Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-08-03 03:53:3725-08-03 03:53:4200:00:050 → 5
Maintaining25-08-03 03:53:4225-08-03 03:58:4300:05:015
Decreasing25-08-03 03:58:4325-08-03 03:58:4400:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 100 (+15) 0 12.60 (+0.42) 3 (0) 67 (+11) 0.33 (+0.05) 0.00 (+0.00)
GET get_analysis_latest_cpe 100 (+10) 0 115.67 (+0.16) 36 (0) 211 (-93) 0.33 (+0.03) 0.00 (+0.00)
GET get_analysis_status 100 (+10) 0 5.66 (+0.89) 1 (0) 55 (+1) 0.33 (+0.03) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 100 (+10) 0 604.98 (-35.94) 136 (-83) 1868 (+157) 0.33 (+0.03) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 (+11) 0 834.93 (-34.14) 432 (-186) 1310 (+140) 0.33 (+0.04) 0.00 (+0.00)
GET list_advisory 100 (+12) 0 483.92 (-3.80) 292 (+46) 772 (-100) 0.33 (+0.04) 0.00 (+0.00)
GET list_advisory_paginated 100 (+13) 0 450.34 (+32.39) 244 (-29) 882 (+274) 0.33 (+0.04) 0.00 (+0.00)
GET list_importer 100 (+15) 0 4.84 (+1.38) 1 (0) 47 (-4) 0.33 (+0.05) 0.00 (+0.00)
GET list_organizations 100 (+12) 0 8.60 (-1.17) 1 (0) 60 (+1) 0.33 (+0.04) 0.00 (+0.00)
GET list_packages 100 (+15) 0 461.77 (+82.88) 104 (+24) 945 (+136) 0.33 (+0.05) 0.00 (+0.00)
GET list_packages_paginated 100 (+15) 0 368.57 (+29.78) 111 (-1) 572 (-110) 0.33 (+0.05) 0.00 (+0.00)
GET list_products 100 (+10) 0 9.00 (+2.41) 2 (-1) 53 (+37) 0.33 (+0.03) 0.00 (+0.00)
GET list_sboms 100 (+10) 0 1205.41 (-26.51) 588 (-28) 1903 (+90) 0.33 (+0.03) 0.00 (+0.00)
GET list_sboms_paginated 100 (+10) 0 1517.05 (+9.49) 476 (+11) 3533 (+445) 0.33 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities 100 (+15) 0 278.36 (+65.84) 78 (+24) 486 (+111) 0.33 (+0.05) 0.00 (+0.00)
GET list_vulnerabilities_paginated 100 (+15) 0 203.18 (+29.76) 68 (+26) 293 (-11) 0.33 (+0.05) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (+11) 0 61.98 (+4.63) 11 (0) 182 (-78) 0.33 (+0.04) 0.00 (+0.00)
GET search_advisory 100 (+15) 0 1035.86 (+89.20) 366 (+149) 2276 (-111) 0.33 (+0.05) 0.00 (+0.00)
GET search_exact_purl 100 (+10) 0 7.22 (+1.28) 2 (-2) 55 (+45) 0.33 (+0.03) 0.00 (+0.00)
GET search_purls 105 (+15) 0 6571.88 (-2320.58) 3808 (+1602) 12402 (-2023) 0.35 (+0.05) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (+11) 0 598.68 (-30.59) 287 (-74) 1078 (+30) 0.33 (+0.04) 0.00 (+0.00)
Aggregated 2105 (+260) 0 720.62 (-98.19) 1 (0) 12402 (-2023) 7.02 (+0.87) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (0) 8 (0) 10 (+1) 13 (-1) 47 (+6) 54 (+5) 64 (+9) 67 (+11)
GET get_analysis_latest_cpe 100 (0) 110 (0) 130 (+10) 170 (+30) 200 (+20) 200 (-10) 210 (-60) 210 (-90)
GET get_analysis_status 2 (0) 3 (0) 4 (0) 5 (+1) 6 (+1) 45 (+36) 52 (+1) 55 (+1)
GET get_sbom[sha256:720e4451…a939656247164447] 390 (-10) 410 (-10) 500 (-100) 1,000 (0) 1,000 (0) 1,868 (+157) 1,868 (+157) 1,868 (+157)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (-100) 900 (0) 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 470 (-10) 490 (-10) 500 (0) 600 (0) 600 (0) 600 (-100) 772 (-28) 772 (-100)
GET list_advisory_paginated 440 (+30) 480 (+50) 490 (+30) 500 (+10) 600 (+100) 600 (+100) 700 (+100) 882 (+282)
GET list_importer 2 (0) 3 (+1) 3 (0) 4 (0) 7 (+1) 30 (+22) 45 (+27) 47 (-4)
GET list_organizations 3 (-1) 4 (-1) 5 (-2) 10 (0) 27 (-7) 42 (-2) 53 (+6) 60 (+1)
GET list_packages 460 (+70) 470 (+60) 490 (+60) 500 (+30) 600 (+100) 800 (+300) 800 (0) 900 (+100)
GET list_packages_paginated 400 (+30) 410 (+20) 420 (+20) 470 (+50) 490 (0) 500 (0) 572 (-28) 572 (-110)
GET list_products 5 (-1) 6 (0) 6 (-1) 9 (+1) 11 (+1) 45 (+31) 52 (+36) 53 (+37)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,903 (+903) 1,903 (+90) 1,903 (+90) 1,903 (+90)
GET list_sboms_paginated 1,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (-1,000) 3,000 (0) 3,533 (+533)
GET list_vulnerabilities 280 (+70) 310 (+90) 330 (+70) 380 (+100) 410 (+120) 430 (+130) 470 (+100) 486 (+111)
GET list_vulnerabilities_paginated 210 (+30) 210 (+20) 220 (+20) 230 (+20) 270 (0) 280 (+10) 290 (0) 290 (-10)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (+3) 67 (+2) 76 (+5) 110 (+30) 150 (+50) 170 (+40) 170 (-20) 180 (-80)
GET search_advisory 900 (+200) 1,000 (+200) 1,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 6 (0) 6 (0) 6 (0) 7 (0) 8 (+1) 10 (+2) 55 (+45) 55 (+45)
GET search_purls 6,000 (-4,000) 6,000 (-4,000) 7,000 (-4,000) 7,000 (-5,000) 11,000 (-2,000) 11,000 (-3,000) 12,000 (-2,000) 12,000 (-2,000)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (0) 600 (-100) 700 (0) 700 (-100) 800 (0) 900 (+100) 1,000 (+100) 1,000 (0)
Aggregated 310 (+20) 430 (+20) 500 (0) 800 (0) 1,000 (0) 4,000 (+2,000) 7,000 (-5,000) 12,000 (-2,000)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 100 [200]
GET get_analysis_latest_cpe 100 [200]
GET get_analysis_status 100 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 100 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 [200]
GET list_advisory 100 [200]
GET list_advisory_paginated 100 [200]
GET list_importer 100 [200]
GET list_organizations 100 [200]
GET list_packages 100 [200]
GET list_packages_paginated 100 [200]
GET list_products 100 [200]
GET list_sboms 100 [200]
GET list_sboms_paginated 100 [200]
GET list_vulnerabilities 100 [200]
GET list_vulnerabilities_paginated 100 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 [200]
GET search_advisory 100 [200]
GET search_exact_purl 100 [200]
GET search_purls 105 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 [200]
Aggregated 2,105 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 100 (+12) 0 (0) 14.02 (+0.32) 6 (0) 22 (+2) 0.33 (+0.04) 0.00 (+0.00)
1.1 list_organizations 100 (+12) 0 (0) 8.74 (-1.17) 1 (0) 60 (+1) 0.33 (+0.04) 0.00 (+0.00)
1.2 list_advisory 100 (+12) 0 (0) 483.98 (-3.77) 292 (+46) 772 (-100) 0.33 (+0.04) 0.00 (+0.00)
1.3 list_advisory_paginated 100 (+13) 0 (0) 450.40 (+32.38) 244 (-29) 882 (+274) 0.33 (+0.04) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 100 (+15) 0 (0) 12.69 (+0.48) 3 (0) 68 (+12) 0.33 (+0.05) 0.00 (+0.00)
1.5 search_advisory 100 (+15) 0 (0) 1035.94 (+89.23) 366 (+149) 2276 (-111) 0.33 (+0.05) 0.00 (+0.00)
1.6 list_vulnerabilities 100 (+15) 0 (0) 278.43 (+65.84) 78 (+24) 486 (+111) 0.33 (+0.05) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 100 (+15) 0 (0) 203.21 (+29.76) 68 (+26) 293 (-11) 0.33 (+0.05) 0.00 (+0.00)
1.8 list_importer 100 (+15) 0 (0) 4.91 (+1.40) 1 (0) 50 (-1) 0.33 (+0.05) 0.00 (+0.00)
1.9 list_packages 100 (+15) 0 (0) 461.83 (+82.90) 104 (+23) 945 (+136) 0.33 (+0.05) 0.00 (+0.00)
1.10 list_packages_paginated 100 (+15) 0 (0) 368.60 (+29.72) 111 (-1) 572 (-110) 0.33 (+0.05) 0.00 (+0.00)
1.11 search_purls 105 (+15) 0 (0) 6571.93 (-2320.56) 3808 (+1602) 12402 (-2023) 0.35 (+0.05) 0.00 (+0.00)
1.12 search_exact_purl 100 (+10) 0 (0) 7.24 (+1.27) 3 (-1) 55 (+45) 0.33 (+0.03) 0.00 (+0.00)
1.13 list_products 100 (+10) 0 (0) 9.02 (+2.43) 2 (-1) 53 (+37) 0.33 (+0.03) 0.00 (+0.00)
1.14 list_sboms 100 (+10) 0 (0) 1205.47 (-26.51) 588 (-28) 1903 (+90) 0.33 (+0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 100 (+10) 0 (0) 1517.12 (+9.49) 476 (+10) 3533 (+445) 0.33 (+0.03) 0.00 (+0.00)
1.16 get_analysis_status 100 (+10) 0 (0) 5.69 (+0.90) 1 (0) 55 (+1) 0.33 (+0.03) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 100 (+10) 0 (0) 115.72 (+0.11) 36 (0) 211 (-93) 0.33 (+0.03) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 100 (+10) 0 (0) 605.03 (-36.00) 136 (-83) 1868 (+157) 0.33 (+0.03) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 100 (+11) 0 (0) 62.04 (+4.62) 11 (0) 182 (-81) 0.33 (+0.04) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 100 (+11) 0 (0) 835.00 (-34.20) 432 (-186) 1310 (+140) 0.33 (+0.04) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 100 (+11) 0 (0) 598.75 (-30.56) 287 (-74) 1078 (+30) 0.33 (+0.04) 0.00 (+0.00)
Aggregated 2,205 (+272) 0 (0) 687.94 (-93.60) 1 (0) 12402 (-2023) 7.35 (+0.91) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 100 (+12) 14815.22 (-2165.76) 10216 (+1970) 19932 (-3599) 0.33 (+0.04) 20.00 (+2.40)
Aggregated 5 (0) 100 (+12) 14815.22 (-2165.76) 10216 (+1970) 19932 (-3599) 0.33 (+0.04) 20.00 (+2.40)

User Metrics