NITRSCT: A Software Security tool for collection and analysis of Kernel Calls
Pushkar Kishore, Swadhin Kumar Barisal, Shikhar Vaish · 2019
Software security is the way of developing software such that, it should function well under malicious attack. In this paper, we design and develop an automation tool named NITRSCT (NITR System Call Tracer), using Microsoft's package to listen to the system calls generated by processes or threads during a context switch. It will allow any version of the Windows Operating System to serve as a system call tracer. The said Windows Service can be installed and controlled through Windows Service Manager. This service stores the sequence of system calls in the form of a trace file as well as a text file along with the SQL database for more verbosity. This sequence represents the normal behaviour of the software. A well-defined log file with different level of verbosity along with the Event Manager enables the user to be well informed about the errors that might have incurred while running services on their systems. Therefore, the dataset will help improve the true positive rates detected by anomaly detection systems.