Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-07-27 03:48:5025-07-27 03:48:5500:00:050 → 5
Maintaining25-07-27 03:48:5525-07-27 03:53:5500:05:005
Decreasing25-07-27 03:53:5525-07-27 03:54:0300:00:080 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 100 (-8) 0 9.74 (-1.07) 3 (0) 58 (-13) 0.33 (-0.03) 0.00 (+0.00)
GET get_analysis_latest_cpe 100 (-10) 0 104.51 (-19.34) 30 (-5) 368 (+60) 0.33 (-0.03) 0.00 (+0.00)
GET get_analysis_status 100 (-10) 0 5.42 (-0.87) 1 (0) 57 (+1) 0.33 (-0.03) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 100 (-10) 0 699.63 (-6.78) 201 (+55) 1692 (-214) 0.33 (-0.03) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 (-9) 0 819.76 (-72.60) 324 (-65) 1184 (+15) 0.33 (-0.03) 0.00 (+0.00)
GET list_advisory 100 (-8) 0 470.11 (+11.79) 258 (+30) 746 (-167) 0.33 (-0.03) 0.00 (+0.00)
GET list_advisory_paginated 100 (-8) 0 416.72 (+29.22) 135 (+6) 586 (-7) 0.33 (-0.03) 0.00 (+0.00)
GET list_importer 100 (-5) 0 2.52 (-0.96) 1 (0) 52 (+3) 0.33 (-0.02) 0.00 (+0.00)
GET list_organizations 100 (-8) 0 5.84 (-4.04) 1 (0) 60 (+9) 0.33 (-0.03) 0.00 (+0.00)
GET list_packages 100 (-5) 0 481.61 (+78.70) 99 (-2) 957 (+105) 0.33 (-0.02) 0.00 (+0.00)
GET list_packages_paginated 100 (-5) 0 402.82 (+37.20) 91 (-17) 587 (-31) 0.33 (-0.02) 0.00 (+0.00)
GET list_products 100 (-10) 0 8.69 (-2.23) 2 (-1) 54 (-12) 0.33 (-0.03) 0.00 (+0.00)
GET list_sboms 100 (-10) 0 1067.03 (-188.64) 592 (+16) 1500 (-454) 0.33 (-0.03) 0.00 (+0.00)
GET list_sboms_paginated 100 (-10) 0 1278.84 (-166.85) 486 (+67) 3206 (+95) 0.33 (-0.03) 0.00 (+0.00)
GET list_vulnerabilities 100 (-5) 0 287.23 (+60.79) 67 (+11) 409 (+86) 0.33 (-0.02) 0.00 (+0.00)
GET list_vulnerabilities_paginated 100 (-5) 0 188.06 (+7.93) 71 (+29) 311 (+7) 0.33 (-0.02) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (-9) 0 65.49 (+4.26) 9 (-2) 188 (-11) 0.33 (-0.03) 0.00 (+0.00)
GET search_advisory 100 (-8) 0 906.77 (+18.95) 330 (+152) 1885 (-213) 0.33 (-0.03) 0.00 (+0.00)
GET search_exact_purl 100 (-10) 0 6.65 (-0.67) 2 (0) 50 (-4) 0.33 (-0.03) 0.00 (+0.00)
GET search_purls 105 (-5) 0 7379.31 (+1605.92) 4609 (+2784) 10567 (-4) 0.35 (-0.02) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (-8) 0 521.06 (-106.92) 231 (-48) 852 (-272) 0.33 (-0.03) 0.00 (+0.00)
Aggregated 2105 (-166) 0 736.19 (+70.74) 1 (0) 10567 (-4) 7.02 (-0.55) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 5 (-1) 6 (-1) 7 (-1) 9 (-1) 15 (-7) 43 (-3) 55 (-13) 58 (-13)
GET get_analysis_latest_cpe 90 (-20) 100 (-20) 120 (-30) 160 (-10) 190 (0) 200 (-20) 290 (-10) 368 (+60)
GET get_analysis_status 2 (0) 3 (0) 3 (-1) 5 (0) 7 (+1) 38 (-11) 52 (-2) 57 (+1)
GET get_sbom[sha256:720e4451…a939656247164447] 500 (+70) 700 (+100) 800 (0) 1,000 (0) 1,000 (0) 1,692 (-214) 1,692 (-214) 1,692 (-214)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 900 (0) 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 470 (+20) 480 (+20) 490 (+10) 500 (0) 600 (0) 600 (-100) 700 (-200) 700 (-200)
GET list_advisory_paginated 430 (+40) 440 (+40) 460 (+50) 480 (+50) 490 (+10) 500 (0) 586 (-7) 586 (-7)
GET list_importer 2 (0) 2 (-1) 2 (-1) 2 (-2) 3 (-2) 4 (-2) 13 (-32) 52 (+3)
GET list_organizations 3 (0) 3 (-2) 5 (-1) 7 (-5) 11 (-25) 17 (-25) 45 (-6) 60 (+9)
GET list_packages 450 (+50) 470 (+60) 490 (+60) 500 (+30) 700 (+200) 800 (+200) 900 (+100) 957 (+105)
GET list_packages_paginated 420 (+30) 430 (+30) 470 (+70) 480 (+60) 500 (+10) 500 (+10) 500 (-100) 587 (-13)
GET list_products 5 (-1) 6 (-2) 7 (-2) 8 (-2) 10 (-4) 43 (-15) 53 (-12) 54 (-12)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-954) 1,000 (-954) 1,000 (-954) 1,500 (-454)
GET list_sboms_paginated 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (-1,000) 3,000 (0)
GET list_vulnerabilities 310 (+80) 320 (+80) 340 (+90) 360 (+90) 360 (+70) 400 (+110) 409 (+109) 409 (+89)
GET list_vulnerabilities_paginated 190 (0) 200 (0) 200 (0) 210 (0) 210 (-30) 230 (-20) 290 (+10) 310 (+10)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 63 (+28) 69 (+5) 81 (+6) 110 (+10) 150 (0) 170 (0) 180 (0) 188 (-11)
GET search_advisory 800 (0) 900 (-100) 1,000 (0) 1,000 (0) 1,885 (+885) 1,885 (-115) 1,885 (-115) 1,885 (-115)
GET search_exact_purl 6 (0) 6 (0) 7 (0) 7 (0) 8 (0) 10 (-1) 12 (-41) 50 (-4)
GET search_purls 7,000 (+1,000) 7,000 (+1,000) 9,000 (+2,000) 9,000 (-1,000) 10,000 (0) 10,000 (-571) 10,567 (-4) 10,567 (-4)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 500 (-100) 500 (-100) 600 (-100) 600 (-100) 700 (-100) 800 (-200) 852 (-148) 852 (-148)
Aggregated 340 (+40) 430 (+30) 500 (0) 800 (-100) 1,000 (0) 3,000 (+1,000) 9,000 (-1,000) 10,567 (-4)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 100 [200]
GET get_analysis_latest_cpe 100 [200]
GET get_analysis_status 100 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 100 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 [200]
GET list_advisory 100 [200]
GET list_advisory_paginated 100 [200]
GET list_importer 100 [200]
GET list_organizations 100 [200]
GET list_packages 100 [200]
GET list_packages_paginated 100 [200]
GET list_products 100 [200]
GET list_sboms 100 [200]
GET list_sboms_paginated 100 [200]
GET list_vulnerabilities 100 [200]
GET list_vulnerabilities_paginated 100 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 [200]
GET search_advisory 100 [200]
GET search_exact_purl 100 [200]
GET search_purls 105 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 [200]
Aggregated 2,105 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 100 (-8) 0 (0) 14.14 (+0.71) 9 (+3) 24 (+2) 0.33 (-0.03) 0.00 (+0.00)
1.1 list_organizations 100 (-8) 0 (0) 5.94 (-4.08) 1 (0) 60 (+9) 0.33 (-0.03) 0.00 (+0.00)
1.2 list_advisory 100 (-8) 0 (0) 470.17 (+11.76) 258 (+30) 746 (-167) 0.33 (-0.03) 0.00 (+0.00)
1.3 list_advisory_paginated 100 (-8) 0 (0) 416.74 (+29.21) 135 (+6) 586 (-7) 0.33 (-0.03) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 100 (-8) 0 (0) 9.81 (-1.07) 3 (0) 58 (-13) 0.33 (-0.03) 0.00 (+0.00)
1.5 search_advisory 100 (-8) 0 (0) 906.81 (+18.93) 330 (+152) 1885 (-213) 0.33 (-0.03) 0.00 (+0.00)
1.6 list_vulnerabilities 100 (-5) 0 (0) 287.29 (+60.83) 67 (+11) 409 (+86) 0.33 (-0.02) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 100 (-5) 0 (0) 188.07 (+7.87) 71 (+29) 311 (+6) 0.33 (-0.02) 0.00 (+0.00)
1.8 list_importer 100 (-5) 0 (0) 2.57 (-0.95) 1 (0) 53 (+1) 0.33 (-0.02) 0.00 (+0.00)
1.9 list_packages 100 (-5) 0 (0) 481.63 (+78.68) 99 (-2) 957 (+105) 0.33 (-0.02) 0.00 (+0.00)
1.10 list_packages_paginated 100 (-5) 0 (0) 402.86 (+37.18) 91 (-17) 587 (-31) 0.33 (-0.02) 0.00 (+0.00)
1.11 search_purls 105 (-5) 0 (0) 7379.37 (+1605.90) 4609 (+2784) 10567 (-4) 0.35 (-0.02) 0.00 (+0.00)
1.12 search_exact_purl 100 (-10) 0 (0) 6.68 (-0.67) 2 (0) 50 (-4) 0.33 (-0.03) 0.00 (+0.00)
1.13 list_products 100 (-10) 0 (0) 8.71 (-2.24) 2 (-1) 54 (-12) 0.33 (-0.03) 0.00 (+0.00)
1.14 list_sboms 100 (-10) 0 (0) 1067.08 (-188.62) 593 (+17) 1500 (-454) 0.33 (-0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 100 (-10) 0 (0) 1278.87 (-166.88) 486 (+67) 3206 (+94) 0.33 (-0.03) 0.00 (+0.00)
1.16 get_analysis_status 100 (-10) 0 (0) 5.47 (-0.88) 1 (0) 57 (+1) 0.33 (-0.03) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 100 (-10) 0 (0) 104.56 (-19.32) 30 (-5) 368 (+60) 0.33 (-0.03) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 100 (-10) 0 (0) 699.68 (-6.79) 201 (+55) 1692 (-214) 0.33 (-0.03) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (-9) 0 (0) 65.53 (+4.22) 9 (-2) 188 (-11) 0.33 (-0.03) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 (-9) 0 (0) 819.83 (-72.69) 324 (-65) 1184 (+15) 0.33 (-0.03) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (-8) 0 (0) 521.09 (-106.98) 231 (-48) 852 (-273) 0.33 (-0.03) 0.00 (+0.00)
Aggregated 2,205 (-174) 0 (0) 702.80 (+67.56) 1 (0) 10567 (-4) 7.35 (-0.58) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 100 (-8) 14905.30 (+1064.39) 8293 (-288) 18724 (-2282) 0.33 (-0.03) 20.00 (-1.60)
Aggregated 5 (0) 100 (-8) 14905.30 (+1064.39) 8293 (-288) 18724 (-2282) 0.33 (-0.03) 20.00 (-1.60)

User Metrics