Traditional intrusion detection systems only carry out response when intrusion is detected
while don't respond to "nonexistence" of intrusion.It has two shortcomings.First
when the previous intrusion events that had been responded are proved to be false alarms
the response system cannot correct its response.Secondly
when the intrusion behavior terminates
the response system cannot withdraw the corresponding response so as to eliminate the negative effect.In this paper
a Rollbackable Automated Intrusion Response System (RAIRS) is established to cope with the above two problems.RAIRS can not only automatically detect response
but also detect false alarms and termination of intrusion
and then triggers the rollback of corresponding response to eliminate its negative effect.The experiment proves that the response rollback technique can decrease the response cost so that it can achieve the same security goal with lower cost.