A method for deceiving an attacker based on a honeypot device and the honeypot device

By setting up and bridging multiple virtual network cards in the honeypot device, and configuring different virtual physical addresses and Internet Protocol addresses, the problem of limited physical interfaces of the honeypot device is solved, and the deception and simulation capabilities against attackers are improved.

CN115632838BActive Publication Date: 2026-04-10SHENZHEN ANZHITIAN INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-09
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

The limited physical interfaces of honeypot devices mean that multiple honeypot assets share the same physical interface MAC address, making them easy for attackers to identify and resulting in insufficient simulation capabilities.

Method used

By setting up at least two virtual network cards on the physical network card and bridging them with a bridge, different virtual physical addresses and Internet Protocol addresses are configured. For each virtual network card, its Internet Protocol address is compared with the request. If they are the same, the physical address acquisition request is responded to, and the spoofing is carried out by using the independent MAC address of the virtual network card.

Benefits of technology

It improves the deception capabilities of honeypot devices for attackers, and the simulation capability is closer to the production environment, avoiding the problem of insufficient deception caused by multiple honeypot assets responding with the same MAC address in existing technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632838B_ABST
    Figure CN115632838B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a method for deceiving an attacker based on a honeypot device and the honeypot device, relates to the technical field of information security, and is invented to effectively improve the deceptive nature to the attacker. The method for deceiving the attacker based on the honeypot device comprises the following steps: receiving a physical address acquisition request sent by an external device; if at least two virtual network cards are set for a physical network card receiving the physical address acquisition request, the physical address acquisition request is forwarded to each virtual network card; different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different; for each virtual network card, whether the Internet protocol address of the honeypot asset configured by the virtual network card is same as the Internet protocol address in the physical address acquisition request is compared, and if the Internet protocol address is same, a virtual physical address configured by the virtual network card is used to respond to the physical address acquisition request. The application is suitable for responding to the physical address acquisition request.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and in particular to a method for deceiving an attacker based on a honeypot device, a honeypot device and a readable storage medium. BACKGROUND

[0002] With the rapid development of the Internet, people enjoy the convenience brought by the network, but also bring security risks. In order to improve security, threat detection needs to be performed.

[0003] In threat detection, threat detection can be achieved by monitoring data in and out of the honeypot. However, in the prior art, the physical interface (physical network card) of the honeypot device is limited, and a large number of honeypot assets need to be deployed. Therefore, multiple honeypot assets need to be created under one physical interface, and the honeypot assets under one physical interface share the MAC address of the physical interface. When the honeypot assets are subjected to ARP scanning attacks by external devices (attackers), the multiple honeypot assets under the physical interface repeatedly use the MAC address of the physical interface to respond to ARP requests. In this way, the external device (attacker) can easily discover the honeypot based on the large number of repeated MAC addresses in the response. SUMMARY

[0004] Therefore, the present application provides a method for deceiving an attacker based on a honeypot device, a honeypot device and a readable storage medium, which can effectively improve the deception of the attacker.

[0005] In a first aspect, the present application provides a method for deceiving an attacker based on a honeypot device, comprising: receiving a physical address acquisition request sent by an external device; if at least two virtual network cards are set for the physical network card receiving the physical address acquisition request, forwarding the physical address acquisition request to each virtual network card; the physical network card is bridged with the at least two virtual network cards through a network bridge, different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different; for each virtual network card, comparing the Internet protocol address of the honeypot asset configured by the virtual network card with the Internet protocol address in the physical address acquisition request, if they are the same, using the virtual physical address configured by the virtual network card to respond to the physical address acquisition request.

[0006] According to a specific implementation mode of the present application, each virtual network card includes a first sub-virtual network card and a second sub-virtual network card, and the first sub-virtual network card and the second sub-virtual network card constitute a virtual network card pair, wherein the first sub-virtual network card is used to bridge with the network bridge, and the second sub-virtual network card is used to configure a virtual physical address and a honeypot asset.

[0007] According to a specific implementation manner of the embodiment of the present application, the forwarding the physical address acquisition request to each virtual network card comprises: forwarding the received physical address acquisition request to a first virtual sub-network card in each virtual network card; and the comparing, for each virtual network card, the Internet protocol address of the honeypot asset configured by the virtual network card with the Internet protocol address in the physical address acquisition request, and if the same, using the virtual physical address configured by the virtual network card to respond to the physical address acquisition request comprises: forwarding, for each virtual network card, the physical address acquisition request received by the first virtual sub-network card in the virtual network card to a corresponding second virtual sub-network card; comparing the Internet protocol address of the honeypot asset configured by the second virtual sub-network card with the Internet protocol address in the physical address acquisition request, and if the same, using the virtual physical address configured by the second virtual sub-network card to respond to the physical address acquisition request.

[0008] According to a specific implementation manner of the embodiment of the present application, the virtual physical address configured in each virtual network card is determined according to the following steps: generating an initial virtual physical address of a target virtual network card according to a standard format of a physical address; the target virtual network card is any virtual network card to be configured with a virtual physical address; determining a target organization unique identifier corresponding to a honeypot asset according to the type of the honeypot asset configured by the target virtual network card; modifying the information on the bit position of the organization unique identifier in the initial virtual physical address to the target organization unique identifier, and determining the modified initial virtual physical address as the virtual physical address of the target virtual network card.

[0009] According to a specific implementation manner of the embodiment of the present application, the value of a request response parameter in the kernel parameter of the physical network card provided with at least two virtual network cards is a first value, the request response parameter is used to indicate a response mode of responding to the received physical address acquisition request; the first value corresponds to a first response mode, and the first response mode indicates responding to the received acquisition request for accessing the virtual network card; and the comparing, for each virtual network card, the Internet protocol address of the honeypot asset configured by the virtual network card with the Internet protocol address in the physical address acquisition request, and if the same, using the virtual physical address configured by the virtual network card to respond to the physical address acquisition request comprises: each virtual network card acquires the value of the request response parameter; and in the case that the acquired value of the request response parameter is the first value, each virtual network card compares the Internet protocol address of the honeypot asset configured by the virtual network card with the Internet protocol address in the physical address acquisition request; and if the same, using the virtual physical address configured by the virtual network card to respond to the physical address acquisition request.

[0010] According to a specific implementation manner of the embodiment of the present application, the method further comprises: detecting, according to a preset scanning strategy, whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each virtual network card and the physical address of each device in the internal network where the honeypot device is located.

[0011] In a second aspect, the embodiment of the present application provides a honeypot device, and the honeypot device comprises a physical network card, wherein the physical network card is provided with at least two virtual network cards and is bridged with the at least two virtual network cards through a network bridge; different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different; the physical network card is further configured to receive a physical address acquisition request sent by an external device and forward the received physical address acquisition request to each virtual network card through the network bridge, so that each virtual network card responds to the physical address acquisition request with its own virtual physical address in the case that the Internet protocol address in the received physical address acquisition request is the same as the Internet protocol address of the honeypot asset configured by the virtual network card.

[0012] According to a specific implementation manner of the embodiment of the present application, each virtual network card comprises a first sub-virtual network card and a second sub-virtual network card, and the first sub-virtual network card and the second sub-virtual network card constitute a virtual network card pair, wherein the first sub-virtual network card is configured to be bridged with the network bridge, and the second sub-virtual network card is configured to configure a virtual physical address and the honeypot asset.

[0013] According to a specific implementation manner of the embodiment of the present application, the virtual physical address of each virtual network card comprises an organization unique identifier corresponding to the type of the honeypot asset configured by the virtual network card.

[0014] According to a specific implementation manner of the embodiment of the present application, the value of a request response parameter in the kernel parameter of the physical network card is a first value, and the value of the request response parameter in the kernel parameter of each virtual network card is a second value; the request response parameter is used to indicate the response mode of the physical network card or the virtual network card for responding to the received physical address acquisition request; the first value corresponds to a first response mode, and the first response mode indicates responding to each physical address acquisition request for accessing the honeypot device; and the second value corresponds to a second response mode, and the second response mode indicates responding to the acquisition request for accessing the physical network card or the virtual network card.

[0015] According to a specific implementation manner of the embodiment of the present application, the physical network card is further configured to be connected with a scanning module in the honeypot device; and the scanning module is configured to detect whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each virtual network card and the physical address of each device in the internal network where the honeypot device is located.

[0016] In a third aspect, an embodiment of the present application provides a computer readable storage medium, which stores one or more programs, and the one or more programs are executable by one or more processors to implement the method for deceiving an attacker based on a honeypot device.

[0017] The method for deceiving an attacker based on a honeypot device, the honeypot device and the computer readable storage medium provided by the embodiment of the present application can deceive an attacker by receiving a physical address acquisition request sent by an external device, forwarding the physical address acquisition request to each virtual network card if at least two virtual network cards are set for the physical network card receiving the physical address acquisition request, bridging the physical network card with the at least two virtual network cards through a network bridge, configuring different virtual physical addresses and honeypot assets for different virtual network cards, and comparing the Internet Protocol address of the honeypot asset configured for each virtual network card with the Internet Protocol address in the physical address acquisition request. If the Internet Protocol addresses are the same, the virtual physical address configured for the virtual network card is used to respond to the physical address acquisition request. Since the Internet Protocol address of the honeypot asset configured for each virtual network card is compared with the Internet Protocol address in the physical address acquisition request, and if the Internet Protocol addresses are the same, the virtual physical address configured for the virtual network card is used to respond to the physical address acquisition request, different virtual physical addresses and honeypot assets are configured for different virtual network cards, and the Internet Protocol addresses of different honeypot assets are different. In this way, the responses to the physical address acquisition requests of different honeypot assets are different, so that the external device (the attacker) is deceived to believe that the physical address of the real asset is acquired, and the MAC address of the asset in the production environment is simulated to improve the deception of the attacker. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0019] Figure 1 The flowchart of the method for deceiving an attacker based on a honeypot device provided by an embodiment of the present application is shown in the figure.

[0020] Figure 2 The structural diagram of the honeypot device provided by an embodiment of the present application is shown in the figure.

[0021] Figure 3 The structural diagram of the honeypot device provided by another embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0022] The embodiments of the present application will be described in detail below with reference to the drawings. It should be noted that the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0023] As mentioned in the background, the honeypot technology has a history of development as a security tool for many years. The value of the honeypot (honeypot device) can be measured by the information it can obtain, and the information that the network intrusion detection system (NIDS) cannot obtain can be collected by monitoring the data in and out of the honeypot. For example, even if encryption technology is used to protect network traffic, we can still record the keystrokes in an interactive session. In order to detect malicious behavior, intrusion detection systems need to know the characteristics of attacks, and unknown attacks are usually not detected. On the other hand, honeypots can detect unknown attacks, for example, by observing network traffic leaving the honeypot, we can detect vulnerability threats even if using never-before-seen exploit means. Because the honeypot has no production value, any attempt to connect to the honeypot is considered suspicious. Therefore, the false positives generated by analyzing the data collected by the honeypot are less than the false positives caused by the data collected by the intrusion detection system, and with the help of the honeypot, most of the data we collect can help us understand the attack.

[0024] However, the physical interface of the honeypot device is limited, and the honeypot assets to be deployed are large, so it is necessary to create multiple honeypot assets under one physical interface. The honeypot assets under one physical interface share the physical address (MAC address) of the physical interface. When the honeypot assets are attacked by ARP scanning through the Internet Protocol address (IP address) to obtain the physical address (MAC address) of the corresponding host using the ARP protocol, it can be seen that multiple honeypot assets reuse the MAC address of the physical interface, and the simulation capability becomes very limited. Therefore, a technology is needed to enable different honeypot assets under a single physical interface of the honeypot to use different MAC addresses for communication, which is more in line with the actual production environment, thereby improving the simulation capability and achieving the effect of deceiving the attacker.

[0025] The inventor found in the process of implementing the present application that in a honeypot environment, the Bridge network bridge and Veth virtual network card technology can be combined, each virtual network card has an independent MAC address, the honeypot asset is configured on the virtual network card, one honeypot asset corresponds to one virtual network card, the honeypot physical network card and the virtual network card can be connected together through the network bridge to form a virtual local area network, since they belong to the same broadcast domain, all ARP request packets received by the physical network card will be sent to the network bridge, and the network bridge will flood the ARP request packet to all virtual network cards bridged to the network bridge. Therefore, the virtual network card can receive the external ARP request packet, and can respond to the MAC address of itself to these ARP requests, realizing the virtual multiple MAC addresses of the honeypot under the single physical interface of the honeypot for the honeypot asset.

[0026] In order for those skilled in the art to better understand the technical concepts, implementation schemes and beneficial effects of the embodiments of the present application, the following will be described in detail through specific embodiments.

[0027] An embodiment of the present application provides a method for deceiving an attacker based on a honeypot device, which can effectively improve the deception of the attacker.

[0028] Figure 1 A flowchart of the method for deceiving an attacker based on a honeypot device provided by an embodiment of the present application, the method for deceiving an attacker based on a honeypot device of the embodiment can include:

[0029] S101, receiving a physical address acquisition request sent by an external device.

[0030] The physical address request can be an address resolution protocol (ARP) request, which is used to acquire a MAC address through an IP address.

[0031] The physical address acquisition request is used to acquire the physical address of a host.

[0032] S102, if at least two virtual network cards are set for the physical network card receiving the physical address acquisition request, forwarding the physical address acquisition request to each virtual network card.

[0033] The physical network card is bridged with at least two virtual network cards through a network bridge, different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different.

[0034] The physical network card is a hardware device, which works at the bottom layer of OSI, and its hardware function is to receive and send data in the form of a bit stream.

[0035] Bridge, a virtual network device working at Layer 2, has a function similar to a physical switch. When data arrives, the Bridge broadcasts, forwards, or discards the data according to the physical address (MAC, Media Access Control Address) information in the message. The MAC address can also be referred to as a media access control address, which is an address used to identify the location of a network device. In the OSI model, the third layer network layer is responsible for the Internet Protocol (IP) address, and the second layer data link layer is responsible for the MAC address. The MAC address is used to uniquely identify a network card in a network. If a device has one or more network cards, each network card needs and will have a unique MAC address.

[0036] Virtual network card (also known as virtual network adapter), which is a software simulation of a network environment, simulates a network adapter, and mainly establishes a local area network between remote computers. The virtual network card has an independent MAC address.

[0037] The honeypot asset can be a simulated asset simulated according to a real asset in a production environment, deployed in a production network environment, and used to lure attackers to attack it. The honeypot asset of the embodiment can be a router, a computer in a production environment, a server, etc.

[0038] In the case where the physical network card receiving the physical address acquisition request is provided with at least two virtual network cards, after the Bridge receives the physical address acquisition request, the request can be sent to each virtual network card.

[0039] S103, for each virtual network card, compare the Internet Protocol address of the honeypot asset configured by the virtual network card with the Internet Protocol address in the physical address acquisition request. If they are the same, use the virtual physical address configured by the virtual network card to respond to the physical address acquisition request.

[0040] After receiving the physical address acquisition request sent by the Bridge, each virtual network card compares the IP address of the honeypot asset configured by itself with the Internet Protocol address in the physical address acquisition request. In the case where they are the same, use the virtual physical address configured by the virtual network card to respond to the physical address acquisition request.

[0041] When the IP address of the honeypot asset configured by a virtual network card is the same as the IP address in the physical address acquisition request, use the virtual physical address configured by the virtual network card as the response to the physical address acquisition request.

[0042] In the embodiment, a physical address acquisition request sent by an external device is received, if at least two virtual network cards are set for the physical network card receiving the physical address acquisition request, the physical address acquisition request is forwarded to each virtual network card, the physical network card is bridged with the at least two virtual network cards through a network bridge, different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different, for each virtual network card, whether the Internet protocol address of the honeypot asset configured for the virtual network card is same as the Internet protocol address in the physical address acquisition request is compared, if same, the virtual physical address configured for the virtual network card is used to respond to the physical address acquisition request. Since for each virtual network card, whether the Internet protocol address of the honeypot asset configured for the virtual network card is same as the Internet protocol address in the physical address acquisition request is compared, if same, the virtual physical address configured for the virtual network card is used to respond to the physical address acquisition request, and different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different, thus the responses to the physical address acquisition requests of different honeypot assets are different, so that the external device (an attacker) is mistaken to obtain the physical address of the real asset, thereby disguising as the MAC address of the asset in the production environment, improving the deception of the attacker, improving the authenticity of the simulation of the honeypot asset, and avoiding the problem that the response to the physical address acquisition request of the multiple honeypot assets in the prior art is the same physical address, resulting in low deception of the attacker.

[0043] In order to facilitate receiving the physical address acquisition request sent by the network bridge, another embodiment of the application is basically the same as the above-mentioned embodiment, and the difference is that each virtual network card of the embodiment can include a first sub-virtual network card and a second sub-virtual network card, the first sub-virtual network card and the second sub-virtual network card constitute a virtual network card pair, and the first sub-virtual network card is used to bridge with the network bridge, and the second sub-virtual network card is used to configure a virtual physical address and a honeypot asset.

[0044] The second sub-virtual network card is used to configure a honeypot asset, and specifically, the IP address of the honeypot asset is bound on the second sub-virtual network card.

[0045] In some examples, forwarding the physical address acquisition request to each virtual network card can include:

[0046] S102a, forwarding the received physical address acquisition request to a first virtual sub-network card in each virtual network card.

[0047] The first virtual sub-network card can receive the physical address acquisition request.

[0048] In this embodiment, for each virtual network card, it is compared whether the Internet Protocol address of the honeypot asset configured by the virtual network card is same as the Internet Protocol address in the physical address acquisition request, if same, the virtual physical address configured by the virtual network card is used to respond to the physical address acquisition request (S103), which can include:

[0049] S103a, for each virtual network card, the physical address acquisition request received by the first virtual subcard in the virtual network card is forwarded to the corresponding second virtual subcard.

[0050] After the first virtual subcard receives the physical address acquisition request, the address acquisition request can be forwarded to the second virtual subcard corresponding to the first virtual subcard.

[0051] S103b, it is compared whether the Internet Protocol address of the honeypot asset configured in the second virtual subcard is same as the Internet Protocol address in the physical address acquisition request, if same, the virtual physical address configured in the second virtual subcard is used to respond to the physical address acquisition request.

[0052] After receiving the physical address acquisition request forwarded by the first virtual subcard, it is compared whether the Internet Protocol address of the honeypot asset configured in the second virtual subcard is same as the Internet Protocol address in the physical address acquisition request, in the case of same, the virtual physical address configured in the second virtual subcard is used to respond to the physical address acquisition request.

[0053] In order to further improve the degree of attack of the attacker, in some examples, the virtual physical address configured in each virtual network card is determined according to the following steps:

[0054] A1, the initial virtual physical address of the target virtual network card is randomly generated according to the standard format of the physical address.

[0055] The target virtual network card in this embodiment is any virtual network card to be configured with a virtual physical address.

[0056] A2, according to the type of the honeypot asset configured by the target virtual network card, the target organization unique identifier corresponding to the honeypot asset is determined.

[0057] The organization unique identifier (OUI) is assigned to a unit organization by the Institute of Electrical and Electronics Engineers (IEEE), which can include 24 bits (the first 3 bytes of the MAC address). Each unit organization is assigned a global management address (24 bits, or 3 bytes) in turn, which is unique for each network card produced by the manufacturer.

[0058] Different types of honeypot assets have different target organization unique identifiers.

[0059] A3, modify the information on the bit position identifying the organization unique identifier in the initial virtual physical address to the target organization unique identifier, and determine the modified initial virtual physical address as the virtual physical address of the target virtual network card.

[0060] Since the initial virtual physical address is randomly generated, there is a lack of simulation. To improve the deception and simulation degree of the attacker, the OUI information in the MAC address can be modified according to the type of the honeypot asset configured by the target virtual network card. For example, if the honeypot asset is a network device type, the OUI of the relevant network device manufacturer needs to be implanted into the simulated MAC address; if the honeypot asset is an application service type, the OUI of the server manufacturer needs to be implanted into the simulated MAC address.

[0061] To further improve the deception and simulation degree of the attacker, in some examples, the value of the request response parameter in the kernel parameters of the physical network card provided with at least two virtual network cards is a first value, and the request response parameter is used to indicate a response mode of responding to a received physical address acquisition request; the first value corresponds to a first response mode, and the first response mode indicates responding to an acquisition request received for accessing the virtual network card.

[0062] In this embodiment, for each virtual network card, the Internet protocol address of the honeypot asset configured by the virtual network card is compared with the Internet protocol address in the physical address acquisition request. If they are the same, the virtual physical address configured by the virtual network card is used to respond to the physical address acquisition request (S103), which can include:

[0063] S103c, the value of the request response parameter of each virtual network card.

[0064] The request response parameter is also called arp_ignore, and the value of the request response parameter can be a first value or a second value. In this embodiment, the first value corresponds to a first response mode, and the first response mode indicates responding to an acquisition request received for accessing the virtual network card.

[0065] After receiving the physical address acquisition request, the value of the request response parameter of each virtual network card is obtained.

[0066] S103d, in the case where the value of the obtained request response parameter is the first value, each virtual network card compares the Internet protocol address of the honeypot asset configured by the virtual network card with the Internet protocol address in the physical address acquisition request.

[0067] If the value of the request response parameter is the first value, the Internet protocol address of the honeypot asset configured by the virtual network card is compared with the Internet protocol address in the physical address acquisition request.

[0068] S103e, if the same, responding to the physical address acquisition request using the virtual physical address configured by the virtual network card.

[0069] If not the same, the physical address acquisition request is not responded.

[0070] In some examples, the value of the honeypot interface ARP kernel parameter arp_ignore is adjusted. In some examples, by default, the value of arp_ignore of all interfaces of the system is 0, that is, when the interface receives an ARP request for the local IP address, the request includes a destination IP address, whether the destination IP is on the receiving network card or not, the receiving network card MAC address is responded, so that the ARP request receives multiple MAC address responses, therefore, the default arp_ignore parameter value of the interface is set to 1, so that each network card (including the virtual network card) only replies to the ARP request whose destination IP is the network card, and the network card whose destination IP does not respond.

[0071] The honeypot device of the embodiment can be a "black box" arranged by the network administrator, to attract attackers to attack. After the attacker intrudes, the specific attack behavior of the attacker can be known through the honeypot device. Through the honeypot, the contact between hackers can also be eavesdropped, various tools used by hackers can be collected, and their social networks can be mastered.

[0072] In order to improve the MAC address conflict detection mechanism, in some examples, the method of the embodiment can further include: according to a preset scanning strategy, detecting whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each virtual network card, and the physical address of each device in the internal network where the honeypot device is located.

[0073] The preset scanning strategy can be scanning at intervals of a predetermined time, or continuous scanning.

[0074] In some examples, since the actual OUI information is used to modify the randomly generated initial virtual physical address of the target virtual network card, and the modified virtual physical address is used as the virtual physical address of the target virtual network card, the MAC address uniqueness feature is easily destroyed, therefore, in the embodiment, whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each virtual network card, and the physical address of each device in the internal network where the honeypot device is located is detected through a preset scanning strategy, so that whether two or more same MAC addresses appear in the internal network is found in time.

[0075] In the embodiment, a physical address acquisition request sent by an external device is received, if at least two virtual network cards are set for the physical network card receiving the physical address acquisition request, the physical address acquisition request is forwarded to each virtual network card, the physical network card is bridged with the at least two virtual network cards through a network bridge, different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different, for each virtual network card, whether the Internet protocol address of the honeypot asset configured for the virtual network card is same as the Internet protocol address in the physical address acquisition request is compared, if they are same, the virtual physical address configured for the virtual network card is used to respond to the physical address acquisition request, since for each virtual network card, whether the Internet protocol address of the honeypot asset configured for the virtual network card is same as the Internet protocol address in the physical address acquisition request is compared, if they are same, the virtual physical address configured for the virtual network card is used to respond to the physical address acquisition request, and different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different, in this way, the responses to the physical address acquisition requests of different honeypot assets are different, so that the external device (an attacker) mistakenly thinks that the physical address of the real asset is acquired, and thus the MAC address of the asset in the production environment is simulated, the deception to the attacker is improved, in order to facilitate receiving the physical address acquisition request sent by the network bridge, each virtual network card can include a first sub-virtual network card and a second sub-virtual network card, the first sub-virtual network card and the second sub-virtual network card constitute a virtual network card pair, wherein the first sub-virtual network card is used to be bridged with the network bridge, and the second sub-virtual network card is used to configure a virtual physical address and a honeypot asset, in order to further improve the deception to the attacker and the simulation degree, the initial virtual physical address of the target virtual network card can be randomly generated according to the standard format of the physical address, the target organization unique identifier corresponding to the honeypot asset is determined according to the type of the honeypot asset configured for the target virtual network card, the information in the bit position of the organization unique identifier in the initial virtual physical address is modified into the target organization unique identifier, and the modified initial virtual physical address is determined as the virtual physical address of the target virtual network card, in order to further improve the deception to the attacker and the simulation degree, in some examples, the value of a request response parameter in the kernel parameter of the physical network card provided with at least two virtual network cards is a first value, and the value of the request response parameter in the kernel parameter of each virtual network card is a second value; the request response parameter is used to indicate the response mode of responding to the received physical address acquisition request.The first value corresponds to the first response mode, which indicates that a response should be given to each request to obtain the physical address of this honeypot device. The second value corresponds to the second response mode, which indicates that a response should be given to any request to obtain the physical network interface card (NIC) or virtual NIC. To improve the MAC address conflict detection mechanism, a preset scanning strategy can be used to detect whether there is a physical address collision between the physical address of the physical NIC and the physical addresses of each virtual NIC and the physical addresses of other devices in the internal network where the honeypot device is located.

[0076] One embodiment of this application provides a honeypot device that can effectively enhance its deception capabilities against attackers.

[0077] See Figure 2 , Figure 2 A honeypot device provided in one embodiment of this application, such as Figure 2 As shown, the honeypot device in this embodiment may include a physical network interface card (NIC) 1, which is equipped with at least two virtual NICs 2 and is bridged to at least two virtual NICs 2 via a bridge 3. Different virtual NICs 2 are configured with different virtual physical addresses and honeypot assets (not shown in the figure), and the Internet Protocol addresses of different honeypot assets are different. The physical NIC 1 is also used to receive physical address acquisition requests sent by external devices and to forward the received physical address acquisition requests to each virtual NIC 2 via the bridge 3, so that each virtual NIC 2 responds to the physical address acquisition request with its own virtual physical address if the Internet Protocol address in the received physical address acquisition request is the same as the Internet Protocol address of its own configured honeypot asset.

[0078] The honeypot device in this embodiment can be a meticulously planned "black box" set up by network administrators to lure attackers. After an attacker intrudes using external devices, the honeypot device can reveal the attacker's specific attack behavior. Honeypots can also be used to eavesdrop on communications between hackers, collect information on the tools they use, and gain insight into their social networks.

[0079] In some examples, configuring honeypot assets on virtual NIC 2 can specifically involve binding the Internet Protocol Address (IP) of the honeypot assets to the virtual NIC.

[0080] Physical network interface card 1 (NIC 1) is a hardware device operating at the lowest level of the OSI model. Its hardware function is to receive and send data in bitstream format. In some examples, an attacker can send a physical address acquisition request to the physical interface of the honeypot device. The physical interface then forwards this request to the physical NIC connected to it. The physical NIC receives the physical address acquisition request from the physical interface and forwards it to the bridge.

[0081] A physical address request can be an Address Resolution Protocol (ARP) request, which is used to obtain the MAC address from the IP address.

[0082] A virtual network adapter (also known as a virtual network card) is a software-simulated network environment, primarily used to establish local area networks (LANs) between remote computers. A virtual network adapter has its own independent MAC address.

[0083] A Bridge 3 is a Layer 2 virtual network device, functioning similarly to a physical switch. When data arrives, the Bridge broadcasts, forwards, or discards it based on the Media Access Control (MAC) address information in the packet. The MAC address, also known as the Media Access Control address, is used to identify the location of a network device. In the OSI model, Layer 3 (Network Layer) is responsible for Internet Protocol (IP) addresses, while Layer 2 (Data Link Layer) is responsible for MAC addresses. A MAC address uniquely identifies a network interface card (NIC) in a network. If a device has one or more NICs, each NIC needs and will have a unique MAC address.

[0084] Physical network card 1 is bridged to at least two virtual network cards 2 through bridge 2. After receiving a physical address acquisition request, the bridge can send the request to each virtual network card 2 respectively.

[0085] After receiving the physical address acquisition request sent by bridge 2, each virtual network card 3 compares the IP address in the received physical address acquisition request with the IP address of its own configured honeypot asset. If the IP address in the received physical address acquisition request is the same as the IP address of its own configured honeypot asset, it responds to the physical address acquisition request with its own virtual physical address.

[0086] Honeypot assets can be simulated assets based on real assets in the production environment, deployed in the production network environment to lure attackers to attack them. In this embodiment, the honeypot asset can be a router, a computer in the production environment, a server, etc.

[0087] In some examples, at least two virtual network interface cards 20 include a first virtual network interface card and a second virtual network interface card. The first virtual network interface card is configured with a first honeypot asset, and the second virtual network interface card is configured with a second honeypot asset. In this way, the first virtual network interface card can compare the IP address of the first honeypot asset with the IP address in the physical address acquisition request; the second virtual network interface card can compare the IP address of the second honeypot asset with the IP address in the physical address acquisition request.

[0088] When the IP address of the first honeypot asset configured by the first virtual network card is the same as the IP address in the physical address acquisition request, the virtual physical address of the first virtual network card is taken as the response to the physical address acquisition request. When the IP address of the second honeypot asset configured by the second virtual network card is the same as the IP address in the physical address acquisition request, the virtual physical address of the second virtual network card is taken as the response to the physical address acquisition request.

[0089] In the embodiment, the physical network card is provided with at least two virtual network cards, and the at least two virtual network cards are bridged with the network bridge. Different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different. The physical network card is also used for receiving a physical address acquisition request sent by an external device, and forwarding the received physical address acquisition request to each virtual network card through the network bridge, so that each virtual network card responds to the physical address acquisition request with its own virtual physical address when the Internet protocol address in the received physical address acquisition request is the same as the Internet protocol address of the honeypot asset configured by the virtual network card. Since each virtual network card responds to the physical address acquisition request with its own virtual physical address when the Internet protocol address in the received physical address acquisition request is the same as the Internet protocol address of the honeypot asset configured by the virtual network card, and different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different, the responses to the physical address acquisition requests of different honeypot assets are different, so that the external device (attacker) mistakenly believes that the physical address of the real asset has been obtained, thereby disguising as the MAC address of the asset in the production environment, improving the deception of the attacker, improving the authenticity of the simulation of the honeypot asset, and avoiding the problem that the response to the physical address acquisition request of the multiple honeypot assets in the prior art is the same physical address, resulting in low deception of the attacker.

[0090] Referring to Figure 3 In order to facilitate the reception of the physical address acquisition request sent by the network bridge 2, another embodiment of the application is basically the same as the above-mentioned embodiment, except that each virtual network card 2 of the embodiment includes a first sub-virtual network card 20 and a second sub-virtual network card 22, and the first sub-virtual network card 20 and the second sub-virtual network card 22 constitute a virtual network card pair. The first sub-virtual network card 20 is used to bridge with the network bridge, and the second sub-virtual network card 22 is used to configure a virtual physical address and a honeypot asset.

[0091] The second sub-virtual network card 22 is used to configure a honeypot asset, which can specifically bind the IP address of the honeypot asset on the second sub-virtual network card 22.

[0092] In order to further improve the degree of attack of the attacker's fraud and simulation, in some examples, the virtual physical address of each virtual network card contains the organization unique identifier corresponding to the type of honeypot asset configured by the virtual network card.

[0093] The organization unique identifier (OUI) is assigned to a unit organization by the Institute of Electrical and Electronics Engineers (IEEE), which can contain 24 bits (the first 3 bytes of the MAC address). Each unit organization is assigned a global management address (24 bits, or 3 bytes), which is unique for each network card produced by the manufacturer.

[0094] Different types of honeypot assets have different target organization unique identifiers.

[0095] Due to the random generation of the initial virtual physical address, there is a lack of simulation in the degree of simulation, in order to improve the degree of attack of the attacker's fraud and simulation, the OUI information in the MAC address can be modified according to the type of honeypot asset configured by the target virtual network card, for example, if the honeypot asset is a network device type, the OUI of the relevant network device manufacturer needs to be implanted into the simulated MAC address; if the honeypot asset is an application service type, the OUI of the server manufacturer is implanted into the simulated MAC address, which is more appropriate.

[0096] In order to further improve the degree of attack of the attacker's fraud and simulation, in some examples, the value of the request response parameter in the kernel parameter of the physical network card is the first value; the request response parameter is used to indicate the response mode of the physical network card or the virtual network card to the received physical address acquisition request; the first value corresponds to the first response mode, which indicates that the acquisition request accessing the virtual network card is responded.

[0097] The request response parameter is also called arp_ignore, and the value of the request response parameter can be the first value or the second value. In this embodiment, the first value corresponds to the first response mode, which indicates that the acquisition request accessing the virtual network card is responded.

[0098] After receiving the physical address acquisition request, each virtual network card acquires the value of the request response parameter, and in the case that the value of the acquired request response parameter is the first value, each virtual network card compares the Internet protocol address of the honeypot asset configured by the virtual network card with the Internet protocol address in the physical address acquisition request. If the value of the request response parameter is the first value, the Internet protocol address of the honeypot asset configured by the virtual network card is compared with the Internet protocol address in the physical address acquisition request. If they are the same, the virtual physical address configured by the virtual network card is used to respond to the physical address acquisition request; if they are not the same, the physical address acquisition request is not responded.

[0099] In some examples, the value of the honeypot interface ARP kernel parameter arp_ignore is adjusted. In some examples, by default, the value of arp_ignore for all interfaces of the system is 0, i.e., when an interface receives an ARP request for its own IP address, the request including a destination IP address, the interface responds with the MAC address of the receiving network card, regardless of whether the destination IP is on the receiving network card or not. This results in multiple MAC address responses to the ARP request, and thus the default value of the arp_ignore parameter for the interface is set to 1, so that each network card (including virtual network cards) only responds to ARP requests for which the destination IP is that of the network card.

[0100] In order to improve the MAC address conflict detection mechanism, in some examples, the physical network card is also used to connect with a scanning module in the honeypot device; the scanning module is used to detect whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each virtual network card and the physical address of each device in the internal network in which the honeypot device is located.

[0101] Since the initial virtual physical address of the randomly generated target virtual network card is modified using actual OUI information and used as the virtual physical address of the target virtual network card, the MAC address uniqueness feature is easily destroyed, and therefore, in this embodiment, a preset scanning strategy is used to detect whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each virtual network card and the physical address of each device in the internal network in which the honeypot device is located, so as to immediately find out whether two or more same MAC addresses exist in the internal network.

[0102] The honeypot device described above exists in various forms, including but not limited to:

[0103] (1) Ultra-mobile personal computer device: This type of device belongs to the category of personal computers and has computing and processing functions, and generally also has mobile Internet access features. This type of terminal includes PDA, MID, and UMPC devices, such as iPad.

[0104] (2) Server: A device that provides computing services. The components of a server include a processor, a hard disk, a memory, a system bus, etc. The server is similar in architecture to a general-purpose computer, but requires higher processing power, stability, reliability, security, scalability, and manageability due to the need to provide high-reliability services.

[0105] (3) Other electronic devices with data interaction functions.

[0106] The honeypot device of the embodiment is provided with at least two virtual network cards through a physical network card, and is bridged with the at least two virtual network cards through a network bridge, different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different. The physical network card is also used for receiving a physical address acquisition request sent by an external device, and forwarding the received physical address acquisition request to each virtual network card through the network bridge, so that each virtual network card responds to the physical address acquisition request with its own virtual physical address in the case that the Internet protocol address in the received physical address acquisition request is the same as the Internet protocol address of the honeypot asset configured by the virtual network card itself. Since each virtual network card responds to the physical address acquisition request with its own virtual physical address in the case that the Internet protocol address in the received physical address acquisition request is the same as the Internet protocol address of the honeypot asset configured by the virtual network card itself, and different virtual network cards are configured with different virtual physical addresses and honeypot assets, and the Internet protocol addresses of different honeypot assets are different, the responses to the physical address acquisition requests of different honeypot assets are different, so that the external device (an attacker) mistakenly believes that the physical address of the real asset has been acquired, thereby disguising as the MAC address of the asset in the production environment, improving the deception of the attacker, improving the authenticity of the simulation of the honeypot asset. In order to facilitate the reception of the physical address acquisition request sent by the network bridge, each virtual network card includes a first sub-virtual network card and a second sub-virtual network card, and the first sub-virtual network card and the second sub-virtual network card constitute a virtual network card pair. The first sub-virtual network card is used for bridging with the network bridge, and the second sub-virtual network card is used for configuring a virtual physical address and a honeypot asset. In order to further improve the deception of the attacker and the simulation degree, the virtual physical address of each virtual network card contains an organization unique identifier corresponding to the type of the honeypot asset configured by the virtual network card. In order to further improve the deception of the attacker and the simulation degree, the value of a request response parameter in the kernel parameter of the physical network card is a first value, and the value of the request response parameter in the kernel parameter of each virtual network card is a second value. The request response parameter is used for indicating the response mode of the physical network card or the virtual network card pair for responding to the received physical address acquisition request. The first value corresponds to a first response mode, and the first response mode indicates responding to each physical address acquisition request for accessing the honeypot device. The second value corresponds to a second response mode, and the second response mode indicates responding to the acquisition request for accessing the physical network card or the virtual network card. In order to perfect the MAC address conflict detection mechanism, the physical network card is also used for connecting with a scanning module in the honeypot device. The scanning module is used for detecting whether a physical address collision event occurs between the physical address of the physical network card and the physical address of each device in the internal network of the honeypot device.

[0107] In order to better understand the scheme of the present application, the scheme of the present application will be described in detail below with a specific embodiment.

[0108] P0: Adjust the value of the honeypot interface ARP kernel parameter arp_ignore, by default, the value of arp_ignore of all interfaces of the system is 0, that is, when the interface receives an ARP request for the local IP address (including the address on the virtual network card), regardless of whether the destination IP is on the receiving network card, the MAC address of the receiving network card is responded, resulting in a large number of MAC address responses to ARP requests, so the default arp_ignore parameter value of the interface needs to be set to 1, so that each network card (including the virtual network card) only replies to the ARP request whose destination IP is the network card.

[0109] P1: Use the bridge network bridge combined with the veth virtual network card technology to create a bridge network bridge for each honeypot physical interface, and the honeypot physical interface is bridged to the corresponding network bridge. When the interface needs to create a honeypot asset, a veth virtual network card is first created. The veth virtual network card must appear in pairs, one is used to bridge to the network bridge, and one is used to bind the honeypot asset IP. Because each virtual network card has an independent MAC address, and the MAC addresses of each virtual network card are different, the MAC address simulation requirement can be met.

[0110] P2: By modifying the MAC address of the veth virtual network card, according to the type of the honeypot asset, the MAC address of the specific OUI is used to achieve the purpose of false appearance, so as to obtain the trust of the attacker and stimulate the attacker's deeper attack motive.

[0111] P3: Perfect MAC address conflict detection mechanism.

[0112] Because the actual OUI information is used for MAC address simulation, the unique characteristics of the MAC address are destroyed, so it is necessary to regularly scan the MAC address list in the network to avoid MAC address collision events.

[0113] The honeypot device of the embodiment can virtualize multiple MAC addresses under a single physical interface, realize different honeypot assets using different MAC addresses; in addition, according to the type of the honeypot asset, the OUI information related to the asset type is implanted into the simulated MAC address, so that the simulated MAC address is almost the same as the MAC address of the asset in the production environment, and the simulation capability is improved.

[0114] Correspondingly, the embodiment of the application also provides a computer readable storage medium, the computer readable storage medium stores one or more programs, the one or more programs can be executed by one or more processors to implement the method for deceiving an attacker based on a honeypot device provided by any of the foregoing embodiments, so the corresponding technical effects can also be achieved. The foregoing has been described in detail, and will not be repeated here.

[0115] It is to be noted that, in the present document, relational terms such as first and second and the like can be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions. Also, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises a... " does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0116] Each of the embodiments in the present specification is described in a related manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments.

[0117] Especially, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the description of the method embodiments.

[0118] For the convenience of description, the above device is described in various units / modules respectively according to functions. Of course, in the implementation of the present application, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.

[0119] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by a computer program instructing related hardware. The program can be stored in a computer readable storage medium, and when the program is executed, the processes of the above-mentioned embodiments can be included. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM) or a random access memory (RAM) and the like.

[0120] The above description is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in the present application can be easily thought by those skilled in the art, and should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for deceiving an attacker based on a honeypot device, the method comprising: include: Receive physical address retrieval requests from external devices; The physical network interface card (NIC) receiving the physical address acquisition request is configured with at least two virtual NICs, and forwards the physical address acquisition request to each virtual NIC. The physical NIC is bridged to the at least two virtual NICs via a network bridge. Different virtual NICs are configured with different virtual physical addresses and honeypot assets, and the Internet Protocol addresses of different honeypot assets are different. The virtual physical address configured in each virtual NIC is determined according to the following steps: an initial virtual physical address of the target virtual NIC is randomly generated according to the standard format of physical addresses; the target virtual NIC is any virtual NIC whose virtual physical address is to be configured; based on the type of honeypot asset configured in the target virtual NIC, the unique identifier of the target organization corresponding to the honeypot asset is determined; the information in the bit that identifies the unique identifier of the organization in the initial virtual physical address is modified to the unique identifier of the target organization, and the modified initial virtual physical address is determined as the virtual physical address of the target virtual NIC. For each virtual network interface card (NIC), compare the Internet Protocol address (IPA) of the honeypot asset configured for that virtual NIC with the IPA in the physical address acquisition request. If they are the same, use the virtual physical address configured for that virtual NIC to respond to the physical address acquisition request.

2. The method of claim 1, wherein, Each virtual network interface card (NIC) includes a first sub-virtual NIC and a second sub-virtual NIC, which together form a virtual NIC pair. The first sub-virtual NIC is used to bridge with the bridge, and the second sub-virtual NIC is used to configure virtual physical addresses and honeypot assets.

3. The method according to claim 2, characterized in that, The step of forwarding the physical address acquisition request to each virtual network interface card includes: Forward the received physical address retrieval request to the first virtual sub-network card in each virtual network card; For each virtual network interface card (NIC), the step of comparing the Internet Protocol address (IPA) of the honeypot asset configured on that virtual NIC with the IPA in the physical address acquisition request is performed. If they are the same, the virtual physical address configured on the virtual NIC is used to respond to the physical address acquisition request. This includes: For each virtual network interface card (NIC), the physical address acquisition request received by the first virtual sub-NIC in that virtual NIC is forwarded to the corresponding second virtual sub-NIC. Compare whether the Internet Protocol address of the honeypot asset configured in the second virtual sub-NIC is the same as the Internet Protocol address in the physical address acquisition request. If they are the same, then use the virtual physical address configured in the second virtual sub-NIC to respond to the physical address acquisition request.

4. The method according to claim 1, characterized in that, The value of the request-response parameter in the kernel parameters of the physical network card that is configured with at least two virtual network cards is the first value; The request-response parameter is used to indicate the response mode for responding to the received physical address acquisition request; the first value corresponds to the first response mode, which indicates the response to the received acquisition request to access this virtual network card; For each virtual network interface card (NIC), the step of comparing the Internet Protocol address (IPA) of the honeypot asset configured on that virtual NIC with the IPA in the physical address acquisition request is performed. If they are the same, the virtual physical address configured on the virtual NIC is used to respond to the physical address acquisition request. This includes: Each virtual network interface card (NIC) obtains the value of the request-response parameter; If the value of the obtained request response parameter is the first value, each virtual network interface card (NIC) compares whether the Internet Protocol address of the honeypot asset configured for that virtual NIC is the same as the Internet Protocol address in the physical address acquisition request. If they are the same, the virtual physical address configured in the virtual network interface card is used to respond to the physical address acquisition request.

5. The method according to claim 1, characterized in that, The method further includes: According to the preset scanning strategy, detect whether there is a physical address collision event between the physical address of the physical network card and the physical address of each virtual network card and the physical address of each device in the intranet where the honeypot device is located.

6. A honeypot device, characterized in that, The system includes a physical network interface card (NIC), which has at least two virtual NICs connected to it via a bridge. Different virtual NICs are configured with different virtual physical addresses and honeypot assets, and the internet protocol addresses of the different honeypot assets are different. The virtual physical addresses configured in each virtual NIC are determined according to the following steps: an initial virtual physical address for the target virtual NIC is randomly generated according to the standard format of physical addresses; the target virtual NIC is any virtual NIC for which a virtual physical address is to be configured; based on the type of honeypot asset configured in the target virtual NIC, a unique identifier for the target organization corresponding to that honeypot asset is determined; the information in the bits identifying the unique identifier for the organization in the initial virtual physical address is modified to the unique identifier for the target organization, and the modified initial virtual physical address is determined as the virtual physical address of the target virtual NIC. The physical network interface card (NIC) is also used to receive physical address acquisition requests sent by external devices, and to forward the received physical address acquisition requests to each virtual NIC through the bridge, so that each virtual NIC responds to the physical address acquisition request with its own virtual physical address if the Internet Protocol address in the received physical address acquisition request is the same as the Internet Protocol address of its own configured honeypot asset.

7. The honeypot device according to claim 6, characterized in that, Each virtual network interface card (NIC) includes a first sub-virtual NIC and a second sub-virtual NIC. The first sub-virtual NIC and the second sub-virtual NIC constitute a virtual NIC pair. The first sub-virtual NIC is used to bridge with the bridge, and the second sub-virtual NIC is used to configure the virtual physical address and the honeypot assets.

8. The honeypot device according to claim 6, characterized in that, The request-response parameter in the kernel parameters of the physical network card is a first value, and the request-response parameter in the kernel parameters of each virtual network card is a first value; The request-response parameter is used to indicate the response mode for responding to the received physical address acquisition request; the first value corresponds to the first response mode, which indicates the response to the received acquisition request to access this virtual network card; For each virtual network interface card (NIC), the step of comparing the Internet Protocol address (IPA) of the honeypot asset configured on that virtual NIC with the IPA in the physical address acquisition request is performed. If they are the same, the virtual physical address configured on the virtual NIC is used to respond to the physical address acquisition request. This includes: Each virtual network interface card (NIC) obtains the value of the request-response parameter; If the value of the obtained request response parameter is the first value, each virtual network interface card (NIC) compares whether the Internet Protocol address of the honeypot asset configured for that virtual NIC is the same as the Internet Protocol address in the physical address acquisition request. If they are the same, the virtual physical address configured in the virtual network interface card is used to respond to the physical address acquisition request.

9. The honeypot device according to claim 6, characterized in that, The physical network card is also used to connect to the scanning module in the honeypot device; The scanning module is used to detect whether there is a physical address collision event between the physical address of the physical network card and the physical address of each virtual network card and the physical address of each device in the intranet where the honeypot device is located.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more programs, which can be executed by one or more processors to implement the method for deceiving attackers based on honeypot devices as described in any one of claims 1-5.

Citation Information

Patent Citations

  • System and method for deploying virtual honeypots in multiple network segments based on real network environment

    CN110650154A

  • Anti-attack method by counterfeiting IP address based on virtual network equipment

    CN111756712A