
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Sree Vishnu H¹
¹B.Sc Digital & Cyber Forensics Science, Rathinam College of Arts and Science, Coimbatore - 641021, India.
Abstract - The rapid expansion of digital systems has significantly increased exposure to cybersecurity threats. While modern security tools are capable of detecting known attack patterns, many real-world compromises still occur due to weak system configurations and improper user management. These issues are often simple but can lead to serious security incidents if not addressed proactively. This paper presents HCA-Guard (Human & Configuration Analysis Guard), a host-based intrusion detection and response system designed to address these practical challenges. The system focuses on analyzing system configurations, user privileges, and service exposure to identify potential vulnerabilities. It incorporates key features such as reverse shell detection, risk scoring, and automated response mechanisms to improve threat mitigation. When suspicious activity is detected, the system evaluates its severity and performs appropriate actions such as process termination and alert generation. The system operates entirely at the host level, ensuring data privacy and reducing dependency on external infrastructure. Experimental evaluation under different scan modes shows that HCA-Guard can effectively identify both minor misconfigurations and critical vulnerabilities with minimal performance overhead. The results demonstrate that focusing on configuration and human-related risks provides a practical and effective approach to improving endpoint security.
Key Words: CyberSecurity,IntrusionDetection,ConfigurationAnalysis,HumanRiskAssessment,ReverseShellDetection, EndpointSecurity,DigitalForensics
Theincreasingrelianceondigitalsystemsineverydaylifehasmadecybersecurityafundamentalrequirementratherthanan optionalfeature.Frompersonaldevicestoenterprise-levelinfrastructures,systemsarecontinuouslyexposedtothreatsthat targetconfidentiality,integrity,andavailability,andastechnologyadvances,theattacksurfacealsoexpands,makingiteasier forattackerstoexploitvulnerabilities.Althoughsignificantprogresshasbeenmadeindevelopingsecuritytools,manyexisting solutionsprimarilyfocusondetectingknownattacksignaturesorpatterns,which,whileeffectiveagainstpreviouslyidentified threats,donotfullyaddressthedynamicnatureofmoderncyber-attacks.Inmanypracticalsituations,attackersexploitsimple weaknessessuchaspoorlyconfiguredsystems,weakauthenticationmechanisms,andimproperuserprivilegemanagement.It iscommonlyobservedthatsecuritybreachesoccurduetoissuessuchasmisconfiguredsystemsettings,unnecessaryservice exposure,excessiveuserprivileges,andlackofcontinuousmonitoring,andthesefactorsareoftenunderestimatedbecause theydonotappearasdirectthreats,yettheysignificantlyincreasetheriskofsystemcompromise.Toaddressthesechallenges, thispaperintroducesHCA-Guard,ahost-basedintrusiondetectionandresponsesystemthatfocusesonbothconfiguration analysisandhuman-relatedriskfactors,aimingtoidentifyinternalweaknesses,evaluaterisklevels,andprovideappropriate responsemechanisms,therebyofferingapracticalandeffectiveapproachtoimprovingsystemsecurity.
Despitetheavailabilityofnumerouscybersecuritytoolsandframeworks,severalpracticallimitationscontinuetoaffecttheir effectivenessinreal-worldenvironments.Oneoftheprimarylimitationsistheheavyrelianceonsignature-baseddetection techniques,whichareeffectiveinidentifyingknownthreatsbutfailtodetectnew,unknown,ormodifiedattackpatterns, allowing emerging threats to bypass traditional security mechanisms. Another key limitation is the lack of proper configuration-levelanalysis,asmanysystemsdonotactivelyverifywhetherasystemissecurelyconfigured,leavingissues suchasopenports,unnecessaryservices,andweakormisconfiguredsecuritypoliciesundetected,therebyincreasingthe attacksurface.Human-relatedrisksarealsofrequentlyoverlooked,whereusersmayhaveexcessiveprivileges,followweak authentication practices,or manage accountsimproperly,unintentionallyintroducingseriousvulnerabilitiesthatare not adequately addressed by traditional security solutions. Furthermore, many modern systems depend on cloud-based infrastructures,whichintroduceconcernsrelatedtoprivacy,latency,andsystemdependency,makingthemunsuitablefor certainenvironments.Anothermajorchallengeisthegenerationofexcessivealertswithoutproperprioritization,leadingto alertfatigueandmakingitdifficultforuserstoidentifycriticalthreats.Theselimitationshighlighttheneedforamorepractical

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
approachthatfocusesnotonlyonthreatdetectionbutalsoonidentifyingandmitigatingconfigurationandhuman-relatedrisk factorswithinthesystem.

The resultspresentedinTable1demonstrate the effectivenessofHCA-Guardacrossdifferentscanmodes.TheBasic Scan identifiesminorissues,whiletheMediumScandetectsmoderaterisksrelatedtosystemconfiguration.TheDeepScanperforms acomprehensiveevaluationandsuccessfullyidentifiescriticalvulnerabilities.Theseobservationsindicatethatthesystemcan detectandcategorizerisksbasedonseverity,enablingefficientprioritizationandimprovingoverallsystemsecurity.

ThesystemarchitectureofHCA-Guardillustratesthecompleteworkflowoftheproposedintrusiondetectionandresponse system.Theprocessbeginswithdatacollectionfromthehostsystem,includingsystemconfigurations,useractivities,and runningprocesses.Thisdataisthenpassedtotheanalysismodule,wherepotentialthreatsandanomaliesareidentified.Therisk evaluationcomponentassessestheseverityofdetectedissuesbasedonpredefinedcriteriaandassignsappropriaterisklevels. Based on the evaluated risk, the system triggers automated response mechanisms such as process termination or alert generation.Finally,thereportingmoduleprovidesaclearsummaryofdetectedvulnerabilitiesandactionstaken,enablingusers tounderstandandimprovethesecuritypostureofthesystem.
Theproposedsystem,HCA-Guard,isdesignedasahost-basedintrusiondetectionandresponseframeworkthatfocuseson identifying both configuration-related vulnerabilities and human-centric risks. The system continuously monitors system configurations,userprivileges,andrunningprocessestodetectanomaliesandpotentialthreats.Itintegratesmodulessuchas datacollection,threatanalysis,riskevaluation,automatedresponse,andreportingtoensureeffectivethreatdetectionand

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
mitigation.Byoperatingatthehostlevel,thesystemmaintainsdataprivacyandreducesdependencyonexternalinfrastructures whileprovidingefficientandreal-timesecurityanalysis.
ThemethodologyofHCA-Guardfollowsastructuredapproachconsistingofdatacollection,analysis,andresponse.Initially,the systemgathershost-leveldataincludingsystemconfigurations,userprivileges,andactiveprocesses,whicharethenanalyzed toidentifyanomalies,misconfigurations,andpotentialsecurityvulnerabilities.Ariskscoringmechanismisappliedtoclassify detectedissuesbasedontheirseveritylevels,andbasedontheevaluatedrisk,appropriateactionsaretriggeredthroughthe automatedresponsemodule,suchasalertgenerationorprocesstermination.Thesystemoperateswithcontinuousmonitoring andperiodicscanningtoensureconsistentsecurityandsystemstability.
Thesystemperformanceremainedstableacrossdifferentscanmodeswithoutsignificantresourceoverhead.TheBasicScan modewasabletodetectminorissues,whiletheMediumScanidentifiedmoderaterisksrelatedtosystemconfigurationand policysettings.TheDeepScanmodeprovidedacomprehensiveevaluationandsuccessfullydetectedcriticalvulnerabilitiesthat couldpotentiallycompromisesystemsecurity.TheresultsindicatethatHCA-Guardiscapableofidentifyingbothlow-level misconfigurationsandhigh-riskvulnerabilitieseffectively,anditsabilitytocategorizerisksbasedonseverityallowsusersto prioritize actionsand respondefficiently.Additionally,the automated response mechanism reducesthe time required to handle threats,improvingoverall systemsecurityandreliability.The observedresultsconfirmthat the systemperforms efficientlywithminimaloverheadwhilemaintainingeffectivethreatdetectioncapabilities.
This paper presented HCA-Guard, a host-based intrusion detection and response system designed to address practical cybersecurity challenges associated with system misconfigurations and human-related risks. Unlike traditional security solutions that primarily focus on signature-based detection, the proposed system emphasizes identifying underlying vulnerabilitiesthatoftenleadtoreal-worldsecuritybreaches.TheresultsdemonstratethatHCA-Guardiscapableofeffectively detectingandcategorizingrisksacrossdifferentscanmodeswhilemaintainingsystemstabilityandlowresourceoverhead, andtheintegrationofautomatedresponsemechanismsfurtherenhancesthesystem’sabilitytomitigatethreatsinrealtime, reducingdependencyonmanualintervention.Overall,theproposedsystemprovidesapracticalandefficientapproachto improvingendpointsecuritybycombiningconfigurationanalysis,riskevaluation,andautomatedresponse,andfuturework may focus on enhancing detection accuracy through intelligent analysis techniques and extending the system to support network-levelmonitoringforbroadersecuritycoverage.
Theauthorwouldliketoexpresssinceregratitude toDr.T.Velumani,Headofthe Department,Departmentof Computer Science,RathinamCollegeofArtsandScience,Coimbatore,forhisvaluableguidance,support,andencouragementthroughout thedevelopmentofthiswork.
[1]NIST,“FrameworkforImprovingCriticalInfrastructureCybersecurity,”NationalInstituteofStandardsand Technology,2018.
[2]CenterforInternetSecurity(CIS),“CISCriticalSecurityControls,”Version8,2021.
[3]OWASPFoundation,“OWASPTop10:TheTenMostCriticalWebApplicationSecurityRisks,”2021.
[4]W.Stallings,NetworkSecurityEssentials:ApplicationsandStandards,6thed.,Pearson,2018.
[5]M.Bishop,ComputerSecurity:ArtandScience,Addison-Wesley,2003.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Sree Vishnu H iscurrentlyaB.Sc. Digital and Cyber Forensics Science student from Rathinam College of Arts and Science, Coimbatore, India. His interests includecybersecurity,penetration testing,anddigitalforensics.