Distributed systems with multiple interacting services, such as distributed e-commerce systems, are suitable targets for malicious attacks because of the potential financial impact. Intrusion detection in such systems has been an active area of research, while the problem of automated response has received relatively less attention. The thought often is that a system administrator will be included in the loop for troubleshooting once the alert about a possible intrusion has been raised. In this paper, we present the design of automated response mechanisms in an intrusion tolerant system called ADEPTS. The particular type of response we focus on enforces containment in the system, through which it localizes the effect of the intrusion thus allowing the system to provide service, albeit degraded. Containment can be very important in a large class of distributed systems in which a single compromised service can affect other services through the mutual interactions. ADEPTS uses a graph of...