Without an IDS, i'm talking user investigation.
simply user investigation, monitoring outgoing connections at the host, by process. It should be done. And it's easier if svchost.exe is whitelisted.
(Plus alot of spyware - ALL spyware that uses svchost.exe, would be caught and stopped from communicating out. No hole in that concept. And i'm trying to say it's not useless, you say it is but I don't see your argument that it is )
if IDS is running administrative, then when the host is compromised, the IDS could be compromised
wouldn't that be a broken concept, and by your philosophy - worthless, snakeoil even!
And, you were talking of an IDSs that would'n't be compromised if the host is compromised. How can that be?