A network security honeypot system and implementation method based on stream data processing

Through the network security honeypot system based on streaming data processing, the traffic information of honeypot service is analyzed in real time, and the problems of complex deployment and poor real-time performance of honeypot system are solved, real-time early warning of cyberattack behavior is achieved.

CN115378638BActive Publication Date: 2025-07-08CHINA INFOMRAITON CONSULTING & DESIGNING INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210813457.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-12
Publication Date
2025-07-08
Estimated Expiration
2042-07-12

AI Technical Summary

Technical Problem

The existing honeypot system is complex in deployment and poor in real-time, and it is impossible to achieve real-time early warning of cyber attack behavior.

Method used

A network security honeypot system based on streaming data processing is adopted, including honeypot service management module, client, status collection service module, traffic information consumption service module and streaming data processing engine. By analyzing the traffic information of honeypot services in real time, it uses complex event processing technology to achieve real-time early warning.

Benefits of technology

It improves the traffic resolution capabilities of honeypots, realizes real-time early warning of network attack behavior, and improves the real-time and usability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115378638B_ABST
    Figure CN115378638B_ABST
Patent Text Reader

Abstract

The present invention provides a network security honeypot system and an implementation method based on stream data processing. The implementation method includes establishing a connection between a honeypot service management module and a honeypot client; when the honeypot client monitors that there is a message in the honeypot service management queue, managing the honeypot service; a honeypot service running status collection service module monitors the honeypot service status queue, and when there is honeypot service status information in the queue, taking out the data for processing and display; a traffic information consumption service module monitors the honeypot access traffic queue, and when there is honeypot network access traffic information in the queue, taking it out, packaging it into an event, and sending it to the stream data processing engine module; when the received event meets the event processing conditions, the stream data processing engine module triggers event processing rules to process the event, and obtains the early warning information of the honeypot service being attacked. This implementation method can effectively improve the traffic parsing ability of the honeypot and realize real-time early warning of network attack behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network information security honeypots, and particularly relates to a network security honeypot system and an implementation method based on stream data processing. Background Art

[0002] Network security honeypots use simulation technology to form a network security trapping environment, and through a series of luring and disguising means, induce attackers to transfer their attack targets to the trapping environment, and take measures such as interception and blocking, behavior analysis, and tracing and source tracing against them, so as to achieve the purpose of recording and analyzing the attack behaviors of attackers and protecting their own real business environment. At present, most of the honeypot systems on the market are implemented based on containerized deployment and log collection and analysis technologies. Containerized deployment increases the complexity of the deployment and application of the honeypot system. At the same time, log collection and analysis are often post-event analysis, with poor real-time performance. Summary of the Invention

[0003] Object of the Invention: The technical problem to be solved by the present invention is to provide a network security honeypot system and an implementation method based on stream data processing in view of the deficiencies of the prior art.

[0004] To solve the above technical problem, in a first aspect, a network security honeypot system based on stream data processing is disclosed, which includes a honeypot service management module, a honeypot client, a honeypot service running state collection service module, a traffic information consumption service module, a stream data processing engine module, a honeypot service management queue, a honeypot service status queue, and a honeypot access traffic queue;

[0005] The honeypot service management module is used to store honeypot service management instructions into the honeypot service management queue, receive and process connection requests from the honeypot client, and send the connection configuration information of the honeypot service management queue to the honeypot client;

[0006] The honeypot client is used to load the honeypot service configuration information, initiate a connection request to the honeypot service management module, connect to and monitor the honeypot service management queue according to the connection configuration information of the honeypot service management queue; when a message is detected in the honeypot service management queue, take out the honeypot service management instruction and parse it to manage the honeypot service;

[0007] The honeypot service management queue is used to store honeypot service management instructions;

[0008] The honeypot service status queue is used to store the running state information of the honeypot service;

[0009] The honeypot access traffic queue is used to store the access traffic information of the honeypot service;

[0010] The honeypot service running status collection service module is used to monitor the honeypot service status queue, and when there is honeypot service status information in the honeypot service status queue, it retrieves the data for processing and display;

[0011] The traffic information consumption service module is used to monitor the honeypot access traffic queue. When there is honeypot network access traffic information in the honeypot access traffic queue, it retrieves the network access traffic information and packages it into an event, and sends it to the stream data processing engine module;

[0012] The stream data processing engine module is used to create event types and event processing rules for the honeypot service, match the event processing rules according to the received event, and output the early warning information for the attacked honeypot service.

[0013] Further, the network security honeypot system further includes a daemon process, which is used to monitor the working status of the honeypot client. When the working status of the honeypot client is abnormal or stops working, it shuts down and restarts the honeypot client.

[0014] In a second aspect, a method for implementing a network security honeypot system based on stream data processing is disclosed, including:

[0015] Step 1, the honeypot service management module waits for the connection of the honeypot client;

[0016] Step 2, the honeypot client loads the honeypot service configuration information and initiates a connection request to the honeypot service management module;

[0017] Step 3, the honeypot service management module receives and processes the connection request of the honeypot client. After the connection is successful, it sends the connection configuration information of the honeypot service management queue to the honeypot client;

[0018] Step 4, the honeypot client connects to and monitors the honeypot service management queue. When there is a message in the honeypot service management queue, it retrieves the honeypot service management instruction and parses it to manage the honeypot service;

[0019] Step 5, the honeypot service running status collection service module monitors the honeypot service status queue, and when there is honeypot service status information in the honeypot service status queue, it retrieves the data for processing and display;

[0020] Step 6, the traffic information consumption service module monitors the honeypot access traffic queue. When there is honeypot network access traffic information in the honeypot access traffic queue, it retrieves the network access traffic information and packages it into an event, and sends it to the stream data processing engine module;

[0021] Step 7, the streaming data processing engine module creates event types, event handling rules, and event handling conditions for the honeypot service. When the received event meets the event handling conditions, the event handling rules are triggered to process the event, and the attack warning information for the honeypot service is obtained.

[0022] Further, the honeypot service management module and the honeypot client are based on the server / client mode of the TCP protocol. Step 1 includes: the honeypot service management module creates a socket, uses the socket to bind the local network address and port, and the socket listens on the bound port, waiting for the connection request from the honeypot client.

[0023] Step 2 includes: the honeypot client loads the honeypot service configuration information, which is a quadruple <id, honeypotServiceName, honeypotServiceType, honeypotServiceFilePath>. Here, id is the unique identifier of the honeypot service; honeypotServiceName represents the name of the honeypot service; honeypotServiceType represents the type of the honeypot service; honeypotServiceFilePath represents the local path information of the static file of the honeypot service. The honeypot client creates a socket and initiates a connection request to the honeypot service management module.

[0024] Further, in step 3, the process by which the honeypot service management module processes the connection request from the honeypot client includes:

[0025] The honeypot client sends the node information where the honeypot client is located to the honeypot service management module. The node information includes the name of the node, the network address of the node, and the verification code of the node.

[0026] The honeypot service management module verifies the node information sent by the honeypot client to determine whether it is a legitimate node that can establish a connection.

[0027] If the node verification fails, the honeypot service management module disconnects the current connection and the connection fails; if the node verification passes, the connection is successful.

[0028] Further, in step 4, the honeypot service includes a honeypot service protocol and a honeypot service static file.

[0029] The honeypot service management instructions include configuration instructions for configuring the honeypot service and operation instructions for operating the honeypot service. The operation instructions include starting and stopping the honeypot service. The management of the honeypot service includes configuring the honeypot service and performing start and stop operations on the honeypot service.

[0030] Further, the honeypot service status described in step 5 includes port status, heartbeat, system resource usage, service creation time, and service running time information.

[0031] Further, the event described in step 6 is a quadruple E = (id, honeypotType, flowData, timeStamp), where id is the unique identifier of the event, honeypotType represents the attribute of the event, that is, the type of the honeypot service. For different types of honeypot services, the network access traffic information collected is wrapped into events with different attributes. flowData represents the network access traffic information data collected by the honeypot service carried in the event, and timeStamp represents the time when the event occurs, identifying the time of the network traffic information collected by the honeypot service; the traffic information consumption service module creates event instances by calling the constructor of the event class for the original network access traffic information obtained from the honeypot access traffic queue.

[0032] Further, step 7 includes:

[0033] Step 7-1, create a stream data processing engine based on Complex Event Processing (CEP);

[0034] Step 7-2, register the event type in the stream data processing engine and generate relevant configuration objects, where the event type corresponds to the honeypot service type;

[0035] Step 7-3, create an event stream processing engine instance according to the configuration object generated in 7-2 as the container environment for event processing;

[0036] Step 7-4, create and import event processing rules, where the event processing rules correspond to the event type and are used to process the received events;

[0037] Step 7-5, create a listener object and associate the listener object with the event processing rules;

[0038] Step 7-6, create an execution environment object for event stream processing and match it with the event processing conditions in the engine;

[0039] Step 7-7, the execution environment object is responsible for listening to all incoming events, selects the corresponding event processing conditions according to the attribute value honeypotType in the event, and when the event meets the event processing conditions, triggers the corresponding listener to process the event to obtain the attack warning information of the honeypot service.

[0040] Further, the method for implementing the network security honeypot system further includes step 8 of starting a daemon process to monitor the working status of the honeypot client. When the working status of the honeypot client is abnormal or the client stops working, the honeypot client is shut down and restarted.

[0041] Beneficial effects:

[0042] In the analysis process of collecting traffic information by the honeypot of the present invention, a stream data processing technology is introduced, which can perform real-time calculation of data with high availability, low latency, and its own fault tolerance according to a set of processing rules, and can determine the event type according to the attributes in the event, and accurately report early warning information in the first time. Compared with the traditional log collection and analysis technology, it can effectively improve the traffic parsing ability of the honeypot and realize real-time early warning of network attack behaviors. Brief Description of the Drawings

[0043] The following further specifically describes the present invention in conjunction with the drawings and specific embodiments, and the above advantages and other advantages of the present invention will become clearer.

[0044] Figure 1 is a schematic structural diagram of a network security honeypot system based on stream data processing provided by an embodiment of the present application.

[0045] Figure 2 is a schematic diagram of the implementation process of a network security honeypot system based on stream data processing provided by an embodiment of the present application.

[0046] Figure 3 is a schematic diagram of the interaction process between the honeypot service management module and the honeypot client in the method for implementing a network security honeypot system based on stream data processing provided by an embodiment of the present application. Specific Embodiments

[0047] The following will describe the embodiments of the present invention in conjunction with the drawings.

[0048] The first embodiment of the present application discloses a network security honeypot system based on stream data processing, as Figure 1 shown, including a honeypot service management module, a honeypot client, a honeypot service running status collection service module, a traffic information consumption service module, a stream data processing engine module, a honeypot service management queue honeypotManageQueue, a honeypot service status queue honeypotStateQueue, and a honeypot access traffic queue honeypotFlowQueue.

[0049] As Figure 2As shown, the honeypot service management module is used to store the honeypot service management instructions into the honeypot service management queue honeypotManageQueue, receive and process the connection requests from the honeypot client, and send the connection configuration information of the honeypot service management queue to the honeypot client;

[0050] The honeypot client is used to load the honeypot service configuration information, initiate a connection request to the honeypot service management module, connect to and monitor the honeypot service management queue according to the connection configuration information of the honeypot service management queue; when it monitors that there is a message in the honeypot service management queue, it takes out the honeypot service management instruction and parses it to manage the honeypot service;

[0051] The honeypot service management queue honeypotManageQueue is used to store the honeypot service management instructions;

[0052] The honeypot service status queue honeypotStateQueue is used to store the running status information of the honeypot service;

[0053] The honeypot access traffic queue honeypotFlowQueue is used to store the access traffic information of the honeypot service;

[0054] The honeypot service running status collection service module is used to monitor the honeypot service status queue, and when there is honeypot service status information in the honeypot service status queue, it takes out the data for processing and display;

[0055] The traffic information consumption service module is used to monitor the honeypot access traffic queue. When there is honeypot network access traffic information in the honeypot access traffic queue, it takes out the network access traffic information and packages it into an event, and sends it to the stream data processing engine module;

[0056] The stream data processing engine module is used to create the event types and event processing rules of the honeypot service, match the event processing rules according to the received event, and output the attack warning information of the honeypot service.

[0057] The network security honeypot system further includes a daemon process, which is used to monitor the working status of the honeypot client. When the working status of the honeypot client is abnormal or it stops working, it shuts down and restarts the honeypot client.

[0058] The second embodiment of this application discloses a method for implementing a network security honeypot system based on stream data processing, including:

[0059] Step 1, the honeypot service management module waits for the connection of the honeypot client;

[0060] As Figure 3As shown in the figure, the honeypot service management module and the honeypot client are based on the server / client mode of the TCP protocol. Step 1 includes: The honeypot service management module creates a socket, binds the local network address and port using the socket, and the socket listens on the bound port, waiting for the connection request from the honeypot client.

[0061] Step 2: The honeypot client loads the honeypot service configuration information and initiates a connection request to the honeypot service management module. Specifically, it includes: The honeypot client loads the honeypot service configuration information, which is a quadruple <id, honeypotServiceName, honeypotServiceType, honeypotServiceFilePath>. Here, id is the unique identifier of the honeypot service; honeypotServiceName represents the name of the honeypot service; honeypotServiceType represents the type of the honeypot service; honeypotServiceFilePath represents the local path information of the honeypot service static file. The honeypot client creates a socket and initiates a connection request to the honeypot service management module.

[0062] Step 3: The honeypot service management module receives and processes the connection request from the honeypot client. After the connection is successful, it sends the connection configuration information of the honeypot service management queue to the honeypot client.

[0063] The honeypot service management module processes the connection request from the honeypot client, including:

[0064] The honeypot client sends the node information where the honeypot client is located to the honeypot service management module. The node information includes the name of the node, the network address of the node, and the verification code of the node.

[0065] The honeypot service management module verifies the node information sent by the honeypot client to determine whether it is a legal node that can establish a connection.

[0066] If the node verification fails, the honeypot service management module disconnects the current connection and the connection fails; if the node verification passes, the connection is successful.

[0067] Step 4: The honeypot client connects to and listens on the honeypot service management queue. When it monitors that there is a message in the honeypot service management queue, it retrieves the honeypot service management instruction and parses it to manage the honeypot service. The honeypot service includes the honeypot service protocol and the honeypot service static file. For example, the Linux remote access honeypot service based on the SSH protocol, the WEB application honeypot service based on the HTTP / HTTPS protocol, etc.

[0068] Specifically, to implement a Linux remote access honeypot service based on the SSH protocol, it is necessary to implement the SSH protocol in the honeypot client and write the static files of the honeypot service. The honeypot client feeds back information according to the request information transmitted by the user through the SSH protocol, so as to realize the simulation of Linux remote access. For example, if the user sends the "df" command through the SSH protocol, the honeypot client feeds back the static file of the honeypot service corresponding to the "df" command, and the content of this static file is as follows:

[0069]

[0070] The honeypot service management instructions include configuration instructions for configuring the honeypot service and operation instructions for operating the honeypot service. The operation instructions include starting and stopping the honeypot service; managing the honeypot service includes configuring the honeypot service and performing start and stop operations on the honeypot service. Taking the Linux remote access honeypot service based on the SSH protocol as an example, information such as the account password for successful login, the hostname displayed after successful login, and the port of the honeypot service can be configured. The honeypot service management module issues instructions to start or stop the honeypot service, and starts or stops the corresponding SSH protocol service through the honeypot client to realize the start or stop of the honeypot service.

[0071] Step 5, the honeypot service running status collection service module monitors the honeypot service status queue, and when there is honeypot service status information in the honeypot service status queue, it takes out the data for processing and display; the honeypot service status includes port status, heartbeat, system resource usage, service creation time, and service running time information.

[0072] Step 6, the traffic information consumption service module monitors the honeypot access traffic queue. When there is honeypot network access traffic information in the honeypot access traffic queue, the network access traffic information is retrieved and packaged into an event, which is then sent to the stream data processing engine module. For example, a WEB application honeypot service based on the HTTP / HTTPS protocol can collect the request traffic information of users, and the request traffic information is reported to the traffic information consumption service module through the honeypot access traffic queue. The event is a quadruple E = (id, honeypotType, flowData, timeStamp), where id is the unique identifier of the event, honeypotType represents the attribute of the event, that is, the type of the honeypot service. For the network access traffic information collected by different types of honeypot services, they are packaged into events with different attributes. flowData represents the network access traffic information data collected by the honeypot service carried in the event, and timeStamp represents the time when the event occurs, identifying the time of the network traffic information collected by the honeypot service. The traffic information consumption service module creates an event instance by calling the constructor of the event class for the original network access traffic information obtained from the honeypot access traffic queue.

[0073] The constructor of the event class is defined as follows:

[0074] Function Honeypot Access Traffic Event Wrapping Features Abstract Class / Interface Class Name (Object Name) honeypotEventWrap Main Interface virtual int honeypotEventWrap(InputStream mb) = 0;

[0075] The traffic information consumption service module creates an event instance by calling the constructor of the event class for the original access traffic information obtained from the honeypot access traffic queue honeypotFlowQueue through the interface honeypotEventWrap(InputStream mb), thus packaging the original data into an event. The event is a set of xml format files, as shown below:

[0076]

[0077] Step 7, the stream data processing engine module creates the event type, event processing rules, and event processing conditions of the honeypot service. When the received event meets the event processing conditions, the event processing rules are triggered to process the event, and the attack warning information of the honeypot service is obtained. Specifically, it includes the following steps:

[0078] Step 7-1, create a stream data processing engine based on complex event processing CEP (Complex Event Processing);

[0079] Step 7-2: Register the event type in the stream data processing engine and generate relevant configuration objects, where the event type corresponds to the honeypot service type; Define events for various different types of network security honeypot services, with each type of honeypot service defined as an event. For example, define Event 1, Event 2,..., Event N for Redis honeypot, Mysql honeypot,..., WEB application honeypot respectively. After the event definition is completed, it can be registered in the event stream processing engine. As can be seen from Step 6, an event is a quadruple E=(id, honeypotType, flowData, timeStamp). For example, the event object definition of the Resis honeypot service is as follows:

[0080] public class redisEvent / / Resis honeypot service event object

[0081] {

[0082] Int id;

[0083] String honeypotType;

[0084] String flowData;

[0085] String timestamp;

[0086] public String getFlowData()

[0087] {return flowData;}

[0088] }

[0089] The above represents an event object of a Redis honeypot service, where id is used to uniquely identify a certain event, honeypotType is assigned different identifiers for different honeypot types, flowData represents the access traffic information of the Redis honeypot service, and timestamp represents the timestamp when the event occurs.

[0090] Step 7-3: Create an event stream processing engine instance based on the configuration object generated in 7-2 as the container environment for event processing;

[0091] Step 7-4: Create and import event processing rules, where the event processing rules correspond to the event type and are used to process the received events;

[0092] Step 7-5: Create a listener object and associate the listener object with the event processing rules;

[0093] Step 7-6: Create an execution environment object for event stream processing and match it with the event processing conditions in the engine.

[0094] Step 7-7: The execution environment object is responsible for listening to all incoming events, selecting the corresponding event processing conditions based on the honeypotType attribute value in the event, and triggering the corresponding listener to process the event when the event meets the event processing conditions, obtaining the warning information of the honeypot service being attacked. For example: when the execution environment object monitors that an attacker uses a scanner to brute-force the Mysql password and scans and connects to the Mysql honeypot, the stream data processing engine module will quickly analyze the event data, obtain the honeypotType value of the event, compare it with the defined event types and event processing rules, determine that the matching event type is Event 2, and then respond in a timely manner and generate the warning information of being attacked. The warning information is a set of tabular data as follows:

[0095]

[0096]

[0097] The method for implementing the network security honeypot system further includes Step 8: Start the daemon process to monitor the working status of the honeypot client. When the working status of the honeypot client is abnormal or it stops working, shut down and restart the honeypot client.

[0098] In specific implementation, the present application provides a computer storage medium and a corresponding data processing unit. Among them, the computer storage medium can store a computer program, and when the computer program is executed by the data processing unit, it can run the content of the invention of a method for implementing a network security honeypot system based on stream data processing and some or all of the steps in each embodiment. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.

[0099] Those skilled in the art can clearly understand that the technical solutions in the embodiments of the present invention can be implemented by means of a computer program and its corresponding general hardware platform. Based on such an understanding, the essence of the technical solutions in the embodiments of the present invention, or the part that contributes to the prior art, can be embodied in the form of a computer program, that is, a software product. The computer program software product can be stored in the storage medium and includes several instructions for causing a device (which can be a personal computer, a server, a single-chip microcomputer, a MUU, or a network device, etc.) including a data processing unit to execute the methods described in each embodiment or some parts of the embodiments of the present invention.

[0100] The present invention provides a network security honeypot system and an implementation method based on stream data processing. There are many methods and ways to specifically implement this technical solution. The above description is only a specific implementation manner of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. Each component not clearly defined in this embodiment can be implemented by using the prior art.

Claims

1. A network security honeypot system based on stream data processing, characterized in that, It includes a honeypot service management module, a honeypot client, a honeypot service running status collection service module, a traffic information consumption service module, a stream data processing engine module, a honeypot service management queue, a honeypot service status queue, and a honeypot access traffic queue. The honeypot service management module is used to store honeypot service management instructions into the honeypot service management queue, receive and process connection requests from the honeypot client, and send the connection configuration information of the honeypot service management queue to the honeypot client. The honeypot client is used to load the honeypot service configuration information, initiate a connection request to the honeypot service management module, connect to and monitor the honeypot service management queue; when a message is detected in the honeypot service management queue, take out the honeypot service management instruction and parse it to manage the honeypot service. The honeypot service management queue is used to store honeypot service management instructions. The honeypot service status queue is used to store the running status information of the honeypot service. The honeypot access traffic queue is used to store the access traffic information of the honeypot service. The honeypot service running status collection service module is used to monitor the honeypot service status queue, and when there is honeypot service status information in the honeypot service status queue, take out the data for processing and display. The traffic information consumption service module is used to monitor the honeypot access traffic queue. When there is honeypot network access traffic information in the honeypot access traffic queue, take out the network access traffic information and package it into an event, and send it to the stream data processing engine module. The stream data processing engine module is used to create event types and event processing rules for the honeypot service, match the received events with the event processing rules, and output the attack warning information of the honeypot service. The event is a quadruple E = <id, honeypotType, flowData, timeStamp>, where id is the unique identifier of the event, honeypotType represents the attribute of the event, that is, the type of the honeypot service. For the network access traffic information collected by different types of honeypot services, they are packaged into events with different attributes. flowData represents the network access traffic information data collected by the honeypot service carried in the event, and timeStamp represents the time when the event occurs, indicating the time of the network traffic information collected by the honeypot service. The traffic information consumption service module creates an event instance by calling the constructor of the event class for the original network access traffic information obtained from the honeypot access traffic queue. The stream data processing engine module performs the following steps: Step 7-1, create a stream data processing engine based on complex event processing CEP. Step 7-2, register event types in the stream data processing engine and generate relevant configuration objects, where the event types correspond to the honeypot service types. Step 7-3, create an event stream processing engine instance according to the configuration object generated in 7-2 as the container environment for event processing. Step 7-4, create and import event processing rules, and the event processing rules correspond to the event types and are used to process the received events. Step 7-5, create a listener object and associate the listener object with the event processing rules. Step 7-6: Create an execution environment object for event stream processing and match it with event processing conditions in the engine; Step 7-7: The execution environment object is responsible for listening to all incoming events, selecting corresponding event processing conditions according to the honeypotType attribute value in the event. When the event meets the event processing conditions, the corresponding listener is triggered to process the event, and the honeypot service attack warning information is obtained.

2. The network security honeypot system based on stream data processing according to claim 1, wherein It also includes a daemon process, which is used to monitor the working status of the honeypot client. When the working status of the honeypot client is abnormal or it stops working, the honeypot client is shut down and restarted.

3. A method for implementing a network security honeypot system based on stream data processing, characterized in that, It includes: Step 1: The honeypot service management module waits for the honeypot client to connect; Step 2: The honeypot client loads the honeypot service configuration information and initiates a connection request to the honeypot service management module; Step 3: The honeypot service management module receives and processes the connection request of the honeypot client. After the connection is successful, it sends the connection configuration information of the honeypot service management queue to the honeypot client; Step 4: The honeypot client connects to and listens to the honeypot service management queue. When a message is detected in the honeypot service management queue, the honeypot service management instruction is taken out and parsed to manage the honeypot service; Step 5: The honeypot service running status collection service module listens to the honeypot service status queue. When there is honeypot service status information in the honeypot service status queue, the data is taken out for processing and display; Step 6: The traffic information consumption service module listens to the honeypot access traffic queue. When there is honeypot network access traffic information in the honeypot access traffic queue, the network access traffic information is taken out and packaged into an event, and sent to the stream data processing engine module; Step 7: The stream data processing engine module creates the event type, event processing rules, and event processing conditions of the honeypot service. When the received event meets the event processing conditions, the event processing rules are triggered to process the event, and the honeypot service attack warning information is obtained; The event in Step 6 is a quadruple E = <id, honeypotType, flowData, timeStamp>, where id is the unique identifier of the event, honeypotType represents the attribute of the event, that is, the type of the honeypot service. The network access traffic information collected for different types of honeypot services is packaged into events with different attributes. flowData represents the network access traffic information data collected by the honeypot service carried in the event, and timeStamp represents the time when the event occurs, indicating the time of the network traffic information collected by the honeypot service; The traffic information consumption service module creates an event instance by calling the constructor of the event class for the original network access traffic information obtained from the honeypot access traffic queue; Step 7 includes: Step 7-1: Create a stream data processing engine based on complex event processing CEP; Step 7-2: Register the event type in the stream data processing engine and generate relevant configuration objects, where the event type corresponds to the honeypot service type; Step 7-3: Create an event stream processing engine instance according to the configuration object generated in 7-2 as the container environment for event processing; Step 7-4: Create and import an event handling rule, which corresponds to the event type and is used to process the received event; Step 7-5: Create a listener object and associate the listener object with the event handling rule; Step 7-6: Create an execution environment object for event stream processing and match it with the event handling conditions in the engine; The execution environment object is responsible for listening to all incoming events, selecting the corresponding event handling conditions according to the attribute value honeypotType in the event, and triggering the corresponding listener to process the event when the event meets the event handling conditions, so as to obtain the early warning information of the honeypot service being attacked.

4. A method for implementing a network security honeypot system based on stream data processing according to claim 3, characterized in that, The honeypot service management module and the honeypot client are based on the server / client mode of the TCP protocol. Step 1 includes: The honeypot service management module creates a socket socket, binds the local network address and port using the socket, and the socket listens on the bound port, waiting for the connection request from the honeypot client; Step 2 includes: The honeypot client loads the honeypot service configuration information, which is a quadruple <id, honeypotServiceName, honeypotServiceType, honeypotServiceFilePath>, where id is the unique identifier of the honeypot service; honeypotServiceName represents the name of the honeypot service; honeypotServiceType represents the type of the honeypot service; honeypotServiceFilePath represents the local path information of the honeypot service static file; The honeypot client creates a socket socket and initiates a connection request to the honeypot service management module.

5. A method for implementing a network security honeypot system based on stream data processing according to claim 4, characterized in that, In step 3, the process of the honeypot service management module handling the connection request from the honeypot client includes: The honeypot client sends the node information where the honeypot client is located to the honeypot service management module, and the node information includes the name of the node, the network address of the node, and the verification code of the node; The honeypot service management module verifies the node information sent by the honeypot client to determine whether it is a legal node that can establish a connection; If the node verification fails, the honeypot service management module disconnects the current connection and the connection fails; if the node verification passes, the connection is successful.

6. The implementation method of a network security honeypot system based on stream data processing according to claim 5, characterized in that, The honeypot service described in step 4 includes a honeypot service protocol and a honeypot service static file; The honeypot service management instruction includes a configuration instruction for configuring the honeypot service and an operation instruction for operating the honeypot service, and the operation instruction includes starting and stopping the honeypot service; The management of the honeypot service includes configuring the honeypot service and performing start and stop operations on the honeypot service.

7. The implementation method of a network security honeypot system based on stream data processing according to claim 6, characterized in that, The honeypot service status described in step 5 includes port status, heartbeat, system resource usage, service creation time, and service running time information.

8. A method for implementing a network security honeypot system based on stream data processing according to claim 7, characterized in that, It also includes step 8: Start a daemon process to monitor the working status of the honeypot client. When the working status of the honeypot client appears abnormal or stops working, close and restart the honeypot client.

Citation Information

Patent Citations

  • Intelligent network firewall device and network attack protection method

    CN103139184A

  • Security policy self-feedback method based on security log association analysis

    CN112468472A