Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-08-29 03:08:2925-08-29 03:08:3400:00:050 → 5
Maintaining25-08-29 03:08:3425-08-29 03:13:3400:05:005
Decreasing25-08-29 03:13:3425-08-29 03:13:3500:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 60 (-25) 0 13.83 (+2.67) 2 (-1) 68 (+11) 0.20 (-0.08) 0.00 (+0.00)
GET get_analysis_latest_cpe 60 (-25) 0 133.97 (+1.20) 35 (+2) 268 (-56) 0.20 (-0.08) 0.00 (+0.00)
GET get_analysis_status 60 (-25) 0 5.85 (-0.82) 1 (0) 51 (-4) 0.20 (-0.08) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 60 (-25) 0 699.13 (-159.22) 245 (-45) 1633 (-135) 0.20 (-0.08) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (-25) 0 752.87 (-68.97) 378 (+52) 1002 (-187) 0.20 (-0.08) 0.00 (+0.00)
GET list_advisory 60 (-25) 0 477.73 (+2.91) 186 (-85) 754 (-209) 0.20 (-0.08) 0.00 (+0.00)
GET list_advisory_paginated 60 (-25) 0 404.42 (+2.60) 144 (-4) 597 (-158) 0.20 (-0.08) 0.00 (+0.00)
GET list_importer 60 (-22) 0 2.10 (-2.96) 1 (0) 12 (-39) 0.20 (-0.07) 0.00 (+0.00)
GET list_organizations 60 (-25) 0 9.78 (+0.30) 1 (0) 50 (-1) 0.20 (-0.08) 0.00 (+0.00)
GET list_packages 60 (-22) 0 455.00 (+69.37) 98 (+41) 888 (+229) 0.20 (-0.07) 0.00 (+0.00)
GET list_packages_paginated 60 (-22) 0 368.22 (+15.70) 105 (+50) 690 (+105) 0.20 (-0.07) 0.00 (+0.00)
GET list_products 60 (-25) 0 7.53 (-1.77) 4 (+2) 15 (-46) 0.20 (-0.08) 0.00 (+0.00)
GET list_sboms 60 (-25) 0 1066.28 (-83.02) 590 (+64) 1541 (-201) 0.20 (-0.08) 0.00 (+0.00)
GET list_sboms_paginated 60 (-25) 0 1181.63 (-505.93) 474 (-21) 2552 (-849) 0.20 (-0.08) 0.00 (+0.00)
GET list_vulnerabilities 60 (-23) 0 316.52 (+84.63) 111 (+74) 535 (+129) 0.20 (-0.08) 0.00 (+0.00)
GET list_vulnerabilities_paginated 60 (-22) 0 184.30 (+11.25) 50 (+11) 283 (-28) 0.20 (-0.07) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (-25) 0 43.58 (-8.70) 9 (+1) 186 (-11) 0.20 (-0.08) 0.00 (+0.00)
GET search_advisory 60 (-25) 0 907.38 (+43.34) 256 (+114) 2062 (-121) 0.20 (-0.08) 0.00 (+0.00)
GET search_exact_purl 60 (-25) 0 6.90 (-0.56) 5 (+3) 11 (-49) 0.20 (-0.08) 0.00 (+0.00)
GET search_purls 65 (-22) 0 16267.37 (+6939.81) 12429 (+11094) 17719 (+252) 0.22 (-0.07) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (-25) 0 573.27 (-59.24) 249 (-140) 830 (-266) 0.20 (-0.08) 0.00 (+0.00)
Aggregated 1265 (-508) 0 1196.84 (+344.59) 1 (0) 17719 (+252) 4.22 (-1.69) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 7 (+2) 8 (+2) 12 (+4) 13 (+2) 48 (+9) 55 (+3) 58 (+2) 68 (+11)
GET get_analysis_latest_cpe 140 (+10) 150 (0) 170 (0) 180 (0) 190 (0) 210 (0) 250 (-10) 268 (-52)
GET get_analysis_status 2 (0) 2 (-1) 3 (0) 4 (0) 5 (-2) 41 (-12) 48 (-6) 51 (-4)
GET get_sbom[sha256:720e4451…a939656247164447] 600 (-100) 600 (-300) 700 (-300) 800 (-200) 1,000 (-768) 1,633 (-135) 1,633 (-135) 1,633 (-135)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (-100) 800 (-100) 900 (0) 900 (0) 900 (-100) 900 (-100) 1,000 (0) 1,000 (0)
GET list_advisory 460 (-10) 480 (0) 500 (0) 500 (0) 600 (0) 700 (+100) 700 (-100) 754 (-209)
GET list_advisory_paginated 400 (0) 420 (0) 460 (+30) 490 (+10) 500 (0) 597 (+97) 597 (-3) 597 (-158)
GET list_importer 2 (0) 2 (0) 2 (-1) 2 (-2) 3 (-3) 4 (-39) 5 (-45) 12 (-39)
GET list_organizations 3 (-1) 5 (0) 6 (0) 9 (-1) 37 (-1) 43 (+2) 50 (+1) 50 (-1)
GET list_packages 410 (+20) 450 (+40) 470 (+40) 480 (+10) 700 (+210) 888 (+388) 888 (+288) 888 (+229)
GET list_packages_paginated 390 (+20) 410 (+20) 420 (+20) 470 (+60) 480 (+20) 500 (+20) 500 (0) 690 (+105)
GET list_products 7 (+1) 8 (+1) 9 (+1) 9 (0) 10 (-1) 14 (-23) 14 (-46) 15 (-46)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-742) 1,000 (-742) 1,541 (-201) 1,541 (-201)
GET list_sboms_paginated 1,000 (-1,000) 1,000 (-1,000) 1,000 (-1,000) 2,000 (0) 2,000 (-1,000) 2,000 (-1,000) 2,000 (-1,000) 2,552 (-448)
GET list_vulnerabilities 300 (+80) 350 (+120) 360 (+90) 400 (+110) 440 (+130) 500 (+140) 500 (+94) 500 (+94)
GET list_vulnerabilities_paginated 180 (+10) 190 (+10) 200 (+10) 210 (+10) 230 (-20) 240 (-60) 260 (-40) 280 (-30)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 26 (-6) 32 (-8) 62 (-6) 66 (-10) 99 (-11) 110 (-50) 160 (-20) 186 (-11)
GET search_advisory 800 (+200) 900 (+100) 900 (-100) 1,000 (0) 2,000 (0) 2,000 (0) 2,000 (0) 2,000 (0)
GET search_exact_purl 7 (+1) 7 (0) 7 (0) 8 (0) 9 (0) 9 (-1) 10 (-49) 11 (-49)
GET search_purls 17,000 (+6,000) 17,000 (+4,000) 17,000 (+1,000) 17,000 (0) 17,000 (0) 17,719 (+719) 17,719 (+719) 17,719 (+719)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (0) 600 (-100) 600 (-100) 700 (0) 800 (0) 800 (-100) 800 (-200) 800 (-200)
Aggregated 330 (+20) 430 (+10) 500 (0) 800 (0) 1,000 (0) 12,000 (+10,000) 17,000 (0) 17,719 (+719)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 60 [200]
GET get_analysis_latest_cpe 60 [200]
GET get_analysis_status 60 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 60 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 [200]
GET list_advisory 60 [200]
GET list_advisory_paginated 60 [200]
GET list_importer 60 [200]
GET list_organizations 60 [200]
GET list_packages 60 [200]
GET list_packages_paginated 60 [200]
GET list_products 60 [200]
GET list_sboms 60 [200]
GET list_sboms_paginated 60 [200]
GET list_vulnerabilities 60 [200]
GET list_vulnerabilities_paginated 60 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 [200]
GET search_advisory 60 [200]
GET search_exact_purl 60 [200]
GET search_purls 65 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 [200]
Aggregated 1,265 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 60 (-25) 0 (0) 13.28 (-0.50) 7 (0) 24 (+3) 0.20 (-0.08) 0.00 (+0.00)
1.1 list_organizations 60 (-25) 0 (0) 9.95 (+0.21) 1 (0) 50 (-1) 0.20 (-0.08) 0.00 (+0.00)
1.2 list_advisory 60 (-25) 0 (0) 477.78 (+2.84) 186 (-85) 754 (-209) 0.20 (-0.08) 0.00 (+0.00)
1.3 list_advisory_paginated 60 (-25) 0 (0) 404.45 (+2.60) 144 (-4) 597 (-158) 0.20 (-0.08) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 60 (-25) 0 (0) 13.88 (+2.64) 2 (-1) 68 (+11) 0.20 (-0.08) 0.00 (+0.00)
1.5 search_advisory 60 (-25) 0 (0) 907.45 (+43.36) 256 (+114) 2062 (-121) 0.20 (-0.08) 0.00 (+0.00)
1.6 list_vulnerabilities 60 (-23) 0 (0) 316.60 (+84.61) 111 (+74) 535 (+129) 0.20 (-0.08) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 60 (-22) 0 (0) 184.32 (+11.24) 50 (+11) 283 (-28) 0.20 (-0.07) 0.00 (+0.00)
1.8 list_importer 60 (-22) 0 (0) 2.12 (-3.01) 1 (0) 12 (-39) 0.20 (-0.07) 0.00 (+0.00)
1.9 list_packages 60 (-22) 0 (0) 455.07 (+69.37) 98 (+41) 888 (+229) 0.20 (-0.07) 0.00 (+0.00)
1.10 list_packages_paginated 60 (-22) 0 (0) 368.30 (+15.69) 105 (+50) 690 (+105) 0.20 (-0.07) 0.00 (+0.00)
1.11 search_purls 65 (-22) 0 (0) 16267.40 (+6939.73) 12429 (+11094) 17719 (+252) 0.22 (-0.07) 0.00 (+0.00)
1.12 search_exact_purl 60 (-25) 0 (0) 6.93 (-0.63) 5 (+3) 11 (-49) 0.20 (-0.08) 0.00 (+0.00)
1.13 list_products 60 (-25) 0 (0) 7.57 (-1.82) 4 (+1) 15 (-46) 0.20 (-0.08) 0.00 (+0.00)
1.14 list_sboms 60 (-25) 0 (0) 1066.33 (-83.03) 590 (+64) 1541 (-201) 0.20 (-0.08) 0.00 (+0.00)
1.15 list_sboms_paginated 60 (-25) 0 (0) 1181.65 (-505.95) 474 (-21) 2552 (-849) 0.20 (-0.08) 0.00 (+0.00)
1.16 get_analysis_status 60 (-25) 0 (0) 5.88 (-0.82) 1 (0) 51 (-4) 0.20 (-0.08) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 60 (-25) 0 (0) 134.00 (+1.16) 35 (+2) 269 (-55) 0.20 (-0.08) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 60 (-25) 0 (0) 699.25 (-159.16) 246 (-44) 1633 (-135) 0.20 (-0.08) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (-25) 0 (0) 43.68 (-8.68) 9 (+1) 186 (-11) 0.20 (-0.08) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (-25) 0 (0) 752.93 (-68.97) 378 (+52) 1002 (-187) 0.20 (-0.08) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (-25) 0 (0) 573.28 (-59.29) 249 (-140) 830 (-266) 0.20 (-0.08) 0.00 (+0.00)
Aggregated 1,325 (-533) 0 (0) 1142.64 (+329.39) 1 (0) 17719 (+252) 4.42 (-1.78) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 60 (-25) 23987.77 (+6282.37) 17912 (+8391) 26224 (-44) 0.20 (-0.08) 12.00 (-5.00)
Aggregated 5 (0) 60 (-25) 23987.77 (+6282.37) 17912 (+8391) 26224 (-44) 0.20 (-0.08) 12.00 (-5.00)

User Metrics