There is currently no way to detect that this sort of thing is taking place, and short of logging every syscall, it's just not possible without explicit support like this.
As long as the maintinance of this is not a burden, I don't see a problem with this (done sanely, rate limited with decent log messages)
you already have the kernel logging a lot of things, this is just a little more to go into the logs that you can either ignore or take advantage of.
Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds