arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从网络入侵检测到区块链支持的端点检测与响应:去中心化检测与响应架构全景映射

From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures

Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang

arXiv 2610.01872首次发表:更新:

发表机构

École de technologie supérieure (ÉTS); University of Calgary(高等技术学院(ÉTS); 卡尔加里大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对现有综述忽视EDR/XDR架构及混淆区块链角色的局限,提出三轴分类法系统化分析2019-2026年文献,揭示每端点区块链响应缺失的根因,并规划混合链上/链下编排的研究议程。

AI 中文摘要

尽管关于物联网(IoT)和工业物联网(IIoT)网络中区块链辅助入侵检测与防御系统(IDS/IPS)的文献已相当成熟,现有系统综述仍存在两个关键局限:它们忽视了向现代端点检测与响应(EDR)和扩展检测与响应(XDR)架构的结构性转变,并且将区块链的不同功能角色混为一谈,归入单一整体类别。本知识系统化(SoK)通过提出一个三轴分类法来解决这些空白,该分类法根据检测系统类别(NIDS、HIDS、EDR/XDR)、区块链功能角色以及响应自动化成熟度对提案进行分类。综合2019年至2026年间发表于高影响力场所的研究,我们提供了严谨的差距分析,揭示了为何真正的每端点区块链锚定响应循环因延迟、部署和社区不匹配而几乎不存在。此外,我们评估了文献中持续存在的结构性、跨领域挑战,包括受限设备上的共识延迟、后量子密码学脆弱性、智能合约攻击面,以及不断演进的基于大语言模型(LLM)的检测引擎的对抗性脆弱性。最后,我们概述了一个以混合链上/链下编排为核心的综合研究议程,以弥合去中心化信任与快速响应自动化之间的差距。

英文摘要

While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate blockchain's distinct functional roles into a single monolithic category. This Systematization of Knowledge (SoK) addresses these gaps by proposing a three-axis taxonomy that classifies proposals by detection-system class (NIDS, HIDS, EDR/XDR), blockchain functional role, and response-automation maturity. Synthesizing research published in high-impact venues between 2019 and 2026, we provide a rigorous gap analysis exposing why a genuine per-endpoint blockchain-anchored response loop remains nearly nonexistent due to latency, deployment, and community mismatches. Furthermore, we evaluate structural, cross-cutting challenges persisting across the literature, including consensus latency on constrained devices, post-quantum cryptographic vulnerability, smart-contract attack surfaces, and the adversarial vulnerability of evolving LLM-based detection engines. Finally, we outline a comprehensive research agenda centered on hybrid on-chain/off-chain orchestration to bridge the gap between decentralized trust and rapid response automation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑