Sometimes Simpler is Better: A Comprehensive Analysis of State-of-the-Art Provenance-Based Intrusion Detection Systems

Tristan Bilot, Université Paris-Saclay, LISITE, Isep, and Iriguard; Baoxiang Jiang, Xi'an Jiaotong University; Zefeng Li, University of British Columbia; Nour El Madhoun, LISITE, Isep; Khaldoun Al Agha, Université Paris-Saclay; Anis Zouaoui, Iriguard; Thomas Pasquier, University of British Columbia

Provenance-based intrusion detection systems (PIDSs) have garnered significant attention from the research community over the past decade. Although recent studies report near-perfect detection performance, we show that these systems are not viable for practical deployment. We implemented eight state-of-the-art systems within a unified framework and identified nine key shortcomings that hinder their practical adoption. Through extensive experiments, we quantify the impact of these shortcomings using cybersecurity-oriented metrics and propose solutions to address them for real-world applicability. Building on these insights, we demonstrate that most existing systems add unnecessary complexity, whereas a simple neural network achieves state-of-the-art detection on five of seven DARPA datasets while offering a lighter, faster, and real-time detection solution. Finally, we highlight critical open research challenges that remain unaddressed in the current literature, paving the way for future advancements. To support research, we open-source our framework and provide pre-processed datasets with ground truth to support consistent evaluation.

Category: 
Long Presentation

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {309524,
author = {Tristan Bilot and Baoxiang Jiang and Zefeng Li and Nour El Madhoun and Khaldoun Al Agha and Anis Zouaoui and Thomas Pasquier},
title = {Sometimes Simpler is Better: A Comprehensive Analysis of {State-of-the-Art} {Provenance-Based} Intrusion Detection Systems},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {7193--7212},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/bilot},
publisher = {USENIX Association},
month = aug
}

Presentation Video