[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121877-en":3,"doc-seo-121877-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121877,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Natural Language Processing with Machine Learning for Anomaly Detection on System Call Logs","Host intrusion detection and machine learning are studied extensively, yet system-call return data remains challenging because it often lacks call arguments and clear exploit traces. This research applies natural language processing to unstructured raw system call traces from x86_64 GNU Linux, using supervised and unsupervised models to detect both known and unseen threats. Experiments use a Leipzig University dataset and decision-tree based models, comparing Random Forest with Isolation Forest after hyper-parameter tuning. Results show strong anomaly detection when Isolation Forest is combined with PCA, improving accuracy for potential zero-day detection.","Natural Language Processing with machine learning for anomaly detection  \non system call logs  \nSubmitted in partial fulﬁlment of the requirements for the degree of  \nMaster of Science  \nof Rhodes University  \nChristo Goosen  \nGrahamstown, South Africa  \nAbstract  \nHost intrusion detection systems and machine learning have been studied for many years especially on datasets like KDD99 . Current research and systems are focused on low training and processing complex problems such as system call returns, which lack the system call arguments and potential traces of exploits run against a system. With respect to malware and vulnerabilities, signatures are relied upon, and the potential for natural language processing of the resulting logs and system call traces needs further experimentation.  \nThis research looks at unstructured raw system call traces from x86 _ 64 bit GNU Linux operating systems with natural language processing and supervised and unsupervised machine learning techniques to identify current and unseen threats. The research explores whether these tools are within the skill set of information security professionals, or require data science professionals.  \nThe research makes use of an academic and modern system call dataset from Leipzig University and applies two machine learning models based on decision trees. Random Forest as the supervised algorithm is compared to the unsupervised Isolation Forest algorithm for this research, with each experiment repeated after hyper-parameter tuning.  \nThe research ﬁnds conclusive evidence that the Isolation Forest Tree algorithm is eﬀective, when paired with a Principal Component Analysis, in identifying anomalies in the modern Leipzig Intrusion Detection Data Set (LID-DS) dataset combined with samples of executed malware from the Virus Total Academic dataset. The base or default model parameters produce sub-optimal results, whereas using a hyper-parameter tuning technique increases the accuracy to within promising levels for anomaly and potential zero day detection.  \nAcknowledgements  \nI would like to refer to a Nigerian Igbo proverb \"It takes a village to raise a child!\" 1. Indeed it feels like it took a village of Rhodes MSc staﬀ, my family and some previous colleagues and friends for me to have ﬁnished this masters. I dedicate this to all who stuck by me during this challenge.  \nMy wife, Tiana Goosen, who slept many a night alone, while I typed away at this masters.  \nFamily for backing me and for patience.  \nAlan Herbert for supervising me through a very busy and diﬃcult time for focus.  \nKaren Bradshaw for being a phenomenal supervisor and very patient and wise counsel on this journey.  \nLiam Smit for advising, spell checking and for reminding me to do my work.  \nVirus Total for giving me access to the academic dataset, which included a large number of Linux malware samples.  \nThe group behind the Leipzig Intrusion Detection Data Set, for the excellent dataset used in this research.  \n1 [http://www.ngopulse.org/article/it-takes-village-raise-child](http://www.ngopulse.org/article/it-takes-village-raise-child)  \nGlossary  \nAI artiﬁcial intelligence. 48  \nAPI application programming interface. 14, 21  \nAUC area under the curve. 36, 38, 72, 73, 75, 77, 92  \nBoSC bag of system calls. 30, 31, 37, 38  \nbotnets A network of bots (Yamaguchi, 2020) . 18  \nBOW Bag-Of-Words. x, 29, 30, 31, 32, 60  \nc&c command-and-control servers. 20, 46  \nCIA conﬁdentiality integrity availability. 6, 7  \nCVE Common vulnerabilities and exposures. 51  \nDARPA Defense Advanced Research Projects Agency. 1  \nDoS denial of service attack. 7, 15, 20, 24  \nELF executable and linking format. 55  \nHIDS host intrusion detection system. xii, 51, 53  \nIDS intrusion detection systems. 1, 2, 3, 7, 8, 9, 10, 11, 12, 22, 23, 25, 31, 41  \nIPC inter-process communication. 22  \nJSON Javascript object notation. xii, 55  \nLID-DS Leipzig Intrusion Detection Data Set. i, xii, 4, 40, 42, 50, 51, 52, 57, 69, 94 MAC message a","cbCaioY9wrrn911R","https://ap.wps.com/l/cbCaioY9wrrn911R","pdf",1785440,1,124,"English","en",105,"# Glossary\n# List of Figures\n# List of Tables\n# 1 Introduction\n## 1.1 Context of the Research\n## 1.2 Research Motivation\n## 1.3 Research Statement\n## 1.4 Research Objectives\n## 1.5 Approach\n## 1.6 Structure of this Thesis\n# 2 Literature Review\n## 2.1 CIA Model\n### 2.1.1 Conﬁdentiality\n### 2.1.2 Integrity\n### 2.1.3 Availability\n### 2.1.4 Suitability of the model\n## 2.2 Intrusion Detection","[{\"question\":\"What problem does the research address in intrusion detection?\",\"answer\":\"It targets the difficulty of using system call return data for threat detection when logs often lack arguments and obvious exploit traces.\"},{\"question\":\"Which datasets and malware sources are used?\",\"answer\":\"The study uses the Leipzig University academic system-call dataset and combines it with executed malware samples from the VirusTotal Academic dataset.\"},{\"question\":\"How do the machine learning approaches compare, and what is the main result?\",\"answer\":\"Random Forest is compared with Isolation Forest using decision-tree based methods, and the study finds Isolation Forest combined with PCA performs effectively, with hyper-parameter tuning improving anomaly and potential zero-day detection accuracy.\"}]","Natural Language Processing with Machine Learning for Anomaly Detection on System Call Logs | PDF",1785807396,312,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"natural-language-processing-with-machine-learning-for-anomaly-detection-on-system-call-logs","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/natural-language-processing-with-machine-learning-for-anomaly-detection-on-system-call-logs/121877/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-04",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the research address in intrusion detection?","Question",{"text":76,"@type":77},"It targets the difficulty of using system call return data for threat detection when logs often lack arguments and obvious exploit traces.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Which datasets and malware sources are used?",{"text":81,"@type":77},"The study uses the Leipzig University academic system-call dataset and combines it with executed malware samples from the VirusTotal Academic dataset.",{"name":83,"@type":74,"acceptedAnswer":84},"How do the machine learning approaches compare, and what is the main result?",{"text":85,"@type":77},"Random Forest is compared with Isolation Forest using decision-tree based methods, and the study finds Isolation Forest combined with PCA performs effectively, with hyper-parameter tuning improving anomaly and potential zero-day detection accuracy.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]