Cloud honeypot for the entire ship computing environment, attack event perception, and behavior analysis methods

By building a cloud honeypot for the entire ship's computing environment and using link gateways and simulation nodes to simulate real systems, the problem of the ship's computing environment being unable to obtain Internet threat intelligence in real time was solved, the capture and analysis of unknown attack behaviors was achieved, and security protection capabilities were enhanced.

CN115694928BActive Publication Date: 2025-09-26709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211267529.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-17
Publication Date
2025-09-26
Estimated Expiration
2042-10-17

AI Technical Summary

Technical Problem

The ship's computing environment is unable to obtain Internet cloud threat intelligence in real time, resulting in insufficient ability to capture and analyze unknown new attack methods, affecting security protection effectiveness.

Method used

Build a cloud honeypot for the entire ship's computing environment, including a link gateway, a TCP/UDP protocol parsing and authentication engine, a data analysis engine, a honeypot simulation computing service node, and a honeypot simulation storage node. Use deception technology to simulate the real system, capture and analyze unknown attack behaviors, and enhance security protection.

Benefits of technology

It has achieved the capture and analysis of unknown new attack methods, delayed the attacker's progress, provided simulated real services and data, enhanced the security protection capabilities of the entire ship's computing environment, and ensured that the system is not overflowed, infiltrated, and privileges are not seized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115694928B_ABST
    Figure CN115694928B_ABST
Patent Text Reader

Abstract

The present invention discloses a cloud honeypot for the whole ship computing environment, an attack event perception and behavior analysis method, and belongs to the field of data security. The cloud honeypot includes: a link gateway, a TCP / UDP protocol parsing and authentication engine, a data analysis engine, a honeypot simulation computing service node, a honeypot simulation storage node and a proxy gateway, wherein the honeypot simulation computing service node and the honeypot simulation storage node jointly construct a virtual computing storage environment. The present invention constructs a honeypot that has the advantages of both a real system honeypot and a pseudo-system honeypot in the whole ship computing environment, thereby inducing the attacker to attack them, thereby capturing and analyzing the attack behavior, understanding the tools and methods used by the attacker, inferring the attack intentions and motives, and enabling the defender to clearly understand the security threats they face. It solves the problem of capturing and analyzing unknown new attack methods when it is impossible to obtain Internet cloud empowerment in real time, thereby enhancing the security protection capabilities of the actual system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data security, and more specifically, relates to a cloud honeypot for a full-ship computing environment, an attack event perception, and a behavior analysis method. Background Art

[0002] With the advancement of network attack technology, the limitations and vulnerabilities of traditional firewalls, which rely on a rule-based system based on known dangers, are becoming increasingly apparent. If an intruder launches a new attack and the firewall lacks corresponding rules to handle it, the firewall becomes ineffective and the system it protects will be damaged. Therefore, technicians need honeypots to record the intruder's actions and intrusion data, and add new rules to the firewall or manually defend against it when necessary. Honeypot technology uses bait hosts, network services, or information to lure attackers into attacking them. This allows the attackers to capture and analyze the attack behavior, understand their tools and methods, and infer their intentions and motivations. This allows defenders to clearly understand the security threats they face and enhance the security protection capabilities of the actual system through technical and management measures.

[0003] Honeypots can be categorized as real system honeypots and pseudo-system honeypots. Real system honeypots are the most authentic, running a real system with real, exploitable vulnerabilities—the most dangerous. Each intrusion triggers a genuine system reaction, such as an overflow, penetration, or privilege evasion, while also recording the most authentic intrusion information. Pseudo-system honeypots are created by administrators leveraging the powerful mimicry of tools and programs to forge "vulnerabilities" that don't belong to their own platforms. These exploits allow intruders to successfully "penetrate" and, while believing they've succeeded, are effectively trapped within a program framework, fumbling around in a program-created dream world. This allows the administrator to track and record intruders.

[0004] Among the existing publicly available cloud honeypot technologies, one method is to filter out untrusted processes from all currently running processes, inject a hook function into the untrusted process, obtain the untrusted process's call function records and function execution records, traverse the obtained call function records and function execution records, and identify whether the untrusted process poses a risk. This method is ineffective for network attacks that do not generate malicious processes. Another method is to compare the socket sent by the user with the socket specified in the pre-acquired honeypot system. As long as the socket sent by the user belongs to the pre-acquired socket in the honeypot system, regardless of whether the access request sent by the user generates a malicious process, it will be identified as a risk. If this method cannot immediately link to threat intelligence, it will be unable to predict and prevent the threat of unknown new attack methods.

[0005] The Total Ship Computing Environment (TSCE) is a private cloud. It is network-centric, based on an open architecture and off-the-shelf civilian technologies. It integrates all computing operations and basic data from all sensors, weapon resources, command and control systems, and ship platform management systems used by modern ships in both wartime and peacetime. As a private cloud, it is also subject to various security threats from both within and outside the system. Unlike typical private clouds, the TSCE is physically isolated from the internet and cannot obtain threat intelligence in real time through the internet. Therefore, there is an urgent need for a TSCE cloud honeypot technology. This technology can be used to capture and analyze unknown attack behaviors, understand the tools and methods used by attackers, and infer attack intentions and motivations, even when real-time internet cloud access is unavailable. This technology can provide defenders with a clear understanding of the security threats they face, thereby enhancing the security protection capabilities of the actual system. Summary of the Invention

[0006] In response to the defects of the existing technology, the purpose of the present invention is to provide a cloud honeypot for the entire ship computing environment, an attack event perception and behavior analysis method, aiming to solve the problem of capturing and analyzing unknown new attack methods when it is impossible to obtain real-time Internet cloud empowerment, thereby enhancing the security protection capabilities of the actual system.

[0007] To achieve the above objectives, in a first aspect, the present invention provides a cloud honeypot for a full-ship computing environment, wherein the cloud honeypot comprises: a link gateway, a TCP / UDP protocol parsing and authentication engine, a data analysis engine, a honeypot simulation computing service node, a honeypot simulation storage node, and a proxy gateway, wherein the honeypot simulation computing service node and the honeypot simulation storage node jointly construct a virtual computing and storage environment;

[0008] The link gateway is used to provide point-to-point RDP connections for each terminal in the entire ship computing environment;

[0009] The TCP / UDP protocol parsing and authentication engine is used to parse and authenticate information and service requests from the link gateway. For legitimate access, the information and service requests are passed to the proxy gateway. For illegal access or attacks, the attacker's access traffic is diverted to the virtual computing and storage environment. At the same time, the attacker's illegal activities are monitored and detected, and the attack and illegal access data are sent to the data analysis engine.

[0010] The data analysis engine is used to detect application traffic passing through the virtual computing and storage environment in real time, record the traffic, perform application analysis, match the analyzed application data with a signature library, and discover server vulnerability attacks in the data stream; any unauthorized behavior may be suspected of being an attack exploiting an unknown vulnerability; and the identified attack behavior in the application traffic is associated with the domain name process relationship chain and submitted to the operation and maintenance management terminal for interpretation and interruption of the attack chain.

[0011] The honeypot simulation computing service node is used to respond to the attacker's computing service request, provide the attacker with non-real computing services, and provide the attacker with virtual computing services based on the simulated honeypot resources, including infrastructure, platform and software. The attacker can create virtual machines, build applications and service platforms, and use applications in the honeypot; all access requests initiated through the honeypot simulation service node are directed to the honeypot simulation computing service node and the honeypot simulation storage node and receive responses, so that the attacker mistakenly believes that they have obtained real computing services;

[0012] The honeypot simulates a storage node, which is used to respond to the attacker's data read and write service request, and provides the attacker with non-real structured data, so that the attacker mistakenly believes that he has obtained and stolen real data and obtained real storage services;

[0013] The proxy gateway is used to further authenticate the messages authenticated by the TCP / UDP protocol parsing authentication engine, and provide real access to the full-ship computing environment cloud service platform to users who ultimately pass the authentication.

[0014] Preferably, the honeypot simulation computing service node is deployed according to the full-ship computing environment cloud service platform, providing three service modes;

[0015] The three services provided by the honeypot simulation computing service node are: Infrastructure as a Service (IaaS), which virtualizes computing resources such as virtual machines, storage, networks, and operating systems for attackers; Platform as a Service (PaaS), which builds application and service platforms for attackers and provides an on-demand development environment; Software as a Service (SaaS), which provides applications for attackers to run and access data in the honeypot;

[0016] The aforementioned computing resources, applications, and service platforms are deployed as a cloud service platform for the ship's computing environment, but their data and algorithms have been declassified, and access to data is limited to the honeypot simulation storage node;

[0017] The data structure of the honeypot simulation storage node is deployed according to the cloud service platform of the whole ship computing environment. The data uses the real data of the cloud service platform to modify the sensitive data and perform declassification processing. It has a basic database of the whole ship computing environment to simulate the cloud storage service.

[0018] It should be noted that the present invention deceives the entire chain of the attack process, making the attacker believe that the attack is on a real system, and can obtain "real" services and data that confuse the attacker, delay the attacker's time and energy, and buy time for accurate capture and maintenance.

[0019] Preferably, the link gateway is composed of a convergence module, an RDP module, a NAP module and a NP module;

[0020] The aggregation module is used to aggregate data from multiple externally connected physical ports into one port and send the data to the data analysis engine;

[0021] The RDP module is used to realize the conversion of information and service requests;

[0022] The NAP module is used to enforce health requirements for terminals accessing the ship-wide computing environment according to preset rules, including hardware requirements, security update requirements, required computer configurations, and other settings;

[0023] The NP module is used to classify information and service requests into three categories based on the processing results of the PDP module and the NAP module, and send the marked information and service requests to the TCP / UDP protocol parsing and authentication engine. The classification rules are as follows: information and service requests issued by authentication devices within the ship-wide computing environment system are marked as Class A, information and service requests issued by devices outside the system that meet the authentication conditions are marked as Class B, and other information and service requests are marked as Class C.

[0024] Preferably, the data analysis engine is used to mirror a data packet to be detected to a queue to be detected, and the detection process scans and detects the detected data packet, and temporarily releases or blocks various types of information and service requests according to the instructions of the operation and maintenance management terminal:

[0025] The scanning detection includes: determining the location of the visitor by the IP address of the visitor, detecting the health status of the terminal, and determining whether the terminal has the corresponding service access permission.

[0026] Preferably, the TCP / UDP protocol parsing and authentication engine consists of a protocol identification module, an encryption protocol blasting module, a protocol parsing module and a data processing module;

[0027] The protocol identification module is used to identify information and service requests from the link gateway. For encrypted protocols, they are sent to the encryption protocol blasting module. For non-encrypted protocols, they are directly sent to the protocol parsing module.

[0028] The encryption protocol brute force module is used to determine the login authentication status of the encryption protocol based on a multi-feature model, and comprehensively judge whether the current login is successful based on the session duration, protocol interaction, traffic, and tools; it uses fingerprint-based abnormal login detection to identify non-standard program logins, brute force attack logins, and vulnerability attack login behaviors; after identifying the login status, it enters the slow brute force detection engine based on multi-scale time window serialization to identify hidden slow brute force behaviors;

[0029] The data processing module is used to classify and process the identified information and service requests. In the case of illegal access or attack, the attacker's access traffic is immediately diverted to the virtual computing and storage environment. At the same time, these illegal activities are monitored and detected, and the attack and illegal access data are sent to the data analysis engine.

[0030] The data processing module is used to receive instructions from the data analysis engine and perform exception elimination on information and service requests according to the instructions of the operation and maintenance management terminal.

[0031] Preferably, the proxy gateway includes: an identity authentication module, an access control module and a resource proxy module;

[0032] The resource agent module is responsible for establishing, maintaining, and sending and receiving data through the agent gateway tunnel;

[0033] The identity authentication module is used to adopt hybrid authentication, including username and password, LDAP / AD, and hardware feature code authentication methods, to perform bundled authentication of more than multiple factors;

[0034] The access control module is used to allow access that meets the above authentication methods to access the cloud service platform according to security requirements, and to refuse to provide services in the event of an attack.

[0035] To achieve the above-mentioned objectives, in a second aspect, the present invention provides an attack event perception method, which is applied to the cloud honeypot of the whole-ship computing environment as described in the first aspect, and the method comprises:

[0036] The link gateway defines the access of terminals whose health status does not meet the requirements as an attack event;

[0037] The TCP / UDP protocol parsing and authentication engine parses information and service requests, and authenticates the results. It defines four types of abnormal login behaviors as attack events: non-standard program login, brute force attack login, slow brute force behavior login, and vulnerability attack login.

[0038] The data analysis engine determines the legitimacy of access based on the IP address, device MAC address, and related hardware ID number, and defines illegal access as an attack event;

[0039] The proxy gateway uses hybrid authentication, including username and password, LDAP / AD, and hardware signature authentication. It combines information from the operation and maintenance management terminal to determine the legitimacy of access and defines illegal access as an attack incident.

[0040] Preferably, all accesses with exceptions are allowed to access the full-ship computing environment cloud service platform normally. The exceptions are added through the operation and maintenance management terminal, including events, messages and source terminals.

[0041] To achieve the above objectives, in a third aspect, the present invention provides an attack behavior analysis method, which is applied to the cloud honeypot of the whole-ship computing environment as described in the first aspect, and the method comprises:

[0042] All access traffic directed to honeypot simulation computing service nodes and honeypot simulation nodes is considered an attack behavior;

[0043] By analyzing access traffic, we can obtain the attacker's device fingerprint and social fingerprint information, accurately outline the attacker's portrait, and trace the attack chain and attacker behavior.

[0044] To achieve the above objectives, in a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0045] In general, the above technical solutions conceived by the present invention have the following beneficial effects compared with the prior art:

[0046] (1) The present invention proposes a cloud-based honeypot for the entire ship computing environment, which consists of a link gateway, a TCP / UDP protocol parsing and authentication engine, a data analysis engine, a honeypot simulation computing service node, a honeypot simulation storage node, and a proxy gateway. It is used to capture and analyze unknown new attack methods and enhance the data security protection capability of the entire ship computing environment through deception technology. Among them, the data analysis engine uses bypass detection technology to perform real-time bypass detection on traffic to detect and determine attack behaviors; by constructing a honeypot simulation computing service / storage node, while preventing the real system from being invaded by overflow, penetration, and seizure of permissions, it can also track and record the intruder's intrusion behavior; because the honeypot simulation node is built based on the real application environment, but its access resources are limited to the honeypot simulation node, it can provide a simulation of the real computing service of the cloud platform of the entire ship computing environment. It can achieve deception of the entire chain of the attack process, making the attacker believe that the attack is on the real system, and can obtain "real" services and data that confuse the attacker, delaying the attacker's time and energy, and buying time for accurate capture and maintenance.

[0047] (2) The present invention proposes an attack event perception method that uses terminal health status detection, information and service request parsing and authentication, and hybrid authentication methods to perceive various illegal terminal logins, non-standard program logins, brute force attack logins, slow brute force behavior logins, and vulnerability attack logins to identify attack events. To ensure the normal operation of emergency access equipment and services, operation and maintenance managers can add exception exclusion rules to exclude non-attack events, messages, and source terminals that do not meet the rules.

[0048] (3) The present invention proposes a method for analyzing attack behavior. Based on the technical solution of the present invention, all access traffic directed to the honeypot simulation computing service node and the honeypot simulation node is regarded as attack behavior. Since the ship-wide computing environment is a system composed of a limited number of devices, the physical link is relatively fixed, its IP address is statically allocated, and the device MAC address and related hardware ID number are relatively limited and fixed. By analyzing the access traffic, the attacker's device fingerprint and social fingerprint information are obtained, the attacker's portrait is accurately outlined, and the attack link and attacker behavior are traced and analyzed. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 It is a schematic diagram of a cloud honeypot for a whole-ship computing environment provided by an embodiment of the present invention.

[0050] Figure 2 It is a schematic diagram of the working principle of the link gateway provided by an embodiment of the present invention.

[0051] Figure 3 This is a schematic diagram of a TCP / UDP protocol parsing and authentication engine provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0053] This invention builds a honeypot within the ship's computing environment that combines the advantages of both real and pseudo-system honeypots. This allows attackers to be tricked into attacking it, thereby capturing and analyzing the attack behavior, understanding the tools and methods used, and inferring the attack's intent and motivations. This allows defenders to clearly understand the security threats they face. This approach aims to address the problem of capturing and analyzing unknown new attack methods without real-time internet cloud capabilities, thereby enhancing the security protection capabilities of the actual system.

[0054] Figure 1 This is a schematic diagram of a cloud honeypot for the entire ship computing environment provided by an embodiment of the present invention. Figure 1 As shown in the figure, the cloud honeypot for the whole-ship computing environment consists of a link gateway, a TCP / UDP protocol parsing and authentication engine, a data analysis engine, a honeypot simulation computing service node, a honeypot simulation storage node, and a proxy gateway. Among them, the honeypot simulation computing service node and the honeypot simulation storage node are used to build a virtual computing and storage environment.

[0055] Figure 2 This is a schematic diagram of the working principle of the link gateway provided by the embodiment of the present invention. Figure 2As shown, the link gateway consists of a convergence module, an RDP (Remote Display Protocol) module, a NAP (Network Access Protection) module, and an NP (Network Processor) module. It provides point-to-point RDP connections, rather than allowing remote users to access all internal network resources. The convergence module aggregates data from multiple externally connected physical ports into a single port, sending it to the data analysis engine for bypass detection. The RDP module converts information and service requests. The NAP module enforces health requirements for terminals accessing the ship-wide computing environment based on pre-set rules, including hardware requirements, security update requirements, required computer configuration, and other settings. The link gateway responds to all connection requests, obtaining the requested information and service requests on behalf of the data source. The NP module categorizes information and service requests into three categories based on the processing results of the PDP and NAP modules. Information and service requests from authenticated devices within the ship-wide computing environment are categorized as Class A; information and service requests from authenticated devices outside the system are categorized as Class B; and all other information and service requests are categorized as Class C. The marked information and service request are sent to the TCP / UDP protocol parsing and authentication engine.

[0056] Figure 3 This is a schematic diagram of the TCP / UDP protocol parsing and authentication engine provided by an embodiment of the present invention. Figure 3As shown, the TCP / UDP protocol parsing and authentication engine consists of a protocol identification module, an encryption protocol brute force module, a protocol parsing module, and a data processing module. The engine parses and authenticates information and service requests. Combined with the data analysis engine, based on the detection results of bypass data, the information and service requests that meet the rules are handed over to the cloud service platform through the proxy gateway to provide real services. Its workflow is as follows: the protocol identification module identifies information and service requests from the link gateway. For encrypted protocols, the encryption protocol brute force module processes them and then sends them to the protocol parsing module. For non-encrypted protocols, they directly enter the protocol parsing module. The encryption protocol brute force module uses a multi-feature model to determine the login authentication status of the encryption protocol. Based on multi-dimensional features such as session duration, protocol interaction, traffic, and tools, it comprehensively determines whether the login is successful. It uses fingerprint-based abnormal login detection to identify abnormal login behaviors such as non-standard program logins, brute force attack logins, and vulnerability attack logins. After identifying the login status, it enters the slow brute force detection engine based on multi-scale time window serialization to identify hidden slow brute force behaviors. The data processing module categorizes and processes identified information and service requests. In the event of illegal access or attacks, it immediately redirects the attacker's traffic to the virtual computing and storage environment of the ship's cloud-based honeypot. This misleads the attacker into believing they are sniffing a real business system and allows them to attempt illegal operations such as privilege escalation on simulated services and hosts, thereby slowing the attacker's progress. These illegal activities are also monitored and detected, and attack and illegal access data is fed to the data analysis engine for analysis and forensics. The data processing module receives instructions from the data analysis engine and, based on instructions from the operations and maintenance management terminal, makes exceptions for information and service requests.

[0057] The data analysis engine utilizes bypass detection technology, mirroring packets to be inspected to a queue for inspection. The inspection process then scans and inspects the packets, without impacting the performance of the original packets. The data analysis engine performs real-time bypass detection of application traffic passing through the ship's cloud-based honeypot. It then performs application parsing on the traffic and matches the parsed application data against a signature library to identify server vulnerability attacks within the data stream. It also performs syntactic analysis of the traffic and extracts corresponding semantic features, such as dangerous function calls and class declarations. By utilizing a syntax tree, it improves feature extraction accuracy, freeing it from annotation interference and effectively countering various deformation and bypass attacks. Compared to traditional rule matching, it effectively reduces false positives and false negatives. Given the clear permissions and known behaviors of each business role within the ship's computing environment, unauthorized behavior can be suspected of exploiting unknown vulnerabilities. Attacks identified in application traffic are linked to domain name-process relationships and presented to operations and maintenance personnel for interpretation and disruption of the attack chain. The signature library is expandable and contains the features required for business identification. These include, but are not limited to, vulnerability signature libraries, IPS signature libraries, URL classification signature libraries, APR signature libraries, antivirus signature libraries, WAF signature libraries, IP reputation signature libraries, URL reputation signature libraries, and domain name reputation signature libraries. The data analysis engine primarily determines the location of visitors based on their IP addresses and simultaneously monitors the health of the terminal to determine whether the terminal has access rights to the corresponding services. Based on instructions from the operations and maintenance management terminal, the data analysis engine temporarily allows or blocks three types of information and service requests.

[0058] Because the ship's computing environment is a system composed of a limited number of devices, its IP addresses are statically assigned, and device MAC addresses and related hardware ID numbers are relatively limited and fixed. The data analysis engine, combined with the analysis results of the TCP / UDP protocol parsing and authentication engine, analyzes inbound and outbound network traffic to identify malicious network behavior and locate hacker-controlled servers or terminals within the ship's computing environment. It then provides the TCP / UDP protocol parsing and authentication engine with a domain name-process relationship chain, which is then displayed on the operation and maintenance management terminal.

[0059] The simulation nodes include two types: honeypot simulation computing service nodes and honeypot simulation storage nodes. Both simulation nodes are built based on the cloud computing storage service nodes of the full-ship computing environment, simulating real computing service nodes and storage nodes to the greatest extent possible.

[0060] The honeypot simulation computing service node is built based on a real-world application environment. Simulation services, virtual machines, storage access, and other resources are deployed on the same cloud platform as the entire ship's computing environment. However, access to these resources is limited to the honeypot simulation storage node, providing a realistic computing service that simulates the entire ship's computing environment. To ensure the security of the entire ship's computing environment, its computing resources and algorithms are declassified, providing attackers with a relatively realistic application environment without compromising confidentiality. The honeypot simulation computing service node can be used to obtain a large amount of information and capture a variety of attacker behaviors, enabling the discovery of new attack methods and vulnerability exploits. Because the honeypot simulation computing service node provides an attacker with a relatively realistic application environment, it can mislead them into thinking they are sniffing a real business system and attempt to perform illegal operations such as escalating privileges on simulation services and hosts, thereby slowing the attacker's progress. The honeypot simulation computing service node has no regular tasks or fixed active users on the network. Therefore, aside from running normal daemons or services on the system, it should not have any abnormal processes or generate any network traffic. These assumptions help detect attacks: every interaction with the honeypot simulation computing service node is suspicious and can indicate a possible malicious activity. Therefore, all network traffic in and out of the honeypot simulation computing service node is sent to the data analysis engine and recorded. In addition, the system activities are also recorded for future analysis.

[0061] Honeypot emulation storage nodes are built based on a real-world application environment. Their data structures are deployed on a full-scale cloud computing platform. Data is processed to prevent the leakage of real information. They simulate large-capacity storage space and provide simulated cloud storage services. Honeypot emulation storage nodes respond to attackers' data read and write service requests, providing unrealistic structured data that tricks attackers into believing they are accessing real data, thereby slowing their progress. Emulation storage nodes have no regular tasks on the network, and real authorized users do not request data storage services from them. Therefore, aside from running normal daemons or services on the system, they should not have any abnormal processes or generate any network traffic. These assumptions help detect attacks: every request for data read and write services to an emulation storage node is suspicious and can indicate possible malicious activity. Therefore, all network traffic in and out of the emulation storage node is recorded. Furthermore, system activity is recorded for future analysis.

[0062] The proxy gateway is based on the Apache service and mainly includes an identity authentication module, an access control module, and a resource proxy module. The identity authentication module authenticates each user based on the system data provided by the data analysis engine. The access control module receives the authentication results of the identity authentication module, and passes the information and service requests that meet the rules to the resource proxy module for processing, and directs the information and service requests that do not meet the rules to the network honeypot. The resource proxy module is responsible for the establishment, maintenance, and data transmission and reception of the proxy gateway tunnel. The proxy gateway uses a hybrid authentication protection mechanism to authenticate the messages that have been initially authenticated by the UDP protocol parsing authentication engine, and provides real cloud services to authenticated users. A single authentication method is easy to be stolen. In order to further improve the security of identity authentication, the proxy gateway adopts hybrid authentication, including authentication methods such as username and password, LDAP / AD, and hardware feature code. It can perform bundled authentication of multiple factors. According to security requirements, the above authentication methods must be met at the same time to access the cloud platform. Service is denied in the event of an attack.

[0063] It will be easily understood by those skilled in the art that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A cloud honeypot for the entire ship computing environment, characterized in that: The cloud honeypot includes: a link gateway, a TCP / UDP protocol parsing and authentication engine, a data analysis engine, a honeypot simulation computing service node, a honeypot simulation storage node and a proxy gateway, wherein the honeypot simulation computing service node and the honeypot simulation storage node jointly construct a virtual computing and storage environment; The link gateway is used to provide point-to-point RDP connections for each terminal in the entire ship computing environment; The TCP / UDP protocol parsing and authentication engine is used to parse and authenticate information and service requests from the link gateway. For legitimate access, the information and service requests are passed to the proxy gateway. For illegal access or attacks, the attacker's access traffic is diverted to the virtual computing and storage environment. At the same time, the attacker's illegal activities are monitored and detected, and the attack and illegal access data are sent to the data analysis engine. The data analysis engine is used to detect application traffic passing through the virtual computing and storage environment in real time, record the traffic, perform application analysis, match the analyzed application data with a signature library, and discover server vulnerability attacks in the data stream; suspect unauthorized behavior as an attack exploiting an unknown vulnerability; associate the identified attack behavior in the application traffic with a domain name process relationship chain, and submit it to the operation and maintenance management terminal for interpretation and interruption of the attack chain; The honeypot simulation computing service node is used to respond to the attacker's computing service request, provide the attacker with non-real computing services, and provide the attacker with virtual computing services based on the simulated honeypot resources, including infrastructure, platform and software. The attacker can create virtual machines, build applications and service platforms, and use applications in the honeypot; The honeypot simulates a storage node, which is used to respond to the attacker's data read and write service request and provide the attacker with non-real structured data, so that the attacker mistakenly believes that he has stolen real data and obtained real storage service; The proxy gateway is used to further authenticate the message authenticated by the TCP / UDP protocol parsing authentication engine, and provide the user who finally passes the authentication with real access to the full-ship computing environment cloud service platform; All illegal access requests are directed to the honeypot simulation computing service node and the honeypot simulation storage node and receive responses, making the attacker mistakenly believe that they have obtained real computing services.

2. The cloud honeypot according to claim 1, wherein: The honeypot simulation computing service node is deployed according to the cloud service platform of the whole ship computing environment, providing three service modes; The three services provided by the honeypot simulation computing service node are: Infrastructure as a Service, which virtualizes computing resources for attackers; Platform as a Service, which builds applications and service platforms for attackers and provides an on-demand development environment; Software as a Service, which provides applications for attackers and runs them to access data in the honeypot; The aforementioned computing resources, applications, and service platforms are deployed as a cloud service platform for the ship's computing environment, but their data and algorithms have been declassified, and access to data is limited to the honeypot simulation storage node; The data structure of the honeypot simulation storage node is deployed according to the cloud service platform of the whole ship computing environment. The data uses the real data of the cloud service platform to modify the sensitive data and perform declassification processing. It has a database of the whole ship computing environment to simulate the cloud storage service.

3. The cloud honeypot according to claim 1, wherein: The link gateway is composed of a convergence module, an RDP module, a NAP module and a NP module; The aggregation module is used to aggregate data from multiple externally connected physical ports into one port and send the data to the data analysis engine; The RDP module is used to realize the conversion of information and service requests; The NAP module is used to enforce health requirements for terminals accessing the ship-wide computing environment according to preset rules, including hardware requirements, security update requirements, required computer configurations, and other settings; The NP module is used to classify information and service requests into three categories based on the processing results of the PDP module and the NAP module, and send the marked information and service requests to the TCP / UDP protocol parsing and authentication engine. The classification rules are as follows: information and service requests issued by authentication devices within the ship-wide computing environment system are marked as Class A, information and service requests issued by devices outside the system that meet the authentication conditions are marked as Class B, and other information and service requests are marked as Class C.

4. The cloud honeypot according to claim 1, wherein: The data analysis engine is used to mirror a copy of the data packet to be detected to the queue to be detected. The detection process scans and detects the detected data packet and temporarily releases or blocks various information and service requests according to the instructions of the operation and maintenance management terminal: The scanning detection includes: determining the location of the visitor by the IP address of the visitor, detecting the health status of the terminal, and determining whether the terminal has the corresponding service access permission.

5. The cloud honeypot according to claim 1, wherein: The TCP / UDP protocol parsing and authentication engine consists of a protocol identification module, an encryption protocol blasting module, a protocol parsing module, and a data processing module; The protocol identification module is used to identify information and service requests from the link gateway. For encrypted protocols, they are sent to the encryption protocol blasting module. For non-encrypted protocols, they are directly sent to the protocol parsing module. The encryption protocol brute force module is used to determine the login authentication status of the encryption protocol based on a multi-feature model, and comprehensively judge whether the current login is successful based on the session duration, protocol interaction, traffic, and tools; it uses fingerprint-based abnormal login detection to identify non-standard program logins, brute force attack logins, and vulnerability attack logins; After identifying the login status, it enters the slow blasting detection engine based on multi-scale time window serialization to identify hidden slow blasting behaviors; The protocol parsing module is used to classify and process the identified information and service requests. In the case of illegal access or attack, the attacker's access traffic is immediately diverted to the virtual computing and storage environment. At the same time, these illegal activities are monitored and detected, and the attack and illegal access data are sent to the data analysis engine. The data processing module is used to receive instructions from the data analysis engine and perform exception elimination on information and service requests according to the instructions of the operation and maintenance management terminal.

6. The cloud honeypot according to claim 1, wherein: The proxy gateway includes: an identity authentication module, an access control module and a resource proxy module; The resource agent module is responsible for establishing, maintaining, and sending and receiving data through the agent gateway tunnel; The identity authentication module is used to adopt hybrid authentication, including username and password, LDAP / AD, and hardware feature code authentication, to perform bundled authentication of multiple authentication methods; The access control module is used to allow access that meets the above multiple authentication methods to access the cloud service platform according to security requirements, and to refuse to provide services in the event of an attack.

7. An attack event perception method, applied to the cloud honeypot of the whole ship computing environment according to any one of claims 1 to 6, characterized in that: The method includes: The link gateway defines the access of terminals whose health status does not meet the requirements as an attack event; The TCP / UDP protocol parsing and authentication engine parses information and service requests, and authenticates the results. It defines four types of abnormal login behaviors as attack events: non-standard program login, brute force attack login, slow brute force behavior login, and vulnerability attack login. The data analysis engine determines the legitimacy of access based on the IP address, device MAC address, and related hardware ID number, and defines illegal access as an attack event; The proxy gateway uses hybrid authentication, including username and password, LDAP / AD, and hardware signature authentication. It combines information from the operation and maintenance management terminal to determine the legitimacy of access and defines illegal access as an attack incident.

8. The method according to claim 7, wherein All access with exceptions is allowed to access the ship-wide computing environment cloud service platform normally. The exceptions are added through the operation and maintenance management terminal, including events, messages and source terminals.

9. An attack behavior analysis method, applied to the cloud honeypot of the whole ship computing environment according to any one of claims 1 to 6, characterized in that: The method includes: All access traffic directed to honeypot simulation computing service nodes and honeypot simulation storage nodes is considered an attack behavior; By analyzing access traffic, we can obtain the attacker's device fingerprint and social fingerprint information, accurately outline the attacker's portrait, and trace the attack chain and attacker behavior.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which implements the steps of the method according to any one of claims 7 to 9 when executed by a processor.

Citation Information

Patent Citations

  • Honeypot attacker tracing method based on TCP / UDP transparent proxys

    CN111835758A

  • Defense system for cheating

    CN115150124A