Unlock instant, AI-driven research and patent intelligence for your innovation.

Method for Identifying Network Attack and Honeypot Protection System

A technology for identifying network and network attacks, which is applied in the Internet field, can solve problems such as difficult capture effects, and achieve the effects of easy promotion, simple structure, and low implementation cost

Active Publication Date: 2022-04-05
CHINA UNIONPAY
View PDF5 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, if the attacker uses a new attack method, such as a rule not added by the honeypot, it will be difficult to achieve an effective capture effect

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for Identifying Network Attack and Honeypot Protection System
  • Method for Identifying Network Attack and Honeypot Protection System
  • Method for Identifying Network Attack and Honeypot Protection System

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0027] In the following description, specific details are set forth in order to provide a thorough understanding of the present invention. It will be apparent, however, to one skilled in the art that embodiments of the invention may be practiced without these specific details. In the present invention, specific numerical references such as "first element", "second means" and the like may be made. However, specific numerical references should not be construed as necessarily obeying their literal order, but rather that "first element" is different from "second element".

[0028] The specific details set forth herein are exemplary only, and the specific details may vary while remaining within the spirit and scope of the invention. The term "coupled" is defined to mean either directly connected to a component or indirectly connected to a component via another component.

[0029] Preferred embodiments of methods, systems and devices adapted to implement the present invention are ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The present invention relates to a method for identifying a network attack, comprising: receiving an access request via a network; determining the access request based on the degree of difference between a mirrored response of a mirror server to the access request and a corresponding honeypot response of at least one honeypot to the access request Whether it is a network attack; wherein, the mirror server is configured to mirror the production server, and the honeypot system is configured to be a system whose system version is lower than that of the production server. It can provide honeypots that mimic production servers as closely as possible, and identify attack patterns and tools through communication between honeypots and network attackers.

Description

technical field [0001] The invention relates to the technical field of the Internet, more specifically, to a method for identifying network attacks and a honeypot protection system. Background technique [0002] Honeypot technology is to lure the attacker to attack them by arranging some hosts, network services or information as bait, and then capture and analyze the attack behavior, understand the tools and methods used by the attacker, and infer the attack intention and motivation. [0003] As an important part of border security, honeypots can be implemented as highly simulated servers to collect various attack data and prepare for system defense. [0004] However, in the prior art, honeypots are poorly simulated and cannot effectively simulate real production servers. For example, a commonly used honeypot is deployed in an idle IP segment. Normal access requests will not access this IP address, but once this IP is accessed, there is a high probability of abnormal behav...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L9/40H04L67/1095H04L67/60
CPCH04L63/1441H04L67/1095H04L67/60
Inventor 黄自力杨阳陈舟熊璐
Owner CHINA UNIONPAY