Intrusion detection systems (IDS) analyze traffic and host behavior to identify malicious activity like system misuse, unauthorized file changes, and physical break-ins (via host sensors). They are not designed to filter unsolicited bulk email (SPAM), which is handled by email gateways.