Network attack active trapping method based on intelligent scheduling
By building a dynamic honeypot environment and intelligent traffic scheduling, the honeypot system has been solved, and the attack recognition and traceability capabilities with high simulation are achieved, resource consumption is reduced, and defense of advanced persistent threats is supported.
Patent Information
- Application Number
- CN202510697922.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-11
AI Technical Summary
The existing honeypot system has insufficient simulation, inefficient trapping efficiency, high resource consumption and lack of effective traceability capabilities, making it difficult to deal with zero-day attacks and advanced persistent threats.
The active trapping method of network attacks based on intelligent scheduling, by building a dynamic honeypot environment, simulating the interactive logic and data characteristics of the real business system, combining the security situation awareness platform to analyze attack traffic, dynamically generate drainage strategies, switch the attack traffic to the honeypot system, and record the attack behavior chain in the honeypot, extract the attack tool fingerprint and track the attacker's identity.
It realizes high simulation of honeypot environment and real business system, improves the attack recognition rate and logical credibility of inducing data, accurately recognizes attack traffic, reduces resource consumption, and builds a complete electronic evidence link to support judicial evidence collection and proactive countermeasures.
Smart Images

Figure CN120301699A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to an active network attack trapping method based on intelligent scheduling. Background Art
[0002] In the network security defense system, the honeypot technology induces attackers by constructing false targets, providing active monitoring capabilities for traditional passive defenses. In the early days, low-interaction honeypots were easily recognized by attackers due to limited simulation; although high-interaction honeypots improved authenticity, they faced problems such as complex deployment and high maintenance costs. With the development of cloud computing and SDN technologies, dynamic traffic scheduling attempts to redirect attack traffic to the honeypot, but its core still relies on static mirroring to build a simulation environment, and the fixed version characteristics lead to a decline in trapping effectiveness over time.
[0003] Existing solutions mostly use rule matching and traffic mirroring to detect attacks, which require pre-defining a threat feature library and are difficult to cope with zero-day attacks and advanced persistent threats (APTs). In addition, the passive waiting mode for attackers to trigger results in a low capture rate. To improve the coverage range, a large number of public network IP resources need to be occupied, and the operation and maintenance costs increase sharply. Although some database honeypots attempt to simulate business interactions, they are limited to a single protocol and lack cross-layer data association, resulting in a high false alarm rate.
[0004] Current honeypot systems generally focus on recording attack behaviors but rarely build a closed-loop countermeasure ability. Characteristics such as attacker identity concealment and tool fingerprint variability make it difficult for traditional log analysis to achieve effective tracking. Even if some solutions introduce threat intelligence matching, there are still problems such as data isolation and broken evidence chains, which cannot support judicial forensics or active countermeasures. Summary of the Invention
[0005] To solve the problems of insufficient simulation degree, low trapping efficiency, large resource consumption, and lack of effective traceability ability in the existing honeypot system, the present invention proposes an active network attack trapping method based on intelligent scheduling.
[0006] The specific technical solution is as follows: An active network attack trapping method based on intelligent scheduling, including:
[0007] Construct a dynamic honeypot environment according to the real business system mirror, simulate the interaction logic and data characteristics of the real business system, and generate a honeypot system;
[0008] Analyze the network device logs of the access source according to the security situation awareness platform, and capture multi-dimensional features to identify attack traffic;
[0009] Dynamically generate a drainage strategy according to the recognition result of the security situation awareness platform, and seamlessly switch the attack traffic to the honeypot system through the load balancing device;
[0010] Record the attack behavior chain in the honeypot system, extract the fingerprints of attack tools and track the identities of attackers.
[0011] Furthermore, the construction of the dynamic honeypot environment includes:
[0012] Real-time synchronize the configuration files and page elements of the real business system;
[0013] Deploy a version obfuscation system to automatically generate a sequence of adjacent version numbers associated with CVE vulnerabilities;
[0014] Build an associated pseudo-data lake to generate a false database with business logic associations. The false data generation rules are as follows:
[0015] ;
[0016] Wherein, represents a real data sample, represents a traceable digital watermark.
[0017] Furthermore, the operating logic of the version obfuscation system includes:
[0018] Extract the version number range corresponding to the current high-risk vulnerability from the NVD vulnerability library;
[0019] Generate a time-decaying weighted version sequence. The calculation formula is as follows:
[0020] ;
[0021] Wherein, t represents the current time, t0 represents the vulnerability disclosure time, and k represents the decay coefficient.
[0022] Furthermore, the identification of attack traffic includes:
[0023] Detect network layer packet characteristics, including scanning abnormal ports and detecting protocol types;
[0024] Analyze the payload characteristics of the application layer and match known vulnerability exploitation patterns;
[0025] Combine historical attack records with real-time traffic behavior to calculate the dynamic reputation score of the access source IP.
[0026] Furthermore, the traffic diversion strategy includes:
[0027] Maintain the TCP session state of the attack traffic. The security situation awareness platform predicts and synchronizes the sequence number to the honeypot system;
[0028] Copy the SSL / TLS protocol fingerprint of the target service to generate a matching pseudo-certificate;
[0029] Dynamically allocate traffic according to the load of the honeypot system cluster, and the calculation formula of the allocation ratio is as follows:
[0030] ;
[0031] Among them, represents the maximum load capacity of the cluster, represents the current load.
[0032] Furthermore, the replication of the SSL / TLS protocol fingerprint includes:
[0033] Customize and modify the OpenSSL library to simulate the cipher suite priority of the target system;
[0034] Dynamically adjust the initial TCP window size to a random value within the range of [64, 128, 256] KB;
[0035] Insert specific extension fields during the TLS handshake process to replicate the X.509 certificate extension attributes of the target service.
[0036] Furthermore, the extraction of the attack tool fingerprint includes:
[0037] Extract the entropy value feature and code segment signature of the attack tool binary file;
[0038] Construct a virtual privilege escalation path to simulate privilege escalation vulnerabilities and record the attacker's operations;
[0039] Deploy a blockchain tracking module to generate marked virtual currency wallet addresses and monitor dark web transaction flows.
[0040] Furthermore, the implementation of the virtual privilege escalation path includes:
[0041] Plant a fake sudoers file in the honeypot system, and the sudoers file contains configuration items with format errors but can trigger vulnerabilities;
[0042] When the attacker attempts to escalate privileges, guide them to a sandbox environment and return a forged root privilege;
[0043] Inject trap instructions during the operations after privilege escalation to trigger the extraction of attack tool features.
[0044] Furthermore, the construction of the relational pseudo data lake includes:
[0045] Generate a fake customer data table, including the logical association combination of name, mobile phone number, and email;
[0046] Establish a mapping relationship between the order ID and the logistics order number, and the mapping formula is as follows:
[0047] ;
[0048] Embed an invisible watermark in the database comment field, and the watermark encoding rules are as follows:
[0049] 。
[0050] Furthermore, it also includes an attack effectiveness evaluation mechanism:
[0051] Define an attack effectiveness scoring model, and the scoring dimensions of the attack effectiveness scoring model include the dwell time weight W t and the operation depth weight W d ;
[0052] When the comprehensive score exceeds the threshold S threshold equal to 80, trigger the in-depth traceability process;
[0053] Automatically clean up the honeypot instance and recycle resources for low-scoring attacks.
[0054] The above technical solutions have the following advantages or technical effects:
[0055] 1. By synchronizing the configuration of the real business system in real time, deploying the dynamic version obfuscation algorithm, and constructing a GAN-based associated pseudo data lake, the present invention realizes a high degree of simulation of the honeypot environment and the real business system, reduces the attacker recognition rate, and enhances the logical credibility of the induced data.
[0056] 2. Through multi-dimensional attack feature analysis, TCP session maintenance technology, and dynamic replication of SSL / TLS protocol fingerprints, the present invention realizes the accurate identification and seamless switching of attack traffic, improves resource utilization, and at the same time avoids the leakage of defense intentions caused by the exposure of protocol features.
[0057] 3. Through entropy value feature extraction, virtual privilege path construction, and blockchain cross-chain tracing, the present invention realizes the full-chain traceability from the attack tool fingerprint to the dark web transaction, forming a complete electronic evidence chain.
[0058] 4. Through the attack effectiveness scoring model and the time decay weight algorithm, the present invention realizes the intelligent life cycle management of the honeypot instance, reduces the occupation of invalid resources, and dynamically optimizes the vulnerability exposure strategy, thereby extending the attack residence time. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 is the method flow chart of the present invention;
[0060] Figure 2 is the schematic diagram of the honeypot environment of the present invention;
[0061] Figure 3 is the schematic diagram of the intelligent traffic scheduling of the present invention. Detailed Implementation Manner
[0062] To make the technical solution of the present invention clearer, the following further describes the present invention in detail with reference to the accompanying drawings and specific embodiments.
[0063] As Figure 1 shown, a network attack active trapping method based on intelligent scheduling includes:
[0064] S1: Construct a dynamic honeypot virtual environment synchronized with the real business system version in the dynamic honeypot cluster according to the real business system image. Among them, the virtual environment includes an associated pseudo-data lake generated based on a generative adversarial network (GAN) and a dynamically adjusted protocol fingerprint obfuscation system, simulating the interaction logic and data characteristics of the real business system to generate a honeypot system;
[0065] S2: Analyze the network device logs of the access source according to the security situation awareness platform, capture multi-dimensional features to identify attack traffic, and generate a dynamic reputation score by detecting network traffic in real time through a multi-dimensional attack behavior analysis module;
[0066] S3: Dynamically generate a drainage strategy according to the recognition result of the security situation awareness platform, trigger an intelligent traffic scheduling engine based on the dynamic reputation score, seamlessly redirect the attack traffic to the dynamic simulation honeypot cluster, and seamlessly switch the attack traffic to the honeypot system through a load balancing device;
[0067] S4: Implant implantable digital watermarks during the honeypot interaction process, record the attack behavior chain in the honeypot system through the blockchain network, extract the attack tool fingerprint and trace the attacker's identity.
[0068] As Figure 2 shown, the construction of the dynamic honeypot environment includes:
[0069] Real-time synchronize the configuration files and page elements of the real business system: Deploy a non-intrusive monitoring agent in the real business system to capture the following configuration changes in real time: Web service version information (Nginx / Apache version number), database table structure (MySQL table fields and indexes);
[0070] Generate an image template through an incremental synchronization algorithm, and retain the file hash value (MD5 / SHA256) of the real system.
[0071] Deploy a version obfuscation system, and automatically generate an adjacent version number sequence associated with CVE vulnerabilities according to the attack heat;
[0072] Construct an associated pseudo-data lake to generate a false database with business logic associations. The false data generation rules are as follows:
[0073] ;
[0074] Among them, represents the real data sample, represents the traceable digital watermark.
[0075] The operation logic of the version obfuscation system includes:
[0076] Connect to the NVD vulnerability database, and extract the version number range corresponding to the current high-risk vulnerabilities from the NVD vulnerability library (for example, CVE-2021-23002 affects Nginx 1.18.0 - 1.20.1);
[0077] Generate a time-decaying weight version sequence, and control the version display priority through the time-decaying factor. The calculation formula is as follows:
[0078] ;
[0079] Among them, t represents the current time, t0 represents the vulnerability disclosure time, and k represents the decay coefficient;
[0080] For example, the base version: the current version of the real system (such as 1.19.3); adjacent versions: generate version numbers 1.19.2 / 1.19.4, and inject pseudo-vulnerability descriptions;
[0081] In the database query response: append a Base64-encoded watermark (format: timestamp|srcIP|HMAC signature) at the end of the JSON field; modify the header identifier of the BLOB type field (0x89504E47 → 0x89504E48);
[0082] For the network protocol: insert a custom type value (Kind = 254, Value = watermark ciphertext) in the TCP option field.
[0083] Set a preset rotation period, and rotate the service fingerprint according to the preset rotation period. For example, rotate the service fingerprint every 12 hours. The rotation strategy gives priority to displaying high-weight versions and simultaneously matches the SSL / TLS handshake characteristics of the target system.
[0084] The above can achieve real-time feature synchronization between the honeypot environment and the real business system, and interfere with the attacker's service identification through the dynamic version sequence.
[0085] The construction of the relational pseudo-data lake includes:
[0086] Generate a false customer data table, including the logical association combination of name, mobile phone number, email, etc.;
[0087] Establish the mapping relationship between the order ID and the logistics order number. The mapping formula is as follows:
[0088] ; Generate a unique identifier: By hashing the order ID and taking the modulus, generate a fixed-length Logistics ID. This ID can be used to uniquely identify logistics information for easy system management and query.
[0089] Length control: mod 10^10 ensures that the generated Logistics ID is an integer within 10 digits.
[0090] Embed an invisible watermark in the database comment field. The watermark encoding rules are as follows:
[0091] ; Embed a combination of encrypted timestamp and source IP AES encryption in the database comment field. Inject the watermark identifier through the traffic man-in-the-middle decryption module during the SSL / TLS handshake phase. The blockchain network records the mapping relationship between the watermark identifier and the attacker's operation behavior. The watermark can be used to identify the source, time, or location of the data for easy tracking and verification of data legality.
[0092] The identification of attack traffic in step S2 includes:
[0093] Detect network layer packet characteristics, including scanning abnormal ports and detecting protocol types;
[0094] Analyze application layer payload characteristics and match known vulnerability exploitation patterns;
[0095] Combine historical attack records with real-time traffic behavior to calculate the dynamic reputation score of the access source IP.
[0096] Parse protocol characteristics in the traffic: including JA3 fingerprints in the TLS handshake phase and User-Agent format in the HTTP request header;
[0097] Build an attacker profile: including tool types (such as Nmap / Sqlmap, etc.) and attack stages (scanning / vulnerability exploitation / lateral movement).
[0098] The traffic diversion strategy in step S3 includes:
[0099] For scanning behavior: Return a pseudo-service identifier with a trap (such as appending "Welcome totest_server" to the SSH service response);
[0100] For in-depth attacks: Maintain the TCP session state of the attack traffic. The security situation awareness platform predicts and synchronizes the sequence number to the honeypot system, which can hide the switching process from the real business system to the honeypot system;
[0101] Copy the SSL / TLS protocol fingerprints (JA2 / JA3S) of the target service and generate a matching pseudo-certificate;
[0102] Dynamically allocate traffic according to the load of the honeypot system cluster. The calculation formula for the allocation ratio is as follows:
[0103] ;
[0104] Among them, represents the maximum load capacity of the cluster, represents the current load.
[0105] As Figure 3 shown, in intelligent traffic scheduling, the replication of SSL / TLS protocol fingerprints includes:
[0106] Customize and modify the OpenSSL library to simulate the cipher suite priority of the target system;
[0107] Dynamically adjust the initial TCP window size to a random value within the range of [64, 128, 256] KB;
[0108] Insert specific extension fields during the TLS handshake process to replicate the X.509 certificate extension attributes of the target service.
[0109] The extraction of attack tool fingerprints includes:
[0110] Extract the entropy value features and code segment signatures of the attack tool binary file;
[0111] Construct a virtual privilege escalation path, simulate privilege escalation vulnerabilities and record the attacker's operations, such as CVE-2021-3156;
[0112] Deploy a blockchain tracking module to generate tagged virtual currency wallet addresses and monitor dark web transaction flows.
[0113] When the present invention conducts active decoying, it responds to attack behaviors. First, it conducts primary induction, returns a forged vulnerability prompt (such as "PHP 7.2.34 (unsafe)"), opens a false management interface ( / admin / login returns a 302 redirect), and then conducts in-depth interaction, constructs a pseudo privilege escalation path (sudo -l shows a CVE-2021-3156 vulnerability prompt), and implants a trap file ( / root / .ssh / authorized_keys containing a traceable public key) in the environment after privilege escalation.
[0114] The implementation of the virtual privilege escalation path includes:
[0115] Plant a false sudoers file in the honeypot system, and the sudoers file contains configuration items with incorrect formats but can trigger vulnerabilities;
[0116] When an attacker attempts to escalate privileges, guide them to a sandbox environment and return a forged root privilege;
[0117] Inject trap instructions during the operations after privilege escalation to trigger the extraction of attack tool features.
[0118] The honeypot system includes an environment self-destruction mechanism, and sets the survival conditions of honeypot instances:
[0119] a. Interaction frequency > 5 times / hour;
[0120] b. Attack depth > L3 (refer to the MITRE ATT&CK framework);
[0121] For instances that do not meet the conditions, destroy the container and clear the logs, and write the environment destruction record (including the last interaction watermark) to the blockchain.
[0122] An active network attack trapping method based on intelligent scheduling of the present invention further includes an attack effectiveness evaluation mechanism:
[0123] Define an attack effectiveness scoring model, and the scoring dimensions of the attack effectiveness scoring model include the residence duration weight W t and the operation depth weight W d ;
[0124] Among them, , ;
[0125] When the comprehensive score exceeds the threshold S threshold = 80, trigger the in-depth tracing process, which mainly includes:
[0126] Main chain record: attack time, source IP, watermark identifier, captured attack payload (SQL injection statement / binary Shellcode);
[0127] Side chain association: virtual currency transaction records obtained by dark web market crawlers, and wallet addresses used by attackers through watermark matching;
[0128] Automatically clean the honeypot instances and recycle resources for low-scoring attacks.
[0129] The present invention breaks through the static image limitation of traditional honeypots through dynamic simulation environment construction technology, combines intelligent traffic scheduling algorithms to achieve accurate capture and diversion of attack behaviors, and innovatively introduces a blockchain-enhanced tracing system to form the ability to trace the entire life cycle of the attack chain. While improving the authenticity of trapping, it significantly reduces the operation and maintenance costs through an adaptive resource management model, constructs a new generation of network active defense system integrating high simulation, active induction, and reliable traceability, effectively responds to advanced persistent threats (APT) and zero-day attacks, and provides technical support for the protection of critical information infrastructure.
[0130] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent for the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the patent for the present invention shall be subject to the appended claims.
Claims
1. An active network attack trapping method based on intelligent scheduling, characterized in that, Including: Construct a dynamic honeypot environment based on the mirror of the real business system, simulate the interaction logic and data characteristics of the real business system, and generate a honeypot system; Analyze the network device logs of the access source according to the security situation awareness platform, and capture multi-dimensional features to identify attack traffic; Dynamically generate a diversion strategy according to the recognition result of the security situation awareness platform, and seamlessly switch the attack traffic to the honeypot system through the load balancing device; Record the attack behavior chain in the honeypot system, extract the attack tool fingerprint and trace the attacker's identity.
2. The active decoy method for network attacks based on intelligent scheduling according to claim 1, wherein The construction of the dynamic honeypot environment includes: Real-time synchronize the configuration files and page elements of the real business system; Deploy a version confusion system to automatically generate a sequence of adjacent version numbers associated with CVE vulnerabilities; Construct an associated pseudo-data lake to generate a false database with business logic associations. The false data generation rules are as follows: ; Among them, represents a real data sample, represents a traceable digital watermark.
3. The active trap method for network attacks based on intelligent scheduling according to claim 2, characterized in that, The operation logic of the version confusion system includes: Extract the version number range corresponding to the current high-risk vulnerability from the NVD vulnerability library; Generate a time-decaying weighted version sequence, and the calculation formula is as follows: ; Where t represents the current time, t0 represents the vulnerability disclosure time, and k represents the decay coefficient.
4. The active trap method for network attacks based on intelligent scheduling according to claim 1, wherein, The identification of the attack traffic includes: Detect network layer packet characteristics, including scanning abnormal ports and detecting protocol types; Analyze the application layer payload characteristics and match known vulnerability exploitation patterns; Combine historical attack records and real-time traffic behavior to calculate the dynamic reputation score of the access source IP.
5. A method for actively trapping network attacks based on intelligent scheduling according to claim 1, characterized in that, The diversion strategy includes: Maintain the TCP session state of the attack traffic, and the security situation awareness platform predicts and synchronizes the sequence number to the honeypot system; Copy the SSL / TLS protocol fingerprint of the target service and generate a matching pseudo-certificate; Dynamically allocate traffic according to the load of the honeypot system cluster. The adopted allocation ratio calculation formula is as follows: ; Among them, represents the maximum load capacity of the cluster, represents the current load.
6. The active trap method for network attacks based on intelligent scheduling according to claim 5, wherein The replication of the SSL / TLS protocol fingerprint includes: Customize and modify the OpenSSL library to simulate the cipher suite priority of the target system; Dynamically adjust the initial TCP window size to a random value within the range of [64, 128, 256] KB; Insert specific extension fields during the TLS handshake process and copy the X.509 certificate extension attributes of the target service.
7. The active decoy method for network attacks based on intelligent scheduling according to claim 1, characterized in that The extraction of the attack tool fingerprint includes: Extract the entropy value characteristics and code segment signatures of the attack tool binary file; Construct a virtual privilege escalation path, simulate the privilege escalation vulnerability and record the attacker's operations; Deploy a blockchain tracking module to generate a marked virtual currency wallet address and monitor the dark web transaction flow.
8. The active trapping method for network attacks based on intelligent scheduling according to claim 7, wherein, The implementation of the virtual privilege escalation path includes: Plant a false sudoers file in the honeypot system. The sudoers file contains configuration items with format errors but can trigger vulnerabilities; When the attacker attempts to escalate privileges, guide them to the sandbox environment and return a forged root privilege; Inject trap instructions during the operations after privilege escalation to trigger the extraction of attack tool characteristics.
9. A method for actively trapping network attacks based on intelligent scheduling according to claim 2, characterized in that The construction of the associated pseudo-data lake includes: Generate a false customer data table, including the logical association combination of name, mobile phone number, and email; Establish a mapping relationship between the order ID and the logistics order number. The mapping formula is as follows: ; Embed an invisible watermark in the database comment field. The watermark encoding rule is as follows: 。 10. A method for actively trapping network attacks based on intelligent scheduling according to claim 1, characterized in that, It also includes an attack effectiveness evaluation mechanism: Define an attack effectiveness scoring model, and the scoring dimensions of the attack effectiveness scoring model include the dwell time weight W t and the operation depth weight W d ; When the comprehensive score exceeds the threshold S threshold equal to 80, trigger the in-depth traceability process; Automatically clean up honeypot instances and recycle resources for low-scoring attacks.
Citation Information
Cited By
Intelligent tracking and blocking method and system for network attack chain
CN120474841A
Electric power protocol honeypot trapping and abnormity identification method based on GAN
CN120880810A
System and method for detecting abnormal traffic of credential server based on edge computing
CN121217490A
An edge-computing-based Xinchuang server abnormal traffic detection system and method
CN121217490B
Honeynet-based attack trapping and analyzing method and system
CN121619174A