[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126141-en":3,"doc-seo-126141-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126141,687207022233,"Riley","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Agentless Host Intrusion Detection Using Machine Learning Techniques","With the rise in cyberattacks, host intrusion detection systems (HIDSs) protect endpoints at the network security perimeter. Conventional HIDSs depend on a local software agent to collect and process data, increasing attack surface and causing high maintenance overhead. This report builds on a generic agentless endpoint framework that collects transparently raw data and initially uses a threshold-based statistical model. It extends the framework by collecting a larger dataset with more attack vectors and developing and comparing six machine learning models to improve detection efficiency and effectiveness.","Agentless Host Intrusion Detection Using Machine Learning Techniques  \nby  \nJianfeng Liu  \nA Report Submitted in Partial Fulfillment of the Requirements for the Degree of  \nMASTER OF ENGINEERING  \nin the Department of Electrical and Computer Engineering  \n© Jianfeng Liu, 2023  \nUniversity of Victoria  \nAll rights reserved. This thesis may not be reproduced in whole or in part, by photocopy or other means, without the permission of the author.  \nAgentless Host Intrusion Detection Using Machine Learning  \nTechniques  \nby  \nJianfeng Liu  \nSupervisory Committee  \nDr. Issa Traore, Department of Electrical and Computer Engineering Supervisor  \nDr. Mihai Sima, Department of Electrical and Computer Engineering Departmental Member  \nAbstract  \nWith the rise in the frequency and sophistication of cyberattacks, host intrusion detection systems (HIDSs) have become an essential component in monitoring and protecting endpoints in the network security perimeter. Current HIDSs rely on a local software agent deployed on the monitored host that collects and processes or pre-processes required data. However, this architecture has adverse effects such as increased attack surface, and high maintenance cost and overhead.  \nRecently, a generic agentless endpoint framework that collects transparently raw data from the monitored host was proposed by Ghaleb et al [1] along with a basic threshold-based statistical model for intrusion detection as an initial proof of concept.  \nThis report extends the generic agentless framework by collecting a new dataset with more attack vectors and developing and comparing six machine learning models, including knearest neighbors, logistic regression, naïve Bayes, decision tree, random forest, and support vector machine.  \nThe experimental evaluation using the collected dataset confirmed the feasibility of agentless host intrusion detection, with increased detection efficiency and effectiveness.  \nTable of Contents  \nSupervisory Committee ii  \nAbstract iii  \nTable of Contents iv  \nList of Figures v  \nList of Tables vi  \nGlossary vii  \nDedication viii  \nChapter 1- Introduction 1  \n1.1 Background 1  \n1.2 Context 2  \n1.3 Project Objectives and Approach 2  \n1.4 Report Outline 3  \nChapter 2-Feature Model and Data Collection 4  \n2.1 Existing Agentless HIDS Framework 4  \n2.2 Data Source and Feature Model 5  \n2.3 Data Collection 7  \n2.3.1 Normal Activities 7  \n2.3.2 Simulated Attacks 8  \n2.3.3 Data Collection Environment and Process 10  \n2.4 Collected Data 12  \nChapter 3-Detection Models Design and Evaluation 14  \n3.1 Performance Metrics 14  \n3.2 Classification Models 15  \n3.2.1 Using Naïve Bayes 15  \n3.2.2 Using k-NN 16  \n3.2.3 Using Logistic Regression 17  \n3.2.4 Using Decision Tree 18  \n3.2.5 Using Random Forest 18  \n3.2.6 Using Support Vector Machine 19  \n3.3 Comparison of the Selected Models 20  \nChapter 4-Conclusion 22  \nReferences 24  \nList of Figures  \nFigure 2.1: Agentless HIDS Structure .................................................................................................4  \nFigure 2.2: Data Collection Flow.........................................................................................................5  \nFigure 2.3: DOS Attack Schematic....................................................................................................... 9  \nFigure 2.4: ARP Attack Schematic.......................................................................................................9  \nFigure 2.5: Brute Force Schematic....................................................................................................10  \nFigure 2.6: Brute Force Dictionary....................................................................................................10  \nFigure 2.7: Experimental Setup Components.................................................................................11  \nFigure 2.8: Data Collection Process.........................................................................................","cbCaii3HrtloyYJQ","https://ap.wps.com/l/cbCaii3HrtloyYJQ","pdf",958220,5,1,33,"English","en",105,"# Chapter 1 - Introduction\n## Background\n## Context\n## Project Objectives and Approach\n## Report Outline\n# Chapter 2 - Feature Model and Data Collection\n## Existing Agentless HIDS Framework\n## Data Source and Feature Model\n## Data Collection\n## Collected Data\n# Chapter 3 - Detection Models Design and Evaluation\n## Performance Metrics\n## Classification Models\n## Using Naïve Bayes\n## Using k-NN\n## Using Logistic Regression\n## Using Decision Tree\n## Using Random Forest\n## Using Support Vector Machine\n## Comparison of the Selected Models\n# Chapter 4 - Conclusion\n# References","[{\"question\":\"Why are traditional host intrusion detection systems considered problematic?\",\"answer\":\"They rely on a local software agent deployed on the monitored host, which increases attack surface and introduces high maintenance cost and overhead.\"},{\"question\":\"What does the proposed agentless framework do differently?\",\"answer\":\"It collects transparently raw data from the monitored host without requiring an agent, and it supports an initial threshold-based statistical approach for intrusion detection.\"},{\"question\":\"Which machine learning models are compared in the report?\",\"answer\":\"The report develops and compares six models: k-nearest neighbors, logistic regression, naïve Bayes, decision tree, random forest, and support vector machine.\"}]","Agentless Host Intrusion Detection Using Machine Learning Techniques | PDF",1785903375,83,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"agentless-host-intrusion-detection-using-machine-learning-techniques","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/agentless-host-intrusion-detection-using-machine-learning-techniques/126141/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"Why are traditional host intrusion detection systems considered problematic?","Question",{"text":77,"@type":78},"They rely on a local software agent deployed on the monitored host, which increases attack surface and introduces high maintenance cost and overhead.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"What does the proposed agentless framework do differently?",{"text":82,"@type":78},"It collects transparently raw data from the monitored host without requiring an agent, and it supports an initial threshold-based statistical approach for intrusion detection.",{"name":84,"@type":75,"acceptedAnswer":85},"Which machine learning models are compared in the report?",{"text":86,"@type":78},"The report develops and compares six models: k-nearest neighbors, logistic regression, naïve Bayes, decision tree, random forest, and support vector machine.","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":20,"slug":139},19,"General","general"]