SKTRC: Rastreamento Direcionado e Persistente de Eventos do Kernel Linux para Análise de Vulnerabilidades
Resumo
Vulnerabilities in Linux Kernel components may involve internal states that are difficult to observe and transient events that are relevant for security analysis. Although there are well-established tracing mechanisms, these approaches do not always combine targeted collection, contextualization, persistence, and low instrumentation effort. This work introduces the Simple Kernel Trace (SKTRC), a Kernel module aimed at targeted and persistent tracing of internal system events. SKTRC was evaluated in a Proof of Concept (PoC) executed on a native bare metal Linux installation and compared with the native event tracing mechanism. The evaluation used components associated with the Copy Fail vulnerability, which was recently disclosed after remaining present for years in the Linux Kernel. The results indicate that SKTRC makes it possible to collect contextualized logs during the controlled execution of a vulnerability PoC, reduces the instrumentation effort, and facilitates subsequent analysis of security-relevant events.
Referências
Aranya, A. (2004). Tracefs: A File System to Trace Them All. In 3rd USENIX Conference on File and Storage Technologies (FAST 04), San Francisco, CA. USENIX Association.
Billimoria, K. N. (2022). Linux Kernel Debugging: Leverage proven tools and advanced techniques to effectively debug Linux kernels and kernel modules. Packt Publishing Ltd.
Chen, Z., Li, Z., Song, Z., Shi, Z., and Sun, L. (2025). Exp-Arch: A Novel LLM-Powered Approach for Facilitating Exploit Primitive Assessment in the Linux Kernel. In 2025 IEEE 31st International Conference on Parallel and Distributed Systems (ICPADS), pages 01–10.
Esteves, T., Macedo, R., Oliveira, R., and Paulo, J. (2023). Diagnosing applications’ I/O behavior through system call observability. In 2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W), pages 1–8.
Faseeha, U., Jamil Syed, H., Samad, F., Zehra, S., and Ahmed, H. (2025). Observability in Microservices: An In-Depth Exploration of Frameworks, Challenges, and Deployment Paradigms. IEEE Access, 13:72011–72039.
Khan, M. A. and Ezzati-Jivan, N. (2023). Multi-level Adaptive Execution Tracing for Efficient Performance Analysis. In 2023 IEEE/ACIS 21st International Conference on Software Engineering Research, Management and Applications (SERA), pages 104–109.
Luck, T. (2011). Pstore: Generic interface to platform dependent persistent storage – The Linux Kernel Documentation. The Linux Kernel Organization. Disponível em: [link]. Acesso em: 21 Mar. 2026.
Mahadevan, S. V., Takano, Y., and Miyaji, A. (2026). Enhancing Information Flow Control in eBPF Programs via Taint Tracking Mechanisms. Los Alamitos, CA, USA. IEEE Computer Society.
Mazza, S., Calabrò, F., Valla, F., Amer, A., and Facchinetti, T. (2025). Evaluation of the boot time in a Linux automotive environment with security constraints. In 2025 IEEE 30th International Conference on Emerging Technologies and Factory Automation (ETFA), pages 1–4.
O’Brien, D. (2017). Teaching Operating Systems Concepts with SystemTap. In Proceedings of the 2017 ACM Conference on Innovation and Technology in Computer Science Education, ITiCSE ’17, page 335–340, New York, NY, USA. Association for Computing Machinery.
Rosset, T., Wisniewski, L., and Scanzio, S. (2026). A Survey on Platform-Level Data Quality: From Visibility to Controllability. IEEE Access, 14:48262–48276.
Rostedt, S. (2008). ftrace - Function Tracer – The Linux Kernel Documentation. Disponível em: [link]. Acesso em: 2 Mar. 2026.
Song, L. and Li, J. (2024). eBPF: Pioneering Kernel Programmability and System Observability - Past, Present, and Future Insights. In 2024 3rd International Conference on Artificial Intelligence and Computer Information Technology (AICIT), pages 1–10.
Ts’o, T., Zefan, L., and Zanussi, T. (2009). Event Tracing – The Linux Kernel Documentation. The Linux Kernel Organization. Disponível em: [link]. Acesso em: 21 Mar. 2026.
Yang, Z., Solanki, S., Rixner, S., and Dautenhahn, N. (2025). Hi-Res: Precise Exploit Detection Using Object-Granular Memory Monitoring. In 2025 IEEE Security and Privacy Workshops (SPW), pages 79–90.
Zhang, B., Yang, K., Wang, L., Tan, Y.-a., and Hu, S. (2019). Tracing Android Kernel Codes at Early Stage without Extra Hardware Components. In 2019 IEEE Fourth International Conference on Data Science in Cyberspace (DSC), pages 210–216.
