Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-07-25 03:39:4925-07-25 03:39:5400:00:050 → 5
Maintaining25-07-25 03:39:5425-07-25 03:44:5400:05:005
Decreasing25-07-25 03:44:5425-07-25 03:44:5600:00:020 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 100 (-57) 0 13.69 (+0.69) 3 (0) 79 (+10) 0.33 (-0.19) 0.00 (+0.00)
GET get_analysis_latest_cpe 100 (-57) 0 115.19 (-8.50) 31 (-8) 269 (-208) 0.33 (-0.19) 0.00 (+0.00)
GET get_analysis_status 100 (-57) 0 4.36 (-2.65) 1 (0) 53 (-2) 0.33 (-0.19) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 100 (-57) 0 600.53 (-15.33) 203 (+3) 1611 (-90) 0.33 (-0.19) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 (-57) 0 844.75 (-85.74) 496 (-15) 1117 (-392) 0.33 (-0.19) 0.00 (+0.00)
GET list_advisory 100 (-57) 0 481.36 (+25.64) 294 (+48) 897 (+69) 0.33 (-0.19) 0.00 (+0.00)
GET list_advisory_paginated 100 (-57) 0 391.11 (+11.50) 176 (-57) 564 (-146) 0.33 (-0.19) 0.00 (+0.00)
GET list_importer 98 (-58) 0 4.73 (-0.46) 1 (0) 58 (+3) 0.33 (-0.19) 0.00 (+0.00)
GET list_organizations 100 (-57) 0 7.86 (-4.87) 1 (0) 46 (-9) 0.33 (-0.19) 0.00 (+0.00)
GET list_packages 98 (-58) 0 432.51 (+63.95) 85 (-15) 985 (+88) 0.33 (-0.19) 0.00 (+0.00)
GET list_packages_paginated 98 (-57) 0 388.59 (+55.09) 105 (-1) 706 (+183) 0.33 (-0.19) 0.00 (+0.00)
GET list_products 100 (-60) 0 7.07 (-2.21) 3 (+1) 32 (-33) 0.33 (-0.20) 0.00 (+0.00)
GET list_sboms 100 (-60) 0 910.91 (-235.13) 575 (+151) 1454 (-341) 0.33 (-0.20) 0.00 (+0.00)
GET list_sboms_paginated 100 (-58) 0 1200.91 (-228.23) 467 (+43) 2393 (-973) 0.33 (-0.19) 0.00 (+0.00)
GET list_vulnerabilities 98 (-58) 0 243.02 (+9.78) 56 (-8) 401 (+17) 0.33 (-0.19) 0.00 (+0.00)
GET list_vulnerabilities_paginated 98 (-58) 0 186.51 (+9.73) 41 (-22) 316 (+26) 0.33 (-0.19) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (-57) 0 48.44 (-12.67) 10 (+1) 176 (-28) 0.33 (-0.19) 0.00 (+0.00)
GET search_advisory 100 (-57) 0 987.07 (+55.96) 171 (-170) 2512 (+302) 0.33 (-0.19) 0.00 (+0.00)
GET search_exact_purl 100 (-60) 0 6.93 (-1.72) 2 (0) 54 (-11) 0.33 (-0.20) 0.00 (+0.00)
GET search_purls 103 (-57) 0 7544.64 (+5936.98) 1911 (+1368) 11620 (+5821) 0.34 (-0.19) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (-57) 0 531.29 (-183.00) 237 (-35) 999 (-177) 0.33 (-0.19) 0.00 (+0.00)
Aggregated 2093 (-1211) 0 723.97 (+267.06) 1 (0) 11620 (+5821) 6.98 (-4.04) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (0) 7 (0) 10 (0) 13 (+1) 51 (+2) 54 (-3) 68 (+3) 79 (+10)
GET get_analysis_latest_cpe 100 (-10) 110 (-10) 130 (0) 170 (+10) 180 (0) 190 (-40) 260 (-60) 269 (-208)
GET get_analysis_status 2 (0) 3 (0) 3 (0) 4 (-1) 6 (-2) 8 (-42) 48 (-6) 53 (-2)
GET get_sbom[sha256:720e4451…a939656247164447] 460 (+60) 500 (+90) 600 (+100) 800 (-200) 1,000 (0) 1,000 (-701) 1,611 (-90) 1,611 (-90)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 900 (0) 900 (-100) 900 (-100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-509)
GET list_advisory 450 (0) 470 (0) 500 (+10) 600 (+100) 700 (+100) 700 (+100) 800 (+200) 897 (+97)
GET list_advisory_paginated 400 (+20) 410 (+20) 430 (+30) 460 (+40) 490 (+10) 490 (-10) 500 (-100) 564 (-136)
GET list_importer 2 (0) 2 (-1) 3 (0) 4 (0) 6 (-1) 9 (-27) 48 (-4) 58 (+3)
GET list_organizations 3 (-1) 3 (-3) 5 (-6) 9 (-22) 29 (-12) 37 (-7) 45 (-5) 46 (-9)
GET list_packages 420 (+50) 430 (+50) 460 (+70) 490 (+80) 500 (+20) 700 (+200) 900 (+300) 985 (+88)
GET list_packages_paginated 400 (+80) 420 (+80) 440 (+60) 480 (+80) 500 (+80) 600 (+140) 600 (+100) 700 (+200)
GET list_products 5 (0) 6 (0) 7 (0) 8 (-3) 10 (-5) 15 (-32) 31 (-29) 32 (-33)
GET list_sboms 900 (-100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-795) 1,000 (-795) 1,000 (-795)
GET list_sboms_paginated 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (-1,000) 2,000 (-1,000) 2,000 (-1,000)
GET list_vulnerabilities 240 (+10) 260 (+20) 280 (+10) 290 (+10) 300 (0) 310 (+10) 360 (+20) 400 (+20)
GET list_vulnerabilities_paginated 180 (0) 190 (0) 200 (0) 210 (+10) 240 (+30) 280 (+20) 290 (+10) 316 (+26)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 26 (-35) 57 (-10) 65 (-9) 73 (-27) 96 (-34) 120 (-40) 170 (-20) 176 (-24)
GET search_advisory 900 (+200) 1,000 (+200) 1,000 (0) 1,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,512 (+512)
GET search_exact_purl 5 (+1) 6 (+2) 6 (0) 7 (0) 8 (-11) 9 (-42) 53 (-6) 54 (-11)
GET search_purls 7,000 (+6,000) 8,000 (+6,000) 10,000 (+8,000) 11,000 (+9,000) 11,000 (+8,000) 11,620 (+7,620) 11,620 (+6,620) 11,620 (+5,821)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 500 (-200) 600 (-200) 600 (-200) 600 (-300) 700 (-200) 800 (-200) 900 (-100) 999 (-1)
Aggregated 300 (+10) 410 (+20) 500 (0) 800 (0) 1,000 (0) 2,000 (0) 11,000 (+8,000) 11,620 (+5,821)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 100 [200]
GET get_analysis_latest_cpe 100 [200]
GET get_analysis_status 100 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 100 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 [200]
GET list_advisory 100 [200]
GET list_advisory_paginated 100 [200]
GET list_importer 98 [200]
GET list_organizations 100 [200]
GET list_packages 98 [200]
GET list_packages_paginated 98 [200]
GET list_products 100 [200]
GET list_sboms 100 [200]
GET list_sboms_paginated 100 [200]
GET list_vulnerabilities 98 [200]
GET list_vulnerabilities_paginated 98 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 [200]
GET search_advisory 100 [200]
GET search_exact_purl 100 [200]
GET search_purls 103 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 [200]
Aggregated 2,093 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 100 (-57) 0 (0) 14.66 (+0.65) 8 (+2) 22 (-7) 0.33 (-0.19) 0.00 (+0.00)
1.1 list_organizations 100 (-57) 0 (0) 8.03 (-4.81) 1 (0) 46 (-9) 0.33 (-0.19) 0.00 (+0.00)
1.2 list_advisory 100 (-57) 0 (0) 481.41 (+25.61) 294 (+48) 898 (+70) 0.33 (-0.19) 0.00 (+0.00)
1.3 list_advisory_paginated 100 (-57) 0 (0) 391.20 (+11.52) 176 (-57) 564 (-146) 0.33 (-0.19) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 100 (-57) 0 (0) 13.77 (+0.72) 3 (0) 79 (+10) 0.33 (-0.19) 0.00 (+0.00)
1.5 search_advisory 100 (-57) 0 (0) 987.12 (+55.95) 171 (-170) 2512 (+302) 0.33 (-0.19) 0.00 (+0.00)
1.6 list_vulnerabilities 98 (-58) 0 (0) 243.10 (+9.83) 56 (-8) 401 (+17) 0.33 (-0.19) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 98 (-58) 0 (0) 186.55 (+9.71) 41 (-22) 316 (+24) 0.33 (-0.19) 0.00 (+0.00)
1.8 list_importer 98 (-58) 0 (0) 4.80 (-0.45) 1 (0) 58 (+3) 0.33 (-0.19) 0.00 (+0.00)
1.9 list_packages 98 (-58) 0 (0) 432.54 (+63.91) 85 (-15) 985 (+88) 0.33 (-0.19) 0.00 (+0.00)
1.10 list_packages_paginated 98 (-57) 0 (0) 388.66 (+55.08) 105 (-1) 706 (+183) 0.33 (-0.19) 0.00 (+0.00)
1.11 search_purls 103 (-57) 0 (0) 7544.70 (+5936.99) 1911 (+1368) 11620 (+5821) 0.34 (-0.19) 0.00 (+0.00)
1.12 search_exact_purl 100 (-60) 0 (0) 6.97 (-1.75) 2 (0) 54 (-11) 0.33 (-0.20) 0.00 (+0.00)
1.13 list_products 100 (-60) 0 (0) 7.13 (-2.21) 3 (+1) 32 (-33) 0.33 (-0.20) 0.00 (+0.00)
1.14 list_sboms 100 (-60) 0 (0) 910.97 (-235.10) 576 (+152) 1454 (-341) 0.33 (-0.20) 0.00 (+0.00)
1.15 list_sboms_paginated 100 (-58) 0 (0) 1200.99 (-228.23) 467 (+43) 2394 (-972) 0.33 (-0.19) 0.00 (+0.00)
1.16 get_analysis_status 100 (-57) 0 (0) 4.41 (-2.66) 1 (0) 53 (-2) 0.33 (-0.19) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 100 (-57) 0 (0) 115.22 (-8.53) 31 (-8) 269 (-209) 0.33 (-0.19) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 100 (-57) 0 (0) 600.57 (-15.40) 203 (+3) 1611 (-90) 0.33 (-0.19) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (-57) 0 (0) 48.47 (-12.70) 10 (+1) 176 (-28) 0.33 (-0.19) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 (-57) 0 (0) 844.82 (-85.73) 496 (-15) 1117 (-392) 0.33 (-0.19) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (-57) 0 (0) 531.33 (-183.05) 237 (-35) 999 (-177) 0.33 (-0.19) 0.00 (+0.00)
Aggregated 2,193 (-1,268) 0 (0) 690.96 (+254.77) 1 (0) 11620 (+5821) 7.31 (-4.23) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 100 (-57) 15018.21 (+5483.97) 8689 (+2816) 20134 (+7440) 0.33 (-0.19) 20.00 (-11.40)
Aggregated 5 (0) 100 (-57) 15018.21 (+5483.97) 8689 (+2816) 20134 (+7440) 0.33 (-0.19) 20.00 (-11.40)

User Metrics