{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T21:32:29Z","timestamp":1784842349781,"version":"3.55.0"},"reference-count":84,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2015,5,11]],"date-time":"2015-05-11T00:00:00Z","timestamp":1431302400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"AGT International"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2015,7,21]]},"abstract":"<jats:p>The dependency of our society on networked computers has become frightening: In the economy, all-digital networks have turned from facilitators to drivers; as cyber-physical systems are coming of age, computer networks are now becoming the central nervous systems of our physical world\u2014even of highly critical infrastructures such as the power grid. At the same time, the 24\/7 availability and correct functioning of networked computers has become much more threatened: The number of sophisticated and highly tailored attacks on IT systems has significantly increased. Intrusion Detection Systems (IDSs) are a key component of the corresponding defense measures; they have been extensively studied and utilized in the past. Since conventional IDSs are not scalable to big company networks and beyond, nor to massively parallel attacks, Collaborative IDSs (CIDSs) have emerged. They consist of several monitoring components that collect and exchange data. Depending on the specific CIDS architecture, central or distributed analysis components mine the gathered data to identify attacks. Resulting alerts are correlated among multiple monitors in order to create a holistic view of the network monitored. This article first determines relevant requirements for CIDSs; it then differentiates distinct building blocks as a basis for introducing a CIDS design space and for discussing it with respect to requirements. Based on this design space, attacks that evade CIDSs and attacks on the availability of the CIDSs themselves are discussed. The entire framework of requirements, building blocks, and attacks as introduced is then used for a comprehensive analysis of the state of the art in collaborative intrusion detection, including a detailed survey and comparison of specific CIDS approaches.<\/jats:p>","DOI":"10.1145\/2716260","type":"journal-article","created":{"date-parts":[[2015,5,11]],"date-time":"2015-05-11T16:30:57Z","timestamp":1431361857000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":262,"title":["Taxonomy and Survey of Collaborative Intrusion Detection"],"prefix":"10.1145","volume":"47","author":[{"given":"Emmanouil","family":"Vasilomanolakis","sequence":"first","affiliation":[{"name":"Technische Universit\u00e4t Darmstadt\/CASED"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shankar","family":"Karuppayah","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Darmstadt\/CASED"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Max","family":"M\u00fchlh\u00e4user","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Darmstadt\/CASED"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathias","family":"Fischer","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Darmstadt\/CASED"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,5,11]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/WAINA.2012.29"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1041680.1041681"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_9"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/784589.784631"},{"key":"e_1_2_1_6_1","volume-title":"Handbook of Information and Communication Security","author":"Barry Bazara I. A."},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the 14th USENIX Security Symposium. 193--208","author":"Bethencourt John"},{"key":"e_1_2_1_8_1","volume-title":"Kommunikation in Verteilten Systemen (KiVS)","author":"Brinkmeier Michael"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2004.10129096"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the Workshop on Collaborative Methods for Security and Privacy (CollSec). 1--12","author":"Bye Rainer","year":"2010"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.63"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.803069"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"e_1_2_1_14_1","unstructured":"Tsung-huan Cheng Y. Lin Yuan-cheng Lai and Po-ching Lin. 2011. Evasion techniques: Sneaking through your intrusion detection\/prevention systems. IEEE Communications Surveys &amp; Tutorials 99 (2011) 1--10.  Tsung-huan Cheng Y. Lin Yuan-cheng Lai and Po-ching Lin. 2011. Evasion techniques: Sneaking through your intrusion detection\/prevention systems. IEEE Communications Surveys &amp; Tutorials 99 (2011) 1--10."},{"key":"e_1_2_1_16_1","unstructured":"Mark Crosbie B. Dole T. Ellis Ivan Krsul and E. H. Spafford. 1996. Idiot-Users Guide. Technical Report.  Mark Crosbie B. Dole T. Ellis Ivan Krsul and E. H. Spafford. 1996. Idiot-Users Guide. Technical Report."},{"key":"e_1_2_1_17_1","volume-title":"Annual Computer Security Applications","author":"Cuppens Fr\u00e9d\u00e9ric"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830542"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32808-4_6"},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the ACM Workshop on Data Mining for Security Applications. 1--13","author":"Dain Oliver"},{"key":"e_1_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Herve Debar David A. Curry and Benjamin S. Feinstein. 2007. The Intrusion Detection Message Exchange Format (IDMEF). The Internet Engineering Task Force (IETF).  Herve Debar David A. Curry and Benjamin S. Feinstein. 2007. The Intrusion Detection Message Exchange Format (IDMEF). The Internet Engineering Task Force (IETF).","DOI":"10.17487\/rfc4765"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/324119.324126"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/645839.670735"},{"key":"e_1_2_1_24_1","volume-title":"Peer-to-Peer Systems","author":"Douceur John R."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/DEXA.2006.21"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5555\/597917.597921"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2010.12.004"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the USENIX Security Symposium. 241--256","author":"Fogla Prahlad","year":"2006"},{"key":"e_1_2_1_29_1","first-page":"63","article-title":"Collaborative intrusion detection networks and insider attacks","volume":"2","author":"Fung Carol","year":"2011","journal-title":"Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87353-2_9"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/1688933.1688938"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2003.1176982"},{"key":"e_1_2_1_33_1","volume-title":"Information and Communications Security","author":"Garcia Joaquin"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.08.003"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-012-9230-8"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/4236.935182"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1031607.1031663"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the USENIX Symposium on Internet Technologies and Systems (USITS)","volume":"4","author":"Harvey Nicholas J. A.","year":"2003"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/121973.121975"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.5555\/938984.939801"},{"key":"e_1_2_1_41_1","first-page":"84","article-title":"Research on intrusion detection and response: A survey","volume":"1","author":"Kabiri Peyman","year":"2005","journal-title":"International Journal of Network Security"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/775152.775242"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SNPD-SAWN.2005.31"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/646283.687988"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/508791.508835"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/362375.362389"},{"key":"e_1_2_1_47_1","volume-title":"Managing Cyber Threats.","author":"Lazarevic Aleksandar"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/1162666.1162669"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the IEEE Workshop on Information Assurance and Security. IEEE, 333--339","author":"Locasto Michael E."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04474-8_37"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2005.07.011"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.5555\/1754701.1754710"},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the National Information Systems Security Conference (NISSC\u201997)","author":"Phillip"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/1218063.1217938"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_11"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/986537.986581"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/355112.355122"},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the USENIX Annual Techincal Conference. 127--140","author":"Rhea Sean","year":"2004"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/1090191.1080102"},{"key":"e_1_2_1_63_1","volume-title":"Proceedings of the USENIX Conference on System Administration. 229--238","author":"Roesch Martin","year":"1999"},{"key":"e_1_2_1_64_1","first-page":"329","article-title":"Pastry: Scalable, decentralized object location, and routing for large-scale peer-to-peer systems","volume":"2001","author":"Rowstron Antony","year":"2001","journal-title":"Middleware"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISIM.2008.14"},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 14th USENIX Security Symposium. 209--224","author":"Shinoda Yoichi"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352664.1352673"},{"key":"e_1_2_1_68_1","volume-title":"Proceedings of the 14th National Computer Security Conference. 167--176","author":"Snapp Steven","year":"1991"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.90"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00136-5"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.5555\/956415.956438"},{"key":"e_1_2_1_72_1","volume-title":"Advances in Parallel Distributed Computing","author":"Srivastava A."},{"key":"e_1_2_1_73_1","volume-title":"Proceedings of the National Information Systems Security Conference. 361--370","author":"Stuart Steven Cheung","year":"1996"},{"key":"e_1_2_1_74_1","volume-title":"Recent Advances in Intrusion Detection","volume":"2516","author":"Tan Kymie M. C."},{"key":"e_1_2_1_75_1","volume-title":"Recent Advances in Intrusion Detection","author":"Valdes Alfonso"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.5555\/2735338.2735349"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2009.02.010"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2006.180"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2004.01.002"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_2_1_81_1","unstructured":"Vinod Yegneswaran Paul Barford and Somesh Jha. 2004. Global intrusion detection in the domino overlay system. In Network and Distributed System Security (NDSS).  Vinod Yegneswaran Paul Barford and Somesh Jha. 2004. Global intrusion detection in the domino overlay system. In Network and Distributed System Security (NDSS)."},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2007.4317620"},{"key":"e_1_2_1_83_1","volume-title":"Proceedings of the IEEE Workshop on Information Assurance and Security. IEEE, 85--90","author":"Zhang Zheng","year":"2001"},{"key":"e_1_2_1_84_1","volume-title":"Proceedings of the International Conference on Networks. IEEE, 118--123","author":"Zhou Chenfeng Vincent","year":"2005"},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2007.374772"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2008.4575116"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.06.008"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2716260","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2716260","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:16:55Z","timestamp":1750227415000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2716260"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,5,11]]},"references-count":84,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2015,7,21]]}},"alternative-id":["10.1145\/2716260"],"URL":"https:\/\/doi.org\/10.1145\/2716260","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,5,11]]},"assertion":[{"value":"2014-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-01-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-05-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}