CPC G06F 21/53 (2013.01) [G06F 16/245 (2019.01); G06F 2221/033 (2013.01)] | 30 Claims |
1. A method comprising:
instantiating, by at least one hardware processor of a computing node, a user-defined function (UDF) server associated with a plurality of configurations; instantiating, using the plurality of configurations, a plurality of child processes of the UDF server;
configuring using a child process of the plurality of child processes, a filtering process at an operating system (OS) kernel of the computing node, the filtering process comprising a set of system call categories and a corresponding set of filtering policies;
detecting a system call received at the OS kernel is associated with a system call category of the set of system call categories and violates a corresponding filtering policy of the set of filtering policies; and
initiating a tracing event of the system call based on the detecting.
|