A method, device, medium and electronic equipment for generating a honeycomb transformation configuration

By generating honeypot transformation configuration files, the problem of insufficient adaptability of existing honeypot scheduling schemes in dynamic and unknown attack scenarios is solved, realizing efficient and real-time trapping scenario construction and improving the defense capability of the honeypot system.

CN121000535BActive Publication Date: 2026-01-02GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511525402.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-01-02
Estimated Expiration
2045-10-24

AI Technical Summary

Technical Problem

Existing honeypot scheduling schemes rely on historical data and fixed templates, resulting in insufficient adaptability in dynamic and unknown attack scenarios, difficulty in achieving real-time response and efficient trapping, and easy identification and bypass by experienced attackers.

Method used

By acquiring TTP information from the honeycomb array, mapping it to CWE and CVE information, performing CVSS scoring, generating a CVE mirror configuration segment, and combining scene feature information to match honey point mirrors, a honeycomb array transformation configuration file is generated to achieve dynamic trapping scene configuration.

Benefits of technology

It improves the real-time performance and adaptability of the honeypot system, enabling it to adjust the trapping scenario in real time based on attacker behavior, thereby enhancing the trapping effect and defense effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000535B_ABST
    Figure CN121000535B_ABST
Patent Text Reader

Abstract

The application provides a honey array transformation configuration generation method and device, a medium and an electronic equipment, comprising: obtaining TTP information matching CVE to obtain CVE information; obtaining CVSS score according to the CVE information, selecting M CVE information associated with the highest score to generate corresponding CVE mirror configuration section; extracting scene feature information according to the TTP information to generate a feature mirror configuration section; generating a new honeypot configuration section of the service feature according to the TTP information; and mixing the CVE mirror configuration section, the feature mirror configuration section and the honeypot configuration section to generate a honey array transformation configuration file for transforming a trapping scene configuration. By designing the TTP scene information highly associated with the attacker's attack behavior and various threat modeling scales, the application completes the mapping of the attacker's behavior to the vulnerability and the service, selects the honeypot mirror of interest of the attacker, and highly adaptively generates the honey array transformation configuration file in combination with the scene information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a honeynet transformation configuration generation method and device, a medium and an electronic equipment. BACKGROUND

[0002] With its outstanding ability to lure attackers, deception defense technology has stood out in the field of network security. By scheduling honeypots, forming a honeynet, and then building a complete deception and lure scene, how to generate a dynamic lure scene has become a key problem in deception defense technology.

[0003] Current active deception defense products mostly generate dynamic configuration strategies through reinforcement learning and complete information game. However, these schemes have many defects:

[0004] Most current honeypot scheduling schemes use low self-defined honeypots and fixed configuration templates combined with reinforcement learning to complete scheduling and configuration, which has the problems of insufficient scheduling granularity and excessive overhead. The scheduling process based on reinforcement learning usually requires a large amount of computing resources and time for model training and strategy optimization, making it difficult for the system to achieve real-time response and rapid configuration update. In addition, the low flexibility of the fixed template makes the honeypot's camouflage ability weak, which is easily recognized and bypassed by experienced attackers, thereby significantly reducing the concealment and overall defense effect of the honeypot system.

[0005] Many current reinforcement learning-based strategy generation relies on a large amount of historical attack and defense data for model training. If the data is insufficient or does not cover new attack patterns (such as zero-day vulnerabilities), the generated honeypot configuration may not effectively lure attackers. The scheme that uses historical data to update attacker beliefs or evaluate configuration benefits may fail when facing atypical or highly random attacks. The dependence on data results in poor performance of the system in the initial deployment or data-scarce scenarios, significantly limiting its adaptability in dynamic and unknown attack scenarios, and the quality and diversity of the training data directly affect the effectiveness of the strategy.

[0006] The honeypot scheduling schemes in the prior art mainly rely on historical data and experience to develop strategies, which has significant limitations in dealing with dynamic attack behaviors of attackers in the live network. Since the methods of attackers are constantly evolving, preset strategies often cannot accurately fit actual attack scenarios, resulting in a significant reduction in the lure effect of the generated honeypot scene. In addition, the schemes in the prior art are usually based on fixed rules or template configurations, lack adaptability to real-time network environments, and are difficult to adjust flexibly to respond to new or complex attack patterns, thereby significantly reducing the lure rate and overall defense efficiency.

[0007] Therefore, it is necessary to provide a new dynamic trap scene scheduling configuration generation method to improve the real-time performance and availability of dynamic trap scene scheduling. SUMMARY

[0008] The application aims to provide a honeynet transformation configuration generation method to realize real-time transformation of trap scenes according to the behavior of attackers by scheduling honeypots in a honeynet.

[0009] In a first aspect, the application provides a method, which includes: obtaining TTP information in a honeynet, mapping the TTP information to CWE information to obtain corresponding CWE numbers, mapping the CWE numbers to CVE to obtain CVE information; performing CVSS evaluation according to the CVE information to obtain a CVSS score, sorting according to the CVSS score, and selecting M CVE information associated with the highest score to generate a corresponding CVE image configuration segment; extracting scene feature information according to the TTP information, and generating a corresponding feature image configuration segment by matching the scene feature information with a honeypot image; obtaining associated file paths and process information according to the TTP information to generate a honeypot configuration segment of new honeypots and service features; and mixing the CVE image configuration segment, the feature image configuration segment, and the honeypot configuration segment to generate a honeynet transformation configuration file, which is used for transforming trap scene configurations.

[0010] The application provides a method of generating a honeynet transformation configuration file based on real-time attack behavior of attackers to construct a transformed trap scene configuration. By introducing TTP scene information and multiple threat modeling scales highly associated with attack behavior of attackers, the mapping of attack behavior to vulnerabilities and services is completed, the honeypot image of interest of attackers is selected, and the honeynet transformation configuration file is highly self-adaptively generated in combination with the feature content in the scene information.

[0011] In a possible embodiment, mapping the TTP information to the CWE information to obtain corresponding CWE numbers includes: mapping the TTP information to CAPEC to obtain a CAPEC entry; and mapping the CAPEC entry to the CWE to obtain corresponding CWE numbers.

[0012] In another possible embodiment, the CVE image configuration segment and the feature image configuration segment are in JSON format; and the CVE image configuration segment and the feature image configuration segment include image information and basic configuration information of a container.

[0013] In other possible embodiments, extracting scene feature information according to the TTP information and matching the scene feature information with a honeypot image include: extracting process information, extension name information, operating system information, and path information of a scene according to the TTP information; and performing honeypot image matching through process matching, extension name matching, operating system matching, and path matching respectively to obtain a multi-feature matching honeypot image.

[0014] According to the matching of the scene feature information and the honeypot mirror image, the method further includes: selecting a guide and debugging script according to the matched honeypot mirror image, the guide and debugging script including an imported data script and a preset credential script.

[0015] The mixing of the CVE mirror image configuration section, the feature mirror image configuration section and the honeypot configuration section to generate the honeynet transformation configuration file includes: aggregating the CVE mirror image configuration section and the feature mirror image configuration section to generate a service transformation configuration section; and mixing the service transformation configuration section and the honeypot configuration section to generate the honeynet transformation configuration file.

[0016] The application of the honeynet transformation configuration file to transform the trapping scene configuration includes: a honeynet executor parsing the honeynet transformation configuration file, placing a corresponding container in a live network base according to the service transformation configuration section; and placing a system honeypot in the honeypot configuration section through file import and execution.

[0017] In a second aspect, the present application further provides a honeynet transformation configuration generation device, which includes: a mapping unit configured to obtain TTP information in a honeynet, map the TTP information to CWE information to obtain corresponding CWE numbers, and map the CWE numbers to CVE to obtain CVE information; a CVE mirror image matching unit configured to perform CVSS evaluation according to the CVE information to obtain a CVSS score, perform sorting according to the CVSS score, and select M images associated with the CVE information with the highest scores to generate corresponding CVE mirror image configuration sections; a feature mirror image matching unit configured to extract scene feature information according to the TTP information, and match honeypot mirror images according to the scene feature information to generate corresponding feature mirror image configuration sections; a honeypot configuration generation unit configured to obtain associated file paths and process information according to the TTP information to generate honeypot configuration sections of new honeypots and service features; and a honeynet transformation configuration generation unit configured to mix the CVE mirror image configuration sections, the feature mirror image configuration sections and the honeypot configuration sections to generate a honeynet transformation configuration file, the honeynet transformation configuration file being used to transform a trapping scene configuration.

[0018] In a third aspect, the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the above-mentioned honeynet transformation configuration generation method.

[0019] In a fourth aspect, the present application further provides an electronic device, which includes: a processor and a memory; the memory is configured to store a computer program; and the processor is configured to execute the computer program stored in the memory to enable the electronic device to perform the above-mentioned honeynet transformation configuration generation method.

[0020] The beneficial effects of the above-mentioned second aspect to fourth aspect can be referred to the description of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 A flowchart of a method for generating a honeynet transformation configuration is provided for an embodiment of the present application.

[0022] Figure 2 A CVE matching flowchart is provided for an embodiment of the present application.

[0023] Figure 3 A mirror image recommendation flowchart corresponding to a CVE is provided for an embodiment of the present application.

[0024] Figure 4 A scene information matching mirror image flowchart is provided for an embodiment of the present application.

[0025] Figure 5 A honeynet transformation configuration file generation flowchart is provided for an embodiment of the present application.

[0026] Figure 6 A schematic diagram of a device is provided for an embodiment of the present application.

[0027] Figure 7 An electronic device structure schematic diagram is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0028] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings of the present application. Obviously, the described embodiments are part of, but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application. Unless otherwise defined, the technical terms or scientific terms used herein should be understood as the usual meanings understood by those of ordinary skill in the art to which the present application belongs. The words such as "comprise" and similar words used herein mean that the elements or objects before the words cover the elements or objects listed after the words and their equivalents, and do not exclude other elements or objects.

[0029] The present embodiment provides a honeynet transformation configuration generation method, device, medium and electronic device.

[0030] Referring to the drawings accompanying the description Figure 1 The honeynet transformation configuration generation method comprises:

[0031] S101: Obtain TTP information in the honeynet, match CWE information according to the TTP information to obtain corresponding CWE numbers, and match CVE according to the CWE numbers to obtain CVE information.

[0032] In one possible embodiment, the TTP information in the honey array is inferred from the honey spot logs generated by the existing trapping virtual machine containers in the honey array, and there are multiple TTP information entries corresponding to the honey array.

[0033] For example, TTP scenario information is extracted from a knowledge graph based on the attack vectors corresponding to the honeypot logs. The knowledge graph records, in advance, the attacker's behavior and characteristics against different attack methods and attack vectors, as well as associated files, processes, etc. The TTP scenario information is mainly inferred based on the attacker's attack methods, duration, attack vectors, and attack paths shown in the honeypot logs, and the TTP scenario information corresponds to the attack behavior perceived by the honeypots in the honeycomb array.

[0034] In one possible implementation, only a portion of the TTP information acquired in the honeycomb array is meaningful for the current actual attack phase. For example, providing privilege escalation TTPs during the reconnaissance phase is unreasonable, and within the same phase, the severity of multiple different TTPs varies. For instance, in the privilege persistence phase, there are significant differences between simulating high-privilege accounts and hijacking execution flows. Therefore, the acquired TTP information is scored for severity, and the highest-risk TTPs corresponding to the attack phase are selected for mapping and filtering CVEs.

[0035] The TTP information obtained from the honeycomb array is mapped to different attack stages of the ATT&CK matrix and the kill chain matrix to obtain preset weight values. and Then, the TTP information is mapped to the corresponding mitigation measures in the ENGAGE matrix, a preset weight is obtained, and the severity of the harm is described by the mitigation measure weights: This will yield three weights.

[0036] For each feature point in the scene information, a base score is preset by expert experience. The final score for each feature point is calculated according to the following formula: Scores of multiple feature points Summing these values ​​yields a hazard score for a TTP in the current scenario, which is then used to select several TTPs with the highest hazard level for subsequent mapping and CVE selection.

[0037] See the instruction manual appendix Figure 2In a possible embodiment, the corresponding CWE number is obtained by matching the TTP information with the CWE information, including: mapping the TTP information to CAPEC to obtain a CAPEC entry; and mapping the CAPEC entry to the CWE to obtain the corresponding CWE number. Then, the CVE information is obtained by matching the CWE number, and finally a situation that one TTP information corresponds to multiple CVE numbers is formed, that is, the indirect mapping from the "attack scene that is occurring now" and the "techniques and tactics used by the attacker" to the "vulnerability that the attacker may attack or want to attack" is completed.

[0038] By using the direct connection between the TTP and the CAPEC and the connection between the CAPEC and the CWE, the TTP information is used to obtain what attack method is used by the attacker at this location when something is happening (TTP), and then the conversion from the attack method to the existence of some weaknesses of the target system is realized. Then, according to the connection that the existence of the vulnerability in the system leads to what weakness of the system, the vulnerability information that can be exploited is obtained. The above mapping and conversion process can be realized by using the official library, and a new method that can quickly and accurately map the attack scene to the vulnerability that can be exploited is provided.

[0039] S102: The CVSS score is obtained by performing CVSS evaluation according to the CVE information, the CVE information associated with the M CVEs with the highest scores is selected according to the sorting based on the CVSS score, and the corresponding CVE image configuration section is generated.

[0040] Referring to the accompanying drawings Figure 3 In a possible embodiment, multiple CVEs can be obtained according to one TTP information, the CVSS score is obtained according to the CVE information, the CVEs mapped in the TTP are sorted according to the CVSS score, and the M CVEs with the highest scores are selected according to the sorting, and the corresponding CVE image configuration section is generated. The value of M can be set by an administrator.

[0041] In a possible embodiment, there are multiple TTP information in the honeynet, the CVSS score is obtained according to the multiple CVEs obtained according to each TTP information, and the CVEs are sorted according to the CVSS score, and the CVEs with the highest scores corresponding to each TTP information are selected respectively, and the corresponding CVE image configuration section is generated by searching the image associated with the CVE.

[0042] Exemplarily, the generated CVE image configuration section is in the JSON format, and the CVE image configuration section includes information used for deploying the image, and specifically includes information of the image associated with the CVE and basic configuration information of the container. The basic configuration of the container includes the quota of the image to be deployed, such as the occupied CPU, memory and hard disk.

[0043] S103: Extract scene feature information according to TTP information, and generate corresponding feature mirror configuration section according to scene feature matching with the honeypot mirror.

[0044] In a possible embodiment, scene feature information is extracted according to TTP information, and the honeypot mirror of the service is obtained by associating the scene feature information with the service according to the scene feature information.

[0045] In a specific embodiment, scene feature information is extracted according to TTP information, and the honeypot mirror matching according to the scene feature information includes: extracting process information, extension information, operating system information, and path information of the scene according to the TTP information; and performing honeypot mirror matching through process matching, extension matching, operating system matching, and path matching respectively to obtain a honeypot mirror matched with multiple features.

[0046] Referring to the accompanying drawings Figure 4 For example, the scene feature information extracted according to the TTP information includes process, file, sensitive path, operating system, and other information, and the scene feature information is associated with the service through process matching, extension matching, operating system matching, and path matching according to the above information, so that the honeypot mirror of the service is associated with the TTP in a many-to-many manner. For example, according to the file with the.php extension in the scene feature information, and the existence of services such as ThinkPHP and Laravel with the same extension in the honeypot mirror, one extension matching result is obtained according to the file information. According to the multiple different feature points in the extracted scene feature information, fuzzy matching between the scene information and the mirror can be completed, and a batch of mirrors highly matched with the service features can be selected.

[0047] In a specific embodiment, the standard for matching the service according to the scene feature information is a rule maintained by expert experience, that is, the rule maintained by expert experience can be used to index the service that meets the corresponding situation according to the scene feature information, so as to obtain the honeypot mirror of the service. The honeypot mirror of the service that can pass the inspection of several feature points of the rule maintained by expert experience is considered to meet the matching standard. The number of honeypot mirrors matched is variable, and the number change is affected by the matching rule: the higher the matching degree required by the applied matching rule, the fewer the number of honeypot mirrors matched.

[0048] In a possible embodiment, the generated feature mirror configuration section is in JSON format, and the CVE mirror configuration section includes information for deploying the mirror, specifically including information of the mirror associated with the CVE and basic configuration information of the container.

[0049] S104: Generate a new honeypot configuration section of the service feature according to the TTP information, the associated file path, and the process information.

[0050] In one possible implementation, the associated file paths and process information in the TTP information are filtered, and the filtered associated file paths and process information are used to generate honeypot configuration segments for adding new system honeypots and service features. This operation of generating honeypot configuration segments from the filtered associated file paths and process information, by reusing file paths, processes, and other information in the TTP scenario information, adds system honeypots and more service features (such as containing a specific file or process) to the specifically deployed service. This increases the attack surface while improving the authenticity and availability of the service. Specifically, the filtered files are non-core system files that closely match the deployment scenario. For example, in a PHP scenario, config.phar is placed to better induce attackers to download the corresponding file and exploit vulnerabilities in related processes during actual attack and defense, thereby achieving attack behavior detection.

[0051] See the instruction manual appendix Figure 5 In one possible embodiment, after matching the honey spot image based on the scene feature information, the method further includes: selecting a debugging script based on the matched honey spot image, wherein the debugging script includes an import data script and a preset credential script.

[0052] In one specific embodiment, the configuration information section in the script is used to index the corresponding script and record the variable information required for script execution. For example, if a MySQL database-related mirror is selected during mirror matching, several scripts associated with that mirror can be selected for execution. These scripts are pre-prepared, associated with the mirror, and stored in the system. For instance, part of the information associated with the script might be `place-root-credential.sh`, used to store the database user credentials. Executing it requires setting a user credential, which the script sets as a variable. This variable can be entered by the operator or automatically generated.

[0053] A scripting script is a pre-configured file associated with a specific version and image, created in advance for the service. When the corresponding honeypot image is needed, the selected scripting script is written into the configuration information to form the scripting script configuration information segment. For example, when the MySQL image is selected, you can choose to execute either the corresponding data import script or the pre-configured credential script.

[0054] In a possible embodiment, the guide script includes a must-execute script and an optional-execute script. The must-execute script is necessary for configuring the corresponding environment and is executed in a predetermined order. The must-execute script is forcibly associated when the corresponding CVE image is imported. For example, assuming that there is a multi-scenario of Nginx+PHP+ThinkPHP+MySQL, the associated scripts nginx-php-fpm.sh (configuring Nginx and PHP linkage) and php-mysql.sh (configuring PHP and MySQL linkage) are executed in sequence. The optional-execute script is mostly a custom configuration script, which is selected by the user when approving the corresponding transformation scheme.

[0055] S105: mixing the CVE image configuration segment, the feature image configuration segment, and the honeypot configuration segment to generate a honeynet transformation configuration file, the honeynet transformation configuration file being used to transform the trap scene configuration.

[0056] In a possible embodiment, mixing the CVE image configuration segment, the feature image configuration segment, and the honeypot configuration segment to generate a honeynet transformation configuration file includes: aggregating the CVE image configuration segment and the feature image configuration segment to generate a service transformation configuration segment; and mixing the service transformation configuration segment and the honeypot configuration segment to generate the honeynet transformation configuration file.

[0057] For example, the contents and forms of the CVE image configuration segment and the feature image configuration segment generated in this embodiment are consistent, and the complete service transformation configuration segment information required in the honeynet transformation configuration file can be aggregated. The complete service transformation configuration segment and the honeypot configuration segment are mixed into a JSON file to form a complete configuration file that can be read and deployed to revise and add the honeynet topology.

[0058] In a possible embodiment, applying the honeynet transformation configuration file to transform the trap scene configuration includes: a honeynet executor parses the honeynet transformation configuration file, and places a corresponding container in the live network base according to the service transformation configuration segment; and a system honeypot in the honeypot configuration segment is placed by file import and execution.

[0059] In a possible embodiment, the guide script is imported during the generation of the honeynet transformation configuration file. The process of applying the generated honeynet transformation configuration file to transform the trap scene configuration specifically includes: the honeynet executor parses the honeynet transformation configuration file, places a corresponding container in the live network base according to the service transformation configuration segment, places a system honeypot in the honeypot configuration information segment by file import and execution, and finally imports the corresponding guide script into the corresponding container for execution.

[0060] The honey array transformation configuration generation method provided by the application designs a method for generating a honey array transformation configuration file based on real-time attack behaviors of an attacker to construct a trap scene configuration of transformation. By decoupling the deployment and configuration of honey points, introducing TTP scene information highly correlated with attack behaviors of the attacker and multiple threat modeling scales, completing the mapping of attack behaviors to vulnerabilities and services, selecting honey point images of interest to the attacker, and highly adaptively generating the honey array transformation configuration file in combination with the feature content in the scene information, the honey array transformation configuration file is generated.

[0061] According to the corresponding CVE number derived from the TTP information, the deduction from "what is being sent in the current scene" to "what vulnerabilities are being exploited when these things happen" is realized, and the behaviors of the attacker can guide what vulnerabilities should be deployed in the scene next to improve the "sweetness" and trapping ability of the honey array. Selecting a CVE with a relatively high score to generate a corresponding CVE image configuration segment realizes the screening of vulnerability services, and the image highly consistent with the attack behaviors of the attacker is combined into a trap scene, and the trap scene can be highly consistent with the attack behaviors of the attacker while maintaining high real-time performance, and a more realistic trap scene is generated.

[0062] Designing to match the image according to different feature points in the TTP information as a supplement to the image directly matched by the CVE increases the diversity of services finally deployed in the honey array topology, so that the constructed trap scene is more realistic.

[0063] By reusing the file path, process and other information in the TTP scene information, more system honey points and service features (such as containing a specific file or process) are added to the specific deployed services, which increases the attack surface while improving the authenticity and availability of the services.

[0064] The import of the guide script design enables the honey array transformation to further adapt to the scene, thereby producing better trapping effects. Importing the guide script can realize the combination of pre-constructed images and guide scripts to make the constructed trap scene and services more diverse and have stronger orchestration capabilities.

[0065] In summary, the honey array transformation configuration generation method proposed by the application can automatically match images from two stages of vulnerability matching and service feature matching according to the TTP scene information generated by the behaviors of the attacker in the live network, and construct a complete and available topology transformation scheme in combination with the original TTP scene information. The real-time performance and overhead problems caused by the high dependence of the traditional scheme on the pre-set templates and the high dependence of the strategy on reinforcement learning and complete information game are solved, the problem of real-time transformation decision-making of live network information is effectively solved, and high-sweetness transformation is realized. The honey array transformation configuration file consistent with the attack behaviors of the attacker is constructed and generated, and then a corresponding high-sweetness trap scene can be generated.

[0066] See the attachedFigure 6 This embodiment also provides a honeycomb array transformation configuration generation device, which is used to implement the above method embodiment. The device includes:

[0067] The mapping unit 201 is used to obtain TTP information in the honey array, match CWE information according to TTP information to obtain the corresponding CWE number, and match CVE according to CWE number to obtain CVE information.

[0068] CVE image matching unit 202 is used to perform CVSS evaluation based on CVE information to obtain CVSS score, sort according to CVSS score, and select the M images associated with the highest score CVE information to generate the corresponding CVE image configuration segment.

[0069] The feature mirror matching unit 203 is used to extract scene feature information based on TTP information and match honey spot mirrors based on scene feature information to generate corresponding feature mirror configuration segments.

[0070] Honeypoint configuration generation unit 204 is used to generate honeypoint configuration segments with new honeypoints and service characteristics based on the associated file paths and process information obtained from TTP information.

[0071] The honey array transformation configuration generation unit 205 is used to mix the CVE mirror configuration segment, the feature mirror configuration segment and the honey point configuration segment to generate a honey array transformation configuration file, and apply the honey array transformation configuration file to transform the trapping scene configuration.

[0072] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.

[0073] In other embodiments of this application, an electronic device is disclosed, such as... Figure 7 As shown, the electronic device 300 may include: one or more processors 301; a memory 302; a display 303; one or more application programs (not shown); and one or more computer programs 304. These devices can be connected via one or more communication buses 305. The one or more computer programs 304 are stored in the memory and configured to be executed by the one or more processors 301. The one or more computer programs 304 include instructions that can be used to perform actions such as... Figure 1 And the steps in the corresponding embodiments.

[0074] Those skilled in the art can clearly understand the technical solutions of the present application according to the above description of the embodiments, and for the convenience and brevity of description, only the division of the above functional modules is taken as an example, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0075] The functional units in the various embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of a software functional unit.

[0076] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or in other words, the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: a flash memory, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk or an optical disk, and various media that can store program codes.

[0077] The above description is only a specific implementation of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any change or replacement within the technical scope disclosed in the embodiments of the present application should be covered in the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.

Claims

1. A method for generating honeycomb array transformation configurations, characterized in that, The method comprises the following steps: Obtain TTP information in the honeycomb, match CWE information according to the TTP information to obtain corresponding CWE numbers, and match CVE according to the CWE numbers to obtain CVE information; According to the CVE information, CVSS evaluation is performed to obtain a CVSS score, the CVSS score is sorted, and the M images associated with the CVE information with the highest score are selected to generate corresponding CVE image configuration segments; According to the TTP information, scene feature information is extracted, and corresponding feature image configuration segments are generated by matching the honeypot image according to the scene feature information; According to the TTP information, the file path and process information associated with the new honeypot and service features are obtained to generate a honeypot configuration segment of the new honeypot and service features; The CVE image configuration segment, the feature image configuration segment and the honeypot configuration segment are mixed to generate a honeycomb transformation configuration file, and the honeycomb transformation configuration file is used to transform the trap scene configuration.

2. The method of claim 1, wherein, According to the TTP information, the corresponding CWE numbers are obtained by matching the CWE information, which comprises the following steps: Map the TTP information to CAPEC to obtain a CAPEC entry; Map the CAPEC entry to the corresponding CWE number.

3. The method of claim 1, wherein, The CVE image configuration segment and the feature image configuration segment are in JSON format; The CVE image configuration segment and the feature image configuration segment comprise image information and basic configuration information of the container.

4. The method of claim 1, wherein, According to the TTP information, scene feature information is extracted, and corresponding feature image configuration segments are generated by matching the honeypot image according to the scene feature information, which comprises the following steps: According to the TTP information, the process information, the extension name information, the operating system information and the path information of the scene are extracted; Through process matching, extension name matching, operating system matching and path matching, the honeypot image is matched to obtain a multi-feature matching honeypot image.

5. The method of claim 1, wherein, After matching the honeypot image according to the scene feature information, the following steps are further included: Select a guide script according to the matched honeypot image, and the guide script comprises a data import script and a preset credential script.

6. The method of claim 1, wherein, The CVE image configuration segment, the feature image configuration segment and the honeypot configuration segment are mixed to generate a honeycomb transformation configuration file, which comprises the following steps: Aggregate the CVE image configuration segment and the feature image configuration segment to generate a service transformation configuration segment; Mix the service transformation configuration segment with the honeypot configuration segment to generate a honeycomb transformation configuration file.

7. The method of claim 6, wherein, The application of the honeycomb transformation configuration file to transform the trap scene configuration comprises the following steps: The honeycomb executor parses the honeycomb transformation configuration file, and places corresponding containers in the existing network base according to the service transformation configuration segment; The system honeypot in the honeypot configuration segment is placed through file import and execution.

8. A honeycomb transformation configuration generation apparatus characterized by comprising: The device comprises: A mapping unit is configured to obtain TTP information in the honeycomb, match CWE information according to the TTP information to obtain corresponding CWE numbers, and match CVE according to the CWE numbers to obtain CVE information; A CVE image matching unit is configured to perform CVSS evaluation according to the CVE information to obtain a CVSS score, sort the CVSS score, and select the M images associated with the CVE information with the highest score to generate corresponding CVE image configuration segments; The feature mirror matching unit is configured to extract scene feature information according to the TTP information, and match a corresponding feature mirror configuration section according to the scene feature information. The honeypot configuration generation unit is configured to generate a new honeypot and a service feature honeypot configuration section according to the TTP information, the associated file path and the process information. The honeynet transformation configuration generation unit is configured to mix the CVE mirror configuration section, the feature mirror configuration section and the honeypot configuration section to generate a honeynet transformation configuration file, and the honeynet transformation configuration file is used to transform a trapping scene configuration.

9. A computer-readable storage medium having stored thereon a computer program, characterized in that The computer program is executed by a processor to implement the honeynet transformation configuration generation method in any one of claims 1 to 7.

10. An electronic device, comprising: It comprises: a processor and a memory; the memory is configured to store a computer program; the processor is configured to execute the computer program stored in the memory, so that the electronic device executes the honeynet transformation configuration generation method in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Honey array graph generation method and system based on confusion attack graph

    CN118631579A

  • Dynamic honeypot deployment and optimization method and system based on intelligent flow analysis

    CN120614141A