Research Article

A Stateful Approach to Generate Synthetic Events from Kernel Traces

Table 5

Count of different event types in second level of abstraction.

Number of synthetic events in second level of abstraction
Events countSize (MB) File operations Network operations
Check fileSequentially file readSequentially file writeRead write file Network connection HTTP connection DNS connection

227976625 928 673 496 230 43 103 4
542072775 1117742 253 10 372 193 46
887288815066141 19742 440 213 58 103 0
37328387500 53371 32093 1791 888 688 274 108
689618891000 81607 14343 207 69 139 29 0
14050749620006164796921 2505 504 1486 867 285
328868336500094843687095 8047 984 1921 3116 319
6211321671000039506730345220267 1230 11740 16668 651