From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures
Organizations: Dept. of Software and IT Engineering ´Ecole de technologie sup´erieure ( ´ETS) Montr´eal, Qu´ebec, Canada · Dept. of Computer Science University of Calgary Calgary, Alberta, Canada
Abstract
While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate blockchain's distinct functional roles into a single monolithic category. This Systematization of Knowledge (SoK) addresses these gaps by proposing a three-axis taxonomy that classifies proposals by detection-system class (NIDS, HIDS, EDR/XDR), blockchain functional role, and response-automation maturity. Synthesizing research published in high-impact venues between 2019 and 2026, we provide a rigorous gap analysis exposing why a genuine per-endpoint blockchain-anchored response loop remains nearly nonexistent due to latency, deployment, and community mismatches. Furthermore, we evaluate structural, cross-cutting challenges persisting across the literature, including consensus latency on constrained devices, post-quantum cryptographic vulnerability, smart-contract attack surfaces, and the adversarial vulnerability of evolving LLM-based detection engines. Finally, we outline a comprehensive research agenda centered on hybrid on-chain/off-chain orchestration to bridge the gap between decentralized trust and rapid response automation.
Figures & tables
| Primitive | Taxonomy mapping |
|---|---|
| Immutable ledgers | Axis 2: Role L (evidentiary/audit) |
| Consensus protocols | Axis 2: Role T (trust/consensus) |
| Incentive layers | Axis 2: Role I (incentive) |
| FL integrity assurance | Axis 2: Role F (FL-integrity) |
| Smart contracts | Cross-cutting: implements Axis 3 |
| (R2/R3 response automation) atop L/T/I/F |
| Representative System / Source | Detection Class | BC Role | Response | Notes |
|---|---|---|---|---|
| Lightweight federated intrusion prevention, IIoT [ 9 ] | IPS (IIoT) | T, F | R2 | Resource-constrained devices; scalability bottleneck reported |
| Blockchain-FL collaborative IDS, vehicular edge [ 37 ] | NIDS (vehicular) | T, F | R1 | IEEE TVT; FL aggregation secured on-chain |
| CGAN-based collaborative IDS, UAV networks [ 38 ] | NIDS (UAV) | T, F | R1 | Distributed FL across UAV swarm |
| PoFQ consensus for decentralized threat hunting [ 33 ] | NIDS | T | R1–R2 | Novel consensus protocol, trustless setting |
| Securing FL with blockchain + XAI, IoT [ 39 ] | NIDS (IoT) | F | R1 | Explainability layer added to FL-IDS |
| CyberNFTs reward-driven IDS [ 23 ] | NIDS | I, T | R0–R1 | Conceptual; incentive layer is the core contribution |