On Improving Deep Learning Trace Analysis with System Call Arguments

03/11/2021
by   Quentin Fournier, et al.
0

Kernel traces are sequences of low-level events comprising a name and multiple arguments, including a timestamp, a process id, and a return value, depending on the event. Their analysis helps uncover intrusions, identify bugs, and find latency causes. However, their effectiveness is hindered by omitting the event arguments. To remedy this limitation, we introduce a general approach to learning a representation of the event names along with their arguments using both embedding and encoding. The proposed method is readily applicable to most neural networks and is task-agnostic. The benefit is quantified by conducting an ablation study on three groups of arguments: call-related, process-related, and time-related. Experiments were conducted on a novel web request dataset and validated on a second dataset collected on pre-production servers by Ciena, our partnering company. By leveraging additional information, we were able to increase the performance of two widely-used neural networks, an LSTM and a Transformer, by up to 11.3 tasks. Such tasks may be used to detect anomalies, pre-train neural networks to improve their performance, and extract a contextual representation of the events.

READ FULL TEXT

page 2

page 7

research
12/16/2022

Rich Event Modeling for Script Event Prediction

Script is a kind of structured knowledge extracted from texts, which con...
research
11/03/2022

Video Event Extraction via Tracking Visual States of Arguments

Video event extraction aims to detect salient events from a video and id...
research
02/07/2022

Document-Level Event Extraction via Human-Like Reading Process

Document-level Event Extraction (DEE) is particularly tricky due to the ...
research
05/31/2022

Enhancing Event-Level Sentiment Analysis with Structured Arguments

Previous studies about event-level sentiment analysis (SA) usually model...
research
05/02/2019

Context awareness and embedding for biomedical event extraction

Motivation: Biomedical event detection is fundamental for information ex...
research
10/24/2020

Paired Representation Learning for Event and Entity Coreference

Co-reference of Events and of Entities are commonly formulated as binary...

Please sign up or login with your details

Forgot password? Click here to reset