PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
June 10, 2026Journal of Cybersecurity and Privacy0 citationsOpen Access

SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls

View Full Paper
LALalie ArnoudVBVictor BreuxPTPierre-Henri Thevenon

Key Points

  • This research analyzes various system call-based intrusion detection systems to identify trends and performance limitations.
  • Conducted a systematic analysis of 209 publications from 1996 to 2026.
  • Reproduced and evaluated 18 state-of-the-art methods on two public datasets: ADFA-LD and NGIDS-DS.
  • Examined detection performance and operational overhead of these methods.
  • Identified significant shortcomings in state-of-the-art system call-based IDSs.
  • Detailed performance metrics and operational overhead for each evaluated method.
  • Outlined recommendations for improving real-world deployment of these detection systems.

Abstract

The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of 209 publications from the scientific literature between 1996 and early 2026 highlights trends in this field of research and defines a taxonomy presenting the different approaches proposed by researchers. Eighteen state-of-the-art methods, representative of the diversity of approaches proposed in the literature, were reproduced and evaluated on two public datasets, ADFA-LD and NGIDS-DS. The detection performance and overhead of each method are examined in great detail, opening discussions on the shortcomings of the state of the art, limitations of system call-based IDSs, and lines of research that would enable this type of detection system to meet the challenges of deployment in a real-world environment. Finally, recommendations for future work are derived from these findings.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Arnoud et al. (2026) studied this question.

synapsesocial.com/papers/6a28fe716f82f25be989bc21https://doi.org/10.3390/jcp6030099
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1The Study of Intrusion Prediction Based on HsMM2008 · 15 citations
  2. 2Obfuscated malware detection using API call dependency2012 · 19 citations
  3. 3CryptoGuard: Lightweight Hybrid Detection and Response to Host-based Cryptojackers in Linux Cloud Environments2025 · 4 citations
  4. 4Detecting mobile botnets through machine learning and system calls analysis2017 · 29 citations
  5. 5Symbolic analysis meets federated learning to enhance malware identifier2022 · 11 citations