{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T18:01:13Z","timestamp":1754157673300,"version":"3.41.2"},"reference-count":50,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2010,10,12]],"date-time":"2010-10-12T00:00:00Z","timestamp":1286841600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010,10,12]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The paper proposes looking at the automation of the incident response (IR) process, through formal, systematic and standardized methods for collection, normalization and correlation of security data (i.e. vulnerability, exploit and intrusion detection information).<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>The paper proposes the incident response intelligence system (IRIS) that models the context of discovered vulnerabilities, calculates their significance, finds and analyzes potential exploit code and defines the necessary intrusion detection signatures that combat possible attacks, using standardized techniques. It presents the IRIS architecture and operations, as well as the implementation issues.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>The paper presents detailed evaluation results obtained from real\u2010world application scenarios, including a survey of the users' experience, to highlight IRIS contribution in the area of IR.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The paper introduces the IRIS, a system that provides detailed security information during the entire lifecycle of a security incident, facilitates decision support through the provision of possible attack and response paths, while deciding on the significance and magnitude of an attack with a standardized method.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685221011079207","type":"journal-article","created":{"date-parts":[[2010,10,30]],"date-time":"2010-10-30T07:06:50Z","timestamp":1288422410000},"page":"291-309","source":"Crossref","is-referenced-by-count":4,"title":["Expanding topological vulnerability analysis to intrusion detection through the incident response intelligence system"],"prefix":"10.1108","volume":"18","author":[{"given":"Dimitrios","family":"Patsos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sarandis","family":"Mitropoulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christos","family":"Douligeris","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022021920023118100_b1","unstructured":"Aberdeen Group (2003), Turning IT Security into Effective Business Risk Management, Computer Associates S.A., Bridgeton, NJ."},{"key":"key2022021920023118100_b2","doi-asserted-by":"crossref","unstructured":"Adelstein, F. (2006), \u201cLive forensics: diagnosing your system without killing it first\u201d, Communications of the ACM, Vol. 49 No. 2, pp. 63\u20106.","DOI":"10.1145\/1113034.1113070"},{"key":"key2022021920023118100_b3","doi-asserted-by":"crossref","unstructured":"Ammann, P., Wijesekera, D. and Kaushik, S. (2002), \u201cScalable, graph\u2010based network vulnerability analysis\u201d, Proceedings of the 9th ACM Conference on Computer and Communications Security, ACM Press, Washington, DC, USA, pp. 217\u201024.","DOI":"10.1145\/586110.586140"},{"key":"key2022021920023118100_b4","doi-asserted-by":"crossref","unstructured":"Brumley, D., Newsome, J., Song, D., Wang, H. and Jha, S. (2006), \u201cTowards automatic generation of vulnerability\u2010based signatures\u201d, IEEE Symposium on Security and Privacy, Oakland, CA, pp. 2\u201016.","DOI":"10.21236\/ADA462599"},{"key":"key2022021920023118100_b5","doi-asserted-by":"crossref","unstructured":"Brumley, D., Newsome, J., Song, D., Wang, H. and Jha, S. (2007), Theory and Techniques for Automatic Generation of Vulnerability\u2010based Signatures, School of Computer Science, Carnegie Mellon University, Pittsburgh, PA.","DOI":"10.21236\/ADA462599"},{"key":"key2022021920023118100_b6","unstructured":"BugTraq (2009), \u201cBugTraq\u201d, SecurityFocus, available at: www.securityfocus.com\/archive\/1 (accessed October 8, 2009)."},{"key":"key2022021920023118100_b7","unstructured":"CAPEC (2009), \u201cCommon attack pattern enumeration and classification, a community knowledge resource for building secure software\u201d, available at: http:\/\/capec.mitre.org\/ (accessed October 25, 2009)."},{"key":"key2022021920023118100_b8","unstructured":"CCE (2009), \u201cUnique identifiers for common system configuration issues\u201d, Common configuration enumeration, available at: http:\/\/cce.mitre.org\/ (accessed October 25, 2009)."},{"key":"key2022021920023118100_b13","unstructured":"CPE (2009), \u201cA structured naming scheme for IT systems, platforms and packages\u201d, Common platform enumeration, available at: http:\/\/cpe.mitre.org\/ (accessed October 25, 2009)."},{"key":"key2022021920023118100_b15","unstructured":"CWE (2009), \u201cA community\u2010developed dictionary of software weakness types\u201d, Common weaknesses enumeration, available at: http:\/\/cwe.mitre.org\/ (accessed October 25, 2009)."},{"key":"key2022021920023118100_b9","doi-asserted-by":"crossref","unstructured":"Chambers, R. (2006), \u201cVulnerability, coping and policy\u201d, IDS Bulletin, Vol. 37 No. 4, pp. 24\u201031.","DOI":"10.1111\/j.1759-5436.2006.tb00284.x"},{"key":"key2022021920023118100_b10","unstructured":"Chien, E. and Szor, P. (2002), \u201cBlended attacks exploits, vulnerabilities and buffer\u2010overflow techniques in computer viruses\u201d, Virus Bulletin Conference, Virus Bulletin, New Orleans, LA, pp. 1\u201035."},{"key":"key2022021920023118100_b11","unstructured":"Cisco (2009), \u201cProducts and services security advisories, Cisco security advisories and notices, from Cisco Systems\u201d, available at: www.cisco.com\/web\/go\/psirt (accessed October 8, 2009)."},{"key":"key2022021920023118100_b12","doi-asserted-by":"crossref","unstructured":"Conklin, A.D. (2008), \u201cSystems theory model for information security\u201d, paper presented at: 41st Annual International Conference on System Sciences, Big Island, HI.","DOI":"10.1109\/HICSS.2008.421"},{"key":"key2022021920023118100_b14","doi-asserted-by":"crossref","unstructured":"Cui, W., Peinado, M., Wang, H. and Locasto, M. (2007), \u201cShieldGen: automatic data patch generation for unknown vulnerabilities with informed probing\u201d, Proceedings of IEEE Symposium on Security and Privacy, Oakland, CA, pp. 252\u201066.","DOI":"10.1109\/SP.2007.34"},{"key":"key2022021920023118100_b16","doi-asserted-by":"crossref","unstructured":"Debar, H., Thomas, Y., Cuppens, F. and Cuppens\u2010Boulahia, N. (2007), \u201cEnabling automated threat response through the use of a dynamic security policy\u201d, Journal of Computer Virology, Vol. 3, pp. 192\u20105.","DOI":"10.1007\/s11416-007-0039-z"},{"key":"key2022021920023118100_b17","unstructured":"FIRST (2007), \u201cCommon vulnerability scoring system (CVSS\u2010SIG)\u201d, available at: www.first.org\/cvss\/ (accessed May 7, 2010)."},{"key":"key2022021920023118100_b18","unstructured":"Gula, R. (2009), \u201cCorrelating IDS alerts with vulnerability information\u201d, Tenable Network Security, available at: www.nessus.org (accessed October 8, 2009)."},{"key":"key2022021920023118100_b19","doi-asserted-by":"crossref","unstructured":"Hansman, S. and Hunt, R. (2005), \u201cA taxonomy of network and computer attacks\u201d, Computers and Security, Vol. 42 No. 1, pp. 31\u201043.","DOI":"10.1016\/j.cose.2004.06.011"},{"key":"key2022021920023118100_b20","unstructured":"IBM (2009), \u201cProventia network enterprise scanner\u201d, IBM Corporation, available at: www.935.ibm.com\/services\/us\/index.wss\/offering\/iss\/a1027216 (accessed October 8, 2009)."},{"key":"key2022021920023118100_b21","doi-asserted-by":"crossref","unstructured":"Jajodia, S. and Noel, S. (2009), \u201cTopological vulnerability analysis\u201d, in Jajodia, S., Wang, C., Swarup, V. and Liu, P. (Eds), paper presented at Army Research Office Cyber Situational Awareness Workshop.","DOI":"10.1007\/978-1-4419-0140-8_7"},{"key":"key2022021920023118100_b22","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Noel, S. and O'Berry, B. (2006), \u201cTopological analysis of network attack vulnerability\u201d, in Kumar, V., Srivastava, J. and Lazarevic, A. (Eds), Managing Cyber Threats: Issues, Approaches, and Challenges, Springer, Heidelberg, pp. 247\u201066.","DOI":"10.1007\/0-387-24230-9_9"},{"key":"key2022021920023118100_b23","doi-asserted-by":"crossref","unstructured":"Kieyzun, A., Guo, P.J., Jayaraman, K. and Ernst, M.D. (2009), \u201cAutomatic creation of SQL injection and cross\u2010site scripting attacks\u201d, Proceedings of the 2009 IEEE 31st International Conference on Software Engineering, May 16\u201024, Vancouver, Canada, pp. 199\u2010209.","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"key2022021920023118100_b24","doi-asserted-by":"crossref","unstructured":"Killourhy, K., Maxion, R. and Tan, K. (2004), \u201cA defense\u2010centric taxonomy based on attack manifestations\u201d, Proceedings of the International Conference on Dependable Systems & Networks, 28 June\u20101 July, Florence, Italy.","DOI":"10.1109\/DSN.2004.1311881"},{"key":"key2022021920023118100_b25","unstructured":"Kim, D.W., Choi, Y., Kim, I.K., Oh, J.T. and Oh, J.T. (2008), Patent No. US20080083034A1, USA."},{"key":"key2022021920023118100_b26","doi-asserted-by":"crossref","unstructured":"Krasser, S., Conti, G., Grizzard, J. and Gribschaw, J. (2005), \u201cReal\u2010time and forensic network data analysis using animated and coordinated visualization\u201d, Proceedings of the 2005 IEEE Workshop on Information Assurance and Security, United States Military Academy, West Point, NY, pp. 42\u20109.","DOI":"10.1109\/IAW.2005.1495932"},{"key":"key2022021920023118100_b28","unstructured":"McAfee (2009), \u201cMcAfee vulnerability manager (formerly foundstone)\u201d, McAfee, available at: www.mcafee.com\/ (accessed October 8, 2009)."},{"key":"key2022021920023118100_b27","unstructured":"Mathew, S., Britt, D., Giomundo, R. and Upadhyaya, S. (2005), \u201cReal\u2010time multistage attack awareness through enhanced intrusion alert clustering\u201d, Proceedings of Military Communications Conference, MILCOM, Atlantic City, NJ, pp. 1801\u20106."},{"key":"key2022021920023118100_b29","doi-asserted-by":"crossref","unstructured":"Mell, P., Scarfone, K. and Romanosky, S. (2006), \u201cCommon vulnerability scoring system\u201d, IEEE Security and Privacy, Vol. 4 No. 6, pp. 85\u20109.","DOI":"10.1109\/MSP.2006.145"},{"key":"key2022021920023118100_b30","unstructured":"Microsoft (2009), Microsoft Security Response Center, Microsoft Corporation, available at: www.microsoft.com\/security\/msrc\/default.mspx (accessed October 8, 2009)."},{"key":"key2022021920023118100_b31","unstructured":"MITRE (2009), \u201cCommon vulnerabliities and exposures, the standard for information vulnerability names\u201d, available at: http:\/\/cve.mitre.org\/ (accessed October 8, 2009)."},{"key":"key2022021920023118100_b32","doi-asserted-by":"crossref","unstructured":"Mitropoulos, S., Patsos, D. and Douligeris, C. (2006), \u201cOn incident handling and response: a state of the art approach\u201d, Computers and Security, Vol. 25 No. 5, pp. 351\u201070.","DOI":"10.1016\/j.cose.2005.09.006"},{"key":"key2022021920023118100_b33","doi-asserted-by":"crossref","unstructured":"Mitropoulos, S., Patsos, D. and Douligeris, C. (2007), \u201cIncident response requirements for distributed security information management\u201d, Journal of Information Management & Computer Security, Vol. 15 No. 3, pp. 226\u201040.","DOI":"10.1108\/09685220710759568"},{"key":"key2022021920023118100_b36","unstructured":"NIST (2004), \u201cComputer security incident handling guide\u201d, NIST Special Publication 800\u201061, National Institute of Standards and Technology, Gaithersburg, MD."},{"key":"key2022021920023118100_b34","unstructured":"Newsome, J. and Song, D. (2005), \u201cDynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software\u201d, Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA."},{"key":"key2022021920023118100_b35","doi-asserted-by":"crossref","unstructured":"Ning, P. and Xu, D. (2003), \u201cLearning attack strategies from intrusion alerts\u201d, Proceedings of the 10th ACM Conference on Computer and Communications Security (CCS '03), Washington, DC, October, pp. 200\u20109.","DOI":"10.1145\/948109.948137"},{"key":"key2022021920023118100_b37","doi-asserted-by":"crossref","unstructured":"O'Hare, S., Noel, S. and Prole, K. (2008), \u201cA graph\u2010theoretic visualization approach to network risk analysis\u201d, in Goodall, J.R., Conti, G. and Ma, K.\u2010L. (Eds), VizSec 2008, LNCS, Vol. 5210, Springer, Berlin, pp. 60\u20107.","DOI":"10.1007\/978-3-540-85933-8_6"},{"key":"key2022021920023118100_b38","doi-asserted-by":"crossref","unstructured":"Papadaki, M. and Furnell, S.M. (2006), \u201cAchieving automated intrusion response: a prototype implementation\u201d, Information Management & Computer Security, Vol. 14 No. 3, pp. 235\u201051.","DOI":"10.1108\/09685220610670396"},{"key":"key2022021920023118100_b39","unstructured":"SANS (2009), \u201cThe top cyber security risks, two risks dwarf all others, but organizations fail to mitigate them\u201d, available at: http:\/\/sans.org (accessed April 24, 2010)."},{"key":"key2022021920023118100_b40","doi-asserted-by":"crossref","unstructured":"Scarfone, K. and Mell, P. (2008), Guide to Intrusion Detection and Prevention Systems (IDPS), Recommendations of the National Institute of Standards and Technology, SP 800\u201094, NIST, Gaithersburg, MD.","DOI":"10.6028\/NIST.SP.800-94"},{"key":"key2022021920023118100_b41","doi-asserted-by":"crossref","unstructured":"Schultz, E. (2004), \u201cIncident response teams need to change\u201d, Computers and Security Journal, Vol. 4, pp. 87\u20108.","DOI":"10.1016\/j.cose.2004.01.009"},{"key":"key2022021920023118100_b42","unstructured":"SecurityFocus (2009), Vulnerabilities, Security Focus, available at: www.securityfocus.com\/vulnerabilities (accessed October 8, 2009)."},{"key":"key2022021920023118100_b43","unstructured":"Sheyner, O., Haines, J., Jha, S. and Lippmann, R. (2002), \u201cAutomated generation and analysis of attack graphs\u201d, Proceedings of IEEE Symposium on Security and Privacy, Oakland, CA, pp. 273\u201084."},{"key":"key2022021920023118100_b44","doi-asserted-by":"crossref","unstructured":"Srilatha, C., Ajith, A. and Johnson, P.T. (2004), \u201cFeature deduction and ensemble design of intrusion detection systems\u201d, Computers & Security, Vol. 24 No. 4, pp. 295\u2010307.","DOI":"10.1016\/j.cose.2004.09.008"},{"key":"key2022021920023118100_b45","unstructured":"Swiler, L., Phillips, C., Ellis, D. and Chaker, M. (2001), \u201cComputer\u2010attack graph generation tool\u201d, DISCEXII Proceedings, DARPA's Information Survivability Conference and Exposition, Vol. 2, pp. 307\u201021."},{"key":"key2022021920023118100_b46","doi-asserted-by":"crossref","unstructured":"Templeton, S. and Levitt, K. (2000), \u201cA requires\/provides model for computer attacks\u201d, Proceedings of the New Security Paradigms Workshop, Ballycotton, Ireland, pp. 31\u20108.","DOI":"10.1145\/366173.366187"},{"key":"key2022021920023118100_b47","unstructured":"Tenable (2009), \u201cThe network vulnerability scanner\u201d, Tenable Network Security, available at: www.nessus.org\/nessus\/ (accessed October 8, 2009)."},{"key":"key2022021920023118100_b48","unstructured":"Tian, Z., Zhang, W., Ye, Z., Yu, A. and Zhang, H. (2008), \u201cReduction of false positives in intrusion detection via adaptive alert classifier\u201d, Proceedings of the International Conference on Information and Automation (ICIA 2008), 20\u20103 June, Changsha, pp. 1599\u2010602."},{"key":"key2022021920023118100_b49","unstructured":"US\u2010CERT (2009), Vulnerability Notes Database Field Descriptions, United States Computer Emergency Readiness Team (accessed October 8, 2009)."},{"key":"key2022021920023118100_b50","doi-asserted-by":"crossref","unstructured":"Yegneswaran, V., Giffin, J., Barford, P. and Jha, S. (2005), \u201cAn architecture for generating semantics\u2010aware signatures\u201d, Proceedings of the 14th USENIX Security Symposium, Baltimore, MD.","DOI":"10.21236\/ADA449063"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685221011079207","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221011079207\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221011079207\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:20Z","timestamp":1753402160000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/18\/4\/291-309\/187787"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,10,12]]},"references-count":50,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2010,10,12]]}},"alternative-id":["10.1108\/09685221011079207"],"URL":"https:\/\/doi.org\/10.1108\/09685221011079207","relation":{},"ISSN":["0968-5227"],"issn-type":[{"type":"print","value":"0968-5227"}],"subject":[],"published":{"date-parts":[[2010,10,12]]}}}