Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-08-19 03:23:2525-08-19 03:23:3000:00:050 → 5
Maintaining25-08-19 03:23:3025-08-19 03:28:3000:05:005
Decreasing25-08-19 03:28:3025-08-19 03:28:3100:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 60 (-33) 0 12.15 (+1.95) 2 (-1) 72 (+11) 0.20 (-0.11) 0.00 (+0.00)
GET get_analysis_latest_cpe 60 (-35) 0 131.43 (+15.15) 35 (-1) 303 (+39) 0.20 (-0.12) 0.00 (+0.00)
GET get_analysis_status 60 (-35) 0 5.55 (+0.77) 1 (0) 56 (+7) 0.20 (-0.12) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 60 (-35) 0 962.28 (+279.20) 137 (-55) 3414 (+1456) 0.20 (-0.12) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (-34) 0 905.78 (+100.03) 497 (+153) 1441 (+241) 0.20 (-0.11) 0.00 (+0.00)
GET list_advisory 60 (-34) 0 458.93 (-23.85) 122 (-169) 741 (-111) 0.20 (-0.11) 0.00 (+0.00)
GET list_advisory_paginated 60 (-34) 0 401.43 (-27.34) 110 (-19) 818 (+56) 0.20 (-0.11) 0.00 (+0.00)
GET list_importer 60 (-31) 0 3.28 (-0.97) 1 (0) 33 (-22) 0.20 (-0.10) 0.00 (+0.00)
GET list_organizations 60 (-34) 0 8.45 (+1.85) 1 (0) 54 (+9) 0.20 (-0.11) 0.00 (+0.00)
GET list_packages 60 (-31) 0 328.23 (-57.62) 77 (-19) 696 (-179) 0.20 (-0.10) 0.00 (+0.00)
GET list_packages_paginated 60 (-31) 0 312.30 (-41.30) 100 (-2) 572 (-41) 0.20 (-0.10) 0.00 (+0.00)
GET list_products 65 (-30) 0 8.42 (+1.65) 4 (+1) 54 (+40) 0.22 (-0.10) 0.00 (+0.00)
GET list_sboms 65 (-30) 0 1221.69 (-9.61) 631 (+50) 1781 (-28) 0.22 (-0.10) 0.00 (+0.00)
GET list_sboms_paginated 60 (-35) 0 2664.37 (+1173.75) 450 (-41) 5483 (+2102) 0.20 (-0.12) 0.00 (+0.00)
GET list_vulnerabilities 60 (-31) 0 188.87 (-31.81) 50 (+3) 324 (-79) 0.20 (-0.10) 0.00 (+0.00)
GET list_vulnerabilities_paginated 60 (-31) 0 152.93 (-19.00) 40 (+11) 274 (-48) 0.20 (-0.10) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (-34) 0 78.62 (+26.13) 12 (+2) 200 (+28) 0.20 (-0.11) 0.00 (+0.00)
GET search_advisory 60 (-33) 0 952.88 (+17.37) 117 (-17) 2110 (+9) 0.20 (-0.11) 0.00 (+0.00)
GET search_exact_purl 65 (-30) 0 50.72 (+41.05) 3 (0) 85 (+28) 0.22 (-0.10) 0.00 (+0.00)
GET search_purls 65 (-31) 0 14403.11 (+6511.44) 8297 (+7062) 19136 (+4297) 0.22 (-0.10) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (-34) 0 626.85 (+3.17) 230 (-25) 1130 (-75) 0.20 (-0.11) 0.00 (+0.00)
Aggregated 1280 (-686) 0 1180.56 (+411.94) 1 (0) 19136 (+4297) 4.27 (-2.29) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (+1) 7 (+1) 8 (0) 14 (+4) 21 (+6) 56 (+9) 62 (+4) 72 (+11)
GET get_analysis_latest_cpe 110 (+10) 160 (+40) 180 (+50) 180 (0) 220 (+30) 270 (+70) 290 (+70) 300 (+40)
GET get_analysis_status 2 (0) 3 (+1) 3 (0) 4 (0) 7 (0) 34 (+25) 51 (+2) 56 (+7)
GET get_sbom[sha256:720e4451…a939656247164447] 420 (-10) 480 (-20) 700 (-100) 2,000 (+1,000) 3,000 (+2,000) 3,000 (+1,042) 3,000 (+1,042) 3,000 (+1,042)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 900 (+100) 900 (+100) 1,000 (+100) 1,000 (+100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 470 (0) 500 (+30) 500 (0) 600 (+100) 600 (0) 700 (0) 700 (-100) 700 (-152)
GET list_advisory_paginated 400 (-20) 450 (+10) 480 (0) 500 (+10) 500 (0) 500 (-100) 700 (0) 800 (+38)
GET list_importer 2 (0) 2 (0) 3 (0) 4 (+1) 5 (0) 7 (-2) 32 (-17) 33 (-22)
GET list_organizations 4 (+1) 4 (0) 5 (0) 7 (-1) 29 (+13) 38 (+11) 48 (+4) 54 (+9)
GET list_packages 350 (-40) 390 (-20) 400 (-20) 410 (-50) 420 (-70) 500 (-100) 600 (-200) 696 (-179)
GET list_packages_paginated 320 (-60) 380 (-10) 390 (-20) 410 (-50) 450 (-40) 470 (-20) 500 (0) 572 (-28)
GET list_products 7 (+1) 8 (+1) 9 (+1) 10 (+1) 11 (+1) 13 (+2) 13 (-1) 54 (+40)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,781 (-28) 1,781 (-28) 1,781 (-28)
GET list_sboms_paginated 3,000 (+2,000) 3,000 (+1,000) 3,000 (+1,000) 3,000 (+1,000) 5,000 (+3,000) 5,000 (+2,000) 5,000 (+2,000) 5,000 (+2,000)
GET list_vulnerabilities 190 (-30) 220 (-10) 230 (-20) 270 (-10) 300 (0) 300 (-40) 310 (-80) 320 (-80)
GET list_vulnerabilities_paginated 160 (-20) 190 (0) 200 (0) 200 (-10) 220 (-10) 220 (-50) 260 (-40) 270 (-50)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 69 (+36) 87 (+30) 100 (+29) 120 (+25) 170 (+60) 190 (+70) 200 (+40) 200 (+30)
GET search_advisory 700 (-100) 900 (-100) 1,000 (0) 2,000 (+1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 70 (+64) 71 (+64) 72 (+65) 73 (+65) 80 (+71) 81 (+31) 83 (+27) 85 (+28)
GET search_purls 16,000 (+9,000) 17,000 (+9,000) 17,000 (+6,000) 18,000 (+5,000) 18,000 (+4,000) 19,000 (+5,000) 19,000 (+4,161) 19,000 (+4,161)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (0) 700 (+100) 700 (0) 800 (+100) 900 (0) 900 (-100) 1,000 (0) 1,000 (0)
Aggregated 230 (-60) 400 (-10) 500 (0) 900 (+100) 2,000 (+1,000) 8,000 (+6,000) 18,000 (+5,000) 19,000 (+4,161)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 60 [200]
GET get_analysis_latest_cpe 60 [200]
GET get_analysis_status 60 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 60 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 [200]
GET list_advisory 60 [200]
GET list_advisory_paginated 60 [200]
GET list_importer 60 [200]
GET list_organizations 60 [200]
GET list_packages 60 [200]
GET list_packages_paginated 60 [200]
GET list_products 65 [200]
GET list_sboms 65 [200]
GET list_sboms_paginated 60 [200]
GET list_vulnerabilities 60 [200]
GET list_vulnerabilities_paginated 60 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 [200]
GET search_advisory 60 [200]
GET search_exact_purl 65 [200]
GET search_purls 65 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 [200]
Aggregated 1,280 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 60 (-34) 0 (0) 13.27 (-0.53) 7 (0) 20 (0) 0.20 (-0.11) 0.00 (+0.00)
1.1 list_organizations 60 (-34) 0 (0) 8.55 (+1.84) 1 (0) 54 (+9) 0.20 (-0.11) 0.00 (+0.00)
1.2 list_advisory 60 (-34) 0 (0) 459.07 (-23.82) 122 (-169) 741 (-111) 0.20 (-0.11) 0.00 (+0.00)
1.3 list_advisory_paginated 60 (-34) 0 (0) 401.52 (-27.37) 110 (-19) 818 (+56) 0.20 (-0.11) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 60 (-33) 0 (0) 12.18 (+1.95) 2 (-1) 72 (+11) 0.20 (-0.11) 0.00 (+0.00)
1.5 search_advisory 60 (-33) 0 (0) 952.90 (+17.34) 117 (-17) 2110 (+9) 0.20 (-0.11) 0.00 (+0.00)
1.6 list_vulnerabilities 60 (-31) 0 (0) 188.90 (-31.87) 50 (+3) 324 (-79) 0.20 (-0.10) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 60 (-31) 0 (0) 153.00 (-19.05) 40 (+11) 274 (-48) 0.20 (-0.10) 0.00 (+0.00)
1.8 list_importer 60 (-31) 0 (0) 3.30 (-1.01) 1 (0) 33 (-22) 0.20 (-0.10) 0.00 (+0.00)
1.9 list_packages 60 (-31) 0 (0) 328.27 (-57.60) 77 (-19) 696 (-179) 0.20 (-0.10) 0.00 (+0.00)
1.10 list_packages_paginated 60 (-31) 0 (0) 312.35 (-41.29) 100 (-2) 572 (-41) 0.20 (-0.10) 0.00 (+0.00)
1.11 search_purls 65 (-31) 0 (0) 14403.14 (+6511.41) 8297 (+7062) 19136 (+4297) 0.22 (-0.10) 0.00 (+0.00)
1.12 search_exact_purl 65 (-30) 0 (0) 50.75 (+41.06) 3 (0) 85 (+28) 0.22 (-0.10) 0.00 (+0.00)
1.13 list_products 65 (-30) 0 (0) 8.49 (+1.67) 4 (+1) 54 (+39) 0.22 (-0.10) 0.00 (+0.00)
1.14 list_sboms 65 (-30) 0 (0) 1221.74 (-9.58) 631 (+50) 1781 (-28) 0.22 (-0.10) 0.00 (+0.00)
1.15 list_sboms_paginated 60 (-35) 0 (0) 2664.45 (+1173.79) 450 (-41) 5483 (+2102) 0.20 (-0.12) 0.00 (+0.00)
1.16 get_analysis_status 60 (-35) 0 (0) 5.65 (+0.82) 1 (0) 56 (+6) 0.20 (-0.12) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 60 (-35) 0 (0) 131.53 (+15.21) 35 (-1) 303 (+39) 0.20 (-0.12) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 60 (-35) 0 (0) 962.33 (+279.19) 137 (-55) 3414 (+1456) 0.20 (-0.12) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (-34) 0 (0) 78.63 (+26.02) 12 (+2) 200 (+28) 0.20 (-0.11) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (-34) 0 (0) 905.90 (+100.06) 497 (+153) 1441 (+241) 0.20 (-0.11) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (-34) 0 (0) 627.05 (+3.27) 231 (-24) 1130 (-75) 0.20 (-0.11) 0.00 (+0.00)
Aggregated 1,340 (-720) 0 (0) 1127.70 (+394.15) 1 (0) 19136 (+4297) 4.47 (-2.40) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 60 (-34) 23525.98 (+7593.93) 12102 (+3606) 31954 (+7459) 0.20 (-0.11) 12.00 (-6.80)
Aggregated 5 (0) 60 (-34) 23525.98 (+7593.93) 12102 (+3606) 31954 (+7459) 0.20 (-0.11) 12.00 (-6.80)

User Metrics