2012 · International Journal of Computer Science and Network Security
Intrusion Response Systems: Survey and Taxonomy
Evidence basis: full-text-reviewed · Review status: catalog-reviewed; paper-author approval pending
anomaly-detection root-cause-analysis observability
intrusion response systems response cost automated response NIDS HIDS IDMEF adaptive response retroactive response attack paths risk assessment
Core contribution: This survey organizes intrusion-response systems around automation, response cost, decision evaluation, adjustment, execution, attack paths, and risk assessment.
Problem and motivation
Automated intrusion responses can damage services, resources, or users and may turn an attack response into a denial-of-service condition. The paper seeks a taxonomy that exposes these weaknesses and guides response selection (printed pp. 1-3, 10-12).
Method and contribution
This is a conceptual survey/taxonomy, not a new implementation. It classifies IRS by automation degree; alert inputs; response-cost factors; static, statically evaluated, or dynamically evaluated decisions; adaptive versus non-adaptive adjustment; and burst versus retroactive execution (pp. 1-8).
Findings and evidence
The synthesis identifies response cost, system state, response history, attack paths, risk assessment, and prediction as central design dimensions. No original dataset, benchmark, implementation, or quantitative evaluation was verified.
Limitations and future directions
Limitations: Claims are conceptual and depend on the surveyed IRS literature. The paper does not provide a reproducible implementation or empirical benchmark; local binary evidence is unavailable.
Future work: Online response-cost evaluation; response adaptation using history; grouped retroactive response; real single- and multi-step attack datasets; state-aware risk assessment; and attack-path-aware IRS (printed pp. 11-12).
Sources and identifiers
- Institutional publication record publication_signal
- Remote full-text source remote_full_text_read
When to cite this paper
Cite this paper when your work uses or compares the automation-degree taxonomy separating notification, manual, and automated intrusion response.
- The automation-degree taxonomy separating notification, manual, and automated intrusion response.
- Response-cost-aware IRS design, including service/resource, user, privilege, and attack-category impacts.
- The distinction between adaptive/non-adaptive and burst/retroactive response execution.
- The concrete research agenda for real multi-step attack datasets, online cost evaluation, state-aware risk, and attack-path-aware response.
Citation
@article{ezzatiJivan2012intrusionresponse,
author = {Alireza Shameli-Sendi and Naser Ezzati-Jivan and Masoume Jabbarifar and Michel Dagenais},
title = {Intrusion Response Systems: Survey and Taxonomy},
year = {2012},
journal = {International Journal of Computer Science and Network Security},
url = {https://publications.polymtl.ca/14629/}
}Other citation formats for Word and reference managers
Shameli-Sendi, A., Ezzati-Jivan, N., Jabbarifar, M., & Dagenais, M. (2012). Intrusion Response Systems: Survey and Taxonomy. International Journal of Computer Science and Network Security,. https://publications.polymtl.ca/14629/A. Shameli-Sendi, N. Ezzati-Jivan, M. Jabbarifar, and M. Dagenais, "Intrusion Response Systems: Survey and Taxonomy," International Journal of Computer Science and Network Security, 2012, [Online]. Available: https://publications.polymtl.ca/14629/