I had an idea a while back for a HIDS or at least post-infection analysis. You record incoming data and files onto storage. Have a separate machine running it which is instrumented to check all jumps, etc against a whitelist generated when compiling same system. It would eventually spot the compromise plus be able to show the exact sequence of data & instructions that caused it. Which would aid patching it.
Stayed on prevention instead. Thought it would be fun building & optimizing it, though.