Distributed Intrusion Detection Systems: Architecture, Challenges, And Performance Evaluation

  • Unique Paper ID: 208480
  • PageNo: 244-251
  • Abstract:
  • The rapid growth of computer networks, cloud computing, and Internet of Things (IoT) devices has increased the number and complexity of cyberattacks. Traditional Intrusion Detection Systems (IDS), which depend mainly on a central system, can face difficulties when dealing with large amounts of network traffic and monitoring different parts of a network. Distributed Intrusion Detection Systems (DIDS) offer a solution by using multiple detection systems that work together to monitor network activities and identify possible attacks. This paper provides an overview of DIDS and discusses different architectures, including hierarchical, peer to-peer, multi-agent, and cloud- and edge-based approaches. It also explains the main functions of DIDS, such as collecting network data, analysing activities, sharing information between detection nodes, and responding to detected threats. The paper discusses the main benefits of DIDS, including better scalability, improved reliability, and the ability to monitor larger and distributed networks. At the same time, several challenges are considered, such as communication between detection nodes, maintaining consistent information, managing trust, handling high network traffic, and protecting the detection system from attacks. The performance of DIDS can be measured using factors such as detection accuracy, false positive rate, detection time, throughput, and resource usage. Common datasets, including NSLKDD, CICIDS2017, and UNSW-NB15, are used in research to evaluate intrusion detection methods. The paper also discusses the balance between good detection performance and the resources required by the system. Finally, future research areas such as privacy-preserving detection, load balancing, federated learning, blockchain based trust, and edge computing are discussed as possible ways to make Distributed Intrusion Detection Systems more secure, reliable, and efficient.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{208480,
        author = {Mr. Piyush Mahesh Tiwatne and Ms. Sakshi Vishwas Gade and Ms. Pooja Govindram Parmar and Mr. Laxman Jalindar Gaikwad and Prof. Rajashri S. Khadake},
        title = {Distributed Intrusion Detection Systems: Architecture, Challenges, And Performance Evaluation},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {no},
        pages = {244-251},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=208480},
        abstract = {The rapid growth of computer networks, cloud computing, and Internet of Things (IoT) devices has increased the number and complexity of cyberattacks. Traditional Intrusion Detection Systems (IDS), which depend mainly on a central system, can face difficulties when dealing with large amounts of network traffic and monitoring different parts of a network. Distributed Intrusion Detection Systems (DIDS) offer a solution by using multiple detection systems that work together to monitor network activities and identify possible attacks. This paper provides an overview of DIDS and discusses different architectures, including hierarchical, peer to-peer, multi-agent, and cloud- and edge-based approaches. It also explains the main functions of DIDS, such as collecting network data, analysing activities, sharing information between detection nodes, and responding to detected threats. The paper discusses the main benefits of DIDS, including better scalability, improved reliability, and the ability to monitor larger and distributed networks. At the same time, several challenges are considered, such as communication between detection nodes, maintaining consistent information, managing trust, handling high network traffic, and protecting the detection system from attacks. The performance of DIDS can be measured using factors such as detection accuracy, false positive rate, detection time, throughput, and resource usage. Common datasets, including NSLKDD, CICIDS2017, and UNSW-NB15, are used in research to evaluate intrusion detection methods. The paper also discusses the balance between good detection performance and the resources required by the system. Finally, future research areas such as privacy-preserving detection, load balancing, federated learning, blockchain based trust, and edge computing are discussed as possible ways to make Distributed Intrusion Detection Systems more secure, reliable, and efficient.},
        keywords = {Cybersecurity, Distributed Computing, Distributed Intrusion Detection Systems, Federated Learning, Internet of Things, Intrusion Detection, Network Security, Performance Evaluation.},
        month = {September},
        }

Cite This Article

Tiwatne, M. P. M., & Gade, M. S. V., & Parmar, M. P. G., & Gaikwad, M. L. J., & Khadake, P. R. S. (2026). Distributed Intrusion Detection Systems: Architecture, Challenges, And Performance Evaluation. International Journal of Innovative Research in Technology (IJIRT), 244–251.

Related Articles