TCP sessions section

Kaspersky Research Sandbox provides information about TCP sessions that were registered during the web address analysis.

TCP sessions

Field

Description

Source IP

Sender's IP address.

Destination IP

Recipient IP address.

Source port

Source port number (0–65536).

Destination port

Destination port number (0–65536).

Size

Size of data that was sent and received within the TCP session (in bytes).

Packets

Number of packets that were sent and received within the TCP session.

SYN packets

Number of SYN packets that were sent and received within the TCP session.

FIN packets

Number of FIN packets that were sent and received within the TCP session.

Out-of-order packets

Number of out-of-order packets that were sent and received within the TCP session.

Lost ACK packets

Number of lost ACK packets that were sent and received within the TCP session.

Duplicated ACK packets

Number of duplicated ACK packets that were sent and received within the TCP session.

Window In

Number of incoming segments (bytes) that can be sent from server to client before an acknowledgment (ACK packet) is received.

Window Out

Number of outgoing segments (bytes) that can be sent from client to server before an acknowledgment (ACK packet) is received.

Page top