Goose Attack Report

Users: 7

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing26-03-18 02:28:0426-03-18 02:28:1100:00:070 → 7
Maintaining26-03-18 02:28:1126-03-18 02:58:1200:30:017
Decreasing26-03-18 02:58:1226-03-18 02:58:2700:00:150 ← 7

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET download_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 45 (+10) 0 205.09 (+14.63) 29 (-8) 434 (+39) 0.03 (+0.01) 0.00 (+0.00)
GET get_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 45 (+10) 0 166.29 (-7.57) 29 (-36) 311 (+31) 0.03 (+0.01) 0.00 (+0.00)
GET get_advisory_by_doc_id 45 (+10) 0 24.93 (+1.82) 4 (-1) 70 (-32) 0.03 (+0.01) 0.00 (+0.00)
GET get_analysis_latest_cpe 50 (+15) 0 39.02 (+12.33) 4 (-1) 169 (+73) 0.03 (+0.01) 0.00 (+0.00)
GET get_analysis_status 50 (+15) 0 11.90 (-3.10) 2 (0) 70 (-6) 0.03 (+0.01) 0.00 (+0.00)
GET get_purl_details[0000054a-a69b-5…520-80752db183e6] 45 (+10) 0 202.87 (-7.45) 68 (-15) 479 (-85) 0.03 (+0.01) 0.00 (+0.00)
GET get_sbom[sha256:a3442b37…3040057f79c70669] 45 (+10) 0 9622.87 (-3919.31) 284 (-219) 17836 (-7866) 0.03 (+0.01) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019c4a…8ba-3cc0260ef778] 45 (+10) 0 21.36 (+12.07) 3 (+1) 91 (+20) 0.03 (+0.01) 0.00 (+0.00)
GET list_advisory 45 (+10) 0 657.00 (-83.69) 192 (-9) 1109 (-605) 0.03 (+0.01) 0.00 (+0.00)
GET list_advisory_labels 50 (+15) 0 15804.44 (-214.33) 7370 (-3159) 22069 (-1818) 0.03 (+0.01) 0.00 (+0.00)
GET list_advisory_paginated 45 (+10) 0 434.80 (-13.80) 125 (-57) 671 (-12) 0.03 (+0.01) 0.00 (+0.00)
GET list_importer 45 (+10) 0 18.47 (+9.10) 1 (-1) 389 (+324) 0.03 (+0.01) 0.00 (+0.00)
GET list_organizations 45 (+10) 0 307.20 (+1.51) 65 (-80) 564 (+9) 0.03 (+0.01) 0.00 (+0.00)
GET list_packages 46 (+10) 0 476.78 (+17.89) 134 (-45) 979 (-109) 0.03 (+0.01) 0.00 (+0.00)
GET list_packages_paginated 46 (+10) 0 402.91 (+32.00) 136 (+4) 628 (+51) 0.03 (+0.01) 0.00 (+0.00)
GET list_products 50 (+10) 0 10.62 (-1.81) 5 (-1) 27 (-2) 0.03 (+0.01) 0.00 (+0.00)
GET list_sboms 50 (+10) 0 132523.55 (-45785.33) 112847 (-25416) 168217 (-49317) 0.03 (+0.01) 0.00 (+0.00)
GET list_sboms_paginated 50 (+15) 0 1078.92 (+110.35) 704 (+228) 1625 (-1353) 0.03 (+0.01) 0.00 (+0.00)
GET list_vulnerabilities 45 (+10) 0 546.42 (-2.32) 115 (-60) 878 (+76) 0.03 (+0.01) 0.00 (+0.00)
GET list_vulnerabilities_paginated 45 (+10) 0 405.51 (+49.28) 104 (-13) 820 (+142) 0.03 (+0.01) 0.00 (+0.00)
GET sbom_by_package[pkg:oci/web-ter…-bundle&tag=1.11] 45 (+10) 0 156.56 (-25.47) 66 (-17) 332 (-106) 0.03 (+0.01) 0.00 (+0.00)
GET search_advisory 45 (+10) 0 984.42 (+5.22) 223 (-9) 3470 (-445) 0.03 (+0.01) 0.00 (+0.00)
GET search_exact_purl 50 (+10) 0 134.68 (-14.82) 43 (-9) 174 (-207) 0.03 (+0.01) 0.00 (+0.00)
GET search_licenses 148 (-9) 0 23.83 (-16.68) 4 (0) 260 (-339) 0.08 (-0.00) 0.00 (+0.00)
GET search_purls 50 (+10) 0 17893.12 (-1712.26) 8423 (-3499) 24979 (-11518) 0.03 (+0.01) 0.00 (+0.00)
GET search_purls_by_license 149 (-9) 0 12138.69 (+732.29) 4181 (+383) 38108 (-3510) 0.08 (-0.01) 0.00 (+0.00)
GET search_sboms_by_license 148 (-9) 0 25.66 (-12.40) 3 (0) 319 (+139) 0.08 (-0.00) 0.00 (+0.00)
POST get_recommendations[pkg:maven/io.ne…8.1.redhat-00033] 45 (+10) 0 1080.20 (-47.94) 412 (-99) 1667 (-840) 0.03 (+0.01) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/squid] 45 (+10) 0 4.33 (-0.12) 1 (0) 48 (+9) 0.03 (+0.01) 0.00 (+0.00)
Aggregated 1657 (+253) 0 6577.54 (-1273.82) 1 (0) 168217 (-49317) 0.92 (+0.14) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET download_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 200 (0) 220 (+10) 270 (+50) 280 (+50) 300 (0) 310 (-10) 430 (+35) 430 (+35)
GET get_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 180 (-10) 190 (-10) 200 (0) 210 (-40) 260 (-10) 270 (0) 310 (+30) 310 (+30)
GET get_advisory_by_doc_id 16 (+5) 21 (+7) 35 (+15) 41 (-5) 51 (-12) 60 (-5) 70 (-30) 70 (-30)
GET get_analysis_latest_cpe 31 (+12) 45 (+22) 59 (+30) 67 (+34) 74 (+8) 87 (+11) 169 (+73) 169 (+73)
GET get_analysis_status 4 (-1) 5 (0) 7 (-3) 9 (-14) 35 (-19) 63 (+1) 70 (-6) 70 (-6)
GET get_purl_details[0000054a-a69b-5…520-80752db183e6] 180 (-10) 210 (+10) 250 (+20) 280 (-10) 320 (0) 330 (-40) 479 (-85) 479 (-85)
GET get_sbom[sha256:a3442b37…3040057f79c70669] 13,000 (-5,000) 13,000 (-6,000) 15,000 (-5,000) 16,000 (-4,000) 17,000 (-3,000) 17,000 (-3,000) 17,836 (-7,866) 17,836 (-7,866)
GET get_sbom_license_ids[urn:uuid:019c4a…8ba-3cc0260ef778] 11 (+5) 12 (+6) 17 (+9) 32 (+24) 67 (+52) 86 (+71) 91 (+20) 91 (+20)
GET list_advisory 600 (-200) 700 (-100) 700 (-100) 800 (0) 1,000 (0) 1,000 (0) 1,000 (-714) 1,000 (-714)
GET list_advisory_labels 16,000 (+1,000) 16,000 (0) 17,000 (0) 17,000 (-2,000) 19,000 (-1,000) 21,000 (+1,000) 22,000 (-1,887) 22,000 (-1,887)
GET list_advisory_paginated 420 (-60) 490 (-10) 500 (0) 500 (0) 600 (0) 600 (0) 671 (-12) 671 (-12)
GET list_importer 5 (+1) 6 (+1) 9 (+3) 13 (+3) 16 (+4) 66 (+18) 389 (+324) 389 (+324)
GET list_organizations 300 (+10) 310 (+10) 360 (+10) 370 (0) 460 (-10) 500 (+10) 564 (+9) 564 (+9)
GET list_packages 440 (-40) 500 (+10) 600 (+100) 600 (0) 700 (+100) 900 (+200) 979 (-21) 979 (-21)
GET list_packages_paginated 410 (+30) 420 (0) 490 (+20) 500 (0) 600 (+100) 600 (+100) 600 (+23) 600 (+23)
GET list_products 10 (-2) 11 (-2) 11 (-2) 12 (-2) 14 (-2) 20 (+1) 27 (-2) 27 (-2)
GET list_sboms 125,000 (-51,000) 130,000 (-59,000) 137,000 (-60,000) 145,000 (-56,000) 164,000 (-46,000) 167,000 (-43,000) 168,000 (-49,534) 168,000 (-49,534)
GET list_sboms_paginated 1,000 (+400) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,625 (-1,353) 1,625 (-1,353)
GET list_vulnerabilities 600 (0) 600 (0) 700 (+100) 700 (+100) 700 (0) 800 (+100) 878 (+78) 878 (+78)
GET list_vulnerabilities_paginated 380 (+40) 430 (+60) 500 (+60) 500 (+20) 600 (+100) 700 (+200) 800 (+122) 800 (+122)
GET sbom_by_package[pkg:oci/web-ter…-bundle&tag=1.11] 150 (-10) 170 (-10) 180 (-20) 200 (-20) 230 (-90) 300 (-20) 330 (-108) 330 (-108)
GET search_advisory 800 (+100) 900 (0) 1,000 (+100) 1,000 (+100) 1,000 (-2,000) 3,000 (-915) 3,000 (-915) 3,000 (-915)
GET search_exact_purl 150 (+10) 150 (+10) 150 (-40) 160 (-40) 170 (-40) 170 (-40) 170 (-210) 170 (-210)
GET search_licenses 11 (-9) 14 (-14) 20 (-32) 39 (-31) 54 (-30) 79 (-31) 170 (-80) 260 (-339)
GET search_purls 17,000 (-2,000) 18,000 (-1,000) 18,000 (-2,000) 18,000 (-4,000) 22,000 (0) 24,000 (+1,000) 24,979 (-11,021) 24,979 (-11,021)
GET search_purls_by_license 11,000 (+1,000) 12,000 (+1,000) 13,000 (0) 16,000 (+1,000) 20,000 (+1,000) 23,000 (+1,000) 34,000 (0) 38,000 (-3,618)
GET search_sboms_by_license 13 (-5) 15 (-11) 23 (-22) 34 (-35) 62 (-35) 79 (-31) 150 (-30) 319 (+139)
POST get_recommendations[pkg:maven/io.ne…8.1.redhat-00033] 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,667 (+667) 1,667 (-333) 1,667 (-840) 1,667 (-840)
POST post_vulnerability_analyze[pkg:rpm/redhat/squid] 2 (0) 3 (+1) 3 (0) 4 (+1) 9 (+1) 15 (+2) 48 (+9) 48 (+9)
Aggregated 210 (+10) 400 (+20) 700 (+100) 3,000 (-2,000) 16,000 (0) 18,000 (-2,000) 136,000 (-61,000) 168,000 (-49,534)

Status Code Metrics

Method Name Status Codes
GET download_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 45 [200]
GET get_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 45 [200]
GET get_advisory_by_doc_id 45 [200]
GET get_analysis_latest_cpe 50 [200]
GET get_analysis_status 50 [200]
GET get_purl_details[0000054a-a69b-5…520-80752db183e6] 45 [200]
GET get_sbom[sha256:a3442b37…3040057f79c70669] 45 [200]
GET get_sbom_license_ids[urn:uuid:019c4a…8ba-3cc0260ef778] 45 [200]
GET list_advisory 45 [200]
GET list_advisory_labels 50 [200]
GET list_advisory_paginated 45 [200]
GET list_importer 45 [200]
GET list_organizations 45 [200]
GET list_packages 46 [200]
GET list_packages_paginated 46 [200]
GET list_products 50 [200]
GET list_sboms 50 [200]
GET list_sboms_paginated 50 [200]
GET list_vulnerabilities 45 [200]
GET list_vulnerabilities_paginated 45 [200]
GET sbom_by_package[pkg:oci/web-ter…-bundle&tag=1.11] 45 [200]
GET search_advisory 45 [200]
GET search_exact_purl 50 [200]
GET search_licenses 148 [200]
GET search_purls 50 [200]
GET search_purls_by_license 149 [200]
GET search_sboms_by_license 148 [200]
POST get_recommendations[pkg:maven/io.ne…8.1.redhat-00033] 45 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/squid] 45 [200]
Aggregated 1,657 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 45 (+10) 0 (0) 12.18 (-0.68) 6 (-1) 23 (-4) 0.03 (+0.01) 0.00 (+0.00)
1.1 list_organizations 45 (+10) 0 (0) 307.29 (+1.52) 65 (-80) 564 (+9) 0.03 (+0.01) 0.00 (+0.00)
1.2 list_advisory 45 (+10) 0 (0) 657.07 (-83.68) 193 (-8) 1109 (-605) 0.03 (+0.01) 0.00 (+0.00)
1.3 list_advisory_paginated 45 (+10) 0 (0) 434.82 (-13.86) 126 (-56) 671 (-12) 0.03 (+0.01) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 45 (+10) 0 (0) 25.02 (+1.88) 5 (0) 70 (-32) 0.03 (+0.01) 0.00 (+0.00)
1.5 search_advisory 45 (+10) 0 (0) 984.47 (+5.21) 224 (-9) 3470 (-445) 0.03 (+0.01) 0.00 (+0.00)
1.6 list_vulnerabilities 45 (+10) 0 (0) 546.49 (-2.34) 115 (-60) 878 (+76) 0.03 (+0.01) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 45 (+10) 0 (0) 405.53 (+49.30) 105 (-12) 820 (+142) 0.03 (+0.01) 0.00 (+0.00)
1.8 list_importer 45 (+10) 0 (0) 18.51 (+9.08) 1 (-1) 390 (+324) 0.03 (+0.01) 0.00 (+0.00)
1.9 list_packages 46 (+10) 0 (0) 476.80 (+17.89) 134 (-45) 979 (-109) 0.03 (+0.01) 0.00 (+0.00)
1.10 list_packages_paginated 46 (+10) 0 (0) 402.98 (+32.03) 136 (+4) 628 (+51) 0.03 (+0.01) 0.00 (+0.00)
1.11 search_purls 50 (+10) 0 (0) 17893.20 (-1712.23) 8423 (-3499) 24979 (-11518) 0.03 (+0.01) 0.00 (+0.00)
1.12 search_exact_purl 50 (+10) 0 (0) 134.70 (-14.93) 43 (-9) 174 (-208) 0.03 (+0.01) 0.00 (+0.00)
1.13 list_products 50 (+10) 0 (0) 10.68 (-1.74) 5 (-1) 27 (-2) 0.03 (+0.01) 0.00 (+0.00)
1.14 list_sboms 50 (+10) 0 (0) 132523.56 (-45785.34) 112847 (-25416) 168217 (-49317) 0.03 (+0.01) 0.00 (+0.00)
1.15 list_sboms_paginated 50 (+15) 0 (0) 1078.98 (+110.38) 704 (+228) 1625 (-1353) 0.03 (+0.01) 0.00 (+0.00)
1.16 get_analysis_status 50 (+15) 0 (0) 11.96 (-3.04) 2 (0) 70 (-6) 0.03 (+0.01) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 50 (+15) 0 (0) 39.02 (+12.33) 4 (-1) 169 (+73) 0.03 (+0.01) 0.00 (+0.00)
1.18 list_advisory_labels 50 (+15) 0 (0) 15804.52 (-214.28) 7370 (-3159) 22069 (-1818) 0.03 (+0.01) 0.00 (+0.00)
1.19 get_sbom[sha256:a3442b37…3040057f79c70669] 45 (+10) 0 (0) 9622.93 (-3919.29) 284 (-219) 17836 (-7866) 0.03 (+0.01) 0.00 (+0.00)
1.20 sbom_by_package[pkg:oci/web-ter…-bundle&tag=1.11] 45 (+10) 0 (0) 156.67 (-25.39) 66 (-17) 332 (-106) 0.03 (+0.01) 0.00 (+0.00)
1.21 get_sbom_license_ids[urn:uuid:019c4a…8ba-3cc0260ef778] 45 (+10) 0 (0) 21.36 (+12.01) 3 (+1) 91 (+20) 0.03 (+0.01) 0.00 (+0.00)
1.22 post_vulnerability_analyze[pkg:rpm/redhat/squid] 45 (+10) 0 (0) 4.44 (-0.04) 1 (0) 48 (+9) 0.03 (+0.01) 0.00 (+0.00)
1.23 get_purl_details[0000054a-a69b-5…520-80752db183e6] 45 (+10) 0 (0) 202.89 (-7.48) 68 (-15) 479 (-85) 0.03 (+0.01) 0.00 (+0.00)
1.24 get_recommendations[pkg:maven/io.ne…8.1.redhat-00033] 45 (+10) 0 (0) 1080.24 (-47.93) 412 (-99) 1668 (-839) 0.03 (+0.01) 0.00 (+0.00)
1.25 download_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 45 (+10) 0 (0) 205.11 (+14.57) 29 (-8) 434 (+39) 0.03 (+0.01) 0.00 (+0.00)
1.26 get_advisory[5b25cdef-428a-4…29e-fbb3415c22ab] 45 (+10) 0 (0) 166.40 (-7.54) 29 (-36) 311 (+31) 0.03 (+0.01) 0.00 (+0.00)
RestAPIUserSlow
2.0 logon 148 (-9) 0 (0) 10.26 (-0.30) 6 (0) 16 (-14) 0.08 (-0.00) 0.00 (+0.00)
2.1 search_licenses 148 (-9) 0 (0) 23.96 (-16.80) 4 (0) 260 (-339) 0.08 (-0.00) 0.00 (+0.00)
2.2 search_sboms_by_license 148 (-9) 0 (0) 25.72 (-12.39) 3 (0) 319 (+139) 0.08 (-0.00) 0.00 (+0.00)
2.3 search_purls_by_license 149 (-9) 0 (0) 12138.74 (+732.30) 4181 (+383) 38108 (-3510) 0.08 (-0.01) 0.00 (+0.00)
RestAPIUserDelete
3.0 logon 513 (+2) 0 (0) 10.78 (-0.04) 6 (0) 53 (-3) 0.28 (+0.00) 0.00 (+0.00)
RestAdvisoryLableUser
4.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
Aggregated 2,363 (+256) 0 (0) 4612.35 (-619.40) 1 (0) 168217 (-49317) 1.31 (+0.14) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 45 (+10) 182203.33 (-53852.25) 151222 (-36163) 229220 (-36660) 0.03 (+0.01) 9.00 (+2.00)
RestAPIUserSlow 1 (0) 148 (-9) 12124.17 (+671.41) 4213 (+381) 38193 (-3540) 0.08 (-0.00) 148.00 (-9.00)
RestAPIUserDelete 1 (0) 513 (+2) 3509.40 (-16.68) 3018 (0) 4019 (-20) 0.28 (+0.00) 513.00 (+2.00)
RestAdvisoryLableUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
Aggregated 7 (0) 706 (+3) 16705.17 (-168.03) 3018 (0) 229220 (-36660) 0.39 (+0.00) 670.00 (-5.00)

User Metrics