paper

A survey of coordinated attacks and collaborative intrusion detection

  • Authors:

📜 Abstract

Coordinated attacks, such as large-scale stealthy scans, worm outbreaks and distributed denial-of-service (DDoS) attacks, occur in multiple networks simultaneously. Such attacks are extremely difficult to detect using isolated intrusion detection systems (IDSs) that monitor only a limited portion of the Internet. In this paper, we summarize the current research directions in detecting such attacks using collaborative intrusion detection systems (CIDSs). In particular, we highlight two main challenges in CIDS research: CIDS architectures and alert correlation algorithms. We review the current CIDS approaches in terms of these two challenges. We conclude by highlighting opportunities for an integrated solution to large-scale collaborative intrusion detection.

✨ Summary

The paper established a structured survey of collaborative intrusion detection around two central design problems: distributed CIDS architectures and alert-correlation algorithms. It framed coordinated attacks—including distributed scans, worm outbreaks, and DDoS attacks—as threats whose evidence is distributed across network and administrative boundaries, motivating cross-network evidence sharing and integrated detection.

Subsequent research continued to use this framing. Later surveys treated the paper as a foundational reference for collaborative and distributed intrusion detection, including a 2015 taxonomy and survey of CIDS requirements, components, attacks, and approaches, as well as a 2016 survey of ensemble-based collaborative and distributed IDSs. (researchgate.net) The paper’s emphasis on correlating multiple attack events also aligns with later systematic work on multi-step attack detection, which catalogued 181 publications and 119 methods and identified modelling, automation, datasets, and reproducibility as continuing challenges. (sciencedirect.com)

The available citation evidence indicates sustained use in subsequent intrusion-detection surveys and research on alert correlation, anomaly detection, cloud IDSs, and attack detection. (sciencedirect.com)