Fmeter: Extracting Indexable Low-Level System Signatures by Counting Kernel Function Calls

Abstract : System monitoring tools serve to provide operators and developers with an insight into system execution and an understanding of system behavior under a variety of scenarios. Many system abnormalities leave a significant impact on the system execution which may arise out of performance issues, bugs, or errors. Having the ability to quantify and search such behavior in the system execution history can facilitate new ways of looking at problems. For example, operators may use clustering to group and visualize similar system behaviors. We propose a monitoring system that extracts formal, indexable, low-level system signatures using the classical vector space model from the field of information retrieval and text mining. We drive an analogy between the representation of kernel function invocations with terms within text documents. This parallel allows us to automatically index, store, and later retrieve and compare the system signatures. As with information retrieval, the key insight is that we need not rely on the semantic information in a document. Instead, we consider only the statistical properties of the terms belonging to the document (and to the corpus), which enables us to provide both an efficient way to extract signatures at runtime and to analyze the signatures using statistical formal methods. We have built a prototype in Linux, Fmeter, which extracts such low-level system signatures by recording all kernel function invocations. We show that the signatures are naturally amenable to formal processing with statistical methods like clustering and supervised machine learning.
Type de document :
Communication dans un congrès
Priya Narasimhan; Peter Triantafillou. 13th International Middleware Conference (MIDDLEWARE), Dec 2012, Montreal, QC, Canada. Springer, Lecture Notes in Computer Science, LNCS-7662, pp.81-100, 2012, Middleware 2012. 〈10.1007/978-3-642-35170-9_5〉
Liste complète des métadonnées

Littérature citée [45 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01555553
Contributeur : Hal Ifip <>
Soumis le : mardi 4 juillet 2017 - 11:33:03
Dernière modification le : mardi 4 juillet 2017 - 11:34:12
Document(s) archivé(s) le : jeudi 14 décembre 2017 - 23:02:45

Fichier

978-3-642-35170-9_5_Chapter.pd...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Tudor Marian, Hakim Weatherspoon, Ki-Suh Lee, Abhishek Sagar. Fmeter: Extracting Indexable Low-Level System Signatures by Counting Kernel Function Calls. Priya Narasimhan; Peter Triantafillou. 13th International Middleware Conference (MIDDLEWARE), Dec 2012, Montreal, QC, Canada. Springer, Lecture Notes in Computer Science, LNCS-7662, pp.81-100, 2012, Middleware 2012. 〈10.1007/978-3-642-35170-9_5〉. 〈hal-01555553〉

Partager

Métriques

Consultations de la notice

22

Téléchargements de fichiers

23