Network system protection method, device, equipment, storage medium and product

By adding honeypot masquerading features to the network system, attackers are misled into believing that the network system is a honeypot system, which solves the problem of incomplete identity information and attack behavior in existing source tracing and countermeasures technologies, and improves the protection effect of the network system.

CN115695008BActive Publication Date: 2026-04-21INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2022-11-02
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing source tracing and countermeasures technologies suffer from incompleteness and inaccuracy in collecting attacker identity information and attack behavior, which affects the protection effectiveness of network systems.

Method used

Adding honeypot masquerading features to the network system misleads attackers into believing it is a honeypot, thereby stopping their attacks. This includes adding features at the front-end, application, and network layers of the network system, and publishing the network system on information gathering websites.

Benefits of technology

By disguising itself as a honeypot system, attackers can be misled, actual attacks can be reduced, and the security and protection of the network system can be improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115695008B_ABST
    Figure CN115695008B_ABST
Patent Text Reader

Abstract

The application relates to a protection method and device of a network system, equipment, a storage medium and a product. It relates to the technical field of information security. The method comprises the following steps: acquiring a honeypot camouflage feature corresponding to a network system to be protected; adding the honeypot camouflage feature to the network system; and publishing the network system to which the honeypot camouflage feature is added; wherein the honeypot camouflage feature is used to make an attack party identify the published network system as a honeypot system and stop attacking the network system. By using the method, the attack party can mistakenly believe that the network system is a honeypot system, thereby giving up the attack, and the purpose of protecting the network system is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a method, apparatus, device, storage medium and product for protecting a network system. Background Technology

[0002] With the development of internet technology, information security has gradually become a concern. For example, various security vulnerabilities are inevitable in the research and development of hardware and software network systems. Network attackers often exploit these vulnerabilities to launch attacks.

[0003] Currently, attribution mitigation technology is emerging to combat cyberattacks. This technology can lure attackers into launching attacks without exposing network assets, thereby collecting their identity information and attack behavior. This provides a guarantee for the rapid and accurate identification of cyberattacks during subsequent network system security protection.

[0004] However, while existing source tracing and countermeasures technologies can collect attacker identity information and attack behavior, thus providing some assistance in the protection of network systems, the attackers frequently use different identity information and attack behaviors to disguise themselves. This leads to problems such as incompleteness and low accuracy in the identity information and attack behavior collected by source tracing and countermeasures technologies, thereby affecting the protection effectiveness of network systems. Summary of the Invention

[0005] Therefore, it is necessary to provide a network system protection method, device, equipment, storage medium, and product that can efficiently protect the network system without collecting the attacker's identity information and attack behavior, in order to address the above-mentioned technical problems.

[0006] Firstly, this application provides a method for protecting a network system. The method includes:

[0007] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0008] Add honeypot camouflage features to the network system;

[0009] Release to network systems that have added honeypot camouflage features;

[0010] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0011] In one embodiment, adding honeypot masquerading features to the network system includes:

[0012] Add honeypot masquerading features to at least one of the front-end, application, and network layers of the network system.

[0013] In one embodiment, honeypot masquerading features are added to the front-end layer of the network system, including:

[0014] Add the front-end file features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system.

[0015] In one embodiment, honeypot camouflage features are added to the application layer of the network system, including:

[0016] Add the spoofing source tracing request from the honeypot spoofing feature to the application layer of the network system; the spoofing source tracing request is used to obtain information about the network attacker.

[0017] In one embodiment, adding honeypot camouflage features to the network layer of the network system includes:

[0018] Deploy the Internet Protocol IP of the honeypot system from the honeypot camouflage feature to the public network IP of the network layer of the network system.

[0019] The honeypot camouflage feature also includes: honeypot bait information; adding the honeypot camouflage feature to the network system also includes:

[0020] In one embodiment, the honeypot decoy information from the honeypot camouflage feature is added to the network system.

[0021] In one embodiment, the deployment of a network system with added honeypot camouflage features includes:

[0022] The network system with added honeypot camouflage features is published on information gathering websites; these websites are used by attackers to collect network information about the networks to be attacked.

[0023] Secondly, this application also provides a network system protection device. The device includes:

[0024] The acquisition module is used to acquire the honeypot spoofing characteristics corresponding to the network system to be protected.

[0025] Add a module to add honeypot camouflage features to the network system;

[0026] The publishing module is used to publish network systems that have been given honeypot camouflage features;

[0027] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0028] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0029] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0030] Add honeypot camouflage features to the network system;

[0031] Release to network systems that have added honeypot camouflage features;

[0032] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0033] Fourthly, this application also provides a computer-readable storage medium. This computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0034] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0035] Add honeypot camouflage features to the network system;

[0036] Release to network systems that have added honeypot camouflage features;

[0037] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0038] Fifthly, this application also provides a computer program product. This computer program product includes a computer program that, when executed by a processor, performs the following steps:

[0039] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0040] Add honeypot camouflage features to the network system;

[0041] Release to network systems that have added honeypot camouflage features;

[0042] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0043] The aforementioned network system protection methods, devices, equipment, storage media, and products acquire the honeypot masquerading characteristics corresponding to the network system to be protected, add these characteristics to the network system, and then publish the network system with the added honeypot masquerading characteristics. These honeypot masquerading characteristics are used to make attackers identify the published network system as a honeypot system, thereby stopping their attacks. This application adds honeypot masquerading characteristics to the network system, thereby disguising the network system as a common honeypot system. After publishing the network system disguised as a honeypot system, it will have a certain deceptive effect on attackers, causing them to mistakenly believe that the network system is a honeypot system. To avoid their own information being leaked, attackers will usually abandon their attacks, thus achieving the purpose of protecting the network system. Attached Figure Description

[0044] Figure 1 This is a diagram illustrating the application environment of a network system protection method in one embodiment.

[0045] Figure 2 This is a flowchart illustrating a network system protection method in one embodiment;

[0046] Figure 3 This is a flowchart illustrating a network system protection method in another embodiment;

[0047] Figure 4 This is a flowchart illustrating a network system protection method in another embodiment;

[0048] Figure 5 This is a flowchart illustrating a network system protection method in another embodiment;

[0049] Figure 6 This is a structural block diagram of a network system protection device in one embodiment;

[0050] Figure 7 Here is a structural block diagram of the added modules in one embodiment;

[0051] Figure 8 A structural block diagram of adding modules in another embodiment;

[0052] Figure 9 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0053] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0054] With the development of internet technology, cybersecurity has gradually become a concern. For example, various security vulnerabilities are inevitable in the research and development of hardware and software network systems. Cyber ​​attackers often exploit these vulnerabilities to launch attacks.

[0055] Currently, attribution-based countermeasures are emerging to combat cyberattacks. For example, honeypot systems containing fake network assets can be created to mislead attackers and lure them into attacking the honeypot system. Because the honeypot system is built on fake network assets, even if it is attacked, it will not threaten the real network assets. Furthermore, after being attacked, the honeypot system can collect the attacker's identity information and attack behavior, and then build an attribution-based countermeasures database based on this information. During the operation of a network system containing real network assets, the attacker's identity information and attack behavior recorded in this database can be used to identify whether the user accessing the network system is an attacker or a regular user. When the user is identified as an attacker, protective measures can be taken, thereby achieving network system security.

[0056] However, while existing attribution mitigation technologies can collect attacker identity information and attack behaviors, thus providing some assistance in network system protection, the information collected may be incomplete or inaccurate due to attackers frequently using different identities and attack behaviors to disguise themselves. This affects the effectiveness of network system protection. To address this issue, this application provides the following solution.

[0057] The network system protection method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, in one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows. Figure 1 As shown. This computer device includes a processor, memory, and network interface connected via a system bus.

[0058] The computer device's processor provides computing and control capabilities. Its memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The computer device's database stores data related to network system protection. The computer device's network interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a network system protection method.

[0059] The network system protection method disclosed in this application includes: obtaining the honeypot camouflage feature corresponding to the network system to be protected; adding the honeypot camouflage feature to the network system; and publishing the network system with the added honeypot camouflage feature; wherein the honeypot camouflage feature is used to enable the attacker to identify the published network system as a honeypot system and stop attacking the network system.

[0060] In one embodiment, such as Figure 2 As shown, a method for protecting a network system is provided, which can be applied to... Figure 1 Taking a computer device as an example, the explanation includes the following steps:

[0061] S201, Obtain the honeypot spoofing characteristics corresponding to the network system to be protected.

[0062] The network system to be protected can be any internet system containing a large number of internet assets. For example, it could be a website developed or used by an enterprise that contains all of that enterprise's internet assets. It should be noted that the types of internet assets that need protection within a network system are numerous; for example, they could include files and information that need protection. Internet assets refer to the information assets mapped onto the internet by the developers or users of the network system, and can include both software and hardware assets. Software assets include: Web (World Wide Web) websites, apps (applications), and WeChat mini-programs, etc. Hardware assets include: devices such as routers, switches, gateways, firewalls, and WAFs (Web Application Firewalls). The information exposed by these information assets within the network system includes, but is not limited to, IP (Internet Protocol) addresses, domain names, ports, middleware, applications, and technical architecture.

[0063] Honeypot camouflage features refer to the characteristics contained in a honeypot system disguised using honeypot technology. Honeypot technology is essentially a technique to deceive attackers. By deploying decoy hosts, network services, or information, attackers are lured to attack them. This allows for the capture of the attacker's identity information and attack behavior, analysis of the attacker's actions, understanding of the tools and methods used, inference of the attacker's intent and motives, a clear understanding of the security threats they face, and the enhancement of the actual system's security capabilities through technical and management measures.

[0064] Optionally, there are many ways to obtain honeypot camouflage features, and this is not limited. One possible approach is to obtain the type characteristics of the network system to be protected, and based on the type of the network system to be protected, obtain multiple honeypot systems of the same type, obtain all honeypot camouflage features of these multiple honeypot systems, and select the feature with the greatest impact on the honeypot system as the honeypot camouflage feature corresponding to the network system to be protected. Another possible approach is to, based on all the honeypot camouflage features of multiple different types of honeypot systems, and combined with the type of the network system to be protected, select the honeypot camouflage features that match the type of the network system to be protected, and select the feature with the greatest impact on the honeypot system as the honeypot camouflage feature corresponding to the network system to be protected. Yet another possible approach is to analyze the attack situation of existing honeypot systems, find the most frequently attacked locations, extract the features of the most frequently attacked locations, and use them as the honeypot camouflage feature corresponding to the network system to be protected.

[0065] Alternatively, another possible way to obtain the honeypot camouflage features corresponding to the honeypot system is to pre-train a feature extraction model that can extract honeypot camouflage features. By inputting the honeypot system into the feature extraction model, the feature extraction model automatically obtains the honeypot camouflage features corresponding to the honeypot system and outputs the honeypot camouflage features corresponding to the honeypot system.

[0066] S202 adds honeypot camouflage features to the network system.

[0067] Optionally, one way to add honeypot camouflage features to a network system is to classify the acquired honeypot camouflage features and, based on the classification results, automatically input different classes of honeypot camouflage features into the corresponding positions in the network system. The classification of honeypot camouflage features can be done automatically by the network system. Another possible approach is to use a pre-trained feature classification model, inputting the honeypot camouflage features and the network system into a feature addition model, which automatically outputs the network system after adding the honeypot camouflage features to the corresponding positions. Yet another possible approach is to statistically analyze historical attacks on the network system, identify vulnerable locations within the network system, and add honeypot camouflage features to these vulnerable locations.

[0068] S203, publishes information about network systems with added honeypot camouflage features.

[0069] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0070] It's important to note that because honeypot systems can collect the attacker's identity information and attack behavior after being attacked, allowing for attribution and countermeasures, attackers who identify a network system as a honeypot often choose to abandon the attack to save costs and avoid being traced and countermeasured.

[0071] Optionally, in this embodiment, the network system with added honeypot camouflage features can be published either to a search engine or to an information gathering website. Publishing the network system with added honeypot camouflage features to a search engine allows visitors to search for and access it. Visitors include both legitimate users and attackers; that is, once the network system with added honeypot camouflage features is published to a search engine, it becomes accessible to all users.

[0072] In addition, the distribution of network systems with honeypot camouflage features includes: publishing network systems with honeypot camouflage features to information gathering websites; information gathering websites are used by attackers to collect network information about the networks to be attacked.

[0073] Network systems with honeypot camouflage features are published on information gathering websites. This allows attackers to obtain false network information during the initial gathering phase of the network information to be attacked, thus misidentifying the network system with honeypot camouflage features as a honeypot system. It's important to note that numerous studies have shown that attackers typically conduct a reconnaissance phase before launching a cyberattack. Attackers generally use information gathering websites to obtain information useful for their attacks. For example, they obtain port information of network systems to determine if they have vulnerabilities, and then decide on their next attack action.

[0074] In this embodiment, network systems with added honeypot camouflage features are published on search engines and information gathering websites. This facilitates access for legitimate users while also increasing the likelihood that attackers, when collecting network information about the target network, will mistakenly identify the network system with added honeypot camouflage features as a honeypot system, thus abandoning their attack. This achieves the goal of protecting the network system.

[0075] The above embodiments obtain the honeypot masquerading characteristics corresponding to the network system to be protected, add the honeypot masquerading characteristics to the network system, and publish the network system with the added honeypot masquerading characteristics. These honeypot masquerading characteristics are used to make attackers identify the published network system as a honeypot system, thereby stopping their attacks. This application adds honeypot masquerading characteristics to the network system, thereby disguising the network system as a common honeypot system. After publishing the network system disguised as a honeypot system, it will have a certain deceptive effect on attackers, causing them to mistakenly believe that the network system is a honeypot system. To avoid their own information being leaked, attackers will usually abandon their attacks, thus achieving the purpose of protecting the network system.

[0076] Figure 3 This paper presents a method for protecting a network system. To enhance the network system's honeypot camouflage characteristics and increase their distribution across the system, thereby increasing the probability of the network system being identified as a honeypot and better protecting it, the method aims to improve network system protection. Based on the above embodiments, the process of adding honeypot camouflage characteristics to the network system can be further optimized. For example... Figure 3 As shown, the specific steps include the following:

[0077] S301, Obtain the honeypot spoofing characteristics corresponding to the network system to be protected.

[0078] S302, add honeypot masquerading features to at least one of the front-end, application, and network layers of a network system.

[0079] In this context, the front-end layer refers to the front-end portion of the network system, including the presentation layer and the structural layer. The presentation layer of the network system can be the visual design; the structural layer can be the front-end code implementation. This embodiment primarily uses the structural layer of the front-end layer as an example.

[0080] The application layer is the highest layer in the OSI (Orders Sources Identification Technology) reference model. It provides services to users and has user interface functions for network transmission. It is mainly used for communication between users and applications or between applications on the network. It is the entry point for user or application interfaces and protocols to access the network.

[0081] The network layer is the third layer in the OSI reference model, situated between the transport layer and the data link layer. It provides transmission functionality for data frames between two adjacent endpoints in the data link layer. This further manages data communication within the network, transmitting data from the source to the destination, and thus providing the most basic end-to-end data transmission service to the transport layer.

[0082] In this embodiment, the obtained honeypot masquerading features can be first classified according to the system layer of the network system to which they belong, into front-end honeypot masquerading features, application-layer honeypot masquerading features, and network-layer honeypot masquerading features, and then added to the corresponding system layer of the network system.

[0083] It should be noted that the specific methods for adding honeypot spoofing features for different front-end, application, and network layers will be described in detail in subsequent embodiments.

[0084] S303 is used to publish information about network systems that have been modified with honeypot camouflage features.

[0085] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0086] In this embodiment, honeypot camouflage features are added to at least one of the front-end, application, and network layers of the network system, which increases the distribution range of honeypot camouflage features in the network system, thereby increasing the probability that the network system is identified as a honeypot system.

[0087] In one optional embodiment, honeypot masquerading features are added to at least one of the front-end layer, application layer, and network layer of the network system. Adding honeypot masquerading features to the front-end layer of the network system includes:

[0088] Add the front-end file features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system.

[0089] In this context, "front-end files" refers to the files used by the network system in its front-end display. Correspondingly, front-end file characteristics can be the commonly used front-end files within the honeypot system. For example, JavaScript (a lightweight file system with function priority) files in mainstream honeypot systems such as open-source and commercial honeypots have relatively obvious characteristics, thus they can be used as front-end file characteristics. Front-end keyword characteristics can be the features of prominent keywords present in the front-end files of the network system. For example, some honeypot systems use certain front-end keywords for front-end processing operations; therefore, commonly used front-end keywords within the honeypot system can be used as front-end keyword characteristics.

[0090] In this embodiment, the honeypot masquerading features can be added to the front-end layer of the network system by obtaining the front-end file features and front-end keyword features based on the obtained honeypot masquerading features, and automatically adding the obtained front-end file features and front-end keyword features to the corresponding positions in the front-end layer of the network system.

[0091] In the above embodiments, the front-end file features and front-end keyword features in the honeypot camouflage features are added to the front-end layer of the network system, respectively, so that the network system is disguised as a honeypot system at the front-end layer level. This provides a guarantee that the subsequent attacker will mistakenly judge the network system as a honeypot system and thus abandon the attack.

[0092] Furthermore, to enhance the honeypot camouflage capabilities of the network system and better protect it, after adding honeypot camouflage features to the front-end layer of the network system as described above, these features can also be added to the application layer. In one embodiment, adding honeypot camouflage features to the application layer of the network system includes:

[0093] Add the spoofing origination request from the honeypot spoofing feature to the application layer of the network system.

[0094] The disguised source tracing request is used to obtain information about the network attacker. This disguised source tracing request can be pre-constructed and designed to obtain the attacker's identity information and attack behavior. It typically resides at the application layer of the network system. For example, a disguised source tracing request could be a JSONP (JavaScript Object Notation with Padding) cross-domain request. This JSONP request is used by the honeypot system to obtain attacker information during source tracing, thereby creating an attacker profile and accurately locating the attacker. The attacker information obtained based on the disguised source tracing request may include, but is not limited to: the attacker's account information, IP information, and biometric features entered by the attacker when using a browser and operating system.

[0095] In this embodiment, the honeypot spoofing features can be added to the application layer of the network system by obtaining the spoofing source tracing requests from the honeypot spoofing features and automatically adding the obtained spoofing source tracing requests to the application layer of the network system.

[0096] In the above embodiments, honeypot masquerading features are added to the application layer of the network system. By adding features such as cross-domain requests or browser fingerprint collection requests similar to those of a honeypot system, the network system is pretended to obtain user account information, user information, and IP information across domains. This disguises the network system as a honeypot system at the application layer level, thereby increasing the possibility that the attacker will mistakenly judge the network system as a honeypot system, and thus achieving the purpose of protecting the network system.

[0097] Furthermore, to increase the likelihood that the network system will be mistakenly identified as a honeypot system by the attacker, thereby better protecting the network system, after adding honeypot camouflage features to the front-end and application layers of the network system as described above, the honeypot camouflage features can also be added to the network layer of the network system. In one embodiment, adding honeypot camouflage features to the network layer of the network system includes:

[0098] Deploy the Internet Protocol IP of the honeypot system from the honeypot camouflage feature to the public network IP of the network layer of the network system.

[0099] In this context, a public network IP address refers to a wide area network (WAN) IP address, a non-reserved address used to connect to the internet via the public network. Computers on a WAN can freely access each other's computers on the internet. It should be noted that the public network IP address at the network layer of a network system contains multiple IP ports.

[0100] In this embodiment, adding honeypot masquerading features to the network layer of the network system can be achieved by deploying multiple honeypot system IPs on other ports of the public network IP to which the network system belongs. Furthermore, the network system and the real honeypot system are deployed separately, and the external mapping relationship between the network system and the real honeypot system is modified so that the honeypot system is mapped to the public network IP of the network system and is exposed to the outside world. In other words, other IP ports of the public network IP to which the network system belongs are deployed as honeypot systems, and the IP ports of the real honeypot system are exposed to the outside world. It should be noted that during the deployment of the real honeypot system, the same public network IP is typically used, but different ports are used to deploy the corresponding honeypot systems; this is a key characteristic of the honeypot system's network layer.

[0101] In the above embodiments, network layer characteristics of a honeypot system are added to the network layer of the network system. Specifically, other IP ports within the public network IP of the network system are deployed as honeypot system IPs, and these honeypot system IP ports are made publicly accessible. Since attackers scan the publicly accessible ports of a network system, when the same public network IP has multiple publicly accessible ports and is identified as a honeypot system, the likelihood of the attacker determining that the network system is a honeypot system is increased, thereby achieving the effect of protecting the network system.

[0102] Figure 4 A method for protecting a network system is illustrated. This method aims to enhance the network system's honeypot camouflage characteristics and increase the distribution range of these characteristics within the network system, thereby increasing the probability of the network system being identified as a honeypot and ultimately achieving better network system protection. The honeypot camouflage characteristics may further include honeypot decoy information. Based on the above embodiments, the process of adding honeypot camouflage characteristics to the network system can be further optimized. For example... Figure 4 As shown, the specific steps include the following:

[0103] S401, obtain the honeypot spoofing characteristics corresponding to the network system to be protected.

[0104] S402, add honeypot masquerading features to at least one of the front-end, application, and network layers of a network system.

[0105] S403 adds the honeypot decoy information from the honeypot camouflage feature to the network system.

[0106] The honeypot decoy information can be file decoys or directory decoys used to lure attackers, and it has the function of tracing and countermeasures. When access to file decoys or directory decoys is detected, the decoys or decoys can automatically conduct monitoring and early warning, and obtain information such as the visitor's account information, user information, and IP information. At the same time, the visitor's information is regarded as malicious visitor information, added to the internal intelligence database, and shared with other security devices such as WAF and firewalls. When a malicious visitor accesses a file decoy or directory decoy, threat intelligence is generated based on their access behavior, and it can be linked with other security devices such as WAF and firewalls to quickly make an overall response and improve the proactive defense capability of the entire network.

[0107] It should be noted that the internal intelligence repository is evidence-based knowledge collected by the network system regarding existing or potential attack threats it faces, including contexts, mechanisms, indicators, inferences, and actionable recommendations. The evidence-based knowledge in the internal intelligence repository can provide corresponding decision-making recommendations and a basis for action when the network system encounters threats.

[0108] In this embodiment, the honeypot decoy information in the honeypot camouflage feature is added to the network system. This can be done by adding file decoys or directory decoys to the front-end page of the network system, such as the admin or .admin directory or file.

[0109] S404 is used to publish information about network systems that have been modified with honeypot camouflage features.

[0110] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0111] In the above embodiments, honeypot masquerading information is added to at least one of the front-end layer, application layer, and network layer of the network system to be protected, and honeypot decoy information is added to the network system. This further increases the probability that the network system is mistakenly identified as a honeypot system by the attacker, thereby achieving the purpose of protecting the network system.

[0112] It should be noted that when users access or use the network system normally, they use normal access paths and will not access such file or directory baits. However, because attackers use directory brute-force attacks to probe the network system in the early stages of an attack in order to obtain as much information as possible, they may obtain and access file or directory baits.

[0113] It should be noted that the honeypot masquerading features added to the network system, including front-end layer features, application layer features, network layer features, and honeypot decoy information, do not affect the normal use and functionality of the network system. Furthermore, adding file and directory decoys will not affect legitimate users accessing the network system; in fact, it will contribute to network system protection.

[0114] In the above embodiments, by acquiring honeypot decoy information from honeypot camouflage features and adding it to the network system, when an accessor visits a file decoy or directory decoy, this access behavior is treated as malicious traffic, and the accessor's account information, user information, and IP information are acquired and added to the internal intelligence database. Simultaneously, this malicious accessor information is shared with other security devices to further protect the network system, achieving the effect of protecting the network system.

[0115] To facilitate understanding by those skilled in the art, the protection method for the aforementioned network system will be described in detail, taking the addition of honeypot camouflage features and honeypot decoy information at the front-end, application, and network layers of the network system as an example. Figure 5 As shown, the method may include:

[0116] S501, obtain the honeypot spoofing characteristics corresponding to the network system to be protected.

[0117] S502 adds the front-end file feature and front-end keyword feature from the honeypot camouflage features to the front-end layer of the network system.

[0118] S503 adds the spoofing source tracing request from the honeypot spoofing feature to the application layer of the network system; the spoofing source tracing request is used to obtain information about the network attacker.

[0119] S504 deploys the Internet Protocol IP of the honeypot system from the honeypot masquerading feature to the public network IP of the network layer of the network system.

[0120] S505 adds the honeypot decoy information from the honeypot camouflage feature to the network system.

[0121] S506 is used to publish network systems with added honeypot camouflage features.

[0122] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0123] It should be noted that when an attacker views the public network IP of a network system's network layer on an information gathering website, because multiple IP ports of the network system to be protected are deployed with honeypot systems, the attacker may mistakenly identify the network system as a honeypot system and abandon the attack when they see that all the network system's open ports are honeypot systems.

[0124] If the attacker still chooses to attack after checking the public IP of the network system, they will check the front-end layer of the network system. The attacker will see that the front-end layer of the network system contains many front-end files or front-end keywords commonly used in honeypot systems. At this time, the attacker will mistakenly judge the network system as a honeypot system and then abandon the attack.

[0125] If the attacker still chooses to attack after examining the front-end layer of the network system, they will then examine the application layer of the network system. The attacker will find that the application layer of the network system contains tracing requests for obtaining the identity information and access behavior of visitors. At this point, the attacker will mistakenly judge the network system as a honeypot system and thus abandon the attack.

[0126] Furthermore, if the attacker still chooses to attack after examining the network layer, application layer, and front-end layer of the network system, they will use directory brute-force attacks to probe the network system and obtain file or directory decoys. Since file or directory decoys are common characteristics of honeypot systems, the attacker will mistakenly identify the network system as a honeypot and abandon the attack. If the attacker still chooses to attack the network system, they will access the file or directory decoys. At this time, the file or directory decoys can automatically perform monitoring and early warning, and obtain the visitor's account information, user information, and IP information. Simultaneously, the visitor's information is considered malicious visitor information, added to the internal intelligence database, and shared with other security devices, improving the network's proactive defense capabilities and achieving the goal of protecting the network system. In other words, the solution proposed in this application can protect the network system from attacks at multiple levels, improving the security of the network system.

[0127] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0128] Based on the same inventive concept, this application also provides a network system protection device for implementing the network system protection method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more network system protection device embodiments provided below can be found in the limitations of the network system protection method described above, and will not be repeated here.

[0129] In one embodiment, such as Figure 6 As shown, a network system protection device 1 is provided, comprising: an acquisition module 10, an addition module 11, and a publishing module 12, wherein,

[0130] The acquisition module 10 is used to acquire the honeypot spoofing characteristics corresponding to the network system to be protected.

[0131] Add module 11 to add honeypot camouflage features to the network system.

[0132] The publishing module 12 is used to publish network systems with added honeypot camouflage features.

[0133] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0134] In one embodiment, the adding module 11 is used to add honeypot masquerading features to at least one of the front-end layer, application layer, and network layer of the network system.

[0135] In one embodiment, such as Figure 7 As shown, the adding module 11 includes at least one of the following: a front-end layer adding unit 111, an application layer adding unit 112, and a network layer adding unit 113, wherein...

[0136] The front-end layer adds unit 111, which is used to add the front-end file feature and front-end keyword feature from the honeypot camouflage feature to the front-end layer of the network system.

[0137] Application layer addition unit 112 is used to add the spoofing source tracing request from the honeypot spoofing characteristics to the application layer of the network system. The spoofing source tracing request is used to obtain information about the network attacker.

[0138] The network layer addition unit 113 is used to deploy the honeypot system Internet Protocol IP in the honeypot masquerading feature to the public network IP of the network layer of the network system.

[0139] In one embodiment, the honeypot camouflage feature further includes: honeypot bait information. For example... Figure 8 As shown, the adding module 11 also includes a decoy information adding unit 114, which is used to add honeypot decoy information from the honeypot camouflage feature to the network system.

[0140] In one embodiment, the publishing module 12 is used to publish the network system with added honeypot camouflage features to an information gathering website; the information gathering website is used by attackers to collect network information about the network to be attacked.

[0141] The various modules in the protection device of the aforementioned network system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0142] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 9 As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When executed by the processor, the computer program implements a network system protection method. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the computer device casing, or an external keyboard, touchpad, or mouse.

[0143] Those skilled in the art will understand that Figure 9 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0144] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0145] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0146] Add honeypot camouflage features to the network system;

[0147] Release to network systems that have added honeypot camouflage features;

[0148] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0149] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0150] Adding honeypot masquerading features to the network system includes:

[0151] Add honeypot masquerading features to at least one of the front-end, application, and network layers of the network system.

[0152] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0153] Add honeypot masquerading features to the front-end layer of the network system, including:

[0154] Add the front-end file features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system.

[0155] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0156] Adding honeypot masquerading features to the application layer of a network system includes:

[0157] Add the spoofing source tracing request from the honeypot spoofing feature to the application layer of the network system; the spoofing source tracing request is used to obtain information about the network attacker.

[0158] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0159] Adding honeypot camouflage features to the network layer of a network system includes:

[0160] Deploy the Internet Protocol IP of the honeypot system from the honeypot camouflage feature to the public network IP of the network layer of the network system.

[0161] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0162] Honeypot camouflage features also include: honeypot bait information; adding honeypot camouflage features to a network system also includes:

[0163] Add the honeypot decoy information from the honeypot camouflage feature to the network system.

[0164] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0165] Deploying services to network systems that have been given honeypot camouflage features, including:

[0166] The network system with added honeypot camouflage features is published on information gathering websites; these websites are used by attackers to collect network information about the networks to be attacked.

[0167] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0168] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0169] Add honeypot camouflage features to the network system;

[0170] Release to network systems that have added honeypot camouflage features;

[0171] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0172] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0173] Adding honeypot masquerading features to the network system includes:

[0174] Honeypot masquerading features are added to at least one layer of the network system, including the front-end layer, application layer, and network layer. In one embodiment, the computer program, when executed by a processor, further implements the following steps:

[0175] Add honeypot masquerading features to the front-end layer of the network system, including:

[0176] Add the front-end file features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system.

[0177] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0178] Adding honeypot masquerading features to the application layer of a network system includes:

[0179] Add the spoofing source tracing request from the honeypot spoofing feature to the application layer of the network system; the spoofing source tracing request is used to obtain information about the network attacker.

[0180] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0181] Adding honeypot camouflage features to the network layer of a network system includes:

[0182] Deploy the Internet Protocol IP of the honeypot system from the honeypot camouflage feature to the public network IP of the network layer of the network system.

[0183] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0184] Honeypot camouflage features also include: honeypot bait information; adding honeypot camouflage features to a network system also includes:

[0185] Add the honeypot decoy information from the honeypot camouflage feature to the network system.

[0186] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0187] Deploying services to network systems that have been given honeypot camouflage features, including:

[0188] The network system with added honeypot camouflage features is published on information gathering websites; these websites are used by attackers to collect network information about the networks to be attacked.

[0189] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:

[0190] Obtain the honeypot spoofing characteristics corresponding to the network system to be protected;

[0191] Add honeypot camouflage features to the network system;

[0192] Release to network systems that have added honeypot camouflage features;

[0193] Among them, honeypot camouflage features are used to make attackers identify the published network system as a honeypot system and stop attacking the network system.

[0194] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0195] Adding honeypot masquerading features to the network system includes:

[0196] Honeypot masquerading features are added to at least one layer of the network system, including the front-end layer, application layer, and network layer. In one embodiment, the computer program, when executed by a processor, further implements the following steps:

[0197] Add honeypot masquerading features to the front-end layer of the network system, including:

[0198] Add the front-end file features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system.

[0199] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0200] Adding honeypot masquerading features to the application layer of a network system includes:

[0201] Add the spoofing source tracing request from the honeypot spoofing feature to the application layer of the network system; the spoofing source tracing request is used to obtain information about the network attacker.

[0202] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0203] Adding honeypot camouflage features to the network layer of a network system includes:

[0204] Deploy the Internet Protocol IP of the honeypot system from the honeypot camouflage feature to the public network IP of the network layer of the network system.

[0205] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0206] Honeypot camouflage features also include: honeypot bait information; adding honeypot camouflage features to a network system also includes:

[0207] Add the honeypot decoy information from the honeypot camouflage feature to the network system.

[0208] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0209] Deploying services to network systems that have been given honeypot camouflage features, including:

[0210] The network system with added honeypot camouflage features is published on information gathering websites; these websites are used by attackers to collect network information about the networks to be attacked.

[0211] It should be noted that the network system information (including but not limited to honeypot bait information) and user information (including but not limited to the attacker's account information, IP information and user information, etc.) involved in this application are all information authorized by the user or fully authorized by all parties.

[0212] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0213] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0214] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A protection method of a network system, characterized by, The method includes: Obtain the honeypot spoofing characteristics corresponding to the network system to be protected; Add the front-end text features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system; The spoofing origination request in the honeypot spoofing feature is added to the application layer of the network system; wherein, the spoofing origination request is used to obtain information about the network attacker; Deploy the Internet Protocol IP of the honeypot system in the honeypot camouflage feature to the public network IP of the network layer of the network system; The honeypot decoy information in the honeypot camouflage features is added to the front-end page of the network system; the honeypot decoy information is a file decoy or a directory decoy, and the honeypot decoy information is used to automatically carry out monitoring and early warning when the behavior of accessing the file decoy or accessing the directory decoy is detected, obtain the visitor's account information, user information and IP information, and add the visitor's account information, user information and IP information to the internal intelligence database; Release the information to network systems that have been modified with the honeypot camouflage features; The honeypot camouflage feature is used to make the attacker identify the published network system as a honeypot system and stop attacking the network system. The acquisition of honeypot spoofing features corresponding to the network system to be protected includes: Obtain the type of the network system to be protected; Based on the type of the network system to be protected, obtain multiple honeypot systems of the same type as the network system to be protected; Obtain all honeypot camouflage features of multiple honeypot systems, and select the feature with the greatest impact on the honeypot system from all features as the honeypot camouflage feature corresponding to the network system to be protected; or, Obtain all honeypot camouflage features from multiple different types of honeypot systems; Based on the type of the network system to be protected, select honeypot camouflage features that match the type of the network system to be protected, and take the feature that has the greatest impact on the honeypot system as the honeypot camouflage feature corresponding to the network system to be protected.

2. The method of claims 1- wherein, The process of publishing to a network system with the added honeypot camouflage features includes: The network system with the added honeypot camouflage features is published on an information gathering website; the information gathering website is used by attackers to collect network information about the network to be attacked.

3. A protection device of a network system, characterized by comprising: The device includes: The acquisition module is used to acquire the honeypot spoofing characteristics corresponding to the network system to be protected. An add module is used to add the front-end text features and front-end keyword features from the honeypot camouflage features to the front-end layer of the network system; add the camouflage source tracing request from the honeypot camouflage features to the application layer of the network system; wherein, the camouflage source tracing request is used to obtain network attacker information; deploy the honeypot system Internet Protocol IP from the honeypot camouflage features to the public network IP of the network layer of the network system; add the honeypot decoy information from the honeypot camouflage features to the front-end page of the network system; the honeypot decoy information is a file decoy or a directory decoy, and the honeypot decoy information is used to automatically conduct monitoring and early warning when the behavior of accessing the file decoy or accessing the directory decoy is detected, obtain the visitor's account information, user information, and IP information, and add the visitor's account information, user information, and IP information to the internal intelligence database; The publishing module is used to publish network systems with the honeypot camouflage features added. The acquisition module is specifically used to acquire the type of the network system to be protected; acquire multiple honeypot systems of the same type as the network system to be protected based on the type of the network system to be protected; acquire all honeypot camouflage features of the multiple honeypot systems, and take the feature with the greatest impact on the honeypot system as the honeypot camouflage feature corresponding to the network system to be protected; or, acquire all honeypot camouflage features of multiple honeypot systems of different types; select honeypot camouflage features that match the type of the network system to be protected based on the type of the network system to be protected, and take the feature with the greatest impact on the honeypot system as the honeypot camouflage feature corresponding to the network system to be protected.

4. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method of claim 1 or 2.

5. A computer-readable storage medium having stored thereon a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 1 or 2.

6. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 1 or 2.