Zero-day attacks, a persistent issue to traditional cybersecurity systems due to lack of predetermined signatures and behavioral profiles at the time of compromise, are the focus of this survey. The studied methods can be categorized into eight types by methodology: empirical and conceptual frameworks, systematic literature reviews, supervised machine learning and deep learning, unsupervised anomaly detection, vision transformer-based techniques, explainable AI, real-time hybrid detection, and vulnerability-prioritization and ransomware specific architectures. Data suggests zero-day vulnerabilities can remain unaddressed for an extensive length of time, but the likelihood of exploiting them increases considerably after public disclosure. Detected performance results span from the around 90% in the early KDD based methods up to over 99% in some explainable MLP based methods. This cannot be taken at face value, as evaluation is plagued by heterogeneity of datasets, features, attack categories and training configurations used among studies. Challenges that arise consist of encrypted and obfuscated traffic, outdated benchmarks, class imbalance, high latency, false positive rate, poor explainability and evaluation methods not reflective of a zero-day environment. In many instances it seems evidenced, by an increase in family holdout testing, zero-day hit rate and analysis through Wasserstein distance, rather than the standard random-split accuracy. Future research areas have been suggested towards achieving intelligent, transparent and effective real-time zero-day systems that handle out-of-distribution data with ease.
