The Evolution of Network Intrusion Detection Systems: From Legacy to Programmable Networks

Mauro Tropea, Mattia Giovanni Spina, Floriano De Rango · IntechOpen eBooks · 2025

This chapter explores the transformation of Network Intrusion Detection Systems (NIDS) following the evolution of networks from traditional, static infrastructures to programmable entities. Legacy NIDSs are conceived as static, fixed perimeter-based hardware appliances that rely on patterns to detect malicious activities. As cyber threats evolve, these systems become inadequate, unable to keep pace with dynamic, high-speed environments. The rise of Network Function Virtualization (NFV) and Software-Defined Networking (SDN), which made the networks programmable as software, allows for more flexible, adaptive intrusion detection. Using real-time data analytics and machine learning, they enable the rapid identification and mitigation of sophisticated threats. This evolution is crucial in addressing modern cybersecurity challenges, as programmable networks open up to enhanced visibility, scalability, and proactive threat management. Trying to highlight this transition and also providing a practical deployment scenario, this chapter focuses on the innovations that make modern NIDSs more robust by exploiting the evolutionary leap that the network is undergoing.

Read the paper · More papers on PaperTik