An industrial control honeypot trapping method and system

By adopting a cloud-edge dual-layer distributed architecture and iteratively trained industrial control honeypot system, the problems of rigid interaction logic and high maintenance costs of industrial control honeypots are solved. It achieves efficient and dynamic trapping response and adaptive defense, improving the trapping success rate and system defense capabilities.

CN122120014APending Publication Date: 2026-05-29CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE
Filing Date
2026-04-16
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing industrial control honeypot technology suffers from rigid interaction logic that is easily identified, high maintenance costs, inability to achieve dynamic self-adaptation, and difficulty in cross-domain intelligence sharing, resulting in a low success rate of trapping.

Method used

It adopts a cloud-edge dual-layer distributed architecture, utilizes iterative training of global and local models, acquires attack data through honeypot nodes, generates trap response data using a pre-set trap database and local models, and updates the model by combining low-rank adaptive training and federated averaging algorithms to achieve dynamic adaptation and high-fidelity deception.

Benefits of technology

It achieves accurate identification and non-disruptive collection of attack traffic, generates highly realistic deception data, improves the success rate of trapping, extends the interaction depth, fully acquires attack methods, provides samples for model evolution, reduces computing power consumption, and enhances the active defense capability of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120014A_ABST
    Figure CN122120014A_ABST
Patent Text Reader

Abstract

The application provides an industrial control honeypot trapping method and system. Attack data sent by an attacker is obtained by a honeypot node. Whether the trapping response data corresponding to the attack data exists in the preset trapping database is determined by the honeypot node. When the trapping response data exists, the common attack can be quickly responded, the computing power is saved, and the system operation efficiency is improved. When the trapping response data does not exist, the attack data is input into the local model of the current round which is trained in advance by the honeypot node, and the trapping response data is obtained. When there is no matching item in the database, the trapping response data is generated by the local model, unknown attacks and complex instructions are coped with, high-fidelity cheating data is generated, and the high-fidelity cheating data is not easy to be identified by hackers. The trapping response data is sent to the attacker by the honeypot node to obtain the trapping data fed back by the attacker. The trapping response is returned to the attacker, and the subsequent trapping data fed back by the attacker is captured, the trapping time is prolonged, the attack method is completely obtained, and samples are provided for model evolution.
Need to check novelty before this filing date? Find Prior Art