Next Article in Journal
Containment Invariants: Securing Intentionally Vulnerable Systems for Education, Training, and Research
Previous Article in Journal
Towards Responsible AI for IoT Network Security Auditing Using Knowledge Graph and RAGAS
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls

1
Université Grenoble Alpes, CEA, Leti, 38000 Grenoble, France
2
Université Grenoble Alpes, CNRS, Grenoble INP, LIG, 38000 Grenoble, France
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2026, 6(3), 99; https://doi.org/10.3390/jcp6030099
Submission received: 23 March 2026 / Revised: 28 May 2026 / Accepted: 2 June 2026 / Published: 6 June 2026

Abstract

The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of 209 publications from the scientific literature between 1996 and early 2026 highlights trends in this field of research and defines a taxonomy presenting the different approaches proposed by researchers. Eighteen state-of-the-art methods, representative of the diversity of approaches proposed in the literature, were reproduced and evaluated on two public datasets, ADFA-LD and NGIDS-DS. The detection performance and overhead of each method are examined in great detail, opening discussions on the shortcomings of the state of the art, limitations of system call-based IDSs, and lines of research that would enable this type of detection system to meet the challenges of deployment in a real-world environment. Finally, recommendations for future work are derived from these findings.
Keywords: systematic literature review (SLR); intrusion detection systems (IDS); system calls; machine learning (ML) systematic literature review (SLR); intrusion detection systems (IDS); system calls; machine learning (ML)

Share and Cite

MDPI and ACS Style

Arnoud, L.; Breux, V.; Thevenon, P.-H.; Gaussier, É. SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls. J. Cybersecur. Priv. 2026, 6, 99. https://doi.org/10.3390/jcp6030099

AMA Style

Arnoud L, Breux V, Thevenon P-H, Gaussier É. SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls. Journal of Cybersecurity and Privacy. 2026; 6(3):99. https://doi.org/10.3390/jcp6030099

Chicago/Turabian Style

Arnoud, Lalie, Victor Breux, Pierre-Henri Thevenon, and Éric Gaussier. 2026. "SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls" Journal of Cybersecurity and Privacy 6, no. 3: 99. https://doi.org/10.3390/jcp6030099

APA Style

Arnoud, L., Breux, V., Thevenon, P.-H., & Gaussier, É. (2026). SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls. Journal of Cybersecurity and Privacy, 6(3), 99. https://doi.org/10.3390/jcp6030099

Article Metrics

Back to TopTop