sudo insmod task-info.ko
dmesg
{
0xC1731F60, /* task struct root */
432, /* offset of task_struct list */
460, /* offset of mm */
40, /* offset of pgd in mm */
732, /* offset of comm */
};
Note: the new process detection approach listed in the paper is not that stable. Instead, we use some process information to help new process detection.
sudo apt-get build-dep qemu
cd pemu && mkdir build && cd build
../myconfig && make install
cd pemu/plugins && make
cd pemu/build/bin && ./qemu-system-i386 -m 512 image -monitor stdio
(QEMU) pemu ls strace.so
guestos:~$ ls