Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-08-17 03:37:5225-08-17 03:37:5700:00:050 → 5
Maintaining25-08-17 03:37:5725-08-17 03:42:5700:05:005
Decreasing25-08-17 03:42:5725-08-17 03:42:5800:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 95 (-25) 0 12.42 (+1.05) 3 (0) 66 (+10) 0.32 (-0.08) 0.00 (+0.00)
GET get_analysis_latest_cpe 95 (-30) 0 140.98 (+2.83) 30 (0) 294 (+11) 0.32 (-0.10) 0.00 (+0.00)
GET get_analysis_status 95 (-30) 0 5.03 (-1.14) 1 (0) 53 (0) 0.32 (-0.10) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 95 (-30) 0 797.14 (-239.47) 233 (-161) 1900 (-125) 0.32 (-0.10) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 95 (-30) 0 785.79 (+14.37) 445 (-10) 1076 (+13) 0.32 (-0.10) 0.00 (+0.00)
GET list_advisory 95 (-28) 0 453.45 (-24.29) 275 (+27) 812 (-92) 0.32 (-0.09) 0.00 (+0.00)
GET list_advisory_paginated 95 (-25) 0 398.27 (-13.53) 222 (+51) 585 (-63) 0.32 (-0.08) 0.00 (+0.00)
GET list_importer 95 (-25) 0 4.62 (+0.41) 1 (0) 52 (-4) 0.32 (-0.08) 0.00 (+0.00)
GET list_organizations 95 (-28) 0 9.33 (+0.70) 1 (0) 51 (+2) 0.32 (-0.09) 0.00 (+0.00)
GET list_packages 95 (-25) 0 407.25 (-34.85) 96 (-17) 911 (+2) 0.32 (-0.08) 0.00 (+0.00)
GET list_packages_paginated 95 (-25) 0 345.67 (-20.03) 99 (-9) 520 (-252) 0.32 (-0.08) 0.00 (+0.00)
GET list_products 95 (-30) 0 6.21 (-1.02) 3 (+1) 12 (-45) 0.32 (-0.10) 0.00 (+0.00)
GET list_sboms 95 (-30) 0 1084.25 (-122.03) 593 (+84) 1532 (-95) 0.32 (-0.10) 0.00 (+0.00)
GET list_sboms_paginated 95 (-30) 0 1365.98 (-147.81) 473 (-19) 3014 (-75) 0.32 (-0.10) 0.00 (+0.00)
GET list_vulnerabilities 95 (-25) 0 234.12 (-22.20) 56 (0) 382 (-127) 0.32 (-0.08) 0.00 (+0.00)
GET list_vulnerabilities_paginated 95 (-25) 0 172.13 (+2.53) 33 (-7) 293 (+18) 0.32 (-0.08) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 95 (-30) 0 57.68 (-1.72) 10 (0) 184 (+8) 0.32 (-0.10) 0.00 (+0.00)
GET search_advisory 95 (-25) 0 971.72 (-13.27) 246 (+99) 2378 (+269) 0.32 (-0.08) 0.00 (+0.00)
GET search_exact_purl 95 (-30) 0 33.32 (+24.98) 3 (+2) 47 (-12) 0.32 (-0.10) 0.00 (+0.00)
GET search_purls 100 (-25) 0 7621.30 (+3852.68) 4084 (+2793) 9227 (+4216) 0.33 (-0.08) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 95 (-30) 0 608.51 (+51.72) 312 (+75) 1032 (+86) 0.32 (-0.10) 0.00 (+0.00)
Aggregated 2000 (-581) 0 756.02 (+170.42) 1 (0) 9227 (+4216) 6.67 (-1.94) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (+2) 8 (+1) 9 (+1) 12 (-1) 42 (+3) 51 (+6) 60 (+4) 66 (+10)
GET get_analysis_latest_cpe 130 (+10) 160 (+20) 180 (+10) 200 (+10) 210 (0) 220 (-40) 270 (-10) 290 (+10)
GET get_analysis_status 2 (0) 3 (0) 4 (0) 4 (0) 6 (0) 7 (-43) 50 (-3) 53 (0)
GET get_sbom[sha256:720e4451…a939656247164447] 700 (-200) 700 (-300) 900 (-100) 1,000 (-1,000) 1,900 (-100) 1,900 (-100) 1,900 (-100) 1,900 (-100)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (0) 800 (0) 900 (0) 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 440 (-30) 470 (0) 500 (+10) 500 (0) 600 (0) 600 (-100) 700 (-200) 800 (-100)
GET list_advisory_paginated 400 (-10) 410 (-30) 420 (-50) 430 (-50) 460 (-40) 500 (-100) 585 (-15) 585 (-15)
GET list_importer 2 (0) 2 (0) 3 (0) 4 (0) 6 (0) 12 (+2) 48 (+2) 52 (-4)
GET list_organizations 4 (+1) 5 (+1) 7 (+1) 12 (+1) 37 (+6) 37 (+2) 46 (-1) 51 (+2)
GET list_packages 400 (-10) 410 (-10) 450 (-10) 480 (-20) 600 (0) 700 (-100) 800 (-100) 900 (0)
GET list_packages_paginated 360 (-30) 390 (-10) 400 (-20) 420 (-40) 470 (-20) 480 (-20) 500 (-100) 500 (-272)
GET list_products 6 (0) 6 (0) 7 (-1) 8 (-1) 9 (-2) 10 (-5) 11 (-29) 12 (-45)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-627) 1,000 (-627) 1,532 (-95)
GET list_sboms_paginated 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 3,000 (0) 3,000 (0)
GET list_vulnerabilities 230 (-30) 260 (-10) 270 (-30) 290 (-40) 300 (-60) 310 (-100) 370 (-130) 380 (-120)
GET list_vulnerabilities_paginated 180 (+10) 190 (0) 200 (+10) 200 (0) 240 (+30) 260 (+30) 290 (+30) 290 (+15)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 58 (-9) 65 (-5) 76 (-2) 94 (+2) 120 (+20) 130 (+20) 180 (+4) 180 (+4)
GET search_advisory 800 (-100) 900 (-100) 1,000 (0) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 42 (+38) 42 (+38) 43 (+38) 44 (+38) 45 (+14) 45 (-5) 47 (-11) 47 (-12)
GET search_purls 8,000 (+4,000) 8,000 (+4,000) 8,000 (+4,000) 8,000 (+4,000) 9,000 (+5,000) 9,000 (+5,000) 9,000 (+4,000) 9,000 (+4,000)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (+100) 700 (+100) 700 (+100) 700 (0) 800 (0) 800 (0) 900 (0) 1,000 (+100)
Aggregated 300 (-30) 410 (-30) 500 (-100) 800 (-100) 1,000 (0) 3,000 (+1,000) 8,000 (+4,000) 9,000 (+4,000)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 95 [200]
GET get_analysis_latest_cpe 95 [200]
GET get_analysis_status 95 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 95 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 95 [200]
GET list_advisory 95 [200]
GET list_advisory_paginated 95 [200]
GET list_importer 95 [200]
GET list_organizations 95 [200]
GET list_packages 95 [200]
GET list_packages_paginated 95 [200]
GET list_products 95 [200]
GET list_sboms 95 [200]
GET list_sboms_paginated 95 [200]
GET list_vulnerabilities 95 [200]
GET list_vulnerabilities_paginated 95 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 95 [200]
GET search_advisory 95 [200]
GET search_exact_purl 95 [200]
GET search_purls 100 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 95 [200]
Aggregated 2,000 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 95 (-28) 0 (0) 13.88 (+0.31) 7 (0) 25 (+4) 0.32 (-0.09) 0.00 (+0.00)
1.1 list_organizations 95 (-28) 0 (0) 9.47 (+0.77) 1 (0) 51 (+2) 0.32 (-0.09) 0.00 (+0.00)
1.2 list_advisory 95 (-28) 0 (0) 453.51 (-24.27) 275 (+27) 812 (-93) 0.32 (-0.09) 0.00 (+0.00)
1.3 list_advisory_paginated 95 (-25) 0 (0) 398.32 (-13.53) 222 (+51) 585 (-63) 0.32 (-0.08) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 95 (-25) 0 (0) 12.46 (+1.04) 3 (0) 66 (+10) 0.32 (-0.08) 0.00 (+0.00)
1.5 search_advisory 95 (-25) 0 (0) 971.78 (-13.21) 246 (+99) 2378 (+269) 0.32 (-0.08) 0.00 (+0.00)
1.6 list_vulnerabilities 95 (-25) 0 (0) 234.16 (-22.23) 56 (0) 382 (-127) 0.32 (-0.08) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 95 (-25) 0 (0) 172.20 (+2.58) 33 (-7) 293 (+18) 0.32 (-0.08) 0.00 (+0.00)
1.8 list_importer 95 (-25) 0 (0) 4.67 (+0.43) 1 (0) 52 (-4) 0.32 (-0.08) 0.00 (+0.00)
1.9 list_packages 95 (-25) 0 (0) 407.37 (-34.75) 96 (-17) 911 (+2) 0.32 (-0.08) 0.00 (+0.00)
1.10 list_packages_paginated 95 (-25) 0 (0) 345.73 (-20.02) 99 (-9) 520 (-252) 0.32 (-0.08) 0.00 (+0.00)
1.11 search_purls 100 (-25) 0 (0) 7621.31 (+3852.61) 4084 (+2793) 9227 (+4216) 0.33 (-0.08) 0.00 (+0.00)
1.12 search_exact_purl 95 (-30) 0 (0) 33.37 (+25.02) 3 (+2) 47 (-12) 0.32 (-0.10) 0.00 (+0.00)
1.13 list_products 95 (-30) 0 (0) 6.23 (-1.02) 3 (+1) 12 (-45) 0.32 (-0.10) 0.00 (+0.00)
1.14 list_sboms 95 (-30) 0 (0) 1084.32 (-122.04) 593 (+84) 1532 (-96) 0.32 (-0.10) 0.00 (+0.00)
1.15 list_sboms_paginated 95 (-30) 0 (0) 1366.04 (-147.81) 473 (-19) 3014 (-75) 0.32 (-0.10) 0.00 (+0.00)
1.16 get_analysis_status 95 (-30) 0 (0) 5.12 (-1.07) 1 (0) 53 (0) 0.32 (-0.10) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 95 (-30) 0 (0) 141.04 (+2.84) 30 (0) 294 (+11) 0.32 (-0.10) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 95 (-30) 0 (0) 797.21 (-239.46) 233 (-161) 1900 (-125) 0.32 (-0.10) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 95 (-30) 0 (0) 57.76 (-1.67) 10 (0) 184 (+8) 0.32 (-0.10) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 95 (-30) 0 (0) 785.88 (+14.39) 445 (-10) 1076 (+13) 0.32 (-0.10) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 95 (-30) 0 (0) 608.55 (+51.73) 312 (+75) 1033 (+87) 0.32 (-0.10) 0.00 (+0.00)
Aggregated 2,095 (-609) 0 (0) 721.74 (+162.77) 1 (0) 9227 (+4216) 6.98 (-2.03) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 95 (-28) 15407.91 (+3280.86) 7797 (+2623) 19234 (+4158) 0.32 (-0.09) 19.00 (-5.60)
Aggregated 5 (0) 95 (-28) 15407.91 (+3280.86) 7797 (+2623) 19234 (+4158) 0.32 (-0.09) 19.00 (-5.60)

User Metrics