The invention belongs to the technical field of
information security, and particularly relates to an automatic
intrusion response decision making method based on Q-learning. The method comprises the following steps: scanning
system vulnerability, constructing an
attack graph, and establishing a network state layer, an
attack pattern matching layer and a response measure layer according to the
attack graph; establishing a mapping relationship among the network state layer, the attack
pattern matching layer and the response measure layer; receiving an intrusion alarm from a
network defense device, and mapping the intrusion alarm to a corresponding network state; selecting a defense action according to the mapping relationship, and notifying the
system of the result; performing
online learning by using the execution result of the defense action, and updating the mapping relationship between the attack
pattern matching layer and the response measure layer; and returning to the step of mapping the intrusion alarm to the corresponding network state, and performing automatic response decision marking and
online learning, until a defender terminates the defense. By adoption of the automatic
intrusion response decision making method based on Q-learning provided by the invention, evaluation of
multiple response purposes of the strategy can be achieved, the demand of
multiple response purposes can be met, the instantaneity and accuracy of the intrusion detection are improved, the network
resource consumption is reduced, and the overall performance of the
system is improved.