Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-08-31 03:12:5225-08-31 03:12:5700:00:050 → 5
Maintaining25-08-31 03:12:5725-08-31 03:17:5700:05:005
Decreasing25-08-31 03:17:5725-08-31 03:18:0400:00:070 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 60 (+10) 0 11.38 (+1.50) 3 (+1) 66 (+8) 0.20 (+0.03) 0.00 (+0.00)
GET get_analysis_latest_cpe 60 (+10) 0 144.17 (+24.65) 28 (-8) 285 (-30) 0.20 (+0.03) 0.00 (+0.00)
GET get_analysis_status 60 (+10) 0 6.53 (+0.17) 1 (0) 55 (+4) 0.20 (+0.03) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 60 (+10) 0 942.23 (-116.55) 214 (-81) 2060 (-1417) 0.20 (+0.03) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (+10) 0 763.63 (-58.19) 401 (+83) 984 (-299) 0.20 (+0.03) 0.00 (+0.00)
GET list_advisory 60 (+10) 0 460.20 (+20.24) 127 (+19) 800 (-122) 0.20 (+0.03) 0.00 (+0.00)
GET list_advisory_paginated 60 (+10) 0 415.02 (+55.78) 99 (+9) 537 (-18) 0.20 (+0.03) 0.00 (+0.00)
GET list_importer 60 (+10) 0 2.52 (+0.22) 1 (0) 9 (-3) 0.20 (+0.03) 0.00 (+0.00)
GET list_organizations 60 (+10) 0 5.57 (-2.17) 1 (0) 28 (-22) 0.20 (+0.03) 0.00 (+0.00)
GET list_packages 60 (+10) 0 427.57 (+113.99) 89 (+3) 928 (+422) 0.20 (+0.03) 0.00 (+0.00)
GET list_packages_paginated 60 (+10) 0 386.92 (+89.82) 90 (+1) 598 (+135) 0.20 (+0.03) 0.00 (+0.00)
GET list_products 60 (+10) 0 10.78 (+2.68) 3 (-2) 48 (+34) 0.20 (+0.03) 0.00 (+0.00)
GET list_sboms 60 (+10) 0 1197.95 (-17.25) 557 (-93) 1712 (+47) 0.20 (+0.03) 0.00 (+0.00)
GET list_sboms_paginated 60 (+10) 0 1375.25 (-1410.95) 465 (-60) 3110 (-3498) 0.20 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities 60 (+10) 0 325.15 (+51.71) 52 (+4) 565 (-25) 0.20 (+0.03) 0.00 (+0.00)
GET list_vulnerabilities_paginated 60 (+10) 0 188.47 (+6.99) 39 (+13) 281 (-34) 0.20 (+0.03) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (+10) 0 52.12 (-15.90) 9 (-3) 147 (-27) 0.20 (+0.03) 0.00 (+0.00)
GET search_advisory 60 (+10) 0 1062.13 (+258.95) 161 (+41) 2041 (+292) 0.20 (+0.03) 0.00 (+0.00)
GET search_exact_purl 60 (+10) 0 67.95 (+60.87) 7 (+2) 92 (+80) 0.20 (+0.03) 0.00 (+0.00)
GET search_purls 65 (+10) 0 15960.45 (-3150.75) 6443 (-7611) 19008 (-4032) 0.22 (+0.03) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (+10) 0 577.48 (-73.80) 231 (-11) 1225 (-268) 0.20 (+0.03) 0.00 (+0.00)
Aggregated 1265 (+210) 0 1219.61 (-223.64) 1 (0) 19008 (-4032) 4.22 (+0.70) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (0) 7 (+1) 8 (+1) 10 (0) 15 (+2) 52 (+3) 60 (+2) 66 (+8)
GET get_analysis_latest_cpe 130 (+20) 150 (+30) 190 (+70) 200 (+40) 270 (+100) 270 (+80) 280 (-35) 285 (-30)
GET get_analysis_status 2 (-1) 3 (0) 3 (-1) 4 (-1) 8 (+2) 44 (-3) 49 (-2) 55 (+4)
GET get_sbom[sha256:720e4451…a939656247164447] 800 (+200) 900 (+200) 1,000 (+200) 1,000 (-1,000) 2,000 (-1,000) 2,000 (-1,000) 2,000 (-1,000) 2,000 (-1,000)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (0) 800 (-100) 900 (0) 900 (0) 900 (-100) 984 (-16) 984 (-16) 984 (-16)
GET list_advisory 470 (+30) 480 (+20) 500 (+20) 500 (0) 600 (0) 700 (0) 800 (-100) 800 (-100)
GET list_advisory_paginated 430 (+40) 450 (+40) 480 (+50) 490 (+30) 500 (+20) 500 (0) 500 (-55) 500 (-55)
GET list_importer 2 (0) 3 (+1) 3 (0) 3 (0) 4 (+1) 5 (+1) 7 (-5) 9 (-3)
GET list_organizations 3 (0) 4 (0) 6 (0) 7 (-1) 12 (-11) 19 (-17) 21 (-29) 28 (-22)
GET list_packages 430 (+60) 440 (+60) 470 (+80) 500 (+70) 500 (+50) 800 (+340) 900 (+400) 900 (+400)
GET list_packages_paginated 410 (+90) 420 (+50) 460 (+70) 470 (+70) 500 (+80) 500 (+70) 598 (+138) 598 (+138)
GET list_products 7 (0) 8 (0) 10 (0) 12 (+1) 14 (+2) 45 (+32) 47 (+33) 48 (+34)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (-665) 1,712 (+47) 1,712 (+47) 1,712 (+47)
GET list_sboms_paginated 1,000 (-2,000) 1,000 (-2,000) 2,000 (-1,000) 2,000 (-2,000) 2,000 (-3,000) 2,000 (-3,000) 3,000 (-3,608) 3,000 (-3,608)
GET list_vulnerabilities 340 (+60) 350 (+50) 380 (+60) 390 (+30) 460 (-10) 500 (0) 565 (-25) 565 (-25)
GET list_vulnerabilities_paginated 200 (+20) 200 (0) 210 (-40) 210 (-60) 220 (-70) 280 (-20) 280 (-35) 280 (-35)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 37 (-28) 55 (-23) 62 (-29) 81 (-19) 110 (-10) 120 (-10) 130 (-40) 147 (-23)
GET search_advisory 900 (+300) 1,000 (+200) 1,000 (+100) 2,000 (+1,000) 2,000 (+251) 2,000 (+251) 2,000 (+251) 2,000 (+251)
GET search_exact_purl 76 (+69) 81 (+74) 85 (+78) 88 (+80) 90 (+82) 91 (+82) 92 (+80) 92 (+80)
GET search_purls 17,000 (-2,000) 17,000 (-3,000) 18,000 (-3,000) 18,000 (-4,000) 19,000 (-3,000) 19,000 (-4,000) 19,000 (-4,000) 19,000 (-4,000)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 500 (-100) 600 (0) 700 (0) 700 (0) 800 (-200) 900 (-100) 1,000 (0) 1,000 (0)
Aggregated 340 (+60) 450 (+50) 500 (0) 800 (0) 1,000 (-1,000) 7,000 (-7,000) 18,000 (-4,000) 19,000 (-4,000)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 60 [200]
GET get_analysis_latest_cpe 60 [200]
GET get_analysis_status 60 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 60 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 [200]
GET list_advisory 60 [200]
GET list_advisory_paginated 60 [200]
GET list_importer 60 [200]
GET list_organizations 60 [200]
GET list_packages 60 [200]
GET list_packages_paginated 60 [200]
GET list_products 60 [200]
GET list_sboms 60 [200]
GET list_sboms_paginated 60 [200]
GET list_vulnerabilities 60 [200]
GET list_vulnerabilities_paginated 60 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 [200]
GET search_advisory 60 [200]
GET search_exact_purl 60 [200]
GET search_purls 65 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 [200]
Aggregated 1,265 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 60 (+10) 0 (0) 14.18 (+1.26) 7 (0) 21 (-1) 0.20 (+0.03) 0.00 (+0.00)
1.1 list_organizations 60 (+10) 0 (0) 5.88 (-1.96) 1 (0) 28 (-22) 0.20 (+0.03) 0.00 (+0.00)
1.2 list_advisory 60 (+10) 0 (0) 460.28 (+20.30) 127 (+19) 801 (-121) 0.20 (+0.03) 0.00 (+0.00)
1.3 list_advisory_paginated 60 (+10) 0 (0) 415.05 (+55.77) 99 (+9) 537 (-18) 0.20 (+0.03) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 60 (+10) 0 (0) 11.40 (+1.50) 3 (+1) 66 (+8) 0.20 (+0.03) 0.00 (+0.00)
1.5 search_advisory 60 (+10) 0 (0) 1062.20 (+258.98) 161 (+41) 2042 (+293) 0.20 (+0.03) 0.00 (+0.00)
1.6 list_vulnerabilities 60 (+10) 0 (0) 325.18 (+51.66) 52 (+4) 565 (-25) 0.20 (+0.03) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 60 (+10) 0 (0) 188.48 (+6.96) 39 (+13) 281 (-34) 0.20 (+0.03) 0.00 (+0.00)
1.8 list_importer 60 (+10) 0 (0) 2.62 (+0.30) 1 (0) 9 (-3) 0.20 (+0.03) 0.00 (+0.00)
1.9 list_packages 60 (+10) 0 (0) 427.58 (+113.94) 89 (+3) 928 (+422) 0.20 (+0.03) 0.00 (+0.00)
1.10 list_packages_paginated 60 (+10) 0 (0) 386.98 (+89.84) 90 (+1) 598 (+135) 0.20 (+0.03) 0.00 (+0.00)
1.11 search_purls 65 (+10) 0 (0) 15960.46 (-3150.76) 6443 (-7611) 19008 (-4032) 0.22 (+0.03) 0.00 (+0.00)
1.12 search_exact_purl 60 (+10) 0 (0) 67.98 (+60.88) 7 (+2) 92 (+80) 0.20 (+0.03) 0.00 (+0.00)
1.13 list_products 60 (+10) 0 (0) 10.82 (+2.70) 3 (-2) 48 (+34) 0.20 (+0.03) 0.00 (+0.00)
1.14 list_sboms 60 (+10) 0 (0) 1197.98 (-17.24) 557 (-93) 1712 (+47) 0.20 (+0.03) 0.00 (+0.00)
1.15 list_sboms_paginated 60 (+10) 0 (0) 1375.35 (-1410.89) 465 (-60) 3110 (-3498) 0.20 (+0.03) 0.00 (+0.00)
1.16 get_analysis_status 60 (+10) 0 (0) 6.57 (+0.19) 1 (0) 55 (+4) 0.20 (+0.03) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 60 (+10) 0 (0) 144.25 (+24.71) 29 (-7) 285 (-30) 0.20 (+0.03) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 60 (+10) 0 (0) 942.32 (-116.52) 214 (-81) 2061 (-1416) 0.20 (+0.03) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 60 (+10) 0 (0) 52.18 (-15.90) 9 (-3) 148 (-26) 0.20 (+0.03) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 60 (+10) 0 (0) 763.65 (-58.25) 401 (+83) 984 (-299) 0.20 (+0.03) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 60 (+10) 0 (0) 577.52 (-73.82) 231 (-11) 1225 (-268) 0.20 (+0.03) 0.00 (+0.00)
Aggregated 1,325 (+220) 0 (0) 1164.38 (-213.56) 1 (0) 19008 (-4032) 4.42 (+0.73) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 60 (+10) 24012.97 (-4780.21) 10362 (-12244) 28366 (-5370) 0.20 (+0.03) 12.00 (+2.00)
Aggregated 5 (0) 60 (+10) 24012.97 (-4780.21) 10362 (-12244) 28366 (-5370) 0.20 (+0.03) 12.00 (+2.00)

User Metrics