Honeypot Management Method, Device, Honeypot Defense System and Storage Medium

A multi-level role-based management system for honeytrap defense systems limits access and operations based on user roles and positions, enhancing security by preventing attackers from compromising the entire system.

CN115499198BActive Publication Date: 2025-07-15HANGZHOU DBAPPSECURITY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211116894.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-14
Publication Date
2025-07-15
Estimated Expiration
2042-09-14

AI Technical Summary

Technical Problem

The existing honeypot defense system has low security due to single-level management, and attackers can obtain the entire system information through the attack management account.

Method used

By obtaining roles and operation permissions in the honeypot configuration module, setting business positions and user accounts based on roles, establishing the correspondence between roles and user accounts, determining the target honeypots and their permissions that can be seen and managed after logging in to the user account, and realizing hierarchical management.

Benefits of technology

It avoids attackers from obtaining information about the entire honeypot defense system after intrusion of the management account, and improves the security and management flexibility of the honeypot defense system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115499198B_ABST
    Figure CN115499198B_ABST
Patent Text Reader

Abstract

The present application relates to a honeypot management method, device, honeypot defense system and storage medium. The method is applied to a honeypot defense system, which includes a honeypot configuration module. The method includes: obtaining roles and corresponding operation permissions in the honeypot configuration module; setting corresponding business positions based on the roles, and setting corresponding user accounts based on the business positions; obtaining a third correspondence between the roles and the user accounts based on a first correspondence between the roles and the business positions and a second correspondence between the business positions and the user accounts; determining, based on the third correspondence, the target honeypots obtained after the user accounts log in to the honeypot defense system and the corresponding operation permissions; managing the target honeypots based on the operation permissions of the user accounts, so that different user accounts have different management objects and operation permissions according to different corresponding roles, solving the problem of low security of the honeypot defense system caused by single-level management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a honeypot management method, device, honeypot defense system, and storage medium. Background Art

[0002] In recent years, with the deployment of some security devices such as firewalls and intrusion detection systems, although the difficulty of implementing network attacks has been increased to a certain extent, the phenomenon of device intrusion cannot be fundamentally eliminated. Due to the inevitable design defects of products, attackers can always find various software and hardware vulnerabilities of the devices to complete the intrusion behavior. The emergence of honeypot technology has changed the passive defense situation in network attack and defense confrontation. By deploying traps targeted to lure attackers to initiate attacks and monitoring the honeypot scenario, data with higher purity can be captured, which is more conducive to capturing attack samples and analyzing attack behavior characteristics. However, for the existing honeypot defense systems, for the deployment and management of honeypots, they are all implemented through single-level management, that is, the entire honeypot defense system is deployed and managed by a single role. In this way, when an attacker successfully attacks from the management account of this single role, they can obtain the information of the entire honeypot defense system, reducing the security of the honeypot defense system.

[0003] Regarding the problem that the security of the honeypot defense system is relatively low due to single-level management in the related technology, no effective solution has been proposed yet. Summary of the Invention

[0004] In this embodiment, a honeypot management method, device, honeypot defense system, and storage medium are provided to solve the problem that the security of the honeypot defense system is relatively low due to single-level management in the related technology.

[0005] In a first aspect, in this embodiment, a honeypot management method is provided, which is applied to a honeypot defense system. The honeypot defense system includes a honeypot configuration module, and the method includes:

[0006] Obtain the roles and corresponding operation permissions in the honeypot configuration module;

[0007] Set corresponding business positions based on the roles, and set corresponding user accounts based on the business positions;

[0008] Based on the first correspondence between the role and the business position, and the second correspondence between the business position and the user account, obtain the third correspondence between the role and the user account;

[0009] Based on the third correspondence, determine the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system;

[0010] Manage the target honeypot based on the operation permissions of the user account.

[0011] In some embodiments, the honeypot defense system includes an image management module. The user account manages the target honeypot based on the operation permissions, including:

[0012] Determine the service type of the target honeypot based on the real business system;

[0013] Obtain the base image of the target honeypot from the image management module based on the service type;

[0014] Create a corresponding target honeypot based on the base image.

[0015] In some embodiments, after creating the corresponding target honeypot based on the base image, the method further includes:

[0016] When any honeypot in the honeypot defense system is attacked, determine the corresponding attack type based on a pre-set discrimination rule;

[0017] Generate an alarm message based on the attack type and send the alarm message to other honeypots;

[0018] Defend against the attack based on the pre-set handling method corresponding to the attack type in the other honeypots.

[0019] In some embodiments, generating the alarm message based on the attack type and sending the alarm message to other honeypots includes:

[0020] Parse the attack record of the honeypot to obtain the protocol information, address information, and port information corresponding to the attack;

[0021] Generate the alarm message based on the attack type, protocol information, address information, and port information.

[0022] In some embodiments, setting the corresponding business position based on the role includes:

[0023] When there is a restriction relationship between at least two roles, set different business positions for the at least two roles.

[0024] In some embodiments, determining the target honeypot and the corresponding operation permissions obtained by the user account after logging in to the honeypot defense system based on the third correspondence includes:

[0025] When the role corresponding to the user account is an operator, the target honeypot obtained by the user account is the honeypot created by the user account.

[0026] In some of these embodiments, determining the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system based on the third correspondence further includes:

[0027] When the role corresponding to the user account is an auditor, the operation permissions obtained by the user account include viewing;

[0028] When the role corresponding to the user account is an administrator, the operation permissions obtained by the user account include viewing, restarting, pausing, rolling back, and deleting.

[0029] In a second aspect, in the present embodiment, a honeypot management device is provided, which is applied to a honeypot defense system. The honeypot defense system includes a honeypot configuration module, and the honeypot management device includes:

[0030] A first acquisition module, configured to acquire the roles and corresponding operation permissions in the honeypot configuration module;

[0031] A setting module, configured to set corresponding business positions based on the roles, and set corresponding user accounts based on the business positions;

[0032] A second acquisition module, configured to acquire a third correspondence between the role and the user account based on a first correspondence between the role and the business position, and a second correspondence between the business position and the user account;

[0033] A first determination module, configured to determine the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system based on the third correspondence;

[0034] A management module, configured to manage the target honeypot based on the operation permissions of the user account.

[0035] In a third aspect, in the present embodiment, a honeypot defense system is provided. The honeypot defense system includes a hardware and software environment for deploying honeypots, and a honeypot management device as described in the second aspect above for managing the honeypots.

[0036] In a fourth aspect, in the present embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the traffic data statistics method described in the first aspect above are implemented.

[0037] Compared with the related technologies, the honeypot management method provided in this embodiment determines the corresponding relationship between the operation permissions and roles of the honeypot by obtaining the roles and corresponding operation permissions in the honeypot configuration module; configures the positions and users according to the actual usage scenarios of the honeypot defense system by setting corresponding business positions based on roles and corresponding user accounts based on business positions; obtains the third corresponding relationship between roles and user accounts based on the first corresponding relationship between roles and business positions and the second corresponding relationship between business positions and user accounts, that is, binds roles to specific user accounts according to the configuration information and the operation requirements of the honeypot; determines the target honeypots obtained after the user accounts log in to the honeypot defense system and the corresponding operation permissions based on the third corresponding relationship, and gives the scope of the target honeypots managed by the user accounts; manages the target honeypots based on the operation permissions of the user accounts, and gives the operation permissions of the user accounts for the management objects, so that different user accounts have different management objects and operation permissions according to different corresponding roles, avoiding attackers from obtaining the information of the entire honeypot defense system after successfully invading from the management account, and solving the problem of low security of the honeypot defense system caused by single-level management.

[0038] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments and descriptions thereof are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0040] Figure 1 is a block diagram of the application hardware of the honeypot management method in some embodiments of the present application;

[0041] Figure 2 is a flowchart of the honeypot management method in some embodiments of the present application;

[0042] Figure 3 is a flowchart of creating a target honeypot based on operation permissions in some embodiments of the present application;

[0043] Figure 4 is a flowchart of defense in the case of the honeypot being attacked in some embodiments of the present application;

[0044] Figure 5 is a flowchart of the honeypot management method in some preferred embodiments of the present application;

[0045] Figure 6 is a block diagram of the structure of the honeypot management device in some embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] To more clearly understand the purpose, technical solution and advantages of the present application, the present application will be described and explained below in conjunction with the accompanying drawings and embodiments.

[0047] Unless otherwise defined, the technical terms or scientific terms involved in the present application shall have the general meanings understood by those with ordinary skills in the technical field to which the present application belongs. In the present application, words such as "a", "one", "a kind of", "the", "these" and the like do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "comprising", "having" and any variants thereof involved in the present application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The terms "connected", "coupled" and the like involved in the present application do not limit to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "plurality" involved in the present application means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects associated before and after are in an "or" relationship. The terms "first", "second", "third" and the like involved in the present application only distinguish similar objects and do not represent a specific sorting of the objects.

[0048] The method embodiments provided in this embodiment can be executed on a terminal, a computer, a server or a similar computing device. Figure 1 It is a block diagram of the hardware device of a computer for the honeypot management method in some embodiments of the present application. As Figure 1 shown, the computer may include one or more ( Figure 1 only one is shown in Figure 1 the figure) processors 102 and a memory 104 for storing data. Among them, the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above computer may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown Figure 1 is only schematic and does not limit the structure of the above computer. For example, the computer may further include more or fewer components than

[0049] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the honeypot management method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.

[0050] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by a communication provider of the computer. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0051] In this embodiment, a honeypot management method is provided, which is applied to a honeypot defense system. The honeypot defense system includes a honeypot configuration module. Figure 2 It is a flowchart of the honeypot management method in some embodiments of the present application, as Figure 2 shown. The process includes the following steps:

[0052] Step S201, obtain the roles and corresponding operation permissions in the honeypot configuration module.

[0053] The honeypot defense system lures attackers to initiate attacks by pretending to have target services or file systems with attack value, so that the intruders actively expose their attack methods and intentions, thereby protecting the real business system from attacks or effectively defending against the attack methods. The honeypot defense system generally includes a disguised environment composed of honeypots, honeypot probes, a honeypot configuration module, etc. Among them, the honeypot configuration module is used to manage the layout, management method, operation permissions, etc. of the honeypots in the honeypot defense system.

[0054] A role refers to a person who is allowed to enter the honeypot defense system and perform corresponding operations. Roles usually include operators, administrators, auditors, etc. The roles in different honeypot defense systems may vary, and the permissions corresponding to the roles may also be different. According to the actual application scenarios and management requirements of the honeypot defense system, different roles and corresponding operation permissions can be set. For example, in the case where the defense system is attacked more frequently or there is more information to be processed, different roles can be set according to the analysis and processing permissions of different files such as attack log files and alarm files. In the case where there are a large number of honeypots in the system and the management pressure is high, hierarchical management or block management permissions can be set for the administrator role.

[0055] Further, in some embodiments, the operation permissions corresponding to an operator may include operations such as creating a honeypot, deleting a honeypot, viewing status information, restarting a honeypot, pausing work, rolling back to a specific state, etc. The operation permissions corresponding to an administrator may include performing any operation on the honeypot, and the operation permissions corresponding to an auditor may include viewing the status information and historical operation information of the honeypot, but without the permission to edit or modify the honeypot status.

[0056] Step S202, set corresponding business positions based on roles, and set corresponding user accounts based on business positions.

[0057] A business position refers to the actual position responsible for the role responsibilities in the honeypot defense system. For example, for the administrator of the honeypot defense system, the corresponding business position may be the R & D position in the enterprise's information security department; for the auditor, the corresponding business position may be the quality audit position in the information security department, etc. The corresponding relationship between roles and business positions can be adjusted according to the different functional departments and position settings of the enterprise.

[0058] A user account refers to the account used by the specific person in this business position to log in to the honeypot defense system. For the convenience of management, the position can be corresponded to the user account, so that even if the personnel change, it will not affect the use of this user account.

[0059] Generally, a role and a business position can be in one-to-one correspondence, or one role can correspond to multiple business positions, or one business position can correspond to multiple roles. A business position and a personnel account can be in one-to-one correspondence, or one personnel account can correspond to multiple business positions, or one business position can correspond to multiple personnel accounts.

[0060] In another embodiment, corresponding business departments can also be set based on roles, and corresponding user accounts can be set based on business departments, that is, using business departments instead of business positions. The corresponding relationship between roles and user accounts can also be established by setting both business departments and business positions at the same time.

[0061] Step S203: Based on the first correspondence between roles and business positions and the second correspondence between business positions and user accounts, obtain the third correspondence between roles and user accounts.

[0062] According to the one-to-one or one-to-many relationship between roles and business positions and the one-to-one or one-to-many relationship between business positions and user accounts described in step S202, obtain the third correspondence between roles and user accounts, and the third correspondence can also be one-to-one or one-to-many.

[0063] Step S204: Based on the third correspondence, determine the target honeypot obtained after the user account logs in to the honeypot defense system and the corresponding operation permissions.

[0064] After determining the third correspondence between roles and user accounts, when the user account logs in to the honeypot defense system, determine the role corresponding to the user account according to this third correspondence, and then set the operation permissions of the user account according to the operation permissions of this role. The target honeypot refers to the honeypot that the user account can operate. The target honeypots of different roles can be different. For example, the target honeypots of administrators can be all the honeypots included in the system, and the target honeypots of operators can be the honeypots corresponding to the levels or business modules to which the operator belongs, or only the honeypots created by the operator himself. After the user account logs in to the honeypot defense system, it can only see the target honeypots corresponding to the user account and has the corresponding operation permissions for the target honeypots. Other honeypots cannot be displayed.

[0065] Step S205: Manage the target honeypot based on the operation permissions of the user account.

[0066] Through the above steps S201 - S205, by obtaining the roles and corresponding operation permissions in the honeypot configuration module, determine the correspondence between the operation permissions of the honeypot and the roles; by setting the corresponding business positions based on the roles and setting the corresponding user accounts based on the business positions, perform position and user configuration according to the actual usage scenario of the honeypot defense system; by obtaining the third correspondence between roles and user accounts, that is, bind the roles to specific user accounts according to the configuration information and the operation requirements of the honeypot; by determining the target honeypot obtained after the user account logs in to the honeypot defense system and the corresponding operation permissions based on the third correspondence, give the scope of the target honeypots visible and manageable by the user account; by managing the target honeypot based on the operation permissions of the user account, give the operation permissions of the user account for the management objects, so that different user accounts have different management objects and operation permissions according to the different corresponding roles, avoiding attackers from obtaining the information of the entire honeypot defense system after successfully invading from the management account, and solving the problem of low security of the honeypot defense system caused by single-level management.

[0067] In some of the embodiments, the honeypot defense system includes an image management module.Figure 3 It is a flowchart for a user account in some embodiments of the present application to create a target honeypot based on operation permissions. As Figure 3 shown, this process includes the following steps:

[0068] Step S301, determine the service type of the target honeypot based on the real business system.

[0069] The honeypot defense system lures attackers by simulating the real business system. Therefore, corresponding honeypots can be created according to the service type of the real business system. For example, the real business system can include Web services, email systems, database systems, desktop operating systems, applications, industrial control systems, Internet of Things systems, etc. For the above business systems, there are corresponding service types such as email honeypots, database honeypots, industrial control honeypots (such as Conpot honeypots), Internet of Things honeypots (such as OSPF honeypots, Linksys router honeypots), middleware honeypots (such as Jboss vulnerability honeypots, Weblogic honeypots), etc. The network layout, connection method, and transmission protocol used by honeypots of different service types can be different.

[0070] Step S302, obtain the base image of the target honeypot from the image management module based on the service type.

[0071] The image management module includes the base images for honeypot deployment, corresponding to different service types. The base image can be regarded as an independent software package of the honeypot, containing all the content required to run the honeypot service, including code, libraries, environment variables, and configuration files, etc. Based on the base image, an instance of the corresponding target honeypot can be created to provide the honeypot service. The custom attributes of the honeypot can also be configured to construct a honeypot that conforms to the business scenario. For example, for a Web service honeypot, Web page data can be customized, etc. Information such as the CPU, memory, and open ports of the base image can also be set or modified.

[0072] Step S303, create the corresponding target honeypot based on the base image.

[0073] Through the above steps S301 - S303, by determining the service type of the target honeypot based on the real business system, determining the network services and resources that the target honeypot needs to simulate, obtaining the corresponding base image from the image management module, obtaining the honeypot independent software package corresponding to this service type, the construction of the running environment is completed; by creating the target honeypot based on the base image, the creation of the target honeypot that simulates the real business system is completed, improving the efficiency of honeypot creation.

[0074] In some of these embodiments, after creating the corresponding target honeypot based on the base image, it also involves the defense process in case the honeypot is attacked. Figure 4It is a flowchart for defense when a honeypot in some embodiments of the present application is attacked. As Figure 4 shown, the process includes the following steps:

[0075] Step S401, when any honeypot in the honeypot defense system is attacked, determine the corresponding attack type based on a pre-set discrimination rule.

[0076] When a honeypot in the honeypot defense system is attacked, determine the attack type through the discrimination rule. The attack type can include brute force cracking, port scanning, illegal login, illegal external connection, email social engineering attack, malicious Trojan back connection, etc. according to different business systems. Different attack types correspond to different discrimination rules. For example, for an attack of brute force cracking of account passwords, the login sessions of network transmission protocols such as the TELNET protocol and the SSH protocol can be monitored. When the number of login authentication failure messages from the same source IP exceeds 10 times within a short period, it can be determined that the attacker is performing brute force cracking. For an attack of the port scanning type, the traffic data of the TCP protocol can be monitored. When a large number of abnormal TCP connection (or close) messages are sent from the same source IP address within a short period and the ports are constantly changing, it can be determined that the attacker is performing port scanning.

[0077] Step S402, generate an alarm message based on the attack type and send the alarm message to other honeypots.

[0078] The alarm message can include the attack type, attack time, source IP address, destination IP address, etc. Integrate the above information based on a pre-determined structure, generate an alarm message and send it to other honeypots in the honeypot defense system.

[0079] Step S403, based on the disposal methods pre-set in other honeypots corresponding to the attack type, defend against the attack.

[0080] The attack type and the corresponding disposal methods are pre-set in the honeypot. When receiving the alarm message, perform corresponding defense according to the attack type and related attack information in the alarm message. For example, for an attack of the brute force cracking or port scanning type, extract information such as the source IP address in the alarm message, add the source IP address to the blacklist, or discard all data packets sent by the source IP address. It is also possible to perform a reverse attack according to the attacker information provided in the alarm message. For example, the honeypot uses a scanning tool to reverse scan the attacker's host to obtain the open ports and running services of the attacker, or log in to the attacker's host, etc.

[0081] Through the above steps S401 - S403, when the honeypot is attacked, the corresponding attack type is determined based on the pre - set discrimination rules. Attack type and relevant attack information are obtained through attack monitoring and discrimination, providing the information required for effective defense. Alarm information is generated based on the attack type and sent to other honeypots to share the attack information, preventing other honeypots from being invaded. Defense against the attack is carried out based on the pre - set handling methods corresponding to the attack type in other honeypots, effectively defending against known attacks and even launching counter - attacks, enhancing the defense ability of the entire honeypot defense system and improving the security of the real business system.

[0082] In some of these embodiments, it involves the specific process of generating alarm information based on the attack type. This process includes the following steps:

[0083] Step S11, parse the attack records of the honeypot to obtain the protocol information, address information, and port information corresponding to the attack.

[0084] When an attacker launches an attack on the honeypot, the honeypot defense system obtains relevant attack information through attack monitoring and discrimination rules, which may include the source IP address, the attacked IP address, the port number from which the attack is launched, the attacked port number, relevant parameters of the attacking host system, communication duration, communication protocol, number of data packets, etc.

[0085] Step S12, generate alarm information based on the attack type, protocol information, address information, and port information.

[0086] After determining the attack type according to the discrimination rules, integrate the attack type and the relevant attack information obtained in step S11 to generate alarm information. The format of the alarm information can be set according to the requirements of different attack types. For example, for port scanning, it is necessary to integrate the attack type, source IP address, attacked IP address, port number from which the attack is launched, attacked port number, communication duration, and communication protocol to generate alarm information. It is also possible to integrate the relevant attack information and generate alarm information according to the defense method corresponding to this attack type. For example, when defending by discarding data packets, it is necessary to integrate the attack type, source IP address, and port number from which the attack is launched to generate alarm information.

[0087] Through the above steps S11 - S12, by parsing the attack records of the honeypot, obtaining the protocol information, address information, and port information corresponding to the attack, and generating alarm information, it provides effective attack information for other honeypots to defend against this attack, improving the success rate of defense of other honeypots and enhancing the defense ability of the honeypot defense system.

[0088] In some of these embodiments, it involves the specific method of setting corresponding business positions based on roles. This method includes:

[0089] When there is a restrictive relationship between at least two roles, different business positions are set for the at least two roles.

[0090] In the process of setting corresponding business positions based on roles, the setting of business positions can be restricted according to the relationship between roles. The restrictive relationship means that there are mutually conflicting or exclusive functions between roles. For example, the function of an operator is to manage the target honeypot and perform relevant operations according to requirements, while the function of an auditor is to review whether the operations of the target honeypot meet the requirements. There is a conflict between the two functions. Therefore, the two roles should be set to be held by personnel in different business positions to avoid the situation where the functions of the roles cannot be effectively implemented. In addition, if there are other restrictions on roles in actual requirements, such as restrictions on the number of personnel, etc., they can all be restricted through the corresponding relationship between roles and business positions.

[0091] The honeypot management method provided in this embodiment determines the restrictive relationship existing between roles, restricts the business positions corresponding to the roles, avoids the situation where honeypot management cannot be effectively implemented due to role function conflicts, and improves the effectiveness of honeypot management.

[0092] In some of these embodiments, based on the third corresponding relationship, determining the target honeypot and the corresponding operation permissions obtained after a user account logs in to the honeypot defense system includes:

[0093] When the role corresponding to the user account is an operator, the target honeypot obtained by the user account is the honeypot created by the user account.

[0094] Only the honeypot created by the user account is used as the target honeypot of the user account, that is, when the target account is an operator, the target account can only see and operate and manage the honeypot created by itself in the honeypot defense system, and cannot see the honeypots created by others, avoiding misoperations on other honeypots and enhancing the security of the honeypot defense system; by decentralized management and operation of the honeypots in the honeypot defense system, the pressure on the administrator is reduced and the flexibility of management is improved; at the same time, it avoids the problem that when an intruder invades the honeypot defense system through a certain operator account and can operate all honeypots, enhancing the security of the honeypot defense system.

[0095] The following describes and illustrates this embodiment through preferred embodiments.

[0096] The honeypot management method of this preferred embodiment is applied to a honeypot defense system, which includes a honeypot configuration module and an image management module. Figure 5 It is the flowchart of the honeypot management method of this preferred embodiment.

[0097] As Figure 5 shown, the process includes the following steps:

[0098] Step S501: Obtain the roles and corresponding operation permissions in the honeypot configuration module;

[0099] The roles in the honeypot configuration module include operator, auditor, and administrator. The operation permissions of the operator include viewing, restarting, pausing, rolling back, and deleting; the operation permissions of the administrator include viewing, restarting, pausing, rolling back, and deleting; the operation permissions of the auditor include viewing.

[0100] Step S502: Set the corresponding business positions based on the roles, and set the corresponding user accounts based on the business positions;

[0101] The business positions of the operator and the auditor are different; the business positions of the administrator and the auditor are also different.

[0102] Step S503: Obtain the third correspondence relationship between the role and the user account based on the first correspondence relationship between the role and the business position, and the second correspondence relationship between the business position and the user account;

[0103] Step S504: Based on the third correspondence relationship, determine the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system;

[0104] When the role corresponding to the user account is an operator, the target honeypot of this user account is the honeypot created by this user account.

[0105] Step S505: Determine the service type of the target honeypot based on the real business system;

[0106] Step S506: Obtain the base image of the target honeypot from the image management module based on the service type;

[0107] Step S507: Create the corresponding target honeypot based on the base image;

[0108] Step S508: When any honeypot in the honeypot defense system is attacked, determine the corresponding attack type based on the preset discrimination rules;

[0109] Step S509: Analyze the attack records of the honeypot to obtain the protocol information, address information, and port information corresponding to the attack;

[0110] Step S510: Generate an alarm message based on the attack type, protocol information, address information, and port information;

[0111] Step S511: Send the alarm message to other honeypots;

[0112] Step S512: Defend against the attack based on the preset disposal method corresponding to the attack type in other honeypots.

[0113] Through the above steps S501 to S512, the corresponding relationship between the operation permissions of the honeypot and the roles is determined. The positions and users are configured according to the actual usage scenarios of the honeypot defense system. The roles are bound to specific user accounts according to the configuration information and the operation requirements of the honeypot, and the scope and operation permissions of the target honeypots visible and manageable by the user accounts are given, enabling different user accounts to undertake different management functions, avoiding the attacker from obtaining the information of the entire honeypot defense system after successfully invading from the management account, and solving the problem of low security of the honeypot defense system caused by single-level management; creating target honeypots according to the real business system to improve the ability of the honeypot defense system to lure attacks; when any honeypot is attacked, by determining the attack type, collecting attack information to generate alarm information, and sending the alarm information to other honeypots, the security of the entire honeypot defense system is improved.

[0114] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0115] In some embodiments, the present application also provides a honeypot management device, which is applied to a honeypot defense system. The honeypot defense system includes a honeypot configuration module. The honeypot management device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. The following terms "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function.

[0116] In some embodiments, Figure 6 is the structural block diagram of the honeypot management device of this embodiment, as Figure 6 shown, the device includes:

[0117] A first acquisition module 61, configured to acquire the roles and corresponding operation permissions in the honeypot configuration module;

[0118] A setting module 62, configured to set corresponding business positions based on the roles, and set corresponding user accounts based on the business positions;

[0119] A second acquisition module 63, configured to acquire the third corresponding relationship between the roles and the user accounts based on the first corresponding relationship between the roles and the business positions and the second corresponding relationship between the business positions and the user accounts;

[0120] A first determination module 64, configured to determine the target honeypots and corresponding operation permissions obtained after the user accounts log in to the honeypot defense system based on the third corresponding relationship;

[0121] The management module 65 is used to manage the target honeypot based on the operation permissions of the user account.

[0122] In the honeypot management device provided in this embodiment, the first acquisition module 61 determines the correspondence between the operation permissions of the honeypot and the roles; the setting module 62 configures the positions and users according to the actual usage scenarios of the honeypot defense system; the second acquisition module 63 binds the roles to specific user accounts according to the configuration information and the operation requirements of the honeypot; the determination module 64 determines the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system, and gives the scope of the target honeypot visible and manageable by the user account; the management module 65 gives the operation permissions of the user account for the management object, so that different user accounts have different management objects and operation permissions according to different corresponding roles, avoiding the attacker from obtaining the information of the entire honeypot defense system after successfully invading from the management account, and solving the problem of low security of the honeypot defense system caused by single-level management.

[0123] In some of these embodiments, the honeypot defense system includes an image management module, and the management module further includes a determination sub-module, an acquisition sub-module, and a creation sub-module. The determination sub-module is used to determine the service type of the target honeypot based on the real business system; the acquisition sub-module is used to obtain the base image of the target honeypot from the image management module based on the service type; the creation sub-module is used to create the corresponding target honeypot based on the base image.

[0124] In the honeypot management device provided in this embodiment, the determination sub-module determines the network services and resources that the target honeypot needs to simulate, the acquisition sub-module obtains the corresponding base image from the image management module, obtains the honeypot independent software package corresponding to this service type, and completes the construction of the operating environment; the creation sub-module completes the creation of the target honeypot that simulates the real business system, improving the efficiency of honeypot creation.

[0125] In some of these embodiments, the honeypot management device further includes a second determination module, a generation module, and a defense module. The second determination module is used to determine the corresponding attack type based on the preset discrimination rules when any honeypot in the honeypot defense system is attacked; the generation module is used to generate an alarm message based on the attack type and send the alarm message to other honeypots; the defense module is used to defend against the attack based on the preset handling method corresponding to the attack type in other honeypots.

[0126] In the honeypot management device provided in this embodiment, the corresponding attack type is determined by the second determination module and relevant attack information is obtained, providing the information required for effective defense; the warning information is generated by the generation module and shared with other honeypots to prevent other honeypots from being invaded; the attack is defended by the defense module based on the corresponding disposal methods preset in other honeypots, effectively defending against known attacks and even launching counterattacks, enhancing the defense ability of the entire honeypot defense system and improving the security of the real business system.

[0127] It should be noted that the above-mentioned each module can be a functional module or a program module, which can be implemented by software or by hardware. For the modules implemented by hardware, the above-mentioned each module can be located in the same processor; or the above-mentioned each module can also be located in different processors in any combined form.

[0128] In this embodiment, a honeypot defense system is also provided. The honeypot defense system includes the hardware and software environment for deploying honeypots, and the honeypot management device for managing honeypots in the above embodiment.

[0129] In the honeypot defense system provided in this embodiment, the corresponding relationship between the operation permissions and roles of the honeypot is determined by obtaining the roles and corresponding operation permissions in the honeypot configuration module, the positions and users are configured according to the actual usage scenarios of the honeypot defense system, and the roles are bound to specific user accounts by obtaining the third corresponding relationship between the roles and user accounts; by determining the scope and operation permissions of the target honeypots visible and managed by the user accounts based on the third corresponding relationship, different user accounts have different management objects and operation permissions according to different corresponding roles, preventing attackers from obtaining the information of the entire honeypot defense system after successfully invading from the management account, and solving the problem of low security of the honeypot defense system caused by single-level management.

[0130] In addition, in combination with the honeypot management method provided in the above embodiment, a storage medium can also be provided to implement it in this embodiment. A computer program is stored on the storage medium; when the computer program is executed by a processor, any one of the honeypot management methods in the above embodiment is implemented.

[0131] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiment and the optional implementation manners, and will not be repeated in this embodiment.

[0132] It should be understood that the specific embodiments described here are only used to explain this application, rather than to limit it. According to the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of this application.

[0133] Obviously, the accompanying drawings are only some examples or embodiments of the present application. For those of ordinary skill in the art, the present application can also be applied to other similar situations based on these drawings without creative efforts. Additionally, it can be understood that although the work done during this development process may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in the present application are only routine technical means and should not be regarded as insufficient disclosure of the present application.

[0134] The term "embodiment" in this application means that the specific features, structures, or characteristics described in connection with an embodiment can be included in at least one embodiment of the present application. The phrase appears in various positions in the specification and does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in this application can be combined with other embodiments without conflict.

[0135] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of patent protection. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several variations and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A honeypot management method, applied to a honeypot defense system, characterized in that The honeypot defense system includes a honeypot configuration module, and the method includes: Obtain the roles and corresponding operation permissions in the honeypot configuration module; Set corresponding business positions based on the roles, and set corresponding user accounts based on the business positions; Obtain the third correspondence between the role and the user account based on the first correspondence between the role and the business position, and the second correspondence between the business position and the user account; Based on the third correspondence, determine the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system; Manage the target honeypot based on the operation permissions of the user account; The honeypot defense system includes an image management module, and the user account manages the target honeypot based on the operation permissions, including: Determine the service type of the target honeypot based on the real business system; Obtain the basic image of the target honeypot from the image management module based on the service type; Create a corresponding target honeypot based on the basic image; After creating the corresponding target honeypot based on the basic image, the method further includes: When any honeypot in the honeypot defense system is attacked, determine the corresponding attack type based on the pre-set discrimination rules; Generate an alarm message based on the attack type, and send the alarm message to other honeypots; Defend against the attack based on the pre-set handling method corresponding to the attack type in the other honeypots.

2. The method according to claim 1, wherein The generating an alarm message based on the attack type and sending the alarm message to other honeypots includes: Parse the attack record of the honeypot to obtain the protocol information, address information, and port information corresponding to the attack; Generate the alarm message based on the attack type, protocol information, address information, and port information.

3. The method according to claim 1, wherein The setting corresponding business positions based on the roles includes: When there is a restriction relationship between at least two roles, set different business positions for the at least two roles.

4. The method according to claim 1, wherein The determining the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system based on the third correspondence includes: When the role corresponding to the user account is an operator, the target honeypot obtained by the user account is the honeypot created by the user account.

5. The method according to claim 1, characterized in that, The determining the target honeypot and the corresponding operation permissions obtained after the user account logs in to the honeypot defense system based on the third correspondence further includes: When the role corresponding to the user account is an auditor, the operation permissions obtained by the user account include viewing; When the role corresponding to the user account is an administrator, the operation permissions obtained by the user account include viewing, restarting, pausing, rolling back, and deleting.

6. A honeypot management device is applied to a honeypot defense system, and is characterized in that, The honeypot defense system includes a honeypot configuration module, and the honeypot management device includes: A first acquisition module for acquiring the roles and corresponding operation permissions in the honeypot configuration module; A setting module for setting corresponding business positions based on the roles and setting corresponding user accounts based on the business positions; A second acquisition module, configured to acquire a third correspondence relationship between the role and the user account based on the first correspondence relationship between the role and the business position and the second correspondence relationship between the business position and the user account; A first determination module, configured to determine a target honeypot and corresponding operation permissions obtained after the user account logs in to the honeypot defense system based on the third correspondence relationship; A management module, configured to manage the target honeypot based on the operation permissions of the user account; The honeypot defense system includes an image management module, and the management module further includes a determination sub-module, an acquisition sub-module, and a creation sub-module; the determination sub-module is configured to determine the service type of the target honeypot based on the real business system; the acquisition sub-module is configured to acquire the base image of the target honeypot from the image management module based on the service type; the creation sub-module is configured to create the corresponding target honeypot based on the base image; The honeypot management device further includes a second determination module, a generation module, and a defense module; the second determination module is configured to determine the corresponding attack type based on a preset discrimination rule when any honeypot in the honeypot defense system is attacked; the generation module is configured to generate an alarm message based on the attack type and send the alarm message to other honeypots; the defense module is configured to defend against the attack based on the preset disposal method corresponding to the attack type in other honeypots.

7. A honeypot defense system, characterized in that, The honeypot defense system includes a hardware and software environment for deploying the honeypot, and the honeypot management device according to claim 6 for managing the honeypot.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the honeypot management method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • WEB honeypot background management system and method based on Docker

    CN114510709A