Research Article
A Stateful Approach to Generate Synthetic Events from Kernel Traces
Table 4
Count of different event types in first level of abstraction.
| | | Number of synthetic events in first level of abstraction | Events count | Size (MB) | File operations | Network operations | | | File open | File read | File write | File close | Socket create | Socket connect | Socket receive | Socket send | Socket close |
| 2279766 | 25 | 2727 | 8401 | 12913 | 2327 | 150 | 112 | 4583 | 7911 | 150 | 5420727 | 75 | 2474 | 18563 | 30251 | 2122 | 370 | 718 | 21523 | 26570 | 611 | 8872888 | 150 | 86780 | 59108 | 20913 | 86536 | 154 | 106 | 7574 | 10767 | 161 | 37328387 | 500 | 87484 | 158484 | 1025703 | 88143 | 673 | 979 | 60880 | 70651 | 1070 | 68961889 | 1000 | 98583 | 218789 | 6507052 | 96226 | 159 | 73 | 57965 | 62003 | 168 | 140507496 | 2000 | 161458 | 562239 | 5980178 | 161577 | 2140 | 2500 | 166420 | 245718 | 2638 | 328868336 | 5000 | 1045710 | 612821 | 23001032 | 1044562 | 4592 | 5154 | 137733 | 296566 | 5356 | 621132167 | 10000 | 755647 | 3541833 | 23214444 | 720016 | 27676 | 20741 | 735271 | 1288181 | 29059 |
|
|