The rapidly increasing series of Internet-scale disrupted threat is a pressing problem for every organization that utilizes the network. Many research institutions focus on collaborative security, of which collaborative intrusion detection is an important component. Sharing data among widely distributed intrusion detection systems is essential. To this end, IDWG (intrusion detection working group) proposed a draft in IDMEF (intrusion detection message exchange format). This paper aims at improving the IDMEF data model to foster interoperability and to maximize extensibility the messages which represented in XML. This is expected to become a generally-useful type of data. Finally, it implements the new IDMEF data model in XML.