Goose Attack Report

Users: 5

Target Host: http://trustify:8080/

goose v0.18.0

Plan overview

Action Started Stopped Elapsed Users
Increasing25-09-02 03:12:3025-09-02 03:12:3500:00:050 → 5
Maintaining25-09-02 03:12:3525-09-02 03:17:3500:05:005
Decreasing25-09-02 03:17:3525-09-02 03:17:3600:00:010 ← 5

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
GET get_advisory_by_doc_id 120 (+66) 0 12.46 (-2.73) 3 (0) 61 (-27) 0.40 (+0.22) 0.00 (+0.00)
GET get_analysis_latest_cpe 124 (+69) 0 111.01 (-25.43) 36 (+10) 277 (-94) 0.41 (+0.23) 0.00 (+0.00)
GET get_analysis_status 124 (+69) 0 8.61 (-1.08) 1 (0) 56 (+3) 0.41 (+0.23) 0.00 (+0.00)
GET get_sbom[sha256:720e4451…a939656247164447] 124 (+69) 0 545.62 (-314.45) 176 (-22) 1639 (-370) 0.41 (+0.23) 0.00 (+0.00)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 121 (+66) 0 815.13 (+39.37) 395 (-73) 1177 (+151) 0.40 (+0.22) 0.00 (+0.00)
GET list_advisory 120 (+65) 0 478.67 (-55.46) 280 (+105) 983 (-2) 0.40 (+0.22) 0.00 (+0.00)
GET list_advisory_paginated 120 (+66) 0 415.09 (-42.61) 118 (-103) 699 (+51) 0.40 (+0.22) 0.00 (+0.00)
GET list_importer 120 (+70) 0 4.18 (+1.58) 1 (0) 48 (+31) 0.40 (+0.23) 0.00 (+0.00)
GET list_organizations 120 (+65) 0 7.18 (-0.14) 1 (0) 45 (+2) 0.40 (+0.22) 0.00 (+0.00)
GET list_packages 120 (+70) 0 434.81 (-31.89) 119 (+35) 910 (+28) 0.40 (+0.23) 0.00 (+0.00)
GET list_packages_paginated 120 (+70) 0 369.96 (-30.46) 105 (-5) 728 (+118) 0.40 (+0.23) 0.00 (+0.00)
GET list_products 125 (+70) 0 7.03 (-1.10) 2 (-2) 57 (+44) 0.42 (+0.23) 0.00 (+0.00)
GET list_sboms 125 (+70) 0 1072.74 (+26.54) 496 (-130) 1580 (-16) 0.42 (+0.23) 0.00 (+0.00)
GET list_sboms_paginated 125 (+70) 0 1289.97 (-141.45) 327 (-178) 2694 (-151) 0.42 (+0.23) 0.00 (+0.00)
GET list_vulnerabilities 120 (+70) 0 241.66 (-92.42) 53 (-50) 425 (-132) 0.40 (+0.23) 0.00 (+0.00)
GET list_vulnerabilities_paginated 120 (+70) 0 189.12 (-26.48) 42 (-1) 312 (+30) 0.40 (+0.23) 0.00 (+0.00)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 121 (+66) 0 49.06 (+5.06) 10 (-1) 185 (+20) 0.40 (+0.22) 0.00 (+0.00)
GET search_advisory 120 (+66) 0 978.83 (+32.73) 136 (-149) 2186 (+268) 0.40 (+0.22) 0.00 (+0.00)
GET search_exact_purl 125 (+70) 0 8.00 (-22.42) 2 (-5) 65 (+29) 0.42 (+0.23) 0.00 (+0.00)
GET search_purls 125 (+70) 0 4641.34 (-14702.28) 449 (-9111) 6083 (-14888) 0.42 (+0.23) 0.00 (+0.00)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 120 (+65) 0 590.24 (+7.55) 235 (-68) 1107 (-45) 0.40 (+0.22) 0.00 (+0.00)
Aggregated 2559 (+1432) 0 590.51 (-751.23) 1 (0) 6083 (-14888) 8.53 (+4.77) 0.00 (+0.00)

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
GET get_advisory_by_doc_id 6 (-1) 7 (-3) 8 (-3) 11 (-3) 44 (0) 51 (+1) 59 (-7) 61 (-27)
GET get_analysis_latest_cpe 100 (-20) 110 (-40) 110 (-70) 120 (-80) 170 (-50) 180 (-70) 260 (-20) 277 (-93)
GET get_analysis_status 3 (0) 3 (0) 4 (0) 6 (0) 45 (-3) 50 (-3) 55 (+2) 56 (+3)
GET get_sbom[sha256:720e4451…a939656247164447] 330 (-370) 380 (-420) 410 (-590) 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 1,639 (-361) 1,639 (-361)
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 800 (0) 900 (+100) 900 (+100) 1,000 (+100) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0)
GET list_advisory 470 (-30) 500 (0) 500 (0) 500 (-100) 600 (-100) 700 (0) 800 (-100) 983 (-2)
GET list_advisory_paginated 410 (-60) 430 (-60) 470 (-30) 500 (0) 500 (-100) 500 (-100) 600 (0) 699 (+99)
GET list_importer 2 (0) 2 (0) 4 (+2) 5 (+2) 6 (+3) 10 (+4) 46 (+29) 48 (+31)
GET list_organizations 3 (-1) 4 (0) 5 (-1) 7 (-1) 16 (+1) 41 (+11) 44 (+3) 45 (+2)
GET list_packages 410 (-50) 460 (0) 480 (0) 490 (0) 600 (-100) 800 (0) 900 (+18) 900 (+18)
GET list_packages_paginated 390 (-20) 400 (-30) 420 (-10) 480 (-10) 500 (0) 600 (0) 600 (0) 700 (+100)
GET list_products 5 (-3) 6 (-3) 6 (-4) 7 (-3) 10 (-1) 12 (+1) 55 (+43) 57 (+44)
GET list_sboms 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,000 (0) 1,580 (+580) 1,580 (-16)
GET list_sboms_paginated 1,000 (0) 1,000 (-1,000) 1,000 (-1,000) 2,000 (0) 2,000 (0) 2,000 (0) 2,694 (-151) 2,694 (-151)
GET list_vulnerabilities 240 (-90) 260 (-100) 280 (-110) 300 (-120) 310 (-130) 320 (-130) 420 (-137) 425 (-132)
GET list_vulnerabilities_paginated 190 (-20) 200 (-20) 210 (-30) 220 (-50) 260 (-10) 280 (0) 310 (+30) 310 (+30)
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 24 (-9) 55 (+18) 68 (+14) 75 (+11) 110 (+24) 130 (+30) 180 (+30) 185 (+20)
GET search_advisory 900 (0) 1,000 (0) 1,000 (0) 1,000 (0) 2,000 (+1,000) 2,000 (+82) 2,000 (+82) 2,000 (+82)
GET search_exact_purl 4 (-28) 4 (-29) 5 (-29) 7 (-27) 16 (-18) 40 (+5) 55 (+19) 65 (+29)
GET search_purls 5,000 (-15,000) 5,000 (-15,000) 5,000 (-15,000) 5,000 (-15,000) 5,000 (-15,971) 6,000 (-14,971) 6,000 (-14,971) 6,000 (-14,971)
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 600 (0) 600 (0) 700 (+100) 700 (0) 800 (0) 900 (0) 1,000 (0) 1,000 (0)
Aggregated 300 (-90) 410 (-70) 500 (-100) 800 (0) 1,000 (0) 2,000 (-1,000) 5,000 (-15,000) 6,000 (-14,971)

Status Code Metrics

Method Name Status Codes
GET get_advisory_by_doc_id 120 [200]
GET get_analysis_latest_cpe 124 [200]
GET get_analysis_status 124 [200]
GET get_sbom[sha256:720e4451…a939656247164447] 124 [200]
GET get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 121 [200]
GET list_advisory 120 [200]
GET list_advisory_paginated 120 [200]
GET list_importer 120 [200]
GET list_organizations 120 [200]
GET list_packages 120 [200]
GET list_packages_paginated 120 [200]
GET list_products 125 [200]
GET list_sboms 125 [200]
GET list_sboms_paginated 125 [200]
GET list_vulnerabilities 120 [200]
GET list_vulnerabilities_paginated 120 [200]
GET sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 121 [200]
GET search_advisory 120 [200]
GET search_exact_purl 125 [200]
GET search_purls 125 [200]
POST post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 120 [200]
Aggregated 2,559 [200]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
WebsiteUser
0.0 logon 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.1 website_index 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.2 website_openapi 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.3 website_sboms 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.4 website_packages 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.5 website_advisories 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
0.6 website_importers 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser
1.0 logon 120 (+65) 0 (0) 14.47 (+0.88) 7 (0) 29 (+6) 0.40 (+0.22) 0.00 (+0.00)
1.1 list_organizations 120 (+65) 0 (0) 7.42 (-0.11) 2 (+1) 45 (+2) 0.40 (+0.22) 0.00 (+0.00)
1.2 list_advisory 120 (+65) 0 (0) 478.75 (-55.47) 280 (+105) 983 (-2) 0.40 (+0.22) 0.00 (+0.00)
1.3 list_advisory_paginated 120 (+66) 0 (0) 415.17 (-42.57) 118 (-103) 699 (+51) 0.40 (+0.22) 0.00 (+0.00)
1.4 get_advisory_by_doc_id 120 (+66) 0 (0) 12.48 (-2.76) 3 (0) 61 (-27) 0.40 (+0.22) 0.00 (+0.00)
1.5 search_advisory 120 (+66) 0 (0) 978.85 (+32.72) 136 (-149) 2186 (+268) 0.40 (+0.22) 0.00 (+0.00)
1.6 list_vulnerabilities 120 (+70) 0 (0) 241.71 (-92.39) 53 (-50) 425 (-132) 0.40 (+0.23) 0.00 (+0.00)
1.7 list_vulnerabilities_paginated 120 (+70) 0 (0) 189.18 (-26.49) 42 (-1) 312 (+30) 0.40 (+0.23) 0.00 (+0.00)
1.8 list_importer 120 (+70) 0 (0) 4.22 (+1.58) 1 (0) 48 (+31) 0.40 (+0.23) 0.00 (+0.00)
1.9 list_packages 120 (+70) 0 (0) 434.87 (-31.83) 119 (+35) 910 (+28) 0.40 (+0.23) 0.00 (+0.00)
1.10 list_packages_paginated 120 (+70) 0 (0) 370.05 (-30.39) 105 (-5) 728 (+118) 0.40 (+0.23) 0.00 (+0.00)
1.11 search_purls 125 (+70) 0 (0) 4641.38 (-14702.30) 449 (-9111) 6083 (-14888) 0.42 (+0.23) 0.00 (+0.00)
1.12 search_exact_purl 125 (+70) 0 (0) 8.05 (-22.41) 2 (-5) 65 (+29) 0.42 (+0.23) 0.00 (+0.00)
1.13 list_products 125 (+70) 0 (0) 7.06 (-1.09) 2 (-2) 57 (+44) 0.42 (+0.23) 0.00 (+0.00)
1.14 list_sboms 125 (+70) 0 (0) 1072.76 (+26.51) 496 (-130) 1580 (-16) 0.42 (+0.23) 0.00 (+0.00)
1.15 list_sboms_paginated 125 (+70) 0 (0) 1290.07 (-141.49) 327 (-178) 2694 (-151) 0.42 (+0.23) 0.00 (+0.00)
1.16 get_analysis_status 124 (+69) 0 (0) 8.65 (-1.04) 1 (0) 56 (+3) 0.41 (+0.23) 0.00 (+0.00)
1.17 get_analysis_latest_cpe 124 (+69) 0 (0) 111.05 (-25.46) 36 (+10) 277 (-94) 0.41 (+0.23) 0.00 (+0.00)
1.18 get_sbom[sha256:720e4451…a939656247164447] 124 (+69) 0 (0) 545.71 (-314.45) 176 (-23) 1639 (-371) 0.41 (+0.23) 0.00 (+0.00)
1.19 sbom_by_package[pkg:maven/io.qu…dhat.com%2fga%2f] 121 (+66) 0 (0) 49.18 (+5.11) 10 (-1) 185 (+19) 0.40 (+0.22) 0.00 (+0.00)
1.20 get_sbom_license_ids[urn:uuid:019731…104-331632a21144] 121 (+66) 0 (0) 815.25 (+39.36) 395 (-73) 1177 (+151) 0.40 (+0.22) 0.00 (+0.00)
1.21 post_vulnerability_analyze[pkg:rpm/redhat/…h=noarch&epoch=1] 120 (+65) 0 (0) 590.30 (+7.55) 235 (-68) 1107 (-45) 0.40 (+0.22) 0.00 (+0.00)
Aggregated 2,679 (+1,497) 0 (0) 564.06 (-715.25) 1 (0) 6083 (-14888) 8.93 (+4.99) 0.00 (+0.00)

Scenario Metrics

Scenario # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
WebsiteUser 0 (0) 0 (0) 0.00 (+0.00) 0 (0) 0 (0) 0.00 (+0.00) 0.00 (+0.00)
RestAPIUser 5 (0) 120 (+65) 12202.08 (-15241.81) 6306 (-7132) 14945 (-15948) 0.40 (+0.22) 24.00 (+13.00)
Aggregated 5 (0) 120 (+65) 12202.08 (-15241.81) 6306 (-7132) 14945 (-15948) 0.40 (+0.22) 24.00 (+13.00)

User Metrics