{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T10:21:08Z","timestamp":1725877268977},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319519654"},{"type":"electronic","value":"9783319519661"}],"license":[{"start":{"date-parts":[[2016,12,29]],"date-time":"2016-12-29T00:00:00Z","timestamp":1482969600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-51966-1_5","type":"book-chapter","created":{"date-parts":[[2016,12,28]],"date-time":"2016-12-28T06:11:08Z","timestamp":1482905468000},"page":"68-84","source":"Crossref","is-referenced-by-count":2,"title":["An Optimal Metric-Aware Response Selection Strategy for Intrusion Response Systems"],"prefix":"10.1007","author":[{"given":"Nadine","family":"Herold","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Wachs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stephan-A.","family":"Posselt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Georg","family":"Carle","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,12,29]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Anuar, N., Papadaki, M., Furnell, S., Clarke, N.: An investigation and survey of response options for intrusion response systems (irss). In: Information Security for South Africa (ISSA) (2010)","DOI":"10.1109\/ISSA.2010.5588654"},{"key":"5_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"136","DOI":"10.1007\/978-3-540-45248-5_8","volume-title":"Recent Advances in Intrusion Detection","author":"I Balepin","year":"2003","unstructured":"Balepin, I., Maltsev, S., Rowe, J., Levitt, K.: Using specification-based intrusion detection for automated response. In: Vigna, G., Kruegel, C., Jonsson, E. (eds.) RAID 2003. LNCS, vol. 2820, pp. 136\u2013154. Springer, Heidelberg (2003). doi: 10.1007\/978-3-540-45248-5_8"},{"key":"5_CR3","unstructured":"Carver, C.A., Hill, J.M., Pooch, U.W.: Limiting uncertainty in intrusion response. In: Proceedings of the IEEE Workshop on Information Assurance and Security (2001)"},{"key":"5_CR4","doi-asserted-by":"crossref","unstructured":"Costante, E., Fauri, D., Etalle, S., den Hartog, J., Zannone, N.: A hybrid framework for data loss prevention and detection. In: Proceedings of the Workshop on Research for Insider Threats (WRIT) (2016)","DOI":"10.1109\/SPW.2016.24"},{"key":"5_CR5","doi-asserted-by":"crossref","DOI":"10.1515\/9781400884179","volume-title":"Linear Programming and Extensions","author":"G Dantzig","year":"1963","unstructured":"Dantzig, G.: Linear Programming and Extensions. Princeton University Press, Princeton (1963)"},{"key":"5_CR6","volume-title":"Information Assurance: Dependability and Security in Networked Systems","author":"B Foo","year":"2008","unstructured":"Foo, B., Glause, M.W., Howard, G.M., Wu, Y.S., Bagchi, S., Spafford, E.H.: Intrusion response systems: a survey. In: Qian, Y., Joshi, J., Tipper, D., Krishnamurthy, P. (eds.) Information Assurance: Dependability and Security in Networked Systems. Morgan Kaufmann, Burlington (2008)"},{"key":"5_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1007\/978-3-642-33704-8_14","volume-title":"Computer Network Security","author":"G Gonzalez Granadillo","year":"2012","unstructured":"Gonzalez Granadillo, G., D\u00e9bar, H., Jacob, G., Gaber, C., Achemlal, M.: Individual countermeasure selection based on the return on response investment index. In: Kotenko, I., Skormin, V. (eds.) MMM-ACNS 2012. LNCS, vol. 7531, pp. 156\u2013170. Springer, Heidelberg (2012). doi: 10.1007\/978-3-642-33704-8_14"},{"key":"5_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-319-47560-8_3","volume-title":"Secure IT Systems","author":"G Gonzalez-Granadillo","year":"2016","unstructured":"Gonzalez-Granadillo, G., Alvarez, E., Motzek, A., Merialdo, M., Garcia-Alfaro, J., Debar, H.: Towards an automated and dynamic risk management response system. In: Brumley, B.B., R\u00f6ning, J. (eds.) NordSec 2016. LNCS, vol. 10014, pp. 37\u201353. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-47560-8_3"},{"key":"5_CR9","doi-asserted-by":"crossref","unstructured":"Granadillo, G.G., Motzek, A., Garcia-Alfaro, J., Debar, H.: Selection of mitigation actions based on financial and operational impact assessments. In: 11th International Conference on Availability, Reliability and Security (ARES) (2016)","DOI":"10.1109\/ARES.2016.3"},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"Hasswa, A., Zulkernine, M., Hassanein, H.: Routeguard: an intrusion detection and response system for mobile ad hoc networks. In: IEEE International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob) (2005)","DOI":"10.1109\/WIMOB.2005.1512922"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Jahnke, M., Thul, C., Martini, P.: Graph based metrics for intrusion response measures in computer networks. In: 32nd IEEE Conference on Local Computer Networks (LCN) (2007)","DOI":"10.1109\/LCN.2007.45"},{"key":"5_CR12","doi-asserted-by":"crossref","first-page":"875","DOI":"10.1109\/TKDE.2010.151","volume":"23","author":"A Kamra","year":"2011","unstructured":"Kamra, A., Bertino, E.: Design and implementation of an intrusion response system for relational databases. IEEE Trans. Knowl. Data Eng. 23, 875\u2013888 (2011)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"5_CR13","doi-asserted-by":"crossref","unstructured":"Kanoun, W., Cuppens-Boulahia, N., Cuppens, F., Dubus, S., Martin, A.: Intelligent response system to mitigate the success likelihood of ongoing attacks. In: 6th International Conference on Information Assurance and Security (IAS) (2010)","DOI":"10.1109\/ISIAS.2010.5604054"},{"key":"5_CR14","volume-title":"Complexity of Computer Computations","author":"R Karp","year":"1972","unstructured":"Karp, R.: Reducibility among combinatorial problems. In: Miller, R.E., Thatcher, J.W., Bohlinger, J.D. (eds.) Complexity of Computer Computations. Plenum Press, New York (1972)"},{"key":"5_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"626","DOI":"10.1007\/978-3-642-15497-3_38","volume-title":"Computer Security \u2013 ESORICS 2010","author":"N Kheir","year":"2010","unstructured":"Kheir, N., Cuppens-Boulahia, N., Cuppens, F., Debar, H.: A service dependency model for cost-sensitive intrusion response. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol. 6345, pp. 626\u2013642. Springer, Heidelberg (2010). doi: 10.1007\/978-3-642-15497-3_38"},{"key":"5_CR16","volume-title":"Toward Cost-sensitive Modeling for Intrusion Detection and Response","author":"W Lee","year":"2002","unstructured":"Lee, W., Miller, M., Stolfo, S.J., Fan, W., Zadok, E.: Toward Cost-sensitive Modeling for Intrusion Detection and Response. IOS Press, Amsterdam (2002)"},{"key":"5_CR17","doi-asserted-by":"crossref","first-page":"1102","DOI":"10.1016\/j.compeleceng.2012.06.001","volume":"38","author":"V Mateos","year":"2012","unstructured":"Mateos, V., Villagr\u00e1, V.A., Romero, F., Berrocal, J.: Definition of response metrics for an ontology-based automated intrusion response systems. Comput. Electr. Eng. 38, 1102\u20131114 (2012)","journal-title":"Comput. Electr. Eng."},{"key":"5_CR18","doi-asserted-by":"crossref","first-page":"2465","DOI":"10.1016\/j.eswa.2009.07.079","volume":"37","author":"CM Mu","year":"2010","unstructured":"Mu, C.M., Li, Y.: An intrusion response decision-making model based on hierarchical task network planning. Expert Syst. Appl. 37, 2465\u20132472 (2010)","journal-title":"Expert Syst. Appl."},{"key":"5_CR19","doi-asserted-by":"crossref","unstructured":"Ossenb\u00fchl, S., Steinberger, J., Baier, H.: Towards automated incident handling: how to select an appropriate response against a network-based attack? In: 9th International Conference on IT Security Incident Management IT Forensics (IMF) (2015)","DOI":"10.1109\/IMF.2015.13"},{"key":"5_CR20","unstructured":"Porras, P.A., Neumann, P.G.: EMERALD: event monitoring enabling responses to anomalous live disturbances. In: National Information Systems Security Conference (1997)"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Ragsdale, D., Carver, C., Humphries, J., Pooch, U.: Adaptation techniques for intrusion detection and intrusion response systems. In: IEEE International Conference on Systems, Man, and Cybernetics (2000)","DOI":"10.1109\/ICSMC.2000.884341"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"Scarfone, K.A., Grance, T., Masone, K.: Computer security incident handling guide (spp. 800\u201361 rev. 1.). Technical report, National Institute of Standards & Technology (2008)","DOI":"10.6028\/NIST.SP.800-61r1"},{"key":"5_CR23","first-page":"1","volume":"12","author":"A Shameli-Sendi","year":"2012","unstructured":"Shameli-Sendi, A., Ezzati-jivan, N., Jabbarifar, M., Dagenais, M.: Intrusion response systems: survey and taxonomy. Int. J. Comput. Sci. Netw. Secur. (IJCSNS) 12, 1\u201314 (2012)","journal-title":"Int. J. Comput. Sci. Netw. Secur. (IJCSNS)"},{"key":"5_CR24","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-8348-8194-6","volume-title":"Metriken - Der Schl\u00fcssel Zum Erfolgreichen Security und Compliance Monitoring: Design, Implementierung und Validierung in Der Praxis","author":"A Sowa","year":"2011","unstructured":"Sowa, A., Fedtke, S.: Metriken - Der Schl\u00fcssel Zum Erfolgreichen Security und Compliance Monitoring: Design, Implementierung und Validierung in Der Praxis. Vieweg+Teubner Verlag, Heidelberg (2011)"},{"key":"5_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1007\/3-540-45474-8_9","volume-title":"Recent Advances in Intrusion Detection","author":"D Sterne","year":"2001","unstructured":"Sterne, D., Djahandari, K., Wilson, B., Babson, B., Schnackenberg, D., Holliday, H., Reid, T.: Autonomic response to distributed denial of service attacks. In: Lee, W., M\u00e9, L., Wespi, A. (eds.) RAID 2001. LNCS, vol. 2212, pp. 134\u2013149. Springer, Heidelberg (2001). doi: 10.1007\/3-540-45474-8_9"},{"key":"5_CR26","doi-asserted-by":"crossref","unstructured":"Strasburg, C., Stakhanova, N., Basu, S., Wong, J.: A framework for cost sensitive assessment of intrusion response selection. In: 33rd Annual IEEE International Computer Software and Applications Conference (COMPSAC) (2009)","DOI":"10.1109\/COMPSAC.2009.54"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Strasburg, C., Stakhanova, N., Basu, S., Wong, J.S.: Intrusion response cost assessment methodology. In: Proceedings of the 4th International Symposium on Information, Computer, and Communications Security (ASIACCS) (2009)","DOI":"10.1145\/1533057.1533112"},{"key":"5_CR28","doi-asserted-by":"crossref","unstructured":"Sultana, S., Midi, D., Bertino, E.: Kinesis: a security incident response and prevention system for wireless sensor networks. In: Proceedings of the 12th ACM Conference on Embedded Network Sensor Systems (SenSys) (2014)","DOI":"10.1145\/2668332.2668351"},{"key":"5_CR29","doi-asserted-by":"crossref","unstructured":"Toth, T., Kruegel, C.: Evaluating the impact of automated intrusion response mechanisms. In: Proceedings of 18th Annual Computer Security Applications Conference (2002)","DOI":"10.1109\/CSAC.2002.1176302"},{"key":"5_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1007\/978-3-540-74320-0_7","volume-title":"Recent Advances in Intrusion Detection","author":"S-H Wang","year":"2007","unstructured":"Wang, S.-H., Tseng, C.H., Levitt, K., Bishop, M.: Cost-sensitive intrusion responses for mobile ad hoc networks. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 127\u2013145. Springer, Heidelberg (2007). doi: 10.1007\/978-3-540-74320-0_7"},{"key":"5_CR31","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/65.484228","volume":"10","author":"G White","year":"1996","unstructured":"White, G., Fisch, E., Pooch, U.: Cooperating security managers: a peer-based intrusion detection system. IEEE Netw. 10, 20\u201323 (1996)","journal-title":"IEEE Netw."},{"key":"5_CR32","unstructured":"Wu, Y., Liu, S.: A cost-sensitive method for distributed intrusion response. In: 12th International Conference on Computer Supported Cooperative Work in Design (CSCWD) (2008)"},{"key":"5_CR33","doi-asserted-by":"crossref","first-page":"605","DOI":"10.1016\/j.cose.2009.03.005","volume":"28","author":"Z Zhang","year":"2009","unstructured":"Zhang, Z., Ho, P.H., He, L.: Measuring ids-estimated attack impacts for rational incident response: a decision theoretic approach. Comput. Secur. 28, 605\u2013614 (2009). Elsevier Advanced Technology Publications","journal-title":"Comput. Secur."}],"container-title":["Lecture Notes in Computer Science","Foundations and Practice of Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-51966-1_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,25]],"date-time":"2017-06-25T02:55:33Z","timestamp":1498359333000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-51966-1_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,12,29]]},"ISBN":["9783319519654","9783319519661"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-51966-1_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016,12,29]]}}}