We use cookies to make your experience of our website better. Details of our privacy policy is available here, and is also linked in the footer text on all pages.

Centre for Security, Communications and Network Research (CSCAN)  

Centre for Security, Communications and Network Research

Plymouth University

CSCAN with Plymouth University

Request a publication

Paper Title

A Response Strategy Model for Intrusion Response Systems

Authors

Anuar NB, Papadaki M, Furnell SM, Clarke NL

Publication/Conference

27th IFIP International Information Security and Privacy Conference - SEC2012

Reference

Heraklion, Crete, Greece, 4-6 June, pp573-578

Year

2012

Abstract

There are several types of security systems, which focus on detecting, mitigating and responding to incidents. Current response systems are largely based on manual incident response selection strategies, which can introduce delays between detection and response time. However, it would be beneficial if critical and urgent incidents are addressed as soon as possible before they jeopardised critical systems. As a result, the Risk Index Model (RIM) has been proposed earlier in our previous study, as a method of prioritising incidents based upon two decision factors namely impact on assets and likelihood of threat and vulnerability. This paper extends RIM by using it as the basis for mapping inci-dents with various response options. The proposed mapping model, Response Strategy Model (RSM) is based on risk response planning and time management concepts and it is evaluated using the DARPA 2000 dataset. The case study analysis upon the dataset has shown a significant result in mapping incident into different quadrants. In particular, the results have shown a significant relationship between the incident classification with incident priorities where false incidents are likely to be categorised as low priority incidents and true incidents are likely to be categorised as the high priority incident.

Status

Sorry, this publication is not currently available to the public due to copyright restrictions.

We are unable to provide copies of this publication at present.


Centre for Security, Communications and Network Research (CSCAN), Room A304 Portland Square, Plymouth University, Plymouth, PL4 8AA, United Kingdom
Telephone: +44 (0) 1752 586234, Fax: +44 (0) 1752 586300, Email: info@cscan.org