This invention relates to the field of
network security technology and discloses a proactive
threat hunting and attribution method for AI agents and
honeypot-based technology. The method deploys a
threat-aware agent at the network boundary to continuously capture inbound and outbound data packets, performs protocol
parsing and
payload feature extraction on the packets, generates
network behavior fingerprints, and matches them in real-time with a known
attack signature database. When the matching degree exceeds a dynamic threshold, a high-interaction
honeypot environment is activated to simulate real business services, inducing
attack traffic to enter and perform isolation operations. The entire operation sequence of the
attack traffic within the
honeypot environment is recorded, generating an attack behavior
graph based on this. The attribution analysis agent extracts persistent connection points and timestamps from the graph, reconstructs the attack path, and performs
correlation analysis with a
threat intelligence
database, outputting an attribution report. This method effectively improves
network security protection capabilities and can better cope with complex and ever-changing
network attack environments.