An attacker perception and portrait construction method, system, medium and processor based on IP grayscale value and trapping technology
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGXI POWER GRID CORP
- Filing Date
- 2026-04-10
- Publication Date
- 2026-07-10
Smart Images

Figure CN122372261A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, system, medium, and processor for attacker perception and profiling based on IP grayscale values and decoy techniques. Background Technology
[0002] Currently, cyberattacks are becoming increasingly complex, covert, and persistent. Traditional passive defense systems (such as rule-based firewalls and signature-based intrusion detection systems) often suffer from limitations when facing new types of attacks, including delayed identification, high false positive rates, and difficulty in tracing the attacker's complete intent and behavioral chain. To enhance proactive defense capabilities, the industry has introduced technologies such as threat intelligence, honeypots, and sandboxes to lure and monitor attackers.
[0003] However, within the existing technological framework, the key links of risk identification, decoy handling, behavioral analysis, and intelligence production are often isolated or loosely coupled, limiting the overall effectiveness of proactive defense. Specifically: 1) Risk assessment of visitors often relies on a single dimension (such as IP reputation), making it difficult to achieve accurate and dynamic risk grading, thus failing to provide differentiated basis for subsequent handling; 2) Decoy environments are often statically deployed, unable to intelligently match decoy scenarios and monitoring strategies with different interaction depths based on the visitor's real-time risk level, resulting in resource waste or monitoring blind spots; 3) Monitoring data on attack behavior is scattered, lacking unified and real-time aggregation and analysis capabilities, making it difficult to quickly and accurately identify attackers and extract their tactical intentions from massive behavioral logs; 4) Even when attack behavior is captured, there is a lack of systematic methods for constructing multi-dimensional profiles and assessing threats against attackers, making it difficult to form shareable and actionable high-value threat intelligence.
[0004] Therefore, there is a need for an attacker perception and profiling method, system, medium, and processor based on IP grayscale values and decoy techniques. Summary of the Invention
[0005] To address the problem of isolated or loosely coupled network security detection methods in existing technologies, this invention provides a method, system, medium, and processor for attacker perception and profiling based on IP grayscale values and decoy techniques. This method organically integrates multiple previously isolated processes, such as risk identification, intelligent decoys, behavioral analysis, and profiling, forming a closed-loop proactive defense process. The tight coupling and data interoperability between these processes enable the system to continuously track, deeply analyze, and collaboratively respond to attackers, significantly improving the systematic nature and overall effectiveness of the proactive defense system. The specific technical solution is as follows: A method for attacker perception and profiling based on IP grayscale values and decoy techniques includes: S1: Monitor accessing IPs in real time and calculate grayscale values to determine the risk level of accessing IPs; S2: Presets multi-level internal trapping environments and monitoring strategies, and matches guidance strategies according to the risk level of the accessing IP; S3: Based on the guidance strategy, transparently guide access traffic to the matching internal trapping environment, and perform comprehensive behavior monitoring and data collection within the trapping environment; S4: Perform real-time analysis and aggregation of behavioral data obtained from the trapping environment, and determine whether the visitor is an attacker based on a predefined attack behavior feature library and a judgment model; the judgment model comprehensively evaluates the feature matching degree, the degree of malicious intent, and the degree of behavioral deviation from multiple dimensions. S5: If identified as an attacker, an attacker profile is constructed based on accumulated behavioral data and a threat assessment is conducted.
[0006] Furthermore, in step S1, the real-time monitoring of the accessing IP and the calculation of grayscale values to determine the risk level of the accessing IP includes the following steps: S11: Monitor accessing IPs in real time to collect raw data; S12: Clean and standardize the original data, extract several dimensional features for grayscale calculation and normalize them. S13: Construct a grayscale calculation model and calculate the IP grayscale value based on several dimensional features; S14: Classify the risk level of accessing IPs based on grayscale values.
[0007] Furthermore, in step S13, the grayscale calculation model is as follows: ; in, This represents the grayscale value of the accessing IP address; Indicates the total number of feature dimensions; Indicates the first The weights of each feature; Indicates the first Normalized scores for each feature.
[0008] Furthermore, in step S2, the preset multi-level internal trapping environment and monitoring strategy, and the matching of guidance strategies based on the risk level of the accessing IP, include the following steps: S21: Pre-set and maintain an internal trapping environment library with multiple levels, wherein the trapping environment is deployed in an isolated network or virtualization platform that is completely under the control of the party; S22: Configure corresponding deep monitoring probes and logging strategies for each type of trapping environment; S23: Based on the IP risk level output in S1, match the corresponding traffic redirection and monitoring strategies.
[0009] Furthermore, in step S3, the process of transparently guiding access traffic to a matching internal trapping environment according to the guidance strategy, and performing comprehensive behavior monitoring and data collection within the trapping environment, includes the following steps: S31: Employ network layer redirection, application layer proxy, or DNS spoofing techniques to transparently redirect traffic to the trapping environment, ensuring that attackers are unaware of it; S32: Deploy monitoring components within the trapping environment; S33: All monitoring components will send the collected behavioral data to the central data analysis platform through a secure internal network; S34: Record all bootstrap decision logs, including bootstrap time, source IP, target trapping environment, and decision reasons, for use in subsequent strategy auditing and optimization.
[0010] Further, step S4, which involves real-time analysis and aggregation of behavioral data obtained from the trapping environment, and determining whether a visitor is an attacker based on a predefined attack behavior feature library and judgment model, includes the following steps: S41: Receive and aggregate structured behavioral data reported by each trapping environment in real time from the central data analysis platform, reassemble the sessions according to the source IP and time window, and form a complete behavioral sequence log; S42: Based on a predefined attack behavior feature library, perform feature extraction and matching on behavior sequence logs; S43: Construct an attack determination model and calculate the attack confidence score based on the feature matching results; S44: Set the judgment threshold and output the judgment result based on the confidence score; S45: Record the judgment process and basis, including the list of matched features, details of each score, judgment time and final result, for use in subsequent auditing and model optimization.
[0011] Furthermore, in step S43, the attack determination model is as follows: ; in, Score the attack confidence level; Degree of malicious intent; For behavioral deviation; , , These are the weighting coefficients; This represents the feature matching degree.
[0012] An attacker perception and profiling system based on IP grayscale values and decoy techniques, applied to the aforementioned attacker perception and profiling method based on IP grayscale values and decoy techniques, includes: The IP analysis module is used to monitor accessing IPs in real time and calculate grayscale values to determine the risk level of the accessing IPs. The matching module is used to preset multi-level internal trapping environments and monitoring strategies, and to match guidance strategies based on the risk level of the accessing IP. The trapping module is used to transparently guide access traffic to a matching internal trapping environment according to the guidance strategy, and to perform comprehensive behavior monitoring and data collection within the trapping environment. The judgment module is used to perform real-time analysis and aggregation of behavioral data obtained from the trapping environment. Based on a predefined attack behavior feature library and judgment model, it determines whether the visitor is an attacker. The judgment model comprehensively evaluates the feature matching degree, the degree of malicious intent, and the degree of behavioral deviation from multiple dimensions. The profiling module is used to build an attacker profile and conduct threat assessment based on accumulated behavioral data if the attacker is identified.
[0013] A computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to execute the attacker perception and profiling method based on IP grayscale value and decoy technology described above.
[0014] A processor for running a program, wherein the program executes the attacker perception and profiling method based on IP grayscale values and decoy techniques described above.
[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This solution achieves dynamic and accurate assessment of access IP risk by introducing a multi-dimensional feature fusion-based IP grayscale value calculation model. Compared to traditional static judgment methods that rely on a single reputation database, this solution can comprehensively analyze behavioral characteristics, threat intelligence, contextual relationships, and other multi-source information for real-time scoring and classification, significantly improving the accuracy and adaptability of risk identification and providing a reliable basis for subsequent differentiated handling.
[0016] 2. This solution constructs a multi-level internal trapping environment library and can intelligently match corresponding trapping scenarios and monitoring strategies based on IP risk levels. Compared to traditional statically deployed honeypot systems, this solution achieves on-demand resource allocation and dynamic adjustment of guidance strategies, avoiding over-monitoring of low-risk traffic while ensuring in-depth interaction and behavioral capture of high-risk attackers, thus improving the overall efficiency and targeting of the trapping system.
[0017] 3. By using a central data analysis platform to aggregate, reconstruct, and match behavioral data reported from multiple decoy environments in real time, this solution achieves unified analysis and rapid judgment of attack behaviors. The scattered monitoring data in traditional solutions is integrated here. Combined with a predefined attack signature library and a multi-dimensional judgment model, the system can accurately identify attack intent from complex behavioral sequences, improving the real-time performance and reliability of threat detection.
[0018] 4. This solution not only detects attack behaviors but also builds attacker profiles and conducts threat assessments based on accumulated behavioral data. By extracting multi-dimensional fingerprints of attack tools, behavioral patterns, and infrastructure, it forms standardized attacker profiles and threat intelligence, achieving a leap from passive defense to proactive intelligence production, and providing strong support for attack attribution and defense strategy optimization.
[0019] 5. This solution organically integrates several previously isolated processes, such as risk identification, intelligent trapping, behavioral analysis, and profile building, into a closed-loop proactive defense process. The tight coupling and data interoperability between these processes enable the system to continuously track attackers, conduct in-depth analysis, and respond collaboratively, significantly improving the systematic nature and overall effectiveness of the proactive defense system. Attached Figure Description
[0020] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the accompanying drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.
[0021] Figure 1 This is a flowchart illustrating a method for attacker perception and profiling based on IP grayscale values and decoy techniques.
[0022] Figure 2 A schematic diagram of the system structure for attacker perception and profiling based on IP grayscale values and decoy techniques. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] It should be understood that, when used in this specification, the terms “comprising” and “including” indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0025] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0026] It should also be further understood that the term "and / or" as used in this specification refers to any combination of one or more of the associated listed items, as well as all possible combinations, and includes such combinations.
[0027] Example 1 like Figure 1 The diagram illustrates a method for attacker perception and profiling based on IP grayscale values and decoy techniques, which includes the following steps: S1: Monitor the accessing IP in real time and calculate the gray value to determine the risk level of the accessing IP.
[0028] S11: Monitor access IPs in real time and collect raw data including but not limited to the following: The source IP address, timestamp, request method (e.g., GET / POST), and request path of the access request; Historical access behavior logs, including past request records from the same IP address; External threat intelligence data, such as a known malicious IP database and IP reputation scores; Contextual information, including access frequency, session duration, and request interval distribution.
[0029] S12: Clean and standardize the raw data, extract several dimensional features for grayscale calculation, and normalize them. These dimensional features mainly include: Behavioral statistical characteristics: number of requests per unit time, proportion of non-routine requests, and dispersion of access paths; Intelligence matching characteristics: whether the IP appears in the real-time threat intelligence database and whether it belongs to a known malicious network segment; Contextual characteristics: whether access was made during abnormal time periods, or whether attempts were made to access sensitive interfaces or resources; Protocol and payload characteristics: Whether the abnormal fields in the request header, the length and format of the payload conform to common attack patterns.
[0030] S13: Construct a grayscale calculation model and calculate the IP grayscale value (range 0–100) based on several dimensional features. The grayscale calculation model is as follows: ; in, This represents the grayscale value of the accessing IP address, ranging from 0 to 100. Indicates the total number of feature dimensions; Indicates the first The weights of each feature satisfy... ; Indicates the first The normalized score of each feature ranges from 0 to 100. The model formula achieves multi-dimensional comprehensive quantification of IP risk by weighted summation of the normalized scores of each feature and their corresponding weights, providing a unified gray value index for subsequent risk classification.
[0031] 1. Statistical characteristics of behavior (continuous type): ; in , These are the lower and upper bound thresholds for the behavioral statistical features, respectively. The original feature value is denoted as 0. In the formula, continuous feature values are mapped to the 0~100 range through linear transformation, and truncated using upper and lower bound thresholds to ensure that features of different dimensions can participate in grayscale value calculation in a unified manner.
[0032] 2. Intelligence matching features: If it is a Boolean value (such as in a malicious IP database), then Otherwise ; If it is a credit rating (0–1), then .
[0033] 3. Contextual features (rule matching type): ; in For the total number of rules, The formula calculates the proportion of context rules matched by the current IP to the total number of rules, and converts it into a percentage score, which can effectively quantify the degree of anomaly in the context environment.
[0034] 4. Protocol and payload characteristics (anomaly counting type): in, The number of anomalies detected. The maximum number of outliers is the threshold; the formula uses the number of detected outliers and the preset maximum threshold. The ratio is used to quantify the degree of anomaly between the protocol and the payload, and the score is limited to 100 by a minimum function to avoid a single feature from excessively affecting the grayscale value.
[0035] S14: Based on the grayscale values, the accessing IPs are classified into three risk levels: Low risk (0-40): Characteristic performance is normal, considered a normal user; Medium risk (41-75): Some characteristics are abnormal, and the visitor is considered suspicious; High risk (76-100): Multiple characteristics are obviously abnormal, indicating a potential attacker.
[0036] This classification is based on historical attack data statistics to ensure that each level has good distinguishability.
[0037] S2: Presets multi-level internal trapping environments and monitoring strategies, and matches guidance strategies according to the risk level of the accessing IP.
[0038] S21: Pre-set and maintain a multi-level internal trapping environment library, wherein the trapping environment is deployed in an isolated network or virtualization platform under complete control, including but not limited to the following types: Low-interaction honeypots: Simulate simple responses from common services (such as SSH, HTTP, and databases) for initial probe behavior identification; High-interaction honeypots: deploy virtual machines or containers that closely resemble real systems, allowing attackers to engage in substantial interactions in order to capture the complete attack chain; Sandbox environment: Used to isolate suspicious files or code execution and record all their system calls, network activity, and memory changes; Simulated business environment: Replicating some real business logic and data (using anonymized or fake data) to detect targeted business logic attacks.
[0039] Traditional honeypots are often statically deployed, treating all traffic equally, which can easily lead to exposure or wasted resources. This solution dynamically matches the trapping environment based on the IP risk level (e.g., low risk → simple honeypot, high risk → high-interaction sandbox), which enhances the realism of the trapping while preventing attackers from detecting it.
[0040] S22: For each type of trapping environment, configure corresponding deep monitoring probes and logging policies to ensure that the following data are collected without omission: Network layer: Full traffic packet capture (PCAP).
[0041] Host layer: system calls, process tree, file operations, registry modifications (Windows) or configuration changes (Linux).
[0042] Application layer: database queries, web request / response content, API call sequences.
[0043] User layer: Keyboard logging (within the trapping environment), screen recording.
[0044] S23: Based on the IP risk level output in S1, match the corresponding traffic redirection and monitoring strategies: Low risk (0-40): Traffic is redirected to normal business systems, and only baseline security monitoring is applied.
[0045] Medium risk (41-75): Redirect access requests to unconventional ports, paths, or services to a low-interaction honeypot or basic sandbox environment via network redirection or reverse proxy, and initiate standard monitoring.
[0046] High risk (76-100): The entire session (or newly created session) is completely guided to a high-interaction honeypot or advanced sandbox environment through a transparent gateway or DNS resolution control, and comprehensive deep monitoring and behavior recording are initiated.
[0047] S3: Based on the guidance strategy, the access traffic is transparently guided to the matching internal trapping environment, and comprehensive behavior monitoring and data collection are performed within the trapping environment.
[0048] S31: Employ one or more of the following techniques to transparently redirect traffic to the trapping environment, ensuring that attackers are unaware of it: Network layer redirection: Configure policy-based routing on firewalls or routers to forward traffic from specific source IPs to the trapping environment network segment; Application layer proxy: Deploy reverse proxies (such as Nginx, HAProxy) to forward requests to different backends (real business or trapping environment) based on request characteristics and source IP risk level. DNS spoofing / dynamic resolution: Controls internal DNS to return the IP address of the trapping environment for domain name resolution requests from high-risk IPs.
[0049] S32: Within the trapping environment, deploy and run legitimate monitoring components, including: Host Intrusion Detection System (HIDS) Agent; Full-traffic sniffers (such as those deployed next to virtual switches in a trapping environment); Behavior recording tools (such as TerminalRecorder, ScreenCapture); Customized application log enhancement module.
[0050] S33: All monitoring components will collect behavioral data and send it to the central data analysis platform via a secure internal network. The data format is structured logs, including: Event timestamp, trapping environment identifier, source IP; Behavior type (network connection, file creation, command execution, etc.); Behavior details and context; Raw network load or file sample (securely processed).
[0051] S34: Record all bootstrap decision logs, including bootstrap time, source IP, target trapping environment, and decision reasons, for use in subsequent strategy auditing and optimization.
[0052] Once an attacker is lured into the trapping environment, all their subsequent actions (including lateral movement, persistence attempts, and data leakage) are continuously monitored and recorded, forming a complete attack behavior chain. This "immersive" monitoring makes it difficult for attackers to escape and provides full-cycle data for subsequent profile building.
[0053] S4: Perform real-time analysis and aggregation of behavioral data obtained from the trapping environment, and determine whether the visitor is an attacker based on a predefined attack behavior feature library and judgment model; the judgment model comprehensively evaluates the feature matching degree, the degree of malicious intent, and the degree of behavioral deviation in a multi-dimensional manner.
[0054] S41: Receive and aggregate structured behavioral data reported by each trapping environment in real time from the central data analysis platform described in S33, reassemble the sessions according to source IP and time window, and form a complete behavioral sequence log. Each log entry contains: Session identifier, source IP, trapping environment type, start and end timestamps; A list of behavioral events, each event including event type, target object, execution result, and associated payload or file hash; Contextual tags, such as whether to attempt privilege escalation, whether to perform lateral movement, and whether to attempt data transfer.
[0055] S42: Based on a predefined attack behavior feature library, perform feature extraction and matching on behavior sequence logs. The predefined attack behavior feature library includes, but is not limited to: Vulnerability exploitation characteristics: Known vulnerability exploitation payload characteristics and abnormal system call sequences; Malicious tool characteristics: Command patterns and execution traces of common attack tools (such as Mimikatz and Nmap); Lateral movement characteristics: intranet scanning behavior, credential theft attempts, and remote service brute-force attacks; Persistence features: scheduled task creation, service installation, startup item modification, and hidden file creation; Data outbound characteristics: abnormal external connection behavior, high-volume uploads, and establishment of encrypted tunnels.
[0056] Furthermore, feature extraction and matching of behavioral sequence logs refers to extracting events from the behavioral sequence logs and matching them with a predefined feature library. For each matched feature j, the matching strength is calculated as follows: Matching strength : A continuous value between 0 and 1, indicating the significance of the feature being triggered.
[0057] Example: If the feature is "attempting brute force", It can be calculated based on the number of attempts (e.g., min(number of attempts / 10, 1)); ; If the feature is "using known exploit payload", then It can be based on similarity or confidence scores of load matching.
[0058] Furthermore, the feature matching degree is determined based on the matching strength. ; ; in, The total number of matched features; The matching strength (0–1) is the value of the j-th feature. The feature weight for the j-th feature is a preset weight value that indicates the importance of the feature in attack determination (e.g., "obtaining a system shell" has a greater weight than "port scanning"); the formula uses a weighted average of the strengths of each matching feature. (weight) Then convert it to a percentage to obtain the overall feature matching degree. It can comprehensively reflect the degree of conformity between the current behavior and the predefined attack signature database, providing a basis for attack judgment.
[0059] S43: Construct an attack detection model and calculate the attack confidence score based on feature matching results. The model adopts a multi-dimensional weighted scoring method, as shown in the following formula: ; in, Assign an attack confidence score, ranging from 0 to 100; The degree of malicious intent is calculated based on the density and severity of events related to malicious intent in the behavioral sequence. The behavioral deviation measure is the difference between the user's behavior and the baseline behavior of a normal user. , , Let be the weighting coefficient, satisfying + + =1; In the formula, the feature matching degree, the degree of malicious intent, and the degree of behavioral deviation are linearly weighted by weight coefficients to obtain the attack confidence score, which realizes a multi-dimensional comprehensive assessment of the attack probability and improves the accuracy and robustness of the judgment.
[0060] ; in, This represents the total number of maliciously intent-driven events identified in the sequence of actions. Indicates the first The severity score (0~1) of each malicious intent event is preset; Indicates the first The weight of each event reflects its importance in intent determination and is predetermined. The formula calculates the severity score of malicious intent events by weighted averaging and converting it into a percentage, thus obtaining the degree of intent malice. This quantifies the strength of the subjective malice behind the attacker's behavior and supplements the intent-level information that simple feature matching cannot reflect.
[0061] ; in, This represents the total number of behavioral features used for deviation calculation; For the observed first One eigenvalue; The first for normal user baseline One eigenvalue; For the first The weight of each feature reflects the degree of influence of that feature on the judgment of normality of behavior. The formula calculates the weighted absolute deviation between the observed behavioral feature value and the normal baseline feature value, and converts it into a percentage to obtain the behavioral deviation degree. This can effectively identify abnormal behaviors that are significantly different from normal user behavior patterns, thereby discovering unknown or variant attacks.
[0062] S44: Set the judgment threshold and output the judgment result based on the confidence score: like They were identified as attackers. like If the behavior is deemed suspicious, the existing trapping environment will remain unchanged while enhanced monitoring will be initiated. like If the condition is deemed normal, the current trapping session will end and resources will be released.
[0063] S45: Record the judgment process and basis, including the list of matched features, details of each score, judgment time and final result, for use in subsequent auditing and model optimization.
[0064] Traditional IDS / IPS only detect known attack signatures, making it difficult to identify the attacker's overall intent. This solution, through multi-dimensional feature fusion and an attack confidence model, not only determines "whether an attack has occurred," but also assesses the "strength of the attack intent" and "the degree of behavioral deviation," achieving more accurate threat assessment.
[0065] S5: If identified as an attacker, an attacker profile is constructed based on accumulated behavioral data and a threat assessment is conducted.
[0066] S51: For IPs identified as attackers, aggregate their full-cycle deep monitoring data, system logs, and network traffic records across all relevant trapping environments, and reconstruct their complete attack behavior sequence from initial probe to ongoing activity in chronological order.
[0067] S52: Extract highly recognizable static and dynamic fingerprints from the integrated behavioral sequence, including: Tool fingerprint: Hash, script characteristics, and command patterns of attack software uploaded, downloaded, or executed in the trapping environment; Behavioral fingerprints: the sequence of attack methods, lateral movement paths, time patterns, and target selection patterns exhibited within the trapping environment; Environmental fingerprinting includes the C2 (command and control) server address exposed during the attack, the download source of the third-party tools used, and the configuration information hard-coded in the attack payload.
[0068] S53: The extracted fingerprint information is correlated and fused to generate a standardized attacker profile, which mainly includes: Identity identification zone: IP address, associated malicious infrastructure (such as C2 domain / IP address), potential attack organization or family affiliation (matched via TTPs). Behavioral Archives: Attack timelines, toolchains, tactics, techniques and processes (TTPs) reconstructed from data of the entrapment environment. Intent assessment area: speculated attack objectives (such as intelligence gathering, ransomware deployment, or establishing persistent backdoors).
[0069] S54: Combine profile information to conduct a multi-dimensional threat assessment of attackers: Technical capability assessment: Scoring is based on the degree of automation of tools, proficiency in exploiting vulnerabilities, and anti-detection awareness demonstrated in the trapping environment; Potential Hazard Assessment: Scoring is based on the similarity of its TTPs to known high-threat attack patterns and the potential damage it may cause to our real assets. Activity and focus assessment: Scored based on the duration of attack sessions, depth of interaction, and positivity of lateral movement attempts in the trapping environment; Intelligence value assessment: Scored based on the scarcity of the sample hash captured in this trap, the new C2 infrastructure exposed, or the new attack patterns associated with it.
[0070] S55: The generated attacker profiles and threat assessment results are persistently stored in the local threat intelligence database. These profiles and assessment results are based on legitimate monitoring and do not contain any non-public personal information. Depending on the policy, anonymized TTPs intelligence, malicious sample fingerprints, and related infrastructure information can be shared to a higher-level threat intelligence platform for cross-system and cross-organizational collaborative defense and attack attribution. The entire process not only serves defense but also generates high-quality threat intelligence (such as new attack tools, TTPs, C2 infrastructure, etc.), which can be used for internal optimization or external sharing. This "defense as intelligence" model enables the system to have self-iterative and continuous learning capabilities.
[0071] Traditional solutions often remain at the level of "blocking attacks," lacking a deep understanding of the attacker. This solution extracts multi-dimensional features such as tool fingerprints, behavioral patterns, and C2 infrastructure to construct a relatable and predictable attacker profile, supporting subsequent threat hunting and attribution tracing.
[0072] Example 2 like Figure 2 The diagram shows a structural schematic of an attacker perception and profiling system based on IP grayscale values and decoy techniques. Applied to the aforementioned attacker perception and profiling method based on IP grayscale values and decoy techniques, it includes: The IP analysis module is used to monitor accessing IPs in real time and calculate grayscale values to determine the risk level of the accessing IPs. The matching module is used to preset multi-level internal trapping environments and monitoring strategies, and to match guidance strategies based on the risk level of the accessing IP. The trapping module is used to transparently guide access traffic to a matching internal trapping environment according to the guidance strategy, and to perform comprehensive behavior monitoring and data collection within the trapping environment. The judgment module is used to perform real-time analysis and aggregation of behavioral data obtained from the trapping environment. Based on a predefined attack behavior feature library and judgment model, it determines whether the visitor is an attacker. The judgment model comprehensively evaluates the feature matching degree, the degree of malicious intent, and the degree of behavioral deviation from multiple dimensions. The profiling module is used to build an attacker profile and conduct threat assessment based on accumulated behavioral data if the attacker is identified.
[0073] Example 3 A computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to execute the attacker perception and profiling method based on IP grayscale value and decoy technology described above.
[0074] Example 4 A processor for running a program, wherein the program executes the attacker perception and profiling method based on IP grayscale values and decoy techniques described above.
[0075] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This solution achieves dynamic and accurate assessment of access IP risk by introducing a multi-dimensional feature fusion-based IP grayscale value calculation model. Compared to traditional static judgment methods that rely on a single reputation database, this solution can comprehensively analyze behavioral characteristics, threat intelligence, contextual relationships, and other multi-source information for real-time scoring and classification, significantly improving the accuracy and adaptability of risk identification and providing a reliable basis for subsequent differentiated handling.
[0076] 2. This solution constructs a multi-level internal trapping environment library and can intelligently match corresponding trapping scenarios and monitoring strategies based on IP risk levels. Compared to traditional statically deployed honeypot systems, this solution achieves on-demand resource allocation and dynamic adjustment of guidance strategies, avoiding over-monitoring of low-risk traffic while ensuring in-depth interaction and behavioral capture of high-risk attackers, thus improving the overall efficiency and targeting of the trapping system.
[0077] 3. By using a central data analysis platform to aggregate, reconstruct, and match behavioral data reported from multiple decoy environments in real time, this solution achieves unified analysis and rapid judgment of attack behaviors. The scattered monitoring data in traditional solutions is integrated here. Combined with a predefined attack signature library and a multi-dimensional judgment model, the system can accurately identify attack intent from complex behavioral sequences, improving the real-time performance and reliability of threat detection.
[0078] 4. This solution not only detects attack behaviors but also builds attacker profiles and conducts threat assessments based on accumulated behavioral data. By extracting multi-dimensional fingerprints of attack tools, behavioral patterns, and infrastructure, it forms standardized attacker profiles and threat intelligence, achieving a leap from passive defense to proactive intelligence production, and providing strong support for attack attribution and defense strategy optimization.
[0079] 5. This solution organically integrates several previously isolated processes, such as risk identification, intelligent trapping, behavioral analysis, and profile building, into a closed-loop proactive defense process. The tight coupling and data interoperability between these processes enable the system to continuously track attackers, conduct in-depth analysis, and respond collaboratively, significantly improving the systematic nature and overall effectiveness of the proactive defense system.
[0080] This solution discloses an attacker perception and profiling method, system, medium, and processor based on IP grayscale values and decoy techniques, relating to the field of network security technology. The method includes: real-time monitoring of accessing IPs and calculation of grayscale values based on multi-dimensional features to achieve dynamic risk classification; intelligent matching of multi-level decoy environments and monitoring strategies according to risk levels; guiding traffic into corresponding decoy environments through transparent guidance technology for comprehensive behavioral monitoring and data collection; real-time analysis of behavioral data based on a predefined feature library and judgment model to identify attackers; and constructing multi-dimensional profiles from accumulated attacker behavioral data and conducting threat assessment. This invention achieves closed-loop linkage of risk identification, decoy handling, behavioral analysis, and intelligence production, improving the accuracy of attacker perception, decoy efficiency, and threat intelligence production capabilities, thereby enhancing the overall effectiveness of the proactive defense system. This invention can be used in numerous general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices, etc.
[0081] Those skilled in the art will recognize that the units of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.
[0082] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical functional division. In actual implementation, there may be other division methods, such as multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored.
[0083] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0084] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the specification of the present invention.
Claims
1. A method for attacker perception and profiling based on IP grayscale values and decoy techniques, characterized in that, include: S1: Monitor accessing IPs in real time and calculate grayscale values to determine the risk level of accessing IPs; S2: Presets multi-level internal trapping environments and monitoring strategies, and matches guidance strategies according to the risk level of the accessing IP; S3: Based on the guidance strategy, transparently guide access traffic to the matching internal trapping environment, and perform comprehensive behavior monitoring and data collection within the trapping environment; S4: Perform real-time analysis and aggregation of behavioral data obtained from the trapping environment, and determine whether the visitor is an attacker based on a predefined attack behavior feature library and judgment model; The judgment model comprehensively evaluates features, malicious intent, and behavioral deviation from multiple dimensions. S5: If identified as an attacker, an attacker profile is constructed based on accumulated behavioral data and a threat assessment is conducted.
2. The attacker perception and profiling method based on IP grayscale value and decoy technology according to claim 1, characterized in that, In step S1, the real-time monitoring of the accessing IP and the calculation of grayscale values to determine the risk level of the accessing IP includes the following steps: S11: Monitor accessing IPs in real time to collect raw data; S12: Clean and standardize the original data, extract several dimensional features for grayscale calculation and normalize them. S13: Construct a grayscale calculation model and calculate the IP grayscale value based on several dimensional features; S14: Classify the risk level of accessing IPs based on grayscale values.
3. The attacker perception and profiling method based on IP grayscale value and decoy technology according to claim 2, characterized in that, In step S13, the grayscale calculation model is as follows: ; in, This represents the grayscale value of the accessing IP address; Indicates the total number of feature dimensions; Indicates the first The weights of each feature; Indicates the first Normalized scores for each feature.
4. The attacker perception and profiling method based on IP grayscale value and decoy technology according to claim 1, characterized in that, In step S2, the preset multi-level internal trapping environment and monitoring strategy, and the matching of guidance strategies based on the risk level of the accessing IP, include the following steps: S21: Pre-set and maintain an internal trapping environment library with multiple levels, wherein the trapping environment is deployed in an isolated network or virtualization platform that is completely under the control of the party; S22: Configure corresponding deep monitoring probes and logging strategies for each type of trapping environment; S23: Based on the IP risk level output in S1, match the corresponding traffic redirection and monitoring strategies.
5. The attacker perception and profiling method based on IP grayscale value and decoy technology according to claim 1, characterized in that, In step S3, the process of transparently guiding access traffic to a matching internal trapping environment according to the guidance strategy, and performing comprehensive behavior monitoring and data collection within the trapping environment, includes the following steps: S31: Employ network layer redirection, application layer proxy, or DNS spoofing techniques to transparently redirect traffic to the trapping environment, ensuring that attackers are unaware of it; S32: Deploy monitoring components within the trapping environment; S33: All monitoring components will send the collected behavioral data to the central data analysis platform through a secure internal network; S34: Record all bootstrap decision logs, including bootstrap time, source IP, target trapping environment, and decision reasons, for use in subsequent strategy auditing and optimization.
6. The attacker perception and profiling method based on IP grayscale value and decoy technology according to claim 5, characterized in that, Step S4, which involves real-time analysis and aggregation of behavioral data obtained from the trapping environment, and determining whether the visitor is an attacker based on a predefined attack behavior feature library and judgment model, includes the following steps: S41: Receive and aggregate structured behavioral data reported by each trapping environment in real time from the central data analysis platform, reassemble the sessions according to the source IP and time window, and form a complete behavioral sequence log; S42: Based on a predefined attack behavior feature library, perform feature extraction and matching on behavior sequence logs; S43: Construct an attack determination model and calculate the attack confidence score based on the feature matching results; S44: Set the judgment threshold and output the judgment result based on the confidence score; S45: Record the judgment process and basis, including the list of matched features, details of each score, judgment time and final result, for use in subsequent auditing and model optimization.
7. The attacker perception and profiling method based on IP grayscale value and decoy technology according to claim 6, characterized in that, In step S43, the attack determination model is as follows: ; in, Score the attack confidence level; Degree of malicious intent; For behavioral deviation; , , These are the weighting coefficients; This represents the feature matching degree.
8. An attacker perception and profiling system based on IP grayscale values and decoy techniques, characterized in that, The attacker perception and profiling method based on IP grayscale value and decoy technology, applied to any one of claims 1 to 7, includes: The IP analysis module is used to monitor accessing IPs in real time and calculate grayscale values to determine the risk level of the accessing IPs. The matching module is used to preset multi-level internal trapping environments and monitoring strategies, and to match guidance strategies based on the risk level of the accessing IP. The trapping module is used to transparently guide access traffic to a matching internal trapping environment according to the guidance strategy, and to perform comprehensive behavior monitoring and data collection within the trapping environment. The judgment module is used to perform real-time analysis and aggregation of behavioral data obtained from the trapping environment. Based on a predefined attack behavior feature library and judgment model, it determines whether the visitor is an attacker. The judgment model comprehensively evaluates the feature matching degree, the degree of malicious intent, and the degree of behavioral deviation from multiple dimensions. The profiling module is used to build an attacker profile and conduct threat assessment based on accumulated behavioral data if the attacker is identified.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to execute the attacker perception and profiling method based on IP grayscale value and decoy technology as described in any one of claims 1 to 7.
10. A processor, characterized in that, The processor is used to run a program, wherein the program executes the attacker perception and profiling method based on IP grayscale value and decoy technology as described in any one of claims 1 to 7.