• DocumentCode
    2362182
  • Title

    An investigation and survey of response options for Intrusion Response Systems (IRSs)

  • Author

    Anuar, Nor Badrul ; Papadaki, Maria ; Furnell, Steve ; Clarke, Nathan

  • Author_Institution
    Centre for Security, Commun. & Network Res., Univ. of Plymouth, Plymouth, UK
  • fYear
    2010
  • fDate
    2-4 Aug. 2010
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The rise of attacks and incidents need additional and distinct methods of response. This paper starts a discussion by differentiating the type of operation mode such as Intrusion Detection Systems (IDSs), Intrusion Prevention Systems (IPSs) and Intrusion Response Systems (IRSs). Using characteristics of response and attack time frame, a response model is proposed to distinguish between active and passive response options. The characteristics of response include level of operations, speed and time of response, ability to learn and ability to cooperate with other devices. This paper uses the attack time frame as a response model to show the relationship between active and passive response. Furthermore, the Response Model for Intrusion Response Systems shows some other different approaches and stages of active response. Finally, in order to investigate the most common response used by security practitioner and to justify the response model, studies involving 34 samples products from both commercial and non-commercial are analysed. As a result, this paper shows a clear distinction between the options of responses.
  • Keywords
    security of data; active response; attack time frame; intrusion detection system; intrusion prevention system; intrusion response system; passive response; response model; security practitioner; Fires; Home appliances; Intrusion detection; Real time systems; Time factors; Intrusion Response Systems (IRSs); active; proactive; reactive and passive response;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security for South Africa (ISSA), 2010
  • Conference_Location
    Sandton, Johannesburg
  • Print_ISBN
    978-1-4244-5493-8
  • Type

    conf

  • DOI
    10.1109/ISSA.2010.5588654
  • Filename
    5588654