ABSTRACT Operating systems are increasingly targeted by cyber attacks that exploit system-level resources and compromise process behaviour. Traditional intrusion detection methods often rely on network monitoring or signature-based approaches, which may fail to detect new or evolving threats. This research proposes an intelligent intrusion detection framework that analyses system call activity generated by running processes in an operating system. System calls act as the interface between user applications and the operating system kernel, making them a valuable source for understanding program behaviour. The proposed framework monitors patterns of system calls such as file access, execution requests, permission changes, and process creation. These behavioural patterns are used to distinguish between normal and malicious process activities. A machine learning model is trained to classify process behaviour based on system call features and identify abnormal patterns that may indicate an intrusion. Experimental evaluation demonstrates that the framework can effectively detect suspicious behaviour while maintaining reliable detection performance. By focusing on system call activity at the operating system level, the proposed approach enhances security by enabling early detection of potential threats and strengthening system protection against cyber attacks. Keywords: Intrusion Detection System, Operating System Security, System Call Analysis, Machine Learning, Behavioural Analysis.
Meenakshi et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: