Honeypot system, attack information capturing method, and storage medium

By integrating multiple processors and peripheral IP cores into a system-on-a-chip (SoC), various subsystems are formed, solving the problem that honeypot systems only support a single protocol. This enables the capture of attack information under different protocols, broadens the application scope, and reduces device space and power consumption.

CN113535632BActive Publication Date: 2026-05-22CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD
Filing Date
2021-07-19
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Existing honeypot systems only support a single protocol and cannot capture attack information in scenarios other than that protocol, which limits their application scope, especially in the Industrial Internet where they cannot cover multiple industrial control protocols.

Method used

By integrating multiple processors, peripheral IP cores, and I/O modules into a system-on-a-chip (SoC), and using different protocols and architectures, multiple subsystems can be formed, enabling the capture of attack information under different protocols.

Benefits of technology

This expands the application scope of honeypot systems, making them particularly suitable for the Industrial Internet. They possess excellent tailoring characteristics, saving equipment space and power consumption, and enabling flexible adjustment to target scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113535632B_ABST
    Figure CN113535632B_ABST
Patent Text Reader

Abstract

The present disclosure provides a honeypot system, an attack information capturing method and a computer readable storage medium, and relates to the technical field of information security. The honeypot system comprises: a plurality of processors integrated on a system on chip (SoC), different processors adopting different processor architectures; a plurality of peripheral IP cores, different peripheral IP cores adopting different protocols; a plurality of IO modules corresponding to the plurality of peripheral IP cores one by one; a memory for storing executable instructions of the processors; wherein the plurality of processors, the plurality of peripheral IP cores and the plurality of IO modules can form a plurality of subsystems for capturing attack information under different processor architectures. The honeypot system of the present disclosure supports capturing attack information under different protocols, breaks through the limitation of the honeypot system in the related art that only supports a single protocol, widens the application range, and is particularly beneficial to application in the industrial internet involving a plurality of industrial control protocols.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0008] , ,

[0007] , ,

[0006] , ,

[0005] , ,

[0004] , , ,

[0010] ,

[0009]

[0001] The present disclosure relates to the field of information security technology, and particularly to a honeypot system, an attack information capture method, and a computer-readable storage medium. Background Art

[0002] The honeypot technology is an active defense technology against network attacks. By deploying devices as baits (i.e., honeypot systems), it induces the attacker to launch attacks on them, thereby capturing and analyzing attack information for implementing corresponding active defenses.

[0003] In the related art, most honeypot systems only support a single protocol and cannot capture attack information in scenarios other than this protocol, thus greatly limiting their application scope. Summary of the Invention

[0004] The present disclosure provides a honeypot system, an attack information capture method, and a computer-readable storage medium, thereby at least to some extent solving the problem that the honeypot system only supports a single protocol.

[0005] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be partly learned through the practice of the present disclosure.

[0006] According to a first aspect of the present disclosure, a honeypot system is provided, including: a system-on-chip (SoC) integrated with multiple processors; multiple peripheral IP cores embedded in the SoC, where at least two of the peripheral IP cores use different protocols; multiple IO modules corresponding to the multiple peripheral IP cores one by one; a memory for storing executable instructions of the processors; wherein the multiple processors, the multiple peripheral IP cores, and the multiple IO modules can form multiple subsystems for capturing attack information under different protocols.

[0007] Optionally, at least two of the multiple processors use different processor architectures.

[0008] Optionally, the processor architectures used by the processors include any of the following: X86 architecture, ARM architecture, MIPS architecture, C51 architecture.

[0009] Optionally, the protocols used by the peripheral IP cores include any of the following: TCP / IP protocol, BACnet protocol, Modbus protocol, MQTT protocol, AMQP protocol, CoAP protocol, WiFi protocol, Bluetooth protocol, Zigbee protocol, NFC protocol, GPS protocol, LORA protocol, 2G wireless communication protocol, 3G wireless communication protocol, 4G wireless communication protocol, 5G wireless communication protocol.

[0010] According to a second aspect of this disclosure, an attack information capture method is provided, applied to a honeypot system as described in the first aspect above. The method includes: configuring at least one processor, at least one peripheral IP core, and at least one I / O module of the honeypot system according to honeypot configuration information to form a subsystem corresponding to the honeypot configuration information; and capturing attack information using the subsystem under the protocol adopted by the peripheral IP core.

[0011] Optionally, the honeypot system includes a first processor, a first peripheral IP core, and a first I / O module, wherein the first peripheral IP core corresponds to the first I / O module. Before configuring at least one processor, at least one peripheral IP core, and at least one I / O module of the honeypot system according to the honeypot configuration information, the method further includes: when the honeypot system is started, using the first processor to load a bootloader to configure the first peripheral IP core and the first I / O module into a working state; registering with the master control device through the first peripheral IP core and the first I / O module; after registering with the master control device, initializing other processors other than the first processor, other peripheral IP cores other than the first peripheral IP core, and other I / O modules other than the first I / O module.

[0012] Optionally, after registering with the master control device, the method further includes: receiving the honeypot configuration information sent by the master control device.

[0013] Optionally, when capturing attack information, the method further includes: sending workload information to the master control device, so that the master control device updates the honeypot configuration information according to the workload information.

[0014] Optionally, after capturing the attack information, the method further includes: when the attack information is successfully matched with a preset rule, sending the attack information to the main control device.

[0015] According to a third aspect of this disclosure, a computer-readable storage medium is provided, on which a computer program is stored, wherein the computer program, when executed by a processor, implements the attack information capture method of the second aspect described above and its possible implementations.

[0016] The technical solution disclosed herein has the following beneficial effects:

[0017] The honeypot system integrates different IP cores via a SoC (System-on-a-Chip). On one hand, it supports capturing attack information under different protocols, overcoming the limitation of other honeypot systems supporting only a single protocol, thus broadening its application scope. This is particularly beneficial for industrial internet applications involving multiple control protocols. Furthermore, the honeypot system possesses excellent customization capabilities, allowing for flexible adjustments to suit specific scenarios. On the other hand, this solution is functionally equivalent to setting up multiple physical honeypots. In comparison, integrating multiple IP cores onto a SoC saves the total PCB area and space required, while also reducing power consumption and dimensional complexity.

[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0020] Figure 1 This diagram illustrates a schematic structural diagram of a honeypot system according to this exemplary embodiment.

[0021] Figure 2 A schematic diagram of a system architecture in this exemplary embodiment is shown;

[0022] Figure 3 This diagram illustrates a flowchart of an attack information capture method in this exemplary embodiment;

[0023] Figure 4 This diagram illustrates a system initialization flowchart in this exemplary embodiment;

[0024] Figure 5 This diagram illustrates a schematic flowchart of an attack information capture method in this exemplary embodiment. Detailed Implementation

[0025] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this disclosure more comprehensive and complete, and to fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, apparatus, steps, etc., can be employed. In other instances, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0026] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0027] The flowchart shown in the attached diagram is merely an illustrative example and does not necessarily include all steps. For example, some steps may be broken down, while others may be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.

[0028] As the demand for information security in the Industrial Internet increases, honeypot technology is being used more and more in the Industrial Internet. However, compared with the traditional Internet, the Industrial Internet involves a wider variety of industrial control protocols. A large-scale industrial control system may involve traditional Internet communication protocols as well as multiple industrial control protocols. Current honeypot systems cannot fully cover these protocols, and therefore cannot adequately capture attack information.

[0029] In view of the above problems, an exemplary embodiment of this disclosure provides a honeypot system. (Reference) Figure 1As shown, the honeypot system 100 may include: a SoC (System-on-Chip) 110, on which multiple processors (111, 112, 113) are integrated; multiple peripheral IP cores (Intellectual Property) (121, 122, 123) are embedded in the SoC 110; multiple I / O (Input / Output) modules (131, 132, 133); and a memory 140.

[0030] It should be understood that Figure 1 The number of components listed is merely illustrative; any number of processors, peripheral IP cores, I / O modules, etc., can be configured according to actual needs. Furthermore, the honeypot system 100 may also include... Figure 1 Other components not shown, such as display module, sensor module, etc.

[0031] SoC 110 can be a SoC chip based on HDL (Hardware Description Language). HDL includes, but is not limited to, VHDL (Very-High-Speed ​​Integrated Circuit HDL), Verilog HDL, etc. SoC 110 can be, for example, an EPLD (Erasable Programmable Logic Device), CPLD (Complex Programming Logic Device), FPGA (Field Programmable Gate Array), hybrid FPGA, and other integrated circuits.

[0032] In one implementation, SoC 110 may adopt a hybrid CPU-FPGA architecture, and the aforementioned multiple processors (111, 112, 113) may include a CPU built into the FPGA, or may include an MCU (Microcontroller Unit) formed based on IP cores (Intellectual Property).

[0033] In one implementation, at least two of the aforementioned processors (111, 112, 113) employ different processor architectures. That is, the processor architectures used by the processors in the honeypot system 100 are not entirely identical and can include any combination of the following architectures: x86 architecture, ARM (Advanced RISC Machine) architecture, MIPS (Microprocessor without Interlocked Piped Stages) architecture, C51 architecture (a 51-core-level microcontroller architecture), etc. For example, processor 111 can be the CPU integrated into a hybrid CPU-FPGA architecture SoC 110, employing an x86 architecture; processor 112 can employ an ARM architecture; and processor 113 can employ a C51 architecture.

[0034] The aforementioned peripheral IP cores (121, 122, 123) are peripheral modules based on IP cores. They can be soft cores that implement various functions. At least two of these peripheral IP cores use different protocols, meaning that the protocols used by the peripheral IP cores in the honeypot system 100 are not entirely the same. These protocols can include any combination of the following: TCP / IP (Transmission Control Protocol / Internet Protocol), BACnet (Building Automation and Control networks protocol), Modbus (a serial communication protocol released by Modicon), MQTT (Message Queuing Telemetry Transport), AMQP (Advanced Message Queuing Protocol), CoAP (Constrained Application Protocol), WiFi (Wireless Fidelity), Bluetooth, Zigbee, NFC (Near Field Communication), and GPS (Global Positioning System). System (Global Positioning System protocol), LoRa protocol (Long Range Radio protocol), 2G / 3G / 4G / 5G wireless communication protocols, etc. For example, peripheral IP core 121 can use the TCP / IP protocol; peripheral IP core 122 can use the Modbus protocol; peripheral IP core 123 can use 2G / 3G / 4G / 5G wireless communication protocols.

[0035] Different processors (111, 112, 113) and different peripheral IP cores (121, 122, 123) in SoC 110 can be connected via an internal bus, which can be an AHB (Advanced High Performance Bus) or similar.

[0036] The aforementioned I / O modules (131, 132, 133) can be peripheral circuit modules corresponding one-to-one with the aforementioned peripheral IP cores (121, 122, 123), such as analog and radio frequency circuits, to achieve the corresponding functions. For example, I / O module 131 can be an Ethernet PHY (physical layer) circuit module; I / O module 132 can be a peripheral driver circuit module such as RS422, RS485 (RS422 and RS485 are both serial data interface standards), CANBus (Controller Area Network Bus); I / O module 133 can be an LTE (Long Term Evolution) peripheral driver circuit.

[0037] Memory 140 is used to store executable instructions for the processor, such as honeypot programs. In one embodiment, memory 140 may include non-volatile memory 141 and volatile memory 142. Non-volatile memory 141 may be a PROM (Programmable Read-Only Memory), EPROM (Erasable PROM), EEPROM (Electrically Erasable Programmable Read-Only Memory), NOR Flash, NAND Flash, etc.; volatile memory may be DDR (Double Data Rate), DDR2 (2nd generation DDR), DDR3 (3rd generation DDR), etc. Generally, honeypot programs can be stored in non-volatile memory 141 and loaded into volatile memory 142 during runtime, with the processor reading and executing program instructions from volatile memory 142.

[0038] In the honeypot system 100, a processor, a peripheral IP core, and an I / O module can form a system capable of interacting with and processing data from the outside world. This exemplary embodiment refers to this as a subsystem of the honeypot system 100. It should be noted that the subsystem typically requires a certain amount of storage space to store the programs and related data running within it; that is, the subsystem may also include a memory. Generally, it is not necessary to set up a separate memory for each subsystem; all subsystems can share the memory 140. Therefore, the memory part is omitted when describing the composition of the subsystems. The subsystem can run a honeypot program to act as a relatively independent honeypot device and capture attack information. This exemplary embodiment can form various subsystems by combining the aforementioned multiple processors (111, 112, 113), multiple peripheral IP cores (121, 122, 123), and multiple I / O modules (131, 132, 133) in different ways. Each subsystem can capture attack information based on the peripheral IP core and the protocol adopted by the peripheral IP core. In other words, the honeypot system 100 can capture attack information under different protocols.

[0039] The following examples illustrate the three subsystems:

[0040] (1) The SoC 110 adopts a hybrid CPU-FPGA architecture. The processor 111 is the CPU built into the SoC 110, which adopts the x86 architecture. The peripheral IP core 121 is an Ethernet IP core that adopts the TCP / IP protocol. The IO module 131 is the Ethernet PHY circuit module. The processor 111, peripheral IP core 121, and IO module 131 form subsystem 1. Subsystem 1 can interact with the outside world based on the TCP / IP protocol. By running a honeypot program on subsystem 1, attack information can be captured under the TCP / IP protocol, realizing the application of honeypot technology in traditional Internet scenarios.

[0041] (2) The processor 112 adopts the C51 architecture, the peripheral IP core 122 adopts the Modbus protocol, and the IO module 132 is an RS422 peripheral driver circuit module. The processor 112, peripheral IP core 122, and IO module 132 form subsystem 2. Subsystem 2 can interact with the outside world based on the Modbus protocol. By running a honeypot program on subsystem 2, attack information can be captured under the Modbus protocol, realizing the application of honeypot technology in the industrial Internet scenario.

[0042] (3) The processor 113 adopts the ARM architecture, the peripheral IP core 123 adopts the 4G communication protocol, and the IO module 133 is an LTE peripheral driver circuit module. The processor 113, the peripheral IP core 123, and the IO module 133 form subsystem 3. Subsystem 3 can interact with the outside world based on the 4G wireless communication protocol. By running the honeypot program on subsystem 3, attack information can be captured under the 4G wireless communication protocol, realizing the application of honeypot technology in mobile communication scenarios such as telephone and SMS.

[0043] As can be seen from the above, the honeypot system of this exemplary embodiment integrates different IP cores through a SoC (System-on-a-Chip). On the one hand, it can support the capture of attack information under different protocols, breaking through the limitation of honeypot systems in related technologies that only support a single protocol, thus broadening the application scope. It is particularly beneficial for application in the Industrial Internet involving multiple industrial control protocols. Furthermore, this honeypot system has good tailoring characteristics and can be flexibly adjusted for target scenarios. On the other hand, this solution is functionally equivalent to setting up multiple honeypot physical machines. In comparison, integrating multiple IP cores into a SoC saves the total PCB (Printed Circuit Board) area and space occupied by the device, and reduces power consumption and dimensional complexity.

[0044] Exemplary embodiments of this disclosure also provide a method for capturing attack information. Figure 2 The system architecture of the operating environment for this method is illustrated, which may include a honeypot system 100 and a master control device 200. The master control device 200 may be a server or a PC (Personal Computer) used to control the honeypot system 100. The honeypot system 100 and the master control device 200 may be connected via a wired or wireless link for data exchange; for example, they may be connected based on Ethernet and TCP / IP protocols.

[0045] The attack information capture method in this exemplary embodiment can be applied to the honeypot system 100 described above. Figure 3 An exemplary flow of the attack information capture method is shown, which may include the following steps S310 and S320:

[0046] Step S310: Configure at least one processor, at least one peripheral IP core, and at least one I / O module of the honeypot system according to the honeypot configuration information to form a subsystem corresponding to the honeypot configuration information.

[0047] Honeypot configuration information is used to configure the architecture and protocols of the honeypot system, such as information configured within the honeypot program. Generally, based on the required architecture and protocols in the honeypot configuration information, the corresponding processors, peripheral IP cores, and I / O modules can be configured to operate, thus forming a specific subsystem.

[0048] In one implementation, the honeypot system may include a first processor, a first peripheral IP core, and a first I / O module. The first processor may be the main processor on a SoC, such as a processor responsible for running an operating system. The first peripheral IP core corresponds to the first I / O module; for example, the first peripheral IP core may be an Ethernet IP core, and the first I / O module may be an Ethernet PHY circuit module. Before configuring at least one processor, at least one peripheral IP core, and at least one I / O module of the honeypot system according to the honeypot configuration information, refer to... Figure 4 As shown, the following steps S410 to S430 can be performed:

[0049] Step S410: When the honeypot system is started, the first processor is used to load the boot program to configure the first peripheral IP core and the first IO module into working state.

[0050] Step S420: Register with the main control device through the first peripheral IP core and the first IO module;

[0051] Step S430: After registering with the main control device, initialize the processors other than the first processor, the peripheral IP cores other than the first peripheral IP core, and the IO modules other than the first IO module.

[0052] Starting the honeypot system refers to powering on the system. The bootloader can be an initialization program after power-on, including configuring the first peripheral IP core and the first I / O module to work. The first peripheral IP core and the first I / O module are Ethernet-related IP cores and I / O modules. After the bootloader is loaded on the first processor, the honeypot system can connect to the outside via Ethernet and then register with the main control device.

[0053] As can be seen from the above, the first processor, the first peripheral IP core, and the first I / O module can form a minimal subsystem for running the honeypot system, including basic processor units and communication units. Of course, this disclosure does not limit the first processor, the first peripheral IP core, and the first I / O module. For example, the boot program can be loaded by the processor with the lowest power consumption, so the first processor can be an 8-bit microcontroller chip with a 51 core. The honeypot system and the main control device can also be connected via an RS422 port and the Modbus protocol, so the first peripheral IP core can be an IP core using the Modbus protocol, and the first I / O module can be an RS422 peripheral driver circuit module.

[0054] Registration primarily involves the authentication process. For example, the honeypot system establishes a connection with the main control device, which could be a persistent connection. Then, it sends authentication information to the main control device. Once the main control device authenticates the honeypot, it can proceed with the subsequent honeypot deployment. Alternatively, the honeypot system can also authenticate the main control device, enabling two-way authentication. Registration can also include information synchronization, such as the honeypot system sending system information and current status information to the main control device to facilitate appropriate control decisions.

[0055] After registration, the honeypot system further initializes other processors, peripheral IP cores, and I / O modules. It should be understood that the honeypot system may initialize only the necessary processors, peripheral IP cores, and I / O modules.

[0056] In one implementation, the honeypot configuration information can be deployed by the master control device. For example, staff can edit relevant feature data on the master control device, including system architecture, tasks, task timing, and whether workload information is uploaded, to form the honeypot configuration information. After registering with the master control device, the honeypot system can receive the honeypot configuration information sent by the master control device. That is, each time the honeypot system starts, the master control device sends the honeypot configuration information to it for system configuration.

[0057] In one implementation, the honeypot configuration information can be directly deployed on the honeypot system. For example, one or more sets of preset honeypot configuration information can be stored in the memory of the honeypot system. After the honeypot system completes the above initialization, it can read the honeypot configuration information from the memory to perform system configuration.

[0058] In one implementation, multiple processors with different processor architectures can be configured to form a heterogeneous subsystem. For example, if a C51 microcontroller and an STM32 (an embedded microcontroller) processor are configured into a subsystem, the subsystem includes both C51 and ARM architectures, thereby increasing the diversity and flexibility of the subsystem.

[0059] Step S320: Capture attack information using the aforementioned subsystem under the protocol adopted by the aforementioned peripheral IP core.

[0060] After configuring the relevant processors, peripheral IP cores, and I / O modules to form a subsystem, the honeypot program's instructions can be executed to capture attack information under the protocol used by the configured peripheral IP cores. For example, in Figure 1In the honeypot system 100, subsystem 1 is formed by configuring processor 111, peripheral IP core 121, and IO module 131 to capture attack information under the TCP / IP protocol; or subsystem 2 is formed by configuring processor 112, peripheral IP core 122, and IO module 132 to capture attack information under the Modbus protocol; and subsystem 3 is formed by configuring processor 113, peripheral IP core 123, and IO module 133 to capture attack information under the 4G wireless communication protocol.

[0061] based on Figure 3 The method shown can configure the processor, peripheral IP cores, and IO modules of the honeypot system according to actual needs to form a corresponding subsystem, capture attack information under the target protocol, and configure multiple processors, multiple peripheral IP cores, and multiple IO modules to capture attack information under multiple protocols simultaneously.

[0062] In one implementation, the attack information capture method may further include the following steps:

[0063] When attack information is captured, workload information is sent to the master control device, so that the master control device updates the honeypot configuration information according to the workload information.

[0064] The workload information refers to the load status of each component in the honeypot system, including processor utilization, memory utilization, I / O module utilization, and total power consumption. The main control device can adjust the honeypot system configuration accordingly based on the workload information to update the honeypot configuration. For example, when the workload is high, some active processors, peripheral IP cores, and I / O modules can be reduced, or lower-power processors, peripheral IP cores, and I / O modules can be used; when the workload is low, some inactive processors, peripheral IP cores, and I / O modules can be put into active status, or higher-power processors, peripheral IP cores, and I / O modules can be used. The honeypot system adjusts the configuration of each processor, peripheral IP core, and I / O module based on the updated honeypot configuration information to change the subsystem architecture. This enables dynamic adjustment of the system architecture during attack information capture, further improving the flexibility of the honeypot system.

[0065] For example, a honeypot system may include various STM32 Cortex cores with different performance levels, such as M3, M4, M7, and M33, with progressively increasing performance and power consumption. The host device can change the core used when the honeypot system's workload changes significantly, obtaining honeypot configuration information. The honeypot system then adjusts the cores based on this configuration information; for example, it might switch from using an M7 core to an M4 core when the workload increases.

[0066] In one implementation, the attack information capture method may further include the following steps:

[0067] After capturing attack information, when the attack information is successfully matched with preset rules, the attack information is sent to the main control device.

[0068] The preset rules refer to the judgment rules determined based on the characteristics of various types of attack information, such as regular expressions. When attack information is successfully matched with preset rules, it indicates that the attack information does indeed belong to the relevant attack or penetration behavior. The information data is then sent to the main control device for storage, and can be analyzed later to determine the corresponding proactive defense strategy. In addition, this honeypot system can capture attack information from different protocols, thereby enabling correlation analysis of these attack information to obtain more in-depth analysis results.

[0069] Figure 5 A schematic flow diagram of an attack information capture method is shown, including:

[0070] Step S510: The honeypot system is powered on and starts up. The first processor loads the boot program and starts the first peripheral IP core and the first I / O module.

[0071] In step S520, the honeypot system interacts with the main control device through the first peripheral IP core and the first IO module, such as registering with the main control device.

[0072] Step S530: Receive honeypot configuration information sent by the master control device and load the honeypot configuration information;

[0073] Step S540: Determine whether the architecture needs to be adjusted. If yes, proceed to step S550; otherwise, proceed to step S560.

[0074] Step S550: Receive the updated honeypot configuration information sent by the master control device, and continue to execute step S560;

[0075] Step S560: Configure the processor, peripheral IP cores, and IO modules according to the honeypot configuration information to form a subsystem with a specific architecture;

[0076] Step S570: Run the honeypot program through the subsystem to capture attack information under relevant protocols;

[0077] Step S580: Send attack information and workload information to the main control device. The attack information is used to analyze the attacker's attack behavior pattern, and the workload information is used to update the honeypot configuration information.

[0078] Exemplary embodiments of this disclosure also provide a computer-readable storage medium that can be implemented as a program product including program code, which, when run on an electronic device, causes the electronic device to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure. In one embodiment, the program product can be implemented as a portable compact disc read-only memory (CD-ROM) including program code and can run on an electronic device, such as a personal computer. However, the program product of this disclosure is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0079] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0080] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0081] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0082] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing devices can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0083] Those skilled in the art will understand that various aspects of this disclosure can be implemented as systems, methods, or program products. Therefore, various aspects of this disclosure can be embodied in entirely hardware implementations, entirely software implementations (including firmware, microcode, etc.), or implementations combining hardware and software aspects, collectively referred to herein as “circuit,” “module,” or “system.” Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.

[0084] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is defined only by the appended claims.

Claims

1. A honeypot system, characterized in that, include: System-on-a-chip (SoC) integrating multiple processors; Multiple peripheral IP cores are embedded in the SoC, wherein at least two peripheral IP cores use different protocols; Multiple I / O modules, each corresponding to one of the multiple peripheral IP cores; Memory for storing the executable instructions of the processor; The multiple processors, multiple peripheral IP cores, and multiple I / O modules can form multiple subsystems. Each subsystem includes at least one processor, at least one peripheral IP core, and at least one I / O module. By running a honeypot program, attack information is captured under the protocol adopted by its peripheral IP core.

2. The honeypot system according to claim 1, characterized in that, At least two of the plurality of processors employ different processor architectures.

3. The honeypot system according to claim 2, characterized in that, Each of the plurality of processors employs one of the following processor architectures: x86, ARM, MIPS, and C51.

4. The honeypot system according to claim 1, characterized in that, Each of the multiple peripheral IP cores adopts one of the following protocols: TCP / IP, BACnet, Modbus, MQTT, AMQP, CoAP, WiFi, Bluetooth, Zigbee, NFC, GPS, LoRa, 2G, 3G, 4G, and 5G wireless communication protocols.

5. A method for capturing attack information, characterized in that, Applied to the honeypot system as described in any one of claims 1 to 4, the method comprises: Configure at least one processor, at least one peripheral IP core, and at least one I / O module of the honeypot system according to the honeypot configuration information to form a subsystem corresponding to the honeypot configuration information; The subsystem is used to capture attack information under the protocol adopted by the peripheral IP core.

6. The method according to claim 5, characterized in that, The honeypot system includes a first processor, a first peripheral IP core, and a first I / O module, wherein the first peripheral IP core corresponds to the first I / O module; before configuring at least one processor, at least one peripheral IP core, and at least one I / O module of the honeypot system according to the honeypot configuration information, the method further includes: When the honeypot system is started, the first processor is used to load the boot program to configure the first peripheral IP core and the first IO module into working state; Register with the main control device through the first peripheral IP core and the first IO module; After registering with the main control device, the processors other than the first processor, the peripheral IP cores other than the first peripheral IP core, and the I / O modules other than the first I / O module are initialized.

7. The method according to claim 6, characterized in that, After registering with the main control device, the method further includes: Receive the honeypot configuration information sent by the main control device.

8. The method according to claim 6, characterized in that, When capturing attack information, the method further includes: The workload information is sent to the master control device, so that the master control device updates the honeypot configuration information according to the workload information.

9. The method according to claim 6, characterized in that, After capturing attack information, the method further includes: When the attack information is successfully matched with the preset rules, the attack information is sent to the main control device.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 5 to 9.