 0.00 (+0.00)
GET list_organizations 10 (-4) 0 14.80 (-8.49) 2 (0) 45 (-8) 0.03 (-0.01) 0.00 (+0.00)
GET list_packages 11 (0) 0 545.82 (-18.36) 165 (-87) 1142 (-530) 0.04 (+0.00) 0.00 (+0.00)
GET list_packages_paginated 11 (0) 0 386.09 (-104.64) 128 (-77) 622 (-706) 0.04 (+0.00) 0.00 (+0.00)
GET list_products 15 (+4) 0 14.93 (-3.16) 3 (-2) 59 (-10) 0.05 (+0.01) 0.00 (+0.00)
GET list_sboms 15 (+4) 0 1418.13 (+116.86) 549 (+121) 2974 (-465) 0.05 (+0.01) 0.00 (+0.00)
GET list_sboms_paginated 15 (+4) 0 2854.73 (-3285.27) 539 (-1458) 12896 (+1892) 0.05 (+0.01) 0.00 (+0.00)
GET list_vulnerabilities 11 (0) 0 365.00 (-35.27) 96 (-16) 446 (-377) 0.04 (+0.00) 0.00 (+0.00)
GET list_vulnerabilities_paginated 11 (0) 0 173.82 (-109.55) 32 (-68) 213 (-466) 0.04 (+0.00) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 10 (-4) 0 24.10 (-47.61) 6 (0) 67 (-127) 0.03 (-0.01) 0.00 (+0.00)
GET search_advisory 10 (-5) 0 893.90 (-468.10) 201 (-101) 1455 (-3051) 0.03 (-0.02) 0.00 (+0.00)
GET search_exact_purl 15 (+4) 0 28.93 (+3.75) 2 (-3) 61 (-48) 0.05 (+0.01) 0.00 (+0.00)
GET search_licenses 1 (0) 0 89408.00 (-57327.00) 89408 (-57327) 89408 (-57327) 0.00 (+0.00) 0.00 (+0.00)
GET search_purls 15 (+4) 0 17308.07 (+7311.79) 10589 (+5971) 24809 (+7455) 0.05 (+0.01) 0.00 (+0.00)
GET search_purls_by_license 1 (0) 0 147471.00 (+36617.00) 147471 (+36617) 147471 (+36617) 0.00 (+0.00) 0.00 (+0.00)
GET search_sboms_by_license 1 (0) 0 78383.00 (-13323.00) 78383 (-13323) 78383 (-13323) 0.00 (+0.00) 0.00 (+0.00)
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 10 (-4) 0 90.30 (-2.27) 8 (0) 180 (+14) 0.03 (-0.01) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 10 (-4) 0 483.70 (-41.37) 95 (-65) 798 (-83) 0.03 (-0.01) 0.00 (+0.00)
Aggregated 366 (-17) 20 5182.23 (+69.42) 1 (0) 147471 (+736) 1.22 (-0.06) 0.07 (-0.03)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 800 (-1,200) 900 (-2,100) 1,000 (-2,000) 1,000 (-3,000) 2,000 (-2,000) 2,000 (-2,000) 2,662 (-2,290) 2,662 (-2,290)
GET download_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 5 (0) 5 (-1) 7 (-21) 20 (-22) 20 (-63) 33 (-50) 33 (-55) 33 (-55)
GET get_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 3 (-2) 5 (-1) 13 (-5) 14 (-13) 14 (-40) 26 (-28) 26 (-30) 26 (-30)
GET get_advisory_by_doc_id 9 (-3) 9 (-3) 9 (-5) 14 (-3) 47 (-30) 52 (-25) 52 (-40) 52 (-40)
GET get_analysis_latest_cpe 210 (-80) 270 (-20) 280 (-30) 290 (-90) 310 (-110) 310 (-110) 480 (+20) 480 (+20)
GET get_analysis_status 3 (-4) 3 (-8) 4 (-47) 4 (-47) 9 (-43) 9 (-43) 61 (-55) 61 (-55)
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 900 (+200) 900 (+200) 900 (+100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET get_sbom[sha256:720e4451…a939656247164447] 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 3,000 (0) 3,000 (0) 4,000 (+367) 4,000 (+367)
GET get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 56,000 (-5,000) 59,000 (-2,000) 59,000 (-5,000) 60,000 (-5,000) 62,926 (-7,074) 62,926 (-7,074) 62,926 (-7,695) 62,926 (-7,695)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 8,000 (0) 8,000 (0) 8,000 (0) 9,000 (+1,000) 10,000 (+1,000) 11,000 (+2,000) 11,000 (-803) 11,000 (-803)
GET list_advisory 1,000 (+400) 1,000 (+400) 1,000 (+200) 1,000 (+100) 1,000 (+100) 1,000 (+100) 1,000 (0) 1,000 (0)
GET list_advisory_labels 13,000 (0) 13,000 (0) 14,000 (0) 18,000 (+4,000) 19,000 (-1,000) 19,000 (-1,000) 19,915 (-2,085) 19,915 (-2,085)
GET list_advisory_paginated 600 (0) 600 (0) 600 (0) 600 (0) 700 (+100) 883 (+283) 883 (-117) 883 (-117)
GET list_importer 3 (0) 4 (0) 5 (0) 5 (-1) 6 (-8) 6 (-8) 8 (-18) 8 (-18)
GET list_organizations 6 (-2) 8 (-15) 13 (-26) 26 (-17) 37 (-14) 45 (-6) 45 (-8) 45 (-8)
GET list_packages 480 (+60) 490 (0) 500 (-100) 600 (0) 1,000 (+400) 1,000 (+400) 1,000 (-672) 1,000 (-672)
GET list_packages_paginated 410 (+10) 430 (+30) 500 (0) 500 (-100) 500 (-100) 500 (-100) 600 (-400) 600 (-400)
GET list_products 10 (+2) 10 (+1) 12 (+2) 14 (+3) 49 (-12) 49 (-12) 59 (-10) 59 (-10)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 2,000 (0) 2,974 (-26) 2,974 (-26) 2,974 (-26) 2,974 (-26)
GET list_sboms_paginated 2,000 (-4,000) 2,000 (-4,000) 3,000 (-4,000) 3,000 (-6,000) 4,000 (-5,000) 4,000 (-5,000) 12,896 (+1,896) 12,896 (+1,896)
GET list_vulnerabilities 430 (+20) 440 (+30) 440 (+20) 440 (-30) 440 (-160) 440 (-160) 446 (-354) 446 (-354)
GET list_vulnerabilities_paginated 200 (-60) 200 (-70) 200 (-70) 210 (-80) 210 (-90) 210 (-90) 210 (-469) 210 (-469)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 12 (-52) 16 (-49) 23 (-46) 31 (-61) 57 (-103) 67 (-93) 67 (-123) 67 (-123)
GET search_advisory 700 (-300) 800 (-200) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000) 1,000 (-3,506) 1,000 (-3,506)
GET search_exact_purl 19 (+10) 22 (+12) 58 (+48) 58 (+28) 60 (-19) 60 (-19) 61 (-48) 61 (-48)
GET search_licenses 89,408 (-57,327) 89,408 (-57,327) 89,408 (-57,327) 89,408 (-57,327) 89,408 (-57,327) 89,408 (-57,327) 89,408 (-57,327) 89,408 (-57,327)
GET search_purls 16,000 (+6,000) 16,000 (+5,000) 24,000 (+13,000) 24,000 (+13,000) 24,809 (+10,809) 24,809 (+10,809) 24,809 (+7,809) 24,809 (+7,809)
GET search_purls_by_license 147,471 (+36,617) 147,471 (+36,617) 147,471 (+36,617) 147,471 (+36,617) 147,471 (+36,617) 147,471 (+36,617) 147,471 (+36,617) 147,471 (+36,617)
GET search_sboms_by_license 78,383 (-13,323) 78,383 (-13,323) 78,383 (-13,323) 78,383 (-13,323) 78,383 (-13,323) 78,383 (-13,323) 78,383 (-13,323) 78,383 (-13,323)
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 80 (-9) 83 (-6) 90 (-20) 170 (+60) 180 (+20) 180 (+20) 180 (+14) 180 (+14)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 500 (0) 600 (+100) 600 (-100) 700 (0) 798 (-2) 798 (-2) 798 (-83) 798 (-83)
Aggregated 440 (-30) 700 (0) 1,000 (0) 2,000 (-1,000) 13,000 (+4,000) 25,000 (+5,000) 63,000 (-7,000) 147,000 (+265)

Status Code Metrics

Method Name Status Codes
DELETE delete_sbom_from_pool_sequential[100 SBOMs] 38 [200]
GET download_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 10 [404]
GET get_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 10 [404]
GET get_advisory_by_doc_id 10 [200]
GET get_analysis_latest_cpe 15 [200]
GET get_analysis_status 15 [200]
GET get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 10 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 15 [200]
GET get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 15 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 10 [200]
GET list_advisory 10 [200]
GET list_advisory_labels 15 [200]
GET list_advisory_paginated 10 [200]
GET list_importer 11 [200]
GET list_organizations 10 [200]
GET list_packages 11 [200]
GET list_packages_paginated 11 [200]
GET list_products 15 [200]
GET list_sboms 15 [200]
GET list_sboms_paginated 15 [200]
GET list_vulnerabilities 11 [200]
GET list_vulnerabilities_paginated 11 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 10 [200]
GET search_advisory 10 [200]
GET search_exact_purl 15 [200]
GET search_licenses 1 [200]
GET search_purls 15 [200]
GET search_purls_by_license 1 [200]
GET search_sboms_by_license 1 [200]
POST get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 10 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 10 [200]
Aggregated 20 [404], 346 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 10 (-4) 0 (0) 14.30 (+1.66) 7 (0) 20 (0) 0.03 (-0.01) 0.00 (+0.00)
1.1 list_organizations 10 (-4) 0 (0) 14.90 (-8.53) 2 (0) 45 (-8) 0.03 (-0.01) 0.00 (+0.00)
1.2 list_advisory 10 (-4) 0 (0) 849.50 (+206.50) 165 (-144) 1170 (+131) 0.03 (-0.01) 0.00 (+0.00)
1.3 list_advisory_paginated 10 (-5) 0 (0) 516.00 (-23.67) 175 (-43) 883 (-128) 0.03 (-0.02) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 10 (-5) 0 (0) 16.10 (-4.97) 3 (-2) 52 (-40) 0.03 (-0.02) 0.00 (+0.00)
1.5 search_advisory 10 (-5) 0 (0) 893.90 (-468.17) 201 (-101) 1455 (-3051) 0.03 (-0.02) 0.00 (+0.00)
1.6 list_vulnerabilities 11 (0) 0 (0) 365.09 (-35.18) 96 (-16) 446 (-377) 0.04 (+0.00) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 11 (0) 0 (0) 173.82 (-109.55) 32 (-68) 213 (-466) 0.04 (+0.00) 0.00 (+0.00)
1.8 list_importer 11 (0) 0 (0) 3.73 (-2.27) 1 (0) 8 (-18) 0.04 (+0.00) 0.00 (+0.00)
1.9 list_packages 11 (0) 0 (0) 545.91 (-18.27) 165 (-87) 1142 (-530) 0.04 (+0.00) 0.00 (+0.00)
1.10 list_packages_paginated 11 (0) 0 (0) 386.18 (-104.55) 128 (-77) 622 (-706) 0.04 (+0.00) 0.00 (+0.00)
1.11 search_purls 15 (+4) 0 (0) 17308.07 (+7311.79) 10589 (+5971) 24809 (+7455) 0.05 (+0.01) 0.00 (+0.00)
1.12 search_exact_purl 15 (+4) 0 (0) 28.93 (+3.75) 2 (-3) 61 (-48) 0.05 (+0.01) 0.00 (+0.00)
1.13 list_products 15 (+4) 0 (0) 14.93 (-3.16) 3 (-2) 59 (-10) 0.05 (+0.01) 0.00 (+0.00)
1.14 list_sboms 15 (+4) 0 (0) 1418.13 (+116.86) 549 (+121) 2974 (-465) 0.05 (+0.01) 0.00 (+0.00)
1.15 list_sboms_paginated 15 (+4) 0 (0) 2854.73 (-3285.27) 539 (-1458) 12896 (+1892) 0.05 (+0.01) 0.00 (+0.00)
1.16 get_analysis_status 15 (+4) 0 (0) 7.27 (-20.37) 2 (0) 61 (-55) 0.05 (+0.01) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 15 (+4) 0 (0) 248.20 (-26.53) 127 (-6) 484 (+20) 0.05 (+0.01) 0.00 (+0.00)
1.18 list_advisory_labels 15 (0) 0 (0) 13901.93 (+731.00) 8439 (+2937) 19915 (-2380) 0.05 (+0.00) 0.00 (+0.00)
1.19 get_sbom[sha256:720e4451…a939656247164447] 15 (0) 0 (0) 1494.20 (+66.33) 362 (-50) 4016 (+382) 0.05 (+0.00) 0.00 (+0.00)
1.20 get_sbom_advisories[sha256:87fd06bc…9d7b8304c0d2d9b2] 15 (0) 0 (0) 56350.87 (-5172.73) 47822 (-3757) 62926 (-7695) 0.05 (+0.00) 0.00 (+0.00)
1.21 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 10 (-4) 0 (0) 24.10 (-47.69) 6 (0) 67 (-128) 0.03 (-0.01) 0.00 (+0.00)
1.22 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 10 (-4) 0 (0) 8613.20 (+335.20) 7591 (+394) 11275 (-528) 0.03 (-0.01) 0.00 (+0.00)
1.23 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 10 (-4) 0 (0) 483.70 (-41.44) 95 (-65) 798 (-84) 0.03 (-0.01) 0.00 (+0.00)
1.24 get_purl_details[b00df2ca-df21-5…874-304e9c54e2bd] 10 (-4) 0 (0) 737.50 (+45.93) 82 (-37) 1305 (+243) 0.03 (-0.01) 0.00 (+0.00)
1.25 get_recommendations[pkg:rpm/redhat/…e-metrics@2.13.8] 10 (-4) 0 (0) 90.30 (-2.27) 8 (0) 180 (+14) 0.03 (-0.01) 0.00 (+0.00)
1.26 download_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 10 (-4) 0 (0) 10.10 (-13.11) 2 (0) 33 (-55) 0.03 (-0.01) 0.00 (+0.00)
1.27 get_advisory[24ae57c3-4b57-4…2c1-83ae26059a89] 10 (-4) 0 (0) 8.30 (-7.27) 1 (0) 26 (-31) 0.03 (-0.01) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
2.1 search_licenses 1 (0) 0 (0) 89408.00 (-57327.00) 89408 (-57327) 89408 (-57327) 0.00 (+0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 1 (0) 0 (0) 78383.00 (-13323.00) 78383 (-13323) 78383 (-13323) 0.00 (+0.00) 0.00 (+0.00)
2.3 search_purls_by_license 1 (0) 0 (0) 147471.00 (+36617.00) 147471 (+36617) 147471 (+36617) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUserDelete
3.0 logon 37 (+6) 0 (0) 9.11 (-0.44) 6 (0) 16 (-2) 0.12 (+0.02) 0.00 (+0.00)
3.1 delete_sbom_from_pool_sequential[100 SBOMs] 38 (+6) 0 (0) 1006.47 (-1442.03) 177 (-441) 2662 (-2291) 0.13 (+0.02) 0.00 (+0.00)
Aggregated 413 (-15) 0 (0) 4592.48 (+17.23) 1 (0) 147471 (+736) 1.38 (-0.05) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 10 (-4) 103221.10 (+748.10) 99552 (+13099) 106101 (-11045) 0.03 (-0.01) 2.00 (-0.80)
RestAPIUserSlow 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUserDelete 1 (0) 37 (+6) 8070.70 (-1486.49) 6665 (-1045) 9553 (-2962) 0.12 (+0.02) 37.00 (+6.00)
Aggregated 6 (0) 47 (+2) 28315.47 (-10148.86) 6665 (-1045) 106101 (-11045) 0.16 (+0.01) 39.00 (+5.20)

User Metrics

Errors

# Error
10 (-4) 404 Not Found: download_advisory[24ae57c3-4b57-4…2c1-83ae26059a89]
10 (-4) 404 Not Found: get_advisory[24ae57c3-4b57-4…2c1-83ae26059a89]