cs.CROct 1, 2026

From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures

Authors: Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang

Organizations: Dept. of Software and IT Engineering ´Ecole de technologie sup´erieure ( ´ETS) Montr´eal, Qu´ebec, Canada · Dept. of Computer Science University of Calgary Calgary, Alberta, Canada

Abstract

While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate blockchain's distinct functional roles into a single monolithic category. This Systematization of Knowledge (SoK) addresses these gaps by proposing a three-axis taxonomy that classifies proposals by detection-system class (NIDS, HIDS, EDR/XDR), blockchain functional role, and response-automation maturity. Synthesizing research published in high-impact venues between 2019 and 2026, we provide a rigorous gap analysis exposing why a genuine per-endpoint blockchain-anchored response loop remains nearly nonexistent due to latency, deployment, and community mismatches. Furthermore, we evaluate structural, cross-cutting challenges persisting across the literature, including consensus latency on constrained devices, post-quantum cryptographic vulnerability, smart-contract attack surfaces, and the adversarial vulnerability of evolving LLM-based detection engines. Finally, we outline a comprehensive research agenda centered on hybrid on-chain/off-chain orchestration to bridge the gap between decentralized trust and rapid response automation.

Figures & tables

Explore similar work

CardsList
  1. Federated Learning over Blockchain-Enabled Cloud Infrastructure

    Apr 21, 2026Saloni Garg, Amit Sagtani, Kamal Kant HiranFederated LearningCloud

  2. Jev-IDS: System One Models for Network Intrusion Detection

    Oct 1, 2026Paulo Severo, Silvio E. Quincozes, Amanda DiasIntrusion DetectionRandom Forest

  3. Agentra: A Supervisable Multi-Agent Framework for Enterprise Intrusion Response

    Jun 16, 2026Raj Patel, Shaswata Mitra, Michele Guida +3Incident ResponseIntrusion Detection