为了在响应决策过程中合理地选择和使用响应因素,对现有入侵响应决策模型中的响应因素进行了统计,并依据所提出的分类标准对响应因素进行了分类.围绕响应时机决策和响应措施决策这两个问题,对响应因素进行分析和讨论,指出已有响应决策模型中对一些响应因素的不当使用.讨论所研发的入侵报警管理与入侵响应系统IDAM&IRS的结构、响应决策过程和实验情况,并阐述了其中所涉及的响应因素.最后,对响应因素在响应决策中的地位和作用等进行了总结.
According to the practical meaning of these response factors, their names are unified for the convenience of discussion. The statistics of response factors in typical response decision-making models is made, meanwhile these response factors are classified according to the proposed standards including the relationship, the subjective and the objective feature, and the origin. In order to choose proper factors in response time decision-making and response measure decision-making processes respectively, a taxonomy of response factors is given. In addition, the problem of the improper response factor used in existing response decision-making models is indicated in the paper. The architecture, response decision-making process and experiments of the intrusion detection alert management & intrusion response system (IDAM&IRS) developed by the authors are shown. Especially, response factors used in IDAM & IRS are discussed in detail. The role and function of response factors are summarized at last.