Dodda, Vineeth Kumar (2025) AI-Powered Detection of OS Command Injection Using TF-IDF and Logistic Regression to Mitigate System Exploitation. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (738kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (540kB) | Preview |
Abstract
OS command injection, a vector connected with privilege escalation, remote code execution, system exploitation, and malware attacks, poses critical risks to modern computing environments [Usama & Aman, 2024; Wang et al., 2024]. These attacks can undermine access controls, compromise entire infrastructures, and result in severe data loss. Existing detection methods, whether based on traditional rules or AI techniques, have notable gaps, as few combine both approaches and focus specifically on command injection linked to broad system attacks [Ferrag et al., 2020; Tasdemir et al., 2023]. To address this, I developed and studied a hybrid system that harnesses TF-IDF feature extraction and logistic regression analysis as part of a custom AI-powered Model Context Protocol (MCP) server, integrating this with GitHub Copilot and open-source large language models for interactive, chat-based detection [Wang et al., 2025; Khare et al., 2023]. The system distinguishes itself both by combining classical machine learning and generative AI, and by offering multi-level analysis: syntax validation, semantic classification, and context-aware enrichment (including command type, severity, verdict, mitigation steps, and execution results). Quantitative evaluation showed performance scores above 0.75 for accuracy, precision, recall, and F1-measure, while qualitative inspection confirmed the system’s ability to deliver detailed, actionable descriptions for each command. In theory, the work advances existing research by demonstrating the value of hybrid ML–AI architectures and novel MCP integration for rapid, robust exploitation detection [Tasdemir et al., 2023; Ye et al., 2024].. Practically, it enables developers and security teams to benefit from a proactive, hassle-free, and instant detection workflow, leveraging continuous updates from the latest LLM models for precise analysis and improved command abuse prevention. Unresolved limitations include the challenges with heavily obfuscated payloads, and the opportunity to further extend detection power with deep learning models and a web dashboard interface, which will be addressed in future work.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Prior, Michael UNSPECIFIED |
| Subjects: | Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 03 Sep 2026 10:50 |
| Last Modified: | 03 Sep 2026 10:50 |
| URI: | https://norma.ncirl.ie/id/eprint/9796 |
Actions (login required)
![]() |
View Item |
Tools
Tools