{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/49411"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/49411","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"The Triple Pot and techniques in distributed system call intrusion detection","abstract":"In cyber security, engineers need to devise ways to protect their systems from hackers. One of the ways that they do this is through intrusion detection. Host based intrusion detection systems reside on the computer and perform internal diagnostics of a computer to detect malware and misuse. These HIDS use a variety of methods to detect and prevent attacks such as file integrity verification, log monitoring, file access patterns and etc. In this thesis, we look at the method of analyzing system calls for anomalous behavior. Programs use system calls to gain access to functions from an operating systems kernel. Therefore, it is theoretically possible to detect when a hacker may be exploiting a program by analyzing system call patterns of an application. However, despite previous work in this area, there remain many challenges to accurately detecting malicious exploits and intruders through system call analysis which have prevented it from being used in real systems. To help bridge the gap and address the challenges in making system call analysis a reality, we introduce a new method of system call analysis that we call the Triple Pot method. Our method utilizes three computers running concurrently on the same network to check for anomalous behavior of an application. The key idea is that by setting up a staged, fake network of computers we can get the hacker to identify their exploit for us. We will show how our method can be used to automatically identify zero day attacks that could not previously have been detected using previous system call analysis methods. In addition, we also introduce a method to aggregate and analyze system calls from distributed machines to use information from multiple computers to detect zero day attacks. We do this by creating a probabilistic model of the networked computer systems to determine the likelihood that an application is exhibiting anomalous behavior that is caused by a malicious hacker. Our methods can accurately locate malicious behavior with low false positives.","abstract_html":"In cyber security, engineers need to devise ways to protect their systems from hackers. One of the ways that they do this is through intrusion detection. Host based intrusion detection systems reside on the computer and perform internal diagnostics of a computer to detect malware and misuse. These HIDS use a variety of methods to detect and prevent attacks such as file integrity verification, log monitoring, file access patterns and etc. In this thesis, we look at the method of analyzing system calls for anomalous behavior. Programs use system calls to gain access to functions from an operating systems kernel. Therefore, it is theoretically possible to detect when a hacker may be exploiting a program by analyzing system call patterns of an application. However, despite previous work in this area, there remain many challenges to accurately detecting malicious exploits and intruders through system call analysis which have prevented it from being used in real systems. To help bridge the gap and address the challenges in making system call analysis a reality, we introduce a new method of system call analysis that we call the Triple Pot method. Our method utilizes three computers running concurrently on the same network to check for anomalous behavior of an application. The key idea is that by setting up a staged, fake network of computers we can get the hacker to identify their exploit for us. We will show how our method can be used to automatically identify zero day attacks that could not previously have been detected using previous system call analysis methods. In addition, we also introduce a method to aggregate and analyze system calls from distributed machines to use information from multiple computers to detect zero day attacks. We do this by creating a probabilistic model of the networked computer systems to determine the likelihood that an application is exhibiting anomalous behavior that is caused by a malicious hacker. Our methods can accurately locate malicious behavior with low false positives.","abstract_has_math":false,"creators":["Chu, Jonathan"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Campbell, Roy H."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2014,"date_issued":"2014-05-30T16:42:36Z","date_published":"2014-05-30T16:42:36Z","updated_at":"2026-07-22T22:25:38Z","subjects":["system call","intrusion detection","security","computers"],"languages":["en"],"rights":["Copyright 2014 Jonathan Ming-Guy Chu"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/49411","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Campbell, Roy H."]},{"key":"dc:creator","label":"Author","values":["Chu, Jonathan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2014-05-30T16:42:36Z","2014-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["system call","intrusion detection","security","computers"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2014 Jonathan Ming-Guy Chu"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/49411"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["In cyber security, engineers need to devise ways to protect their systems from hackers. One of the ways that they do this is through intrusion detection. Host based intrusion detection systems reside on the computer and perform internal diagnostics of a computer to detect malware and misuse. These HIDS use a variety of methods to detect and prevent attacks such as file integrity verification, log monitoring, file access patterns and etc. In this thesis, we look at the method of analyzing system calls for anomalous behavior. Programs use system calls to gain access to functions from an operating systems kernel. Therefore, it is theoretically possible to detect when a hacker may be exploiting a program by analyzing system call patterns of an application. However, despite previous work in this area, there remain many challenges to accurately detecting malicious exploits and intruders through system call analysis which have prevented it from being used in real systems. To help bridge the gap and address the challenges in making system call analysis a reality, we introduce a new method of system call analysis that we call the Triple Pot method. Our method utilizes three computers running concurrently on the same network to check for anomalous behavior of an application. The key idea is that by setting up a staged, fake network of computers we can get the hacker to identify their exploit for us. We will show how our method can be used to automatically identify zero day attacks that could not previously have been detected using previous system call analysis methods. In addition, we also introduce a method to aggregate and analyze system calls from distributed machines to use information from multiple computers to detect zero day attacks. We do this by creating a probabilistic model of the networked computer systems to determine the likelihood that an application is exhibiting anomalous behavior that is caused by a malicious hacker. Our methods can accurately locate malicious behavior with low false positives.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-29T20:14:07Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 mythesis.docx: 1130909 bytes, checksum: 1fa8aa3939267ca78d7d9c914285590b (MD5) Chu_Jonathan.pdf: 507057 bytes, checksum: ddc7699a6c734eb5b7dc37a883c97b5c (MD5)","Made available in DSpace on 2014-05-30T16:42:36Z (GMT). No. of bitstreams: 4 Jonathan_Chu.pdf: 502670 bytes, checksum: 47ded871402416360dd046f5e0010168 (MD5) mythesis.docx: 1129666 bytes, checksum: a88bf35bd4ad1c1be2fa76756098b04f (MD5) 1_mythesis.docx: 1129666 bytes, checksum: a88bf35bd4ad1c1be2fa76756098b04f (MD5) license.txt: 4060 bytes, checksum: 71f36c4ba1a7a03400d4ead625948ba1 (MD5)"]},{"key":"dc:title","label":"Title","values":["The Triple Pot and techniques in distributed system call intrusion detection"]}]}],"canonical_facts":{"dc:contributor":["Campbell, Roy H."],"dc:creator":["Chu, Jonathan"],"dc:date":["2014-05-30T16:42:36Z","2014-05"],"dc:description":["In cyber security, engineers need to devise ways to protect their systems from hackers. One of the ways that they do this is through intrusion detection. Host based intrusion detection systems reside on the computer and perform internal diagnostics of a computer to detect malware and misuse. These HIDS use a variety of methods to detect and prevent attacks such as file integrity verification, log monitoring, file access patterns and etc. In this thesis, we look at the method of analyzing system calls for anomalous behavior. Programs use system calls to gain access to functions from an operating systems kernel. Therefore, it is theoretically possible to detect when a hacker may be exploiting a program by analyzing system call patterns of an application. However, despite previous work in this area, there remain many challenges to accurately detecting malicious exploits and intruders through system call analysis which have prevented it from being used in real systems. To help bridge the gap and address the challenges in making system call analysis a reality, we introduce a new method of system call analysis that we call the Triple Pot method. Our method utilizes three computers running concurrently on the same network to check for anomalous behavior of an application. The key idea is that by setting up a staged, fake network of computers we can get the hacker to identify their exploit for us. We will show how our method can be used to automatically identify zero day attacks that could not previously have been detected using previous system call analysis methods. In addition, we also introduce a method to aggregate and analyze system calls from distributed machines to use information from multiple computers to detect zero day attacks. We do this by creating a probabilistic model of the networked computer systems to determine the likelihood that an application is exhibiting anomalous behavior that is caused by a malicious hacker. Our methods can accurately locate malicious behavior with low false positives.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-29T20:14:07Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 mythesis.docx: 1130909 bytes, checksum: 1fa8aa3939267ca78d7d9c914285590b (MD5) Chu_Jonathan.pdf: 507057 bytes, checksum: ddc7699a6c734eb5b7dc37a883c97b5c (MD5)","Made available in DSpace on 2014-05-30T16:42:36Z (GMT). No. of bitstreams: 4 Jonathan_Chu.pdf: 502670 bytes, checksum: 47ded871402416360dd046f5e0010168 (MD5) mythesis.docx: 1129666 bytes, checksum: a88bf35bd4ad1c1be2fa76756098b04f (MD5) 1_mythesis.docx: 1129666 bytes, checksum: a88bf35bd4ad1c1be2fa76756098b04f (MD5) license.txt: 4060 bytes, checksum: 71f36c4ba1a7a03400d4ead625948ba1 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/49411"],"dc:language":["en"],"dc:rights":["Copyright 2014 Jonathan Ming-Guy Chu"],"dc:subject":["system call","intrusion detection","security","computers"],"dc:title":["The Triple Pot and techniques in distributed system call intrusion detection"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:38Z"}