High-interaction sip honeypot system based on phased interaction control
By constructing a highly interactive SIP honeypot system based on phased interactive control, the shortcomings of existing SIP honeypot systems in terms of interaction strategies are solved. This enables progressive induction and comparative analysis of attacker behavior, improves attack behavior analysis capabilities and resource utilization efficiency, and supports the detection of encrypted malicious traffic.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SUN YAT SEN UNIV
- Filing Date
- 2026-04-17
- Publication Date
- 2026-07-03
AI Technical Summary
Existing SIP honeypot systems have shortcomings in their interaction strategies. They are unable to progressively induce and compare attacker behavior at different interaction stages while ensuring system controllability and security. Furthermore, they lack flexible interaction processing logic, making it difficult to simulate real SIP session flows and identify advanced attack behaviors.
A highly interactive SIP honeypot system based on phased interactive control is adopted. Through a message receiving module, a SIP interactive control module, a session state machine module, and a phase switching control module, a three-stage progressive interactive mode of static foundation, dynamic perception, and phase perception is constructed. The interactive mode is dynamically switched to simulate the signaling flow of a real SIP server, and the recording and statistics module continuously records the characteristics of attack behavior.
It enables the dynamic induction and recording of attacker behavior while ensuring system controllability, enhances the ability to analyze the evolution of attack behavior, provides representative attack data to support the detection of encrypted malicious traffic, and improves resource utilization efficiency and interaction depth.
Smart Images

Figure CN122339784A_ABST
Abstract
Citation Information
Patent Citations
A Reinforcement Learning-Based Method for Generating Honeynet Deployment Strategies in an Intranet Environment
CN119341771B