期刊文献+

可回卷的自动入侵响应系统 被引量:5

Rollbackable Automated Intrusion Response System
下载PDF
导出
摘要 本文描述了入侵响应回卷的形式化方法及其实现 ,然后建立了一个可回卷的自动入侵响应系统模型 .该系统在检测到误报或入侵停止的情况下 ,采取响应回卷动作 ,从而消除了响应带来的负面影响 ,即响应代价 .试验证明 ,响应回卷技术能较好地降低响应代价 ,从而以较低的代价换取相同的安全目标 . Traditional intrusion detection systems only carry out response when intrusion is detected. It has two shortcomings. First, when the previous intrusion events that had been responded are proved to be false alarms, the response system cannot correct its response. Secondly, when the intrusion behavior terminates, the response system cannot withdraw the corresponding response so as to eliminate the negative effect. In this paper, a Rollbackable Automated Intrusion Response System (RAIRS) is established to cope with the above two problems. RAIRS can not only automatically detect response, but also detect false alarms and termination of intrusion, and then triggers the rollback of corresponding response to eliminate its negative effect. The experiment proves that the response rollback technique can decrease the response cost so that it can achieve the same security goal with lower cost.
作者 张剑 龚俭
出处 《电子学报》 EI CAS CSCD 北大核心 2004年第5期769-773,共5页 Acta Electronica Sinica
基金 国家自然科学基金 (No .90 1 0 4 0 31 )
关键词 入侵检测系统 自动响应系统 响应回卷 中止检测算法 Computer networks Condition monitoring Formal logic
  • 相关文献

参考文献6

  • 1Curtis A Carver,Udo W Pooch.An intrusion response taxonomy and its role in automatic intrusion response[A].Proceeding of the 2000 IEEE Workshop on Information Assurance and Security[C].West Point,NY:United states military academy,2000.129-135. 被引量:2
  • 2Christopher W Geib,Robert P Goldman.Plan recognition in intrusion detection system[A].In DARPA Information Survivability Conference & Exposition II[C].Hilton Anaheim,California,2001.46-55. 被引量:1
  • 3Dan Schnackenberg,Kelly Djahandari,Dan Sterne.Infrastructure for intrusion detection and response[A].Proceedings of the DARPA Information Survivability Conference and Exposition(DISCEX) 2000[C].Hilton Head,S.C,2000.1507-1516. 被引量:1
  • 4Dan Schnackenberg,et al.Cooperative intrusion traceback and response architecture(CITRA)[A].Proceedings of the DARPA Information Survivability Conference and Exposition(DISCEX) 2001[C].Anaheim Califonia,2001. 被引量:2
  • 5ZHANG Jian,GONG Jian,DING Yong.Intrusion detection system based on fuzzy default logic[A].Proceeding of the 2003 IEEE Workshop on Fuzzy System[C].St.Louis,2003. 被引量:1
  • 6Wenke Lee,Wei Fan,et al.Toward cost-sensitive modeling for intrusion detection and response[J].Journal of Computer Security,2002,10(1):318-336. 被引量:1

共引文献1

同被引文献48

引证文献5

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部