Information setting method, device and computer-readable storage medium

By setting target induction information in the application to be analyzed, the problem that honeypot products are easily detected and require independent physical hosts is solved, efficient attack perception and confusion are achieved, and the false alarm rate is reduced.

CN115701025BActive Publication Date: 2025-09-05CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110824123.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-21
Publication Date
2025-09-05
Estimated Expiration
2041-07-21

AI Technical Summary

Technical Problem

Honeypot products are easily detected by hackers and require independent physical hosts, resulting in low deployment density and affecting implementation effectiveness.

Method used

By obtaining sample attack events, the information type and setting location of the inducement information are determined, and the target inducement information is directly set in the application to be analyzed without the need for a real independent physical host.

Benefits of technology

It enhances the attack perception effect, is highly confusing, is not easily detected by hackers, and reduces the false alarm rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115701025B_ABST
    Figure CN115701025B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses an information setting method, which includes: obtaining sample attack events for target type applications; based on the sample attack events, determining the information type of the inducement information of applications with different functions; wherein the inducement information is information used to induce attack events; based on the information type, determining the setting location of the inducement information in the target type application; based on the information type, the setting location and information of the application to be analyzed, setting the target inducement information in the application to be analyzed; wherein the type of the application to be analyzed is the target type. The embodiment of the present application also discloses an information setting device and a computer-readable storage medium. The embodiment of the present application can enhance the attack perception effect and is highly confusing, not easily detected by hackers, and also ensures the implementation effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to information setting technology in the field of communication technology, and in particular to an information setting method, device and computer-readable storage medium. Background Art

[0002] With the rapid development of internet technology, network security issues are receiving increasing attention. Intrusion detection technology, as a key component of network security, is a crucial element in network security defense systems. However, faced with the continuous emergence of new attack methods and tools, traditional, passive network defense technologies are increasingly unable to meet network security requirements. Honeypots, as an emerging active defense technology, are gaining increasing attention among network security professionals. Honeypots record and analyze hacker attacks during attacks to gather information and provide early warnings of new attacks. Honeypots can also delay attacks and redirect targets. However, currently used honeypot products are easily detected by hackers and require a separate physical host, resulting in low deployment density, which in turn limits their effectiveness and reduces their deceptive value. Summary of the Invention

[0003] In view of this, the embodiments of the present application hope to provide an information setting method, device and computer-readable storage medium, which solves the problem that honeypot products in relative technology are easily detected by hackers and require independent physical hosts, enhances the attack perception effect and is highly confusing, not easily detected by hackers, and also ensures the implementation effect and reduces the false alarm rate.

[0004] To achieve the above objectives, the technical solution of this application is implemented as follows:

[0005] In a first aspect, a method for setting information is provided, the method comprising:

[0006] Obtain sample attack events against target type applications;

[0007] Based on the sample attack event, determining the information type of the inducement information of applications with different functions; wherein the inducement information is information used to induce the generation of the attack event;

[0008] Based on the information type, determining a setting location of the induction information in the target type application;

[0009] Based on the information type, the setting location, and information of the application to be analyzed, target guidance information is set in the application to be analyzed; wherein the type of the application to be analyzed is the target type.

[0010] Optionally, determining the information type of the inducement information of applications with different functions based on the sample attack event includes:

[0011] Determining initial common attack behaviors based on the sample attack events; wherein the initial common attack behaviors represent common attack behaviors occurring in the initial stage of the sample attack events;

[0012] Based on the initial common attack behavior, the information type of the inducement information of the applications with different functions is determined.

[0013] Optionally, determining the initial common attack behavior based on the sample attack events includes:

[0014] Analyze the sample attack event to determine the attack behavior to be processed corresponding to the sample attack event;

[0015] The attack behaviors to be processed are processed to obtain the initial common attack behaviors.

[0016] Optionally, the processing the attack behavior to be processed to obtain the initial common attack behavior includes:

[0017] Analyzing the attack behaviors to be processed to determine initial common attack behaviors to be processed;

[0018] The initial common attack behaviors to be processed are classified to obtain the initial common attack behaviors.

[0019] Optionally, determining the information type of the inducement information of the applications with different functions based on the initial common attack behavior includes:

[0020] Analyzing the initial common attack behavior to determine the target application corresponding to the initial common attack behavior and the attack content corresponding to the initial common attack behavior; wherein the type of the target application is the target type;

[0021] Based on the attack content and the initial common attack behavior, an information type of the inducement information corresponding to the target application of each function is determined.

[0022] Optionally, the setting target guidance information in the application to be analyzed based on the information type, the setting location, and the information of the application to be analyzed includes:

[0023] Determining the target guidance information based on the information type and the information of the application to be analyzed;

[0024] The target guidance information is set at a target location of the application to be analyzed based on the setting location and the information of the application to be analyzed.

[0025] Optionally, determining the target guidance information based on the information type and the information of the application to be analyzed includes:

[0026] Determining the data information and functions of the application to be analyzed;

[0027] The target guidance information is determined based on the data information of the application to be analyzed, the function, and the information type.

[0028] Optionally, the setting the target guidance information at the target location of the application to be analyzed based on the setting location and the information of the application to be analyzed includes:

[0029] determining the target location based on the setting location, the function, and the information type;

[0030] The target guidance information is set at the target location of the application to be analyzed.

[0031] Optionally, the method further includes:

[0032] When a target attack event is detected, an intrusion alarm is issued and attribute information of the target attack terminal corresponding to the target attack event is obtained;

[0033] The attribute information is stored in a threat intelligence library, and the target attack terminal is identified.

[0034] Optionally, the method further includes:

[0035] A defense process is performed on the target attack event to block the target attack event.

[0036] In a second aspect, an information setting device is provided, the device comprising: a processor, a memory, and a communication bus;

[0037] The communication bus is used to realize the communication connection between the processor and the memory;

[0038] The processor is used to execute the information setting program in the memory to implement the following steps:

[0039] Obtain sample attack events against target type applications;

[0040] Based on the sample attack event, determining the information type of the inducement information of applications with different functions; wherein the inducement information is information used to induce the generation of the attack event;

[0041] Based on the information type, determining a setting location of the induction information in the target type application;

[0042] Based on the information type, the setting location, and information of the application to be analyzed, target guidance information is set in the application to be analyzed; wherein the type of the application to be analyzed is the target type.

[0043] In a third aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the information setting method described above.

[0044] The information setting method, device and computer-readable storage medium provided in the embodiments of the present application obtain sample attack events for target type applications, determine the information type of the inducement information of applications with different functions based on the sample attack events, determine the setting location of the inducement information in the target type application based on the information type, and set the target inducement information in the application to be analyzed based on the information type, setting location and information of the application to be analyzed. In this way, the target inducement information can be set directly in the application to be analyzed without providing a real independent physical host, and the setting location is different for different applications to be analyzed, which solves the problem in the relative technology that the honeypot product has a fixed location, is easily detected by hackers and requires an independent physical host, enhances the attack perception effect and is highly confusing, not easily detected by hackers, and also ensures the implementation effect and reduces the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 A flowchart of an information setting method provided in an embodiment of the present application;

[0046] Figure 2 A flowchart of another information setting method provided in an embodiment of the present application;

[0047] Figure 3 A schematic diagram of the system architecture used by an information setting method provided in an embodiment of the present application;

[0048] Figure 4 A flowchart of another information setting method provided in an embodiment of the present application;

[0049] Figure 5 A schematic diagram of an application of an information setting method provided in an embodiment of the present application;

[0050] Figure 6 A schematic diagram of the structure of an information setting device provided in an embodiment of the present application;

[0051] Figure 7 A schematic diagram of the structure of an information setting device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0052] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application.

[0053] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.

[0054] The embodiment of the present application provides an information setting method, which can be applied to an information setting device. Figure 1 As shown, the method may include the following steps:

[0055] Step 101: Obtain sample attack events targeting target type applications.

[0056] In the embodiment of the present application, the target type application may refer to an application that can use the Internet. In a feasible implementation, the target type application may include a World Wide Web (WEB) type application.

[0057] Among them, the sample attack event may refer to an actual hacker attack event against a WEB application that is used as a sample for subsequent processing; it should be noted that the sample attack event may be a publicly disclosed hacker intrusion event against a WEB application collected from the Internet; in a feasible implementation method, the sample attack event may be the 89,937 intrusion events collected against WEB applications.

[0058] Step 102: Based on the sample attack events, determine the information type of the inducement information of applications with different functions.

[0059] The inducement information is information used to induce an attack event.

[0060] In the embodiments of the present application, applications with different functions may refer to applications used to implement different functions or applications with different functions; information type may refer to the form in which the inducement information exists, or may refer to the type of delivery of the inducement information. Specifically, the information type of the inducement information of applications with different functions may be determined by first determining the initial common attack behavior based on sample attack events, and then determining it based on the initial common attack behavior. In a feasible implementation, the information type mainly includes three types, which may be information, code, and file, etc.

[0061] Step 103: Based on the information type, determine the location of the guidance information in the target type application.

[0062] The "location" may refer to the placement of the inducement information within a web application. It should be noted that the placement may be determined based on the type of inducement information; that is, different types of inducement information may have different placements within a web application. In one feasible implementation, sample attack events may be analyzed to determine the placement of the inducement information based on the location and type of inducement information, combined with historical usage information.

[0063] Step 104: Set target guidance information in the application to be analyzed based on the information type, setting location, and information of the application to be analyzed.

[0064] The type of application to be analyzed is the target type.

[0065] In an embodiment of the present application, the target induction information that needs to be set in the application to be analyzed can be determined based on the information type, setting location and information of the application to be analyzed, and then the target location is determined in the application to be analyzed, so as to set the target induction information at the target location of the application to be analyzed; it should be noted that the application to be analyzed may refer to a WEB application that needs to be delivered with induction information.

[0066] The information setting method provided in the embodiments of the present application obtains sample attack events for target type applications, determines the information type of the inducement information of applications with different functions based on the sample attack events, determines the setting location of the inducement information in the target type application based on the information type, and sets the target inducement information in the application to be analyzed based on the information type, setting location and information of the application to be analyzed. In this way, the target inducement information can be set directly in the application to be analyzed without providing a real independent physical host, and the setting location is different for different applications to be analyzed, which solves the problem in the relative technology that the honeypot product has a fixed location, is easily detected by hackers and requires an independent physical host, enhances the attack perception effect and is highly confusing, not easily detected by hackers, and also ensures the implementation effect and reduces the false alarm rate.

[0067] Based on the above embodiments, the embodiments of the present application provide an information setting method, referring to Figure 2 As shown, the method may include the following steps:

[0068] Step 201: The information setting device obtains sample attack events for target type applications.

[0069] Step 202: The information setting device determines initial common attack behaviors based on sample attack events.

[0070] Among them, the initial common aggressive behavior represents the common aggressive behavior that occurs in the initial stage of the sample attack event.

[0071] In the embodiments of the present application, the information setting device may refer to a client with data processing and storage capabilities. The initial common attack behavior may refer to the common attack behavior during the hacker reconnaissance phase. The initial common attack behavior may be obtained through statistical analysis of collected sample attack events, and the common attack behavior refers to the attack behavior that occurs in all sample attack events. In other words, the initial phase may refer to the reconnaissance phase.

[0072] In a feasible implementation, the initial common attack behaviors determined can include three categories, and each category can include seven subcategories; as shown in Table 1 below, the initial common attack behaviors can include twenty-one subcategories; among them, the initial common attack behaviors of the network-based asset investigation means category can include: investigation behaviors based on IP assets, investigation behaviors based on domain name assets, investigation behaviors based on autonomous domain numbers, investigation behaviors based on Shadon products, investigation behaviors based on search engines, investigation behaviors based on HTTPS certificates, and investigation behaviors based on DNS logs; the initial common attack behaviors of the key system-based asset investigation means category can include: investigation behaviors based on IP assets, investigation behaviors based on domain name assets, investigation behaviors based on autonomous domain numbers, investigation behaviors based on Shadon products, investigation behaviors based on search engines, investigation behaviors based on HTTPS certificates, and investigation behaviors based on DNS logs; Attack behaviors may include: reconnaissance behaviors based on mobile APPs, reconnaissance behaviors based on official accounts / mini-programs, reconnaissance behaviors based on public email systems, reconnaissance behaviors based on public VPN systems, reconnaissance behaviors based on public bastion hosts, reconnaissance behaviors based on public OA systems, and reconnaissance behaviors based on public financial systems; the initial common attack behaviors based on the major category of vulnerability detection methods based on key information may include: reconnaissance behaviors based on public network disks, reconnaissance behaviors based on public source codes, reconnaissance behaviors based on backup source codes, reconnaissance behaviors based on background management pages, reconnaissance behaviors based on comment content, reconnaissance behaviors based on test systems, and reconnaissance behaviors based on sensitive information leaks.

[0073] Network-based asset detection methods Asset detection methods based on key systems Vulnerability detection methods based on key information IP asset-based investigation Mobile APP-based investigation Investigation based on public network disk Domain name asset-based investigation Investigation based on official accounts / mini programs Open source investigation Asset investigation based on autonomous domain number Investigation based on public network mail system Backup source code-based investigation Asset investigation based on Shadon products Investigation based on public network VPN system Investigation based on the background management page Search engine-based asset detection Reconnaissance based on public network bastion host Annotation-based detection Asset detection based on HTTPS certificates Investigation based on public network OA system Test system-based detection Asset detection based on DNS logs Investigation based on public network financial system Detection based on sensitive information leakage

[0074] Table 1

[0075] Step 203: The information setting device determines the information type of the inducement information of applications with different functions based on the initial common attack behavior.

[0076] In an embodiment of the present application, the information setting device can first determine the attack content attacked by the initial common attack behavior based on the initial common attack behavior, and then determine the information type of the inducement information of applications with different functions based on the attack content and the initial common attack behavior; of course, the information type of the inducement information of applications with different functions can be one, two or three types determined from the three type characteristics of information type, code type and file type.

[0077] Step 204: The information setting device determines the setting location of the inducement information in the target type application based on the information type.

[0078] The type of the target application is the target type.

[0079] It should be noted that, in the embodiment of the present application, the location determined in the target type application based on the information type of the inducement information can be a location that is not easily detected by hackers as the set inducement information and can arouse the interest of hackers; as shown in Table 2 below, for different information types of inducement information, the corresponding setting location is different.

[0080]

[0081] Table 2

[0082] Step 205: The information setting device determines target guidance information based on the information type and the information of the application to be analyzed.

[0083] Targeted information refers to information specific to the application being analyzed. This information is specific to each application being analyzed. This information is generated using a random algorithm, ensuring that the resulting target information is unique. This ensures that the content and IP addresses of the honey resources introduced are distinct, ensuring similar services are maintained and significantly reducing the likelihood of being identified by hackers.

[0084] Step 206: The information setting device sets target guidance information at the target location of the application to be analyzed based on the setting location and the information of the application to be analyzed.

[0085] Among them, the information setting device can determine the target location in the application to be analyzed based on the setting location and the information of the application to be analyzed, and then set the determined target induction information at the corresponding target location; it should be noted that the application to be analyzed can include the client's own WEB-type application on the existing network, and can also include third-party WEB-type applications; wherein, third-party WEB-type applications can include mainstream third-party sites on the Internet, such as code hosting sites, network disk sites, blogs, Weibo and other sites. That is to say, the information setting method in the embodiment of the present application can either put the target induction information into the client's own WEB-type application or put the target induction information into a third-party web-type application; and the put target induction information can be a combination of one or more categories of information, code and files, so that hackers can discover and use the above-mentioned target induction information in the process of invading the system, and the attack traffic will be accurately introduced to the cloud, such as Figure 3As shown, a cloud-end architecture can be implemented; that is, information-based, code-based, and file-based target induction information can be set up in the client's own web applications and third-party services. This allows attack traffic to be directed to the cloud in the event of a hacker intrusion. The file resources and server resources in the cloud's honey resource cluster then transmit the corresponding information to the linkage server and analysis and presentation server. Together, the linkage server and analysis and presentation server analyze and process the hacker's attack event. Furthermore, deploying target induction information at numerous nodes across the network to divert traffic can achieve comprehensive intrusion awareness and early warning capabilities.

[0086] It should be noted that, for the description of the same steps and contents in this embodiment as those in other embodiments, reference can be made to the description in other embodiments and will not be repeated here.

[0087] The information setting method provided in the embodiments of the present application can set target induction information directly in the application to be analyzed without providing a real independent physical host, and the setting location of different applications to be analyzed is different, which solves the problem that the honeypot products in the relative technology are fixed in location, easy to be detected by hackers and require an independent physical host, enhances the attack perception effect and is highly confusing, not easy to be detected by hackers, and also ensures the implementation effect and reduces the false alarm rate.

[0088] Based on the above embodiments, the embodiments of the present application provide a method for determining information, referring to Figure 4 As shown, the method may include the following steps:

[0089] Step 301: The information setting device obtains sample attack events targeting target type applications.

[0090] Step 302: The information setting device analyzes the sample attack event and determines the attack behavior to be processed corresponding to the sample attack event.

[0091] The attack behaviors to be processed may refer to all attack behaviors included in the sample attack event, that is, they may be considered as attack behaviors existing in the entire attack process of the sample attack event.

[0092] Step 303: The information setting device processes the attack behavior to be processed to obtain initial common attack behavior.

[0093] In the embodiment of the present application, step 303 can be implemented by the following steps:

[0094] Step 303a: The information setting device analyzes the attack behaviors to be processed and determines the initial common attack behaviors to be processed.

[0095] The initial common attack behaviors to be processed refer to those common to every sample attack event, among the initial attack behaviors included in the sample attack events. Furthermore, these initial common attack behaviors to be processed can include those common to every sample attack event generated by hackers during the reconnaissance phase. It should be noted that the initial common attack behaviors to be processed at this stage are not categorized.

[0096] Step 303b: The information setting device classifies the initial common attack behaviors to be processed to obtain the initial common attack behaviors.

[0097] The initial common offensive behaviors may be obtained by performing statistical analysis on the initial common offensive behaviors to be processed and classifying the initial common offensive behaviors to be processed according to the statistical analysis results.

[0098] Step 304: The information setting device analyzes the initial common attack behavior to determine the target application corresponding to the initial common attack behavior and the attack content corresponding to the initial common attack behavior.

[0099] The type of the target application is the target type.

[0100] It should be noted that the target application refers to the web application corresponding to the initial common attack behavior event; the attack content may refer to the specific content attacked by the initial common attack behavior, that is, the content that the hacker wants to steal.

[0101] Step 305: The information setting device determines the information type of the inducement information corresponding to the target application of each function based on the attack content and the initial common attack behavior.

[0102] The information type of the inducement information may be determined by the information setting device after analyzing the attack content and the initial common attack behavior.

[0103] In a feasible implementation of the embodiment of the present application, as shown in Table 3 below, for proprietary WEB applications and third-party WEB applications with different functions, the corresponding information types of the inducement information are:

[0104] Business Model Information Type Own website Information / Documents Own APP Information / Code / Document Own official account / mini program Information / Code / Document Own API server Information / Documents Own mail system Information / Files / New Temptation Account Own VPN system Information / Documents Proprietary OA system Information / Documents Own financial system Information / Documents Own DNS system New records pointing to honey resource groups Third-party code hosting site Information / Documents Third-party network disk site Information / Documents Third-party social sites Information / Documents

[0105] Table 3

[0106] Step 306: The information setting device determines the data information and functions of the application to be analyzed.

[0107] The data information refers to the data included in the application to be analyzed; the function of the application to be analyzed refers to the function that can be realized by the application to be analyzed or the function that the application to be analyzed has.

[0108] Step 307: The information setting device determines target guidance information based on the data information, function and information type of the application to be analyzed.

[0109] In an embodiment of the present application, the information setting device can analyze the data information, function and information type of the analysis application, construct the induction information belonging to the corresponding information type to obtain the target induction information.

[0110] Step 308: The information setting device determines the target location based on the setting location, function, and information type.

[0111] Step 309: The information setting device sets target guidance information at the target location of the application to be analyzed.

[0112] The method for setting up deceptive information provided in the embodiments of the present application can achieve multi-type, multi-content, and full coverage by directly embedding deceptive information into existing web-based application business systems, greatly optimizing client coverage and appeal. Furthermore, without the need for additional specialized physical equipment, more deceptive information can be deployed at a lower cost, increasing the deployment density of deceptive information and thus ensuring the effectiveness of deceptive information against hackers. Furthermore, the deceptive information is not manually set, and its high degree of simulation reduces the probability of being identified by hackers, resulting in a low false alarm rate. Furthermore, it is integrated with the real business system, not a simulated environment, highly deceptive, and difficult for hackers to detect.

[0113] Based on the foregoing embodiment, in other embodiments of the present application, the information setting method may further include the following steps:

[0114] Step 310: When a target attack event is detected, the information setting device issues an intrusion alarm message and obtains attribute information of the target attack terminal corresponding to the target attack event.

[0115] Among them, after determining that a hacker intrusion has generated an attack event, the information setting device will immediately issue an intrusion alarm message to provide an attack warning; at the same time, it will obtain the attribute information of the target attack terminal used by the hacker, and send the attribute information of the target supply price terminal to the analysis and presentation server for analysis; in a feasible implementation method, the attribute information may include the Internet Protocol (IP) address, Media Access Control (MAC) address, the identifier of the target attack terminal, and other information that can uniquely identify the target attack terminal. Figure 5 As shown, after a hacker attacks a WEB site, application (APP) server, mini-program or public account, as well as a third-party blog, network disk and other services through the Internet, the honey resource cluster will be activated, and the analysis and presentation server will analyze the hacker's attack behavior.

[0116] Step 311: The information setting device stores the attribute information in the threat intelligence library and identifies the target attack terminal.

[0117] In an embodiment of the present application, the information setting includes the attribute information of the hacker's target attack terminal into the threat intelligence library and shares it across the entire network. At the same time, the target attack terminal is identified as powerful data for later tracing and locating the hacker's source; at the same time, this information can be given to the analysis and presentation server to analyze the attack event.

[0118] Based on the foregoing embodiment, in other embodiments of the present application, the information setting method may further include the following steps:

[0119] Step 312: The information setting device performs defense processing on the target attack event to block the target attack event.

[0120] Among them, such as Figure 5 As shown, information processing equipment can interact with the linkage server to perform security emergency response and analysis and judgment through the linkage server, such as transmitting the IP address of the target attack terminal of the invading hacker to the one-click blocking platform or the security operation platform, completing the collaborative analysis and linkage of the entire network, completing the security incident management in a process-based manner, and improving the efficiency of collaborative communication.

[0121] It should be noted that, for the description of the same steps and contents in this embodiment as those in other embodiments, reference can be made to the description in other embodiments and will not be repeated here.

[0122] The information setting method provided in the embodiments of the present application can set target induction information directly in the application to be analyzed without providing a real independent physical host, and the setting location of different applications to be analyzed is different, which solves the problem that the honeypot products in the relative technology are fixed in location, easy to be detected by hackers and require an independent physical host, enhances the attack perception effect and is highly confusing, not easy to be detected by hackers, and also ensures the implementation effect and reduces the false alarm rate.

[0123] The embodiment of the present application provides an information setting device, which can be applied to Figures 1-2 In the information setting method provided in the embodiment corresponding to 4, refer to Figure 6 As shown, the device 4 may include: an acquisition unit 41, a first determination unit 42, a second determination unit 43, and a setting unit 44, wherein:

[0124] An acquisition unit 41 is configured to acquire sample attack events targeting target type applications;

[0125] A first determining unit 42 is configured to determine the type of inducement information of applications with different functions based on the sample attack event;

[0126] Among them, the inducement information is information used to induce an attack event;

[0127] A second determining unit 43 is configured to determine a setting position of the inductive information in the target type application based on the information type;

[0128] A setting unit 44 is configured to set target guidance information in the application to be analyzed based on the information type, the setting location, and the information of the application to be analyzed;

[0129] The type of application to be analyzed is the target class.

[0130] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:

[0131] Based on sample attack events, determine the initial common attack behaviors;

[0132] Among them, the initial common aggressive behavior represents the common aggressive behavior that occurs in the initial stage of the sample attack event;

[0133] Based on the initial common attack behavior, the information type of the inducement information of applications with different functions is determined.

[0134] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:

[0135] Analyze the sample attack events and determine the attack behaviors to be processed corresponding to the sample attack events;

[0136] The attack behaviors to be processed are processed to obtain initial common attack behaviors.

[0137] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:

[0138] Analyze the aggressive behaviors to be processed and determine the initial common aggressive behaviors to be processed;

[0139] The initial common attack behaviors to be processed are classified to obtain the initial common attack behaviors.

[0140] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:

[0141] Analyze the initial common attack behaviors to determine the target applications and attack contents corresponding to the initial common attack behaviors;

[0142] Among them, the type of the target application is the target type;

[0143] Based on the attack content and initial common attack behavior, determine the information type of the induced information corresponding to the target application of each function.

[0144] In other embodiments of the present application, the setting unit 44 is specifically configured to perform the following steps:

[0145] Determine the target inducement information based on the information type and the information of the application to be analyzed;

[0146] Based on the setting location and the information of the application to be analyzed, target guidance information is set at the target location of the application to be analyzed.

[0147] In other embodiments of the present application, the setting unit 44 is specifically configured to perform the following steps:

[0148] Determine the data information and functions of the application to be analyzed;

[0149] Determine target guidance information based on the data information, functions and information type of the application to be analyzed.

[0150] In other embodiments of the present application, the setting unit 44 is specifically configured to perform the following steps:

[0151] Determine the target location based on the setting location, function and information type;

[0152] Target guidance information is set at the target location of the application to be analyzed.

[0153] In other embodiments of this application, refer to Figure 6 As shown, the apparatus may further include a processing unit 45, wherein:

[0154] The processing unit 45 is configured to issue an intrusion alarm message when a target attack event is detected, and obtain attribute information of a target attack terminal corresponding to the target attack event;

[0155] The processing unit 45 is further configured to store the attribute information in a threat intelligence database and identify the target attack terminal.

[0156] In other embodiments of the present application, the processing unit 45 is further configured to perform defense processing on target attack events to block the target attack events.

[0157] It should be noted that the interaction process between the various units in this embodiment can refer to Figures 1-2 The description in the embodiment corresponding to 4 is not repeated here.

[0158] The information setting device provided in the embodiments of the present application can set target induction information directly in the application to be analyzed without providing a real independent physical host, and the setting location of different applications to be analyzed is different, which solves the problem that the honeypot products in the relative technology are fixed in location, easy to be detected by hackers and require an independent physical host, enhances the attack perception effect and is highly confusing, not easy to be detected by hackers, and also ensures the implementation effect and reduces the false alarm rate.

[0159] Based on the above embodiments, the embodiments of the present application provide an information setting device, which can be applied to Figures 1-2 In the information setting method provided in the embodiment corresponding to 4, refer to Figure 7 As shown, the device 5 may include: a processor 51, a memory 52 and a communication bus 53, wherein:

[0160] The communication bus 53 is used to realize the communication connection between the processor 51 and the memory 52;

[0161] The processor 51 is used to execute the information setting program stored in the memory 52 to implement the following steps:

[0162] Obtain sample attack events against target type applications;

[0163] Based on the sample attack events, determine the information type of the inducement information of applications with different functions; wherein the inducement information is information used to induce the generation of attack events;

[0164] Based on the information type, determine the location of the inducement information in the target type application;

[0165] Based on the information type, setting location and information of the application to be analyzed, target guidance information is set in the application to be analyzed; wherein the type of the application to be analyzed is the target type.

[0166] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52, based on the sample attack event, to determine the information type of the inducement information of applications with different functions, so as to implement the following steps:

[0167] Based on the sample attack events, determining the initial common attack behaviors; wherein the initial common attack behaviors represent the common attack behaviors occurring in the initial stage of the sample attack events;

[0168] Based on the initial common attack behavior, the information type of the inducement information of applications with different functions is determined.

[0169] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52 based on the sample attack events, determine the initial common attack behavior, and implement the following steps:

[0170] Analyze the sample attack events and determine the attack behaviors to be processed corresponding to the sample attack events;

[0171] The attack behaviors to be processed are processed to obtain initial common attack behaviors.

[0172] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52 to process the attack behavior to be processed, obtain the initial common attack behavior, and implement the following steps:

[0173] Analyze the aggressive behaviors to be processed and determine the initial common aggressive behaviors to be processed;

[0174] The initial common attack behaviors to be processed are classified to obtain the initial common attack behaviors.

[0175] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52 to determine the information type of the inducement information of applications with different functions based on the initial common attack behavior, so as to implement the following steps:

[0176] Analyze the initial common attack behaviors to determine the target applications and attack contents corresponding to the initial common attack behaviors;

[0177] Among them, the type of the target application is the target type;

[0178] Based on the attack content and initial common attack behavior, determine the information type of the induced information corresponding to the target application of each function.

[0179] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52, based on the information type, setting location, and information of the application to be analyzed, to set target guidance information in the application to be analyzed, so as to implement the following steps:

[0180] Determine the target inducement information based on the information type and the information of the application to be analyzed;

[0181] Based on the setting location and the information of the application to be analyzed, target guidance information is set at the target location of the application to be analyzed.

[0182] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52 based on the information type and the information of the application to be analyzed, and determine the target induction information to implement the following steps:

[0183] Determine the data information and functions of the application to be analyzed;

[0184] Determine target guidance information based on the data information, functions and information type of the application to be analyzed.

[0185] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52, based on the setting location and information of the application to be analyzed, to set target guidance information at the target location of the application to be analyzed, and further implement the following steps:

[0186] Determine the target location based on the setting location, function and information type;

[0187] Target guidance information is set at the target location of the application to be analyzed.

[0188] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52, and may further implement the following steps:

[0189] When a target attack event is detected, an intrusion alarm is issued and the attribute information of the target attack terminal corresponding to the target attack event is obtained;

[0190] The attribute information is stored in the threat intelligence library and the target attack terminal is identified.

[0191] In other embodiments of the present application, the processor 51 is further configured to execute the information setting program stored in the memory 52, and may further implement the following steps:

[0192] Perform defensive processing on targeted attack events to block them.

[0193] It should be noted that the explanation of the steps executed by the processor in the embodiment of the present application can refer to Figures 1-2 The description in the embodiment corresponding to 4 is not repeated here.

[0194] The information setting device provided in the embodiments of the present application can set target induction information directly in the application to be analyzed without providing a real independent physical host, and the setting location of different applications to be analyzed is different, which solves the problem that the honeypot products in the relative technology are fixed in location, easily detected by hackers and require an independent physical host, enhances the attack perception effect and is highly confusing, not easily detected by hackers, and also ensures the implementation effect and reduces the false alarm rate.

[0195] Based on the above embodiments, the embodiments of the present application provide a computer storage medium, which stores one or more programs, which can be executed by one or more processors to implement Figures 1-2 The steps of the information setting method provided in embodiment 4 correspond to those in embodiment 4.

[0196] It should be noted that the specific implementation process of the steps executed by the processor in this embodiment can be referred to Figures 1-2The implementation process of the information setting method provided in the embodiment corresponding to 4 will not be repeated here.

[0197] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0198] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0199] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0200] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0201] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are protected by this application.

Claims

1. An information setting method, characterized in that: The method comprises: Obtain sample attack events against target type applications; Based on the sample attack event, determining the information type of the inducement information of applications with different functions; wherein the inducement information is information used to induce an attack event; the information type represents the form in which the inducement information exists, or the type of delivery of the inducement information; Determining a setting location of the inducement information in the target type application based on the information type, the location of the inducement information of different information types, and historical usage information of the target type application; Based on the information type, the setting location and information of the application to be analyzed, target guidance information is set in the application to be analyzed; wherein the type of the application to be analyzed is the target type; different target guidance information is set in different locations in different applications to be analyzed.

2. The method according to claim 1, characterized in that The determining, based on the sample attack event, the information type of the inducement information of applications with different functions includes: Determining initial common attack behaviors based on the sample attack events; wherein the initial common attack behaviors represent common attack behaviors occurring in the initial stage of the sample attack events; Based on the initial common attack behavior, the information type of the inducement information of the applications with different functions is determined.

3. The method according to claim 2, characterized in that Determining the initial common attack behavior based on the sample attack event includes: Analyze the sample attack event to determine the attack behavior to be processed corresponding to the sample attack event; The attack behaviors to be processed are processed to obtain the initial common attack behaviors.

4. The method according to claim 3, characterized in that The processing of the attack behavior to be processed to obtain the initial common attack behavior includes: Analyzing the attack behaviors to be processed to determine initial common attack behaviors to be processed; The initial common attack behaviors to be processed are classified to obtain the initial common attack behaviors.

5. The method according to claim 2, characterized in that The determining, based on the initial common attack behavior, the information type of the inducement information of the applications with different functions includes: Analyzing the initial common attack behavior to determine the target application corresponding to the initial common attack behavior and the attack content corresponding to the initial common attack behavior; wherein the type of the target application is the target type; Based on the attack content and the initial common attack behavior, an information type of the inducement information corresponding to the target application of each function is determined.

6. The method according to claim 1, characterized in that The step of setting target guidance information in the application to be analyzed based on the information type, the setting location, and the information of the application to be analyzed includes: Determining the target guidance information based on the information type and the information of the application to be analyzed; The target guidance information is set at a target location of the application to be analyzed based on the setting location and the information of the application to be analyzed.

7. The method according to claim 6, characterized in that The determining the target guidance information based on the information type and the information of the application to be analyzed includes: Determining the data information and functions of the application to be analyzed; The target guidance information is determined based on the data information of the application to be analyzed, the function, and the information type.

8. The method according to claim 6, characterized in that The step of setting the target guidance information at the target location of the application to be analyzed based on the setting location and the information of the application to be analyzed includes: determining the target location based on the setting location, the function, and the information type; The target guidance information is set at the target location of the application to be analyzed.

9. The method according to claim 1, characterized in that The method further comprises: When a target attack event is detected, an intrusion alarm is issued and attribute information of the target attack terminal corresponding to the target attack event is obtained; The attribute information is stored in a threat intelligence library, and the target attack terminal is identified.

10. The method according to claim 9, characterized in that The method further comprises: A defense process is performed on the target attack event to block the target attack event.

11. An information setting device, characterized in that: The device includes: a processor, a memory and a communication bus; The communication bus is used to realize the communication connection between the processor and the memory; The processor is used to execute the information setting program in the memory to implement the following steps: Obtain sample attack events against target type applications; Based on the sample attack event, determining the information type of the inducement information of applications with different functions; wherein the inducement information is information used to induce an attack event; the information type represents the form in which the inducement information exists, or the type of delivery of the inducement information; Determining a setting location of the inducement information in the target type application based on the information type, the location of the inducement information of different information types, and historical usage information of the target type application; Based on the information type, the setting location and information of the application to be analyzed, target guidance information is set in the application to be analyzed; wherein the type of the application to be analyzed is the target type; different target guidance information is set in different locations in different applications to be analyzed.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the information setting method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Attack behavior-based honey bait generation method and device, equipment and medium

    CN111787021A