maldeclabs/MalDec-EDR

Criar um script de tracing para extração de dados

Closed this issue · 0 comments

  1. Primeiro contar o número de ocorrência de cada syscall, ex: mmap: 10, close: 2, ...
  2. Depois veja quantas syscalls tem ao todo.
  3. Calcule as porcentagens (frequência) de cada uma, ex: mmap: 10 / tot * 100, close: 1 / tot * 100.
  4. Repetir o processo pra n traces e calcular o desvio padrão entre cada syscall (desvio do mmap, desvio do close, etc).

Exemplo de saída do programa (csv):

syscall,std
accept4,0.501860
access,0.021368
arch_prctl,0.021368
bind,0.021368
brk,0.106838
clone,0.042735
close,1.389992
connect,0.085471
dup2,0.064103
...