Lalie Arnoud, Victor Breux, Pierre-Henri Thevenon, Éric Gaussier
This repository contains the research material used for the Systematic Literature Review (SLR) presented in the article "SoK: An in-depth analysis of Intrusion Detection Systems based on System Calls", published in MDPI Journal of Cybersecurity and Privacy (DOI: 10.3390/jcp6030099).
The result of searches in the Scopus, IEEE Xplore, and ACM Guide to Computing Literature digital libraries are respectively available in the following files:
scopus.csv(293 publications)xplore.csv(121 publications)acm.csv(132 publications)
As stated in associated publication, searches were performed on December, 4th 2025.
In the literature_analysis.xlsx spreadsheet are listed:
- Formatted references for collected publications following the search for primary studies (
rawpage); - Reasons for inclusion or exclusion of each publication, both for the literature analysis and for the reproduction of presented intrusion detection method, followed by the characteristics identified according to the taxonomy defined in the article (
processedpage); - Computing of the number of publications concerned for each identified characteristic and by year of publication, enabling the study of trends in the research field (
temporal analysispage).
For further information or clarification regarding this work, do not hesitate to contact us using the following format: Firstname.Name@cea.fr
We kindly ask that any derivations or publications arising from this research provide a citation for the associated journal article:
@Article{jcp6030099,
AUTHOR = {Arnoud, Lalie and Breux, Victor and Thevenon, Pierre-Henri and Gaussier, Éric},
TITLE = {SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls},
JOURNAL = {Journal of Cybersecurity and Privacy},
VOLUME = {6},
YEAR = {2026},
NUMBER = {3},
ARTICLE-NUMBER = {99},
URL = {https://www.mdpi.com/2624-800X/6/3/99},
ISSN = {2624-800X},
ABSTRACT = {The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of 209 publications from the scientific literature between 1996 and early 2026 highlights trends in this field of research and defines a taxonomy presenting the different approaches proposed by researchers. Eighteen state-of-the-art methods, representative of the diversity of approaches proposed in the literature, were reproduced and evaluated on two public datasets, ADFA-LD and NGIDS-DS. The detection performance and overhead of each method are examined in great detail, opening discussions on the shortcomings of the state of the art, limitations of system call-based IDSs, and lines of research that would enable this type of detection system to meet the challenges of deployment in a real-world environment. Finally, recommendations for future work are derived from these findings.},
DOI = {10.3390/jcp6030099}
}
1: CEA-Leti, Université Grenoble Alpes, F-38000, Grenoble, France.
2: Laboratoire d'Informatique de Grenoble, Université Grenoble Alpes, Grenoble, France.
This work was supported by the French National Research Agency in the framework of the “Investissements d’avenir” program IRT Nanoelec (ANR-10-AIRT-05), and was partially supported by the French National Research Agency under the France 2030 labels SuperviZ (ANR-22-PECY-0008) and MIAI Cluster (ANR-23-IACL-0006). The views reflected herein do not necessarily reflect the opinion of the French government.
This project is licensed under the GNU General Public License v3.0 (GPLv3). See the LICENSE file for full details.