Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-08-21 03:14:1225-08-21 03:14:1700:00:050 → 5
Maintaining25-08-21 03:14:1725-08-21 03:19:1700:05:005
Decreasing25-08-21 03:19:1725-08-21 03:19:1700:00:000 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 60 (-45) 0 11.57 (-1.77) 3 (0) 57 (-14) 0.20 (-0.15) 0.00 (+0.00)
GET get_analysis_latest_cpe 60 (-49) 0 151.93 (+28.42) 41 (+7) 387 (+75) 0.20 (-0.16) 0.00 (+0.00)
GET get_analysis_status 60 (-49) 0 10.37 (+3.35) 1 (0) 58 (+5) 0.20 (-0.16) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 60 (-49) 0 936.00 (+235.92) 163 (-36) 3094 (+1385) 0.20 (-0.16) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (-48) 0 795.37 (-8.89) 404 (-100) 1124 (+20) 0.20 (-0.16) 0.00 (+0.00)
GET list_advisory 60 (-45) 0 489.78 (+8.58) 119 (-168) 902 (+36) 0.20 (-0.15) 0.00 (+0.00)
GET list_advisory_paginated 60 (-45) 0 392.73 (-13.30) 93 (-29) 713 (+94) 0.20 (-0.15) 0.00 (+0.00)
GET list_importer 58 (-47) 0 2.64 (-0.34) 1 (0) 10 (-35) 0.19 (-0.16) 0.00 (+0.00)
GET list_organizations 60 (-45) 0 6.40 (-2.14) 1 (0) 39 (-11) 0.20 (-0.15) 0.00 (+0.00)
GET list_packages 58 (-47) 0 400.57 (-9.15) 78 (-24) 861 (+62) 0.19 (-0.16) 0.00 (+0.00)
GET list_packages_paginated 55 (-50) 0 358.62 (-14.47) 81 (-15) 838 (+173) 0.18 (-0.17) 0.00 (+0.00)
GET list_products 60 (-50) 0 11.83 (+5.99) 3 (0) 51 (+39) 0.20 (-0.17) 0.00 (+0.00)
GET list_sboms 60 (-50) 0 1148.93 (+58.00) 824 (+240) 1713 (+33) 0.20 (-0.17) 0.00 (+0.00)
GET list_sboms_paginated 60 (-50) 0 1895.00 (+507.12) 471 (+14) 4904 (+2149) 0.20 (-0.17) 0.00 (+0.00)
GET list_vulnerabilities 60 (-45) 0 297.90 (+63.12) 38 (-18) 755 (+350) 0.20 (-0.15) 0.00 (+0.00)
GET list_vulnerabilities_paginated 58 (-47) 0 196.64 (+25.90) 27 (-15) 288 (-12) 0.19 (-0.16) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (-48) 0 43.03 (-14.62) 10 (0) 132 (-119) 0.20 (-0.16) 0.00 (+0.00)
GET search_advisory 60 (-45) 0 823.50 (-39.23) 177 (+38) 1599 (-543) 0.20 (-0.15) 0.00 (+0.00)
GET search_exact_purl 60 (-50) 0 70.48 (+37.97) 8 (+6) 90 (+34) 0.20 (-0.17) 0.00 (+0.00)
GET search_purls 60 (-50) 0 16563.28 (+10412.75) 8186 (+5125) 20457 (+12294) 0.20 (-0.17) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (-45) 0 632.42 (+37.46) 264 (-63) 1304 (+296) 0.20 (-0.15) 0.00 (+0.00)
Aggregated 1249 (-999) 0 1210.05 (+538.04) 1 (0) 20457 (+12294) 4.16 (-3.33) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 5 (-1) 7 (-1) 9 (-1) 15 (-1) 20 (-25) 51 (+2) 55 (-6) 57 (-14)
GET get_analysis_latest_cpe 130 (+30) 150 (+30) 190 (+50) 200 (+30) 230 (+30) 270 (+60) 340 (+50) 387 (+77)
GET get_analysis_status 3 (0) 3 (0) 5 (+1) 8 (+3) 47 (+35) 51 (+3) 54 (+2) 58 (+5)
GET get_sbom[sha256:720e4451…a939656247164447] 500 (-100) 700 (0) 800 (0) 1,000 (0) 3,000 (+2,000) 3,000 (+1,291) 3,000 (+1,291) 3,000 (+1,291)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (0) 800 (-100) 900 (0) 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 470 (0) 480 (-10) 500 (0) 500 (0) 700 (+100) 800 (+100) 800 (0) 900 (+34)
GET list_advisory_paginated 410 (0) 420 (0) 430 (-20) 470 (0) 500 (+10) 600 (0) 600 (0) 700 (+100)
GET list_importer 2 (0) 3 (+1) 3 (0) 4 (+1) 5 (0) 6 (+1) 7 (-17) 10 (-35)
GET list_organizations 4 (+1) 4 (-1) 5 (-2) 6 (-4) 14 (-18) 37 (-2) 38 (-5) 39 (-11)
GET list_packages 420 (+10) 430 (0) 440 (-20) 450 (-20) 470 (-30) 600 (0) 800 (+1) 861 (+62)
GET list_packages_paginated 390 (+10) 400 (-10) 410 (-10) 460 (-10) 500 (0) 500 (0) 600 (0) 800 (+135)
GET list_products 8 (+3) 9 (+3) 10 (+4) 12 (+4) 15 (+6) 50 (+41) 51 (+41) 51 (+39)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,713 (+713) 1,713 (+33) 1,713 (+33)
GET list_sboms_paginated 2,000 (+1,000) 2,000 (0) 2,000 (0) 3,000 (+1,000) 3,000 (+1,000) 4,000 (+2,000) 4,000 (+1,245) 4,904 (+2,149)
GET list_vulnerabilities 330 (+100) 350 (+90) 360 (+90) 390 (+110) 400 (+100) 490 (+150) 600 (+200) 755 (+350)
GET list_vulnerabilities_paginated 210 (+30) 210 (+20) 230 (+30) 240 (+30) 270 (+50) 280 (+10) 288 (-12) 288 (-12)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 25 (-22) 42 (-22) 60 (-8) 70 (-10) 87 (-33) 95 (-75) 110 (-80) 130 (-120)
GET search_advisory 800 (0) 900 (+100) 900 (-100) 1,000 (0) 1,000 (0) 1,599 (-401) 1,599 (-401) 1,599 (-401)
GET search_exact_purl 76 (+30) 76 (+29) 78 (+28) 80 (+29) 83 (+29) 88 (+33) 88 (+33) 90 (+34)
GET search_purls 18,000 (+11,000) 19,000 (+12,000) 20,000 (+13,000) 20,000 (+13,000) 20,000 (+12,000) 20,000 (+12,000) 20,000 (+12,000) 20,000 (+12,000)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (0) 700 (+100) 700 (0) 800 (0) 900 (+100) 1,000 (+100) 1,000 (0) 1,000 (0)
Aggregated 310 (+10) 420 (0) 500 (0) 800 (0) 1,000 (0) 4,000 (+1,000) 20,000 (+13,000) 20,000 (+12,000)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 60 [200]
GET get_analysis_latest_cpe 60 [200]
GET get_analysis_status 60 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 60 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 [200]
GET list_advisory 60 [200]
GET list_advisory_paginated 60 [200]
GET list_importer 58 [200]
GET list_organizations 60 [200]
GET list_packages 58 [200]
GET list_packages_paginated 55 [200]
GET list_products 60 [200]
GET list_sboms 60 [200]
GET list_sboms_paginated 60 [200]
GET list_vulnerabilities 60 [200]
GET list_vulnerabilities_paginated 58 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 [200]
GET search_advisory 60 [200]
GET search_exact_purl 60 [200]
GET search_purls 60 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 [200]
Aggregated 1,249 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 60 (-45) 0 (0) 13.58 (-0.78) 7 (-1) 20 (-5) 0.20 (-0.15) 0.00 (+0.00)
1.1 list_organizations 60 (-45) 0 (0) 6.55 (-2.12) 1 (0) 39 (-11) 0.20 (-0.15) 0.00 (+0.00)
1.2 list_advisory 60 (-45) 0 (0) 489.83 (+8.57) 119 (-168) 902 (+36) 0.20 (-0.15) 0.00 (+0.00)
1.3 list_advisory_paginated 60 (-45) 0 (0) 392.78 (-13.30) 93 (-29) 713 (+94) 0.20 (-0.15) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 60 (-45) 0 (0) 11.60 (-1.77) 3 (0) 57 (-14) 0.20 (-0.15) 0.00 (+0.00)
1.5 search_advisory 60 (-45) 0 (0) 823.55 (-39.23) 177 (+38) 1599 (-543) 0.20 (-0.15) 0.00 (+0.00)
1.6 list_vulnerabilities 60 (-45) 0 (0) 297.92 (+63.09) 38 (-18) 755 (+350) 0.20 (-0.15) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 58 (-47) 0 (0) 196.69 (+25.90) 27 (-15) 288 (-14) 0.19 (-0.16) 0.00 (+0.00)
1.8 list_importer 58 (-47) 0 (0) 2.66 (-0.35) 1 (0) 10 (-35) 0.19 (-0.16) 0.00 (+0.00)
1.9 list_packages 58 (-47) 0 (0) 400.62 (-9.14) 78 (-24) 861 (+62) 0.19 (-0.16) 0.00 (+0.00)
1.10 list_packages_paginated 55 (-50) 0 (0) 358.62 (-14.54) 81 (-15) 838 (+173) 0.18 (-0.17) 0.00 (+0.00)
1.11 search_purls 60 (-50) 0 (0) 16563.33 (+10412.75) 8186 (+5125) 20457 (+12294) 0.20 (-0.17) 0.00 (+0.00)
1.12 search_exact_purl 60 (-50) 0 (0) 70.55 (+38.01) 8 (+6) 90 (+34) 0.20 (-0.17) 0.00 (+0.00)
1.13 list_products 60 (-50) 0 (0) 11.87 (+6.00) 3 (0) 51 (+39) 0.20 (-0.17) 0.00 (+0.00)
1.14 list_sboms 60 (-50) 0 (0) 1148.98 (+58.00) 824 (+240) 1713 (+33) 0.20 (-0.17) 0.00 (+0.00)
1.15 list_sboms_paginated 60 (-50) 0 (0) 1895.13 (+507.19) 471 (+14) 4904 (+2149) 0.20 (-0.17) 0.00 (+0.00)
1.16 get_analysis_status 60 (-49) 0 (0) 10.40 (+3.30) 1 (0) 58 (+5) 0.20 (-0.16) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 60 (-49) 0 (0) 151.95 (+28.36) 41 (+7) 387 (+75) 0.20 (-0.16) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 60 (-49) 0 (0) 936.05 (+235.88) 163 (-36) 3094 (+1385) 0.20 (-0.16) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (-48) 0 (0) 43.05 (-14.66) 10 (0) 132 (-119) 0.20 (-0.16) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (-48) 0 (0) 795.38 (-8.93) 404 (-100) 1124 (+20) 0.20 (-0.16) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (-45) 0 (0) 632.53 (+37.50) 264 (-63) 1304 (+296) 0.20 (-0.15) 0.00 (+0.00)
Aggregated 1,309 (-1,044) 0 (0) 1154.58 (+512.56) 1 (0) 20457 (+12294) 4.36 (-3.48) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 60 (-45) 25084.43 (+11296.31) 13401 (+6619) 32236 (+15050) 0.20 (-0.15) 12.00 (-9.00)
Aggregated 5 (0) 60 (-45) 25084.43 (+11296.31) 13401 (+6619) 32236 (+15050) 0.20 (-0.15) 12.00 (-9.00)

User Metrics