Research Article

A Stateful Approach to Generate Synthetic Events from Kernel Traces

Table 1

Raw events to semantic events.

Raw eventsSemantic events

sys_open event
sys_dup eventFile open
sys_create event

sys_read event
sys_pread64File read
sys_readv event

sys_write event
sys_pwrite64 eventFile write
sys_writev event

sys_kill event
sys_tkill eventProcess kill
sys_tgkill event