Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-07-17 13:59:4225-07-17 13:59:4700:00:050 → 5
Maintaining25-07-17 13:59:4725-07-17 14:04:4700:05:005
Decreasing25-07-17 14:04:4725-07-17 14:04:5000:00:030 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 100 (0) 0 15.17 (+3.09) 3 (0) 61 (0) 0.33 (+0.00) 0.00 (+0.00)
GET get_analysis_latest_cpe 100 (0) 0 118.58 (+4.32) 62 (+24) 174 (-6) 0.33 (+0.00) 0.00 (+0.00)
GET get_analysis_status 100 (0) 0 4.70 (+1.05) 1 (0) 44 (-3) 0.33 (+0.00) 0.00 (+0.00)
GET get_sbom[sha256:f293eb89…6720f692ec5f3081] 100 (0) 100 4.40 (-0.21) 2 (+1) 47 (+13) 0.33 (+0.00) 0.33 (+0.00)
GET get_sbom_license_ids[0195baea-42e3-7…0e3-4c7874263954] 100 (0) 100 1.03 (+0.17) 1 (0) 2 (-1) 0.33 (+0.00) 0.33 (+0.00)
GET list_advisory 100 (0) 0 579.92 (+28.48) 398 (+15) 1243 (+387) 0.33 (+0.00) 0.00 (+0.00)
GET list_advisory_paginated 100 (0) 0 437.44 (+30.66) 213 (+23) 690 (+99) 0.33 (+0.00) 0.00 (+0.00)
GET list_importer 100 (0) 0 6.17 (+2.56) 1 (0) 66 (+18) 0.33 (+0.00) 0.00 (+0.00)
GET list_organizations 100 (0) 0 4.85 (-0.15) 1 (0) 25 (+4) 0.33 (+0.00) 0.00 (+0.00)
GET list_packages 100 (0) 0 505.04 (+7.63) 211 (-93) 954 (+35) 0.33 (+0.00) 0.00 (+0.00)
GET list_packages_paginated 100 (0) 0 397.77 (-4.49) 67 (-41) 685 (+99) 0.33 (+0.00) 0.00 (+0.00)
GET list_products 100 (0) 0 7.07 (+0.22) 2 (-1) 16 (+3) 0.33 (+0.00) 0.00 (+0.00)
GET list_sboms 100 (0) 0 609.44 (-27.60) 494 (-30) 747 (-47) 0.33 (+0.00) 0.00 (+0.00)
GET list_sboms_paginated 100 (0) 0 552.38 (+21.61) 453 (+55) 664 (+59) 0.33 (+0.00) 0.00 (+0.00)
GET list_vulnerabilities 100 (0) 0 254.95 (-16.21) 88 (+5) 415 (+21) 0.33 (+0.00) 0.00 (+0.00)
GET list_vulnerabilities_paginated 100 (0) 0 178.35 (-5.51) 96 (-5) 316 (-45) 0.33 (+0.00) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (0) 0 31.49 (+3.20) 15 (0) 67 (-1) 0.33 (+0.00) 0.00 (+0.00)
GET search_advisory 100 (0) 0 1140.85 (+149.14) 327 (-5) 2137 (+188) 0.33 (+0.00) 0.00 (+0.00)
GET search_exact_purl 100 (0) 0 8.31 (+2.10) 2 (0) 51 (+35) 0.33 (+0.00) 0.00 (+0.00)
GET search_purls 105 (0) 0 9514.20 (-85.60) 3000 (+1589) 13725 (-2227) 0.35 (+0.00) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (0) 0 391.24 (+2.66) 341 (+75) 466 (-138) 0.33 (+0.00) 0.00 (+0.00)
Aggregated 2105 (0) 200 723.95 (+5.36) 1 (0) 13725 (-2227) 7.02 (+0.00) 0.67 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (+1) 8 (+1) 9 (0) 21 (+8) 51 (+9) 53 (+3) 60 (0) 61 (0)
GET get_analysis_latest_cpe 110 (0) 110 (-10) 140 (+10) 150 (+20) 160 (+10) 160 (-20) 170 (-10) 170 (-10)
GET get_analysis_status 2 (0) 2 (0) 3 (0) 3 (0) 5 (+1) 28 (+22) 43 (+6) 44 (-3)
GET get_sbom[sha256:f293eb89…6720f692ec5f3081] 3 (0) 3 (0) 3 (0) 4 (0) 4 (-1) 4 (-3) 47 (+14) 47 (+13)
GET get_sbom_license_ids[0195baea-42e3-7…0e3-4c7874263954] 1 (0) 1 (0) 1 (0) 1 (0) 2 (+1) 2 (0) 2 (0) 2 (-1)
GET list_advisory 500 (+10) 600 (+100) 600 (0) 700 (0) 800 (0) 900 (+100) 1,000 (+200) 1,000 (+144)
GET list_advisory_paginated 440 (+20) 470 (+40) 480 (+30) 500 (+30) 500 (+10) 600 (+100) 600 (+100) 690 (+99)
GET list_importer 3 (+1) 3 (+1) 4 (+1) 5 (+2) 8 (+3) 43 (+37) 48 (+12) 66 (+18)
GET list_organizations 3 (-1) 4 (-1) 5 (-1) 7 (-1) 9 (0) 14 (+3) 16 (0) 25 (+4)
GET list_packages 460 (+10) 490 (+20) 500 (0) 600 (0) 800 (+100) 900 (+100) 900 (0) 954 (+54)
GET list_packages_paginated 420 (+20) 420 (+10) 440 (0) 470 (-10) 490 (-10) 500 (0) 685 (+99) 685 (+99)
GET list_products 6 (0) 7 (0) 9 (+1) 9 (0) 11 (+1) 11 (0) 13 (0) 16 (+3)
GET list_sboms 600 (0) 600 (0) 600 (-100) 600 (-100) 700 (0) 700 (0) 700 (-94) 700 (-94)
GET list_sboms_paginated 500 (0) 600 (+100) 600 (0) 600 (0) 600 (0) 600 (0) 664 (+64) 664 (+64)
GET list_vulnerabilities 270 (-20) 280 (-20) 310 (0) 330 (+10) 360 (+20) 370 (+10) 410 (+30) 415 (+25)
GET list_vulnerabilities_paginated 170 (-20) 180 (-20) 200 (0) 210 (0) 230 (+10) 270 (+20) 300 (-10) 316 (-44)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 21 (0) 25 (+3) 43 (+19) 49 (+1) 57 (+4) 64 (+6) 67 (0) 67 (-1)
GET search_advisory 1,000 (+300) 1,000 (0) 1,000 (0) 2,000 (+51) 2,000 (+51) 2,000 (+51) 2,000 (+51) 2,000 (+51)
GET search_exact_purl 6 (0) 6 (0) 6 (-1) 7 (0) 8 (0) 44 (+34) 50 (+36) 51 (+35)
GET search_purls 12,000 (-1,000) 13,000 (-1,000) 13,000 (-1,000) 13,000 (-2,000) 13,000 (-2,000) 13,000 (-2,952) 13,725 (-2,227) 13,725 (-2,227)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 390 (-10) 390 (-10) 400 (-10) 420 (0) 420 (-10) 450 (+10) 450 (-50) 466 (-134)
Aggregated 160 (-20) 370 (+10) 440 (+10) 500 (0) 700 (0) 2,000 (0) 13,000 (-2,000) 13,725 (-2,227)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 100 [200]
GET get_analysis_latest_cpe 100 [200]
GET get_analysis_status 100 [200]
GET get_sbom[sha256:f293eb89…6720f692ec5f3081] 100 [404]
GET get_sbom_license_ids[0195baea-42e3-7…0e3-4c7874263954] 100 [400]
GET list_advisory 100 [200]
GET list_advisory_paginated 100 [200]
GET list_importer 100 [200]
GET list_organizations 100 [200]
GET list_packages 100 [200]
GET list_packages_paginated 100 [200]
GET list_products 100 [200]
GET list_sboms 100 [200]
GET list_sboms_paginated 100 [200]
GET list_vulnerabilities 100 [200]
GET list_vulnerabilities_paginated 100 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 [200]
GET search_advisory 100 [200]
GET search_exact_purl 100 [200]
GET search_purls 105 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 [200]
Aggregated 1,905 [200], 100 [404], 100 [400]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 100 (0) 0 (0) 14.07 (-0.40) 11 (0) 23 (+1) 0.33 (+0.00) 0.00 (+0.00)
1.1 list_organizations 100 (0) 0 (0) 5.09 (-0.08) 2 (+1) 25 (+2) 0.33 (+0.00) 0.00 (+0.00)
1.2 list_advisory 100 (0) 0 (0) 579.94 (+28.43) 398 (+15) 1243 (+387) 0.33 (+0.00) 0.00 (+0.00)
1.3 list_advisory_paginated 100 (0) 0 (0) 437.55 (+30.73) 213 (+23) 690 (+99) 0.33 (+0.00) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 100 (0) 0 (0) 15.20 (+3.00) 3 (0) 61 (0) 0.33 (+0.00) 0.00 (+0.00)
1.5 search_advisory 100 (0) 0 (0) 1140.89 (+149.15) 327 (-5) 2137 (+188) 0.33 (+0.00) 0.00 (+0.00)
1.6 list_vulnerabilities 100 (0) 0 (0) 255.02 (-16.19) 88 (+5) 415 (+21) 0.33 (+0.00) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 100 (0) 0 (0) 178.43 (-5.45) 96 (-5) 316 (-45) 0.33 (+0.00) 0.00 (+0.00)
1.8 list_importer 100 (0) 0 (0) 6.22 (+2.58) 1 (0) 67 (+19) 0.33 (+0.00) 0.00 (+0.00)
1.9 list_packages 100 (0) 0 (0) 505.07 (+7.59) 211 (-93) 954 (+35) 0.33 (+0.00) 0.00 (+0.00)
1.10 list_packages_paginated 100 (0) 0 (0) 397.87 (-4.50) 67 (-41) 685 (+99) 0.33 (+0.00) 0.00 (+0.00)
1.11 search_purls 105 (0) 0 (0) 9514.26 (-85.60) 3000 (+1589) 13725 (-2227) 0.35 (+0.00) 0.00 (+0.00)
1.12 search_exact_purl 100 (0) 0 (0) 8.38 (+2.13) 2 (0) 51 (+35) 0.33 (+0.00) 0.00 (+0.00)
1.13 list_products 100 (0) 0 (0) 7.11 (+0.24) 2 (-1) 16 (+3) 0.33 (+0.00) 0.00 (+0.00)
1.14 list_sboms 100 (0) 0 (0) 609.47 (-27.60) 494 (-30) 747 (-47) 0.33 (+0.00) 0.00 (+0.00)
1.15 list_sboms_paginated 100 (0) 0 (0) 552.43 (+21.62) 453 (+54) 664 (+59) 0.33 (+0.00) 0.00 (+0.00)
1.16 get_analysis_status 100 (0) 0 (0) 4.78 (+1.07) 1 (0) 44 (-3) 0.33 (+0.00) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 100 (0) 0 (0) 118.60 (+4.32) 62 (+24) 174 (-6) 0.33 (+0.00) 0.00 (+0.00)
1.18 get_sbom[sha256:f293eb89…6720f692ec5f3081] 100 (0) 0 (0) 4.42 (-0.24) 2 (+1) 47 (+13) 0.33 (+0.00) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (0) 0 (0) 31.57 (+3.22) 15 (0) 67 (-1) 0.33 (+0.00) 0.00 (+0.00)
1.20 get_sbom_license_ids[0195baea-42e3-7…0e3-4c7874263954] 100 (0) 0 (0) 1.07 (+0.18) 1 (0) 2 (-1) 0.33 (+0.00) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (0) 0 (0) 391.24 (+2.62) 341 (+75) 466 (-138) 0.33 (+0.00) 0.00 (+0.00)
Aggregated 2,205 (0) 0 (0) 691.11 (+5.12) 1 (0) 13725 (-2227) 7.35 (+0.00) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 100 (0) 14941.01 (-14.80) 8560 (+2395) 19414 (-1832) 0.33 (+0.00) 20.00 (+0.00)
Aggregated 5 (0) 100 (0) 14941.01 (-14.80) 8560 (+2395) 19414 (-1832) 0.33 (+0.00) 20.00 (+0.00)

User Metrics

Errors

# Error
100 (0) 400 Bad Request: get_sbom_license_ids[0195baea-42e3-7…0e3-4c7874263954]
100 (0) 404 Not Found: get_sbom[sha256:f293eb89…6720f692ec5f3081]