Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-07-29 03:51:3025-07-29 03:51:3500:00:050 → 5
Maintaining25-07-29 03:51:3525-07-29 03:56:3600:05:015
Decreasing25-07-29 03:56:3625-07-29 03:56:3700:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 125 (+39) 0 11.31 (-3.63) 2 (-1) 76 (+7) 0.42 (+0.13) 0.00 (+0.00)
GET get_analysis_latest_cpe 125 (+36) 0 120.50 (-21.59) 37 (+6) 389 (-74) 0.42 (+0.12) 0.00 (+0.00)
GET get_analysis_status 125 (+36) 0 5.21 (+0.58) 1 (0) 52 (+2) 0.42 (+0.12) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 125 (+36) 0 773.36 (+104.38) 203 (+69) 1997 (-103) 0.42 (+0.12) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 125 (+37) 0 840.34 (-33.69) 505 (+129) 1218 (+39) 0.42 (+0.12) 0.00 (+0.00)
GET list_advisory 125 (+38) 0 462.53 (-8.82) 263 (+115) 902 (-34) 0.42 (+0.13) 0.00 (+0.00)
GET list_advisory_paginated 125 (+39) 0 393.12 (+6.04) 128 (-24) 667 (+50) 0.42 (+0.13) 0.00 (+0.00)
GET list_importer 125 (+40) 0 4.35 (-0.17) 1 (0) 48 (-2) 0.42 (+0.13) 0.00 (+0.00)
GET list_organizations 125 (+38) 0 8.55 (-0.69) 1 (0) 55 (-1) 0.42 (+0.13) 0.00 (+0.00)
GET list_packages 125 (+40) 0 404.06 (-43.43) 87 (-12) 808 (-88) 0.42 (+0.13) 0.00 (+0.00)
GET list_packages_paginated 125 (+40) 0 353.47 (-39.53) 113 (+8) 612 (+25) 0.42 (+0.13) 0.00 (+0.00)
GET list_products 129 (+39) 0 7.76 (-1.97) 2 (-1) 60 (-14) 0.43 (+0.13) 0.00 (+0.00)
GET list_sboms 129 (+39) 0 1423.60 (+109.24) 532 (-65) 2284 (+398) 0.43 (+0.13) 0.00 (+0.00)
GET list_sboms_paginated 129 (+39) 0 1991.49 (+398.46) 483 (-10) 4012 (+722) 0.43 (+0.13) 0.00 (+0.00)
GET list_vulnerabilities 125 (+40) 0 229.13 (-59.22) 57 (+7) 408 (+6) 0.42 (+0.13) 0.00 (+0.00)
GET list_vulnerabilities_paginated 125 (+40) 0 180.33 (-7.78) 42 (-17) 303 (+19) 0.42 (+0.13) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 125 (+37) 0 82.99 (+22.14) 11 (+1) 200 (-6) 0.42 (+0.12) 0.00 (+0.00)
GET search_advisory 125 (+39) 0 1002.40 (+12.24) 268 (-44) 2356 (+323) 0.42 (+0.13) 0.00 (+0.00)
GET search_exact_purl 129 (+39) 0 8.50 (-0.40) 2 (0) 60 (+2) 0.43 (+0.13) 0.00 (+0.00)
GET search_purls 130 (+40) 0 2963.69 (-5599.55) 809 (-691) 4663 (-9686) 0.43 (+0.13) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 125 (+38) 0 599.31 (+29.38) 298 (0) 1104 (+118) 0.42 (+0.13) 0.00 (+0.00)
Aggregated 2646 (+809) 0 571.35 (-251.92) 1 (0) 4663 (-9686) 8.82 (+2.70) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (-1) 8 (-1) 10 (0) 11 (-3) 28 (-24) 50 (-5) 62 (0) 76 (+7)
GET get_analysis_latest_cpe 100 (-10) 110 (-30) 120 (-50) 160 (-20) 180 (-90) 200 (-110) 290 (-170) 389 (-71)
GET get_analysis_status 2 (0) 3 (+1) 3 (0) 4 (0) 6 (0) 41 (+11) 50 (+1) 52 (+2)
GET get_sbom[sha256:720e4451…a939656247164447] 490 (+60) 600 (0) 1,000 (+400) 1,000 (0) 1,997 (-3) 1,997 (-3) 1,997 (-3) 1,997 (-3)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 900 (0) 900 (0) 900 (-100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 460 (+20) 470 (+10) 500 (0) 500 (0) 600 (0) 600 (-100) 700 (-100) 900 (0)
GET list_advisory_paginated 390 (0) 410 (0) 430 (-20) 440 (-20) 490 (+10) 500 (0) 600 (0) 667 (+67)
GET list_importer 2 (0) 2 (0) 3 (0) 4 (0) 7 (0) 10 (-6) 48 (-1) 48 (-2)
GET list_organizations 3 (-1) 4 (-1) 5 (-2) 7 (-3) 36 (+12) 41 (-6) 47 (-3) 55 (-1)
GET list_packages 390 (-20) 400 (-20) 430 (-30) 480 (-20) 600 (-100) 700 (-100) 800 (-96) 800 (-96)
GET list_packages_paginated 380 (-20) 390 (-20) 400 (-40) 450 (-20) 490 (-10) 500 (0) 600 (+13) 600 (+13)
GET list_products 5 (-2) 6 (-2) 7 (-2) 8 (-3) 11 (-3) 16 (-2) 60 (-6) 60 (-14)
GET list_sboms 1,000 (0) 2,000 (+1,000) 2,000 (+1,000) 2,000 (+114) 2,000 (+114) 2,000 (+114) 2,000 (+114) 2,000 (+114)
GET list_sboms_paginated 2,000 (0) 2,000 (0) 2,000 (0) 3,000 (+1,000) 3,000 (+1,000) 3,000 (0) 4,000 (+1,000) 4,000 (+1,000)
GET list_vulnerabilities 230 (-80) 260 (-70) 280 (-60) 290 (-70) 300 (-70) 320 (-60) 400 (+10) 408 (+8)
GET list_vulnerabilities_paginated 190 (0) 190 (-10) 200 (0) 200 (-10) 220 (-10) 270 (+10) 300 (+20) 300 (+20)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 77 (+35) 87 (+21) 110 (+35) 120 (+20) 170 (+10) 180 (+10) 190 (+10) 200 (-6)
GET search_advisory 800 (0) 1,000 (0) 1,000 (0) 2,000 (+1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 3 (-3) 4 (-2) 5 (-2) 6 (-2) 29 (+20) 47 (-1) 59 (+1) 60 (+2)
GET search_purls 3,000 (-7,000) 3,000 (-7,000) 3,000 (-10,000) 4,000 (-9,000) 4,000 (-10,000) 4,000 (-10,000) 4,663 (-9,337) 4,663 (-9,337)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (+100) 600 (0) 700 (+100) 700 (0) 800 (0) 900 (0) 1,000 (+100) 1,000 (+14)
Aggregated 300 (-30) 400 (-10) 500 (0) 900 (0) 2,000 (0) 2,000 (0) 4,000 (-9,000) 4,663 (-9,337)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 125 [200]
GET get_analysis_latest_cpe 125 [200]
GET get_analysis_status 125 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 125 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 125 [200]
GET list_advisory 125 [200]
GET list_advisory_paginated 125 [200]
GET list_importer 125 [200]
GET list_organizations 125 [200]
GET list_packages 125 [200]
GET list_packages_paginated 125 [200]
GET list_products 129 [200]
GET list_sboms 129 [200]
GET list_sboms_paginated 129 [200]
GET list_vulnerabilities 125 [200]
GET list_vulnerabilities_paginated 125 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 125 [200]
GET search_advisory 125 [200]
GET search_exact_purl 129 [200]
GET search_purls 130 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 125 [200]
Aggregated 2,646 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 125 (+38) 0 (0) 13.93 (-0.03) 7 (0) 20 (0) 0.42 (+0.13) 0.00 (+0.00)
1.1 list_organizations 125 (+38) 0 (0) 8.76 (-0.65) 1 (0) 55 (-1) 0.42 (+0.13) 0.00 (+0.00)
1.2 list_advisory 125 (+38) 0 (0) 462.60 (-8.84) 263 (+115) 902 (-34) 0.42 (+0.13) 0.00 (+0.00)
1.3 list_advisory_paginated 125 (+39) 0 (0) 393.16 (+5.99) 128 (-24) 667 (+50) 0.42 (+0.13) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 125 (+39) 0 (0) 11.37 (-3.62) 2 (-1) 76 (+7) 0.42 (+0.13) 0.00 (+0.00)
1.5 search_advisory 125 (+39) 0 (0) 1002.44 (+12.23) 268 (-44) 2356 (+323) 0.42 (+0.13) 0.00 (+0.00)
1.6 list_vulnerabilities 125 (+40) 0 (0) 229.17 (-59.26) 57 (+7) 409 (+7) 0.42 (+0.13) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 125 (+40) 0 (0) 180.38 (-7.75) 42 (-17) 303 (+19) 0.42 (+0.13) 0.00 (+0.00)
1.8 list_importer 125 (+40) 0 (0) 4.39 (-0.17) 1 (0) 48 (-3) 0.42 (+0.13) 0.00 (+0.00)
1.9 list_packages 125 (+40) 0 (0) 404.08 (-43.44) 87 (-12) 808 (-88) 0.42 (+0.13) 0.00 (+0.00)
1.10 list_packages_paginated 125 (+40) 0 (0) 353.51 (-39.52) 113 (+8) 612 (+25) 0.42 (+0.13) 0.00 (+0.00)
1.11 search_purls 130 (+40) 0 (0) 2963.78 (-5599.49) 809 (-691) 4663 (-9686) 0.43 (+0.13) 0.00 (+0.00)
1.12 search_exact_purl 129 (+39) 0 (0) 8.53 (-0.38) 2 (0) 60 (+2) 0.43 (+0.13) 0.00 (+0.00)
1.13 list_products 129 (+39) 0 (0) 7.81 (-1.97) 2 (-1) 60 (-14) 0.43 (+0.13) 0.00 (+0.00)
1.14 list_sboms 129 (+39) 0 (0) 1423.62 (+109.15) 532 (-65) 2284 (+398) 0.43 (+0.13) 0.00 (+0.00)
1.15 list_sboms_paginated 129 (+39) 0 (0) 1991.56 (+398.42) 483 (-10) 4012 (+722) 0.43 (+0.13) 0.00 (+0.00)
1.16 get_analysis_status 125 (+36) 0 (0) 5.30 (+0.64) 1 (0) 52 (+2) 0.42 (+0.12) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 125 (+36) 0 (0) 120.52 (-21.65) 37 (+6) 389 (-74) 0.42 (+0.12) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 125 (+36) 0 (0) 773.48 (+104.45) 203 (+69) 1997 (-103) 0.42 (+0.12) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 125 (+37) 0 (0) 83.07 (+22.15) 11 (+1) 200 (-6) 0.42 (+0.12) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 125 (+37) 0 (0) 840.44 (-33.67) 505 (+129) 1219 (+40) 0.42 (+0.12) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 125 (+38) 0 (0) 599.38 (+29.42) 298 (0) 1104 (+118) 0.42 (+0.13) 0.00 (+0.00)
Aggregated 2,771 (+847) 0 (0) 545.58 (-240.47) 1 (0) 4663 (-9686) 9.24 (+2.82) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 125 (+38) 11906.35 (-5202.84) 4574 (-4527) 15252 (-9907) 0.42 (+0.13) 25.00 (+7.60)
Aggregated 5 (0) 125 (+38) 11906.35 (-5202.84) 4574 (-4527) 15252 (-9907) 0.42 (+0.13) 25.00 (+7.60)

User Metrics