Response Mechanisms for Intrusion Response Systems (IRSs)
Anuar NB, Furnell SM, Papadaki M, Clarke NL
Proceedings of the Fifth Collaborative Research Symposium on Security, E-learning, Internet and Networking (SEIN 2009), Darmstadt, Germany, ISBN: 978-1-84102-236-9, pp3-14, 2009
The rise of network attacks and incidents need additional and distinct methods of response. This paper discusses the different type of responses in Intrusion Detection Systems (IDSs), Intrusion Prevention Systems (IPSs) and Intrusion Response Systems (IRSs). Using characteristics of responses and the relationship between responses, a more effective model is proposed. The characteristics of responses include the level of operations, the speed and time of responses, the ability to learn and the ability to cooperate with other devices. Using an attack time frame, the relationship between active and passive response are discussed. The response mechanism model distinguishes between active, passive, and different approaches and stages of active responses.

