Method, device and system for honeypot interacting with attack host
Patent Information
- Application Number
- CN202211649318.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-21
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-12-21
AI Technical Summary
然而,转发流量虽然经过边界设备,但边界设备实际上并未对攻击流量内容做相应过滤,致使蜜罐仿真资产接收到较多无意义的攻击流量数据包,影响蜜罐与攻击主机之间的交互效率
[0014]第五方面,本发明实施例提供一种计算机可读存储介质,所述计算机可读存储介质存储有一个或者多个程序,所述一个或者多个程序可被一个或者多个处理器执行,以实现第一方面任一所述的蜜罐与攻击主机交互的方法。
Smart Images

Figure CN115987623B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to methods, apparatus and systems for honeypots to interact with attacking hosts. Background Technology
[0002] In cyberspace, many boundary devices are set up to control network traffic, such as firewalls or network security detection devices. These boundary devices are especially essential in high-security intranet environments.
[0003] When deploying honeypot emulation assets, the existing deployment method typically exposes the working ports of the honeypot emulation assets to the external network environment. For security reasons, border devices are required to forward or map the traffic to the corresponding working ports. However, although the forwarded traffic passes through the border devices, the border devices do not actually filter the attack traffic content accordingly. This causes the honeypot emulation assets to receive a large number of meaningless attack traffic packets, affecting the efficiency of the interaction between the honeypot and the attacking host. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a method, apparatus, electronic device, and storage medium for honeypots to interact with attacking hosts, which facilitates improving the interaction efficiency between honeypots and attacking hosts.
[0005] In a first aspect, the method for honeypots to interact with attacking hosts provided in this embodiment of the invention includes the following steps: obtaining target attack data packets forwarded by a border device; the target attack data packets are obtained by the border device after filtering the received attack traffic; forwarding the target attack data packets to corresponding honeypot assets according to the attack type; the honeypot assets are deployed in multiple ways, and each honeypot asset deploys a honeypot for attack data packets of at least one attack type; receiving a response data packet of the target attack data packet returned by at least one honeypot asset, and forwarding it to the border device, so that the border device forwards the response data packet to the attacking host.
[0006] Preferably, the step of obtaining the target attack data packet forwarded by the border device includes: receiving the complete target attack data packet sent by the border device; the complete target attack data packet contains the data information required to complete a complete data packet transmission process; the step of forwarding the target attack data packet to the corresponding honeypot assets according to the attack type includes: determining each honeypot asset corresponding to the attack type of the target attack data packet, and distributing the complete target attack data packet to the corresponding honeypot assets.
[0007] Preferably, the step of acquiring the target attack data packet forwarded by the border device includes: receiving the target attack data packet transmitted by the border device based on the application layer protocol; the target attack data packet is sent in one or more communication data packets, and the first communication data packet constituting the target attack data packet carries a four-tuple information, and the subsequent communication data packets starting from the second carry a data payload; the step of forwarding the target attack data packet to the corresponding honeypot asset according to the attack type includes: determining each honeypot asset corresponding to the attack type of the target attack data packet; constructing and simulating a TCP protocol stack based on the four-tuple information carried in the first target attack data packet, and establishing a TCP connection with the honeypot asset; concatenating the data payload into the TCP protocol stack and sending it to the corresponding honeypot asset.
[0008] Preferably, before acquiring the target attack data packet forwarded by the border device, the method further includes: establishing a trusted communication connection with the border device; sending a list of deployed honeypot assets to the border device; waiting for the border device to transmit the target attack data packet; and receiving the target attack data packet transmitted by the border device when or after the border device detects that a port of the corresponding network segment has been accessed.
[0009] Preferably, receiving a response data packet of the target attack data packet returned by at least one honeypot asset and forwarding it to the border device includes: receiving response data packets of different attack types of target attack data packets returned by the honeypot asset; and sending the corresponding response data packet to the border device according to the attack type of the obtained target attack data packet, so that the border device sends it to the attacking host.
[0010] Preferably, determining the honeypot assets corresponding to the attack type of the target attack data packet includes: detecting the feature identifier carried in the target attack data packet; determining the honeypot assets corresponding to the attack type of the target attack data packet based on the feature identifier; wherein the feature identifier is used to indicate the honeypot assets corresponding to the attack type of the target attack data packet.
[0011] Secondly, this invention also provides a honeypot-attacking host interaction device, comprising: an acquisition program module for acquiring target attack data packets forwarded by a border device; the target attack data packets are obtained by the border device after filtering the received attack traffic; a forwarding program module for forwarding the target attack data packets to corresponding honeypot assets according to the attack type; the honeypot assets are deployed in multiple ways, each honeypot asset being configured for at least one type of attack traffic data packet; and a transceiver program module for receiving response data packets of the target attack data packets returned by at least one honeypot asset and forwarding them to the border device, so that the border device forwards the response data packets to the attacking host.
[0012] Thirdly, the present invention also provides a honeypot and attack host interaction system, comprising: a boundary device, an intermediate program unit, and honeypot assets; wherein, the honeypot assets are associated with honeypots, and the boundary device stores honeypot information of the honeypot assets; the boundary device is used to acquire attack traffic sent by the attack host, filter the attack traffic to obtain target attack traffic, and send the target attack traffic to the intermediate program unit; the intermediate program unit is used to interact with the boundary device and the honeypot assets to implement any of the methods described in the first aspect.
[0013] Fourthly, the present invention also provides an electronic device comprising: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed within the space enclosed by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, for executing the method of honeypot and attack host interaction described in any of the first aspects above.
[0014] Fifthly, embodiments of the present invention provide a computer-readable storage medium storing one or more programs, which can be executed by one or more processors to implement the method of honeypot and attack host interaction as described in any of the first aspects.
[0015] This invention provides a method, apparatus, electronic device, and storage medium for honeypot-attacking host interaction. The method comprises the following steps: acquiring target attack data packets forwarded by a border device; the target attack data packets are obtained by the border device after filtering received attack traffic; forwarding the target attack data packets to corresponding honeypot assets according to attack type; multiple honeypot assets are deployed, each honeypot asset deploying a honeypot for at least one attack type of attack data packet; receiving response data packets of the target attack data packets returned by at least one honeypot asset, and forwarding them to the border device, so that the border device forwards the response data packets to the attacking host. By pre-filtering the received target traffic data packets, the processing of meaningless traffic data by intermediate modules and / or honeypot assets is reduced, thus improving the interaction efficiency between the honeypot and the attacking host. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a schematic diagram of a method for interaction between a honeypot and an attacking host according to an embodiment of the present invention;
[0018] Figure 2 This is a schematic diagram of a method for interaction between a honeypot and an attacking host according to another embodiment of the present invention;
[0019] Figure 3 This is a schematic diagram of the architecture of an embodiment of the network attack defense and detection device of the present invention;
[0020] Figure 4 This is a schematic diagram of another embodiment of the network attack defense and detection device of the present invention;
[0021] Figure 5 This is a schematic block diagram illustrating the architecture of an embodiment of the electronic device of the present invention. Detailed Implementation
[0022] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0023] It should be understood that the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0024] Example 1
[0025] Figure 1 This is a schematic flowchart illustrating the method for interaction between a honeypot and an attacking host according to an embodiment of the present invention. Please refer to it. Figure 1 As shown, the method for honeypot and attack host interaction provided in this embodiment of the invention can be applied to network security defense scenarios. It should be noted that the method can be embedded in a manufactured product in the form of software, and when the user uses the product, the method steps of this application can be reproduced.
[0026] The method for interaction between a honeypot and an attacking host provided in this embodiment of the invention includes the following steps:
[0027] S110. Obtain the target attack data packet forwarded by the border device; the target attack data packet is obtained by the border device after filtering the received attack traffic.
[0028] It is understandable that before forwarding attack traffic data, the edge device can filter out some attack traffic that is not related to the honeypot emulation asset deployed in the backend (also referred to as honeypot asset in this article), and send the attack traffic that corresponds to the type of honeypot emulation asset as the target attack traffic data packet to the honeypot emulation asset. This can improve the efficiency of the honeypot emulation asset in processing traffic data packets.
[0029] The boundary device can be a firewall or other network security devices or tools. The honeypot emulation asset is typically deployed for attack traffic packets of a specific network attack type; however, it can also be deployed on a single device for attack traffic packets of multiple network attack types. The honeypot asset is preferably deployed as a high-interaction honeypot asset, but a low-interaction honeypot asset is also possible. The honeypot asset can be an internal network IP address carrying the honeypot service, or a device with the internal network IP address and carrying the honeypot control system. Attack traffic, also known as malicious traffic, generally refers to abnormal access traffic marked with addresses, ports, or behaviors.
[0030] To enable the border device to forward target attack traffic packets of a predetermined type to the honeypot emulation asset, specifically, before obtaining the target attack packets forwarded by the border device, the method further includes: establishing a trusted communication connection with the border device; sending a list of deployed honeypot assets to the border device; waiting for the border device to transmit the target attack packets; and receiving the target attack packets transmitted by the border device when or after the border device detects that a port of the corresponding network segment has been accessed.
[0031] In this embodiment, an intermediate component (sometimes referred to as an intermediate module in this text) can be constructed to assist honeypot assets in redirecting traffic to border devices of different manufacturers and topology node locations, and to support the transmission of highly interactive response data from the honeypot to the incoming traffic. Of course, this intermediate component can also be integrated with a firewall.
[0032] After establishing a trusted communication connection with the edge device through the intermediate component, the list of honeypot assets deployed in the backend is sent to the edge device in advance. The edge device can store the list of honeypot assets. When the edge device detects that the port of the corresponding network segment is accessed, it obtains the attack traffic data packet from the port, filters the attack traffic data packet according to the honeypot asset type identifier in the honeypot asset list, obtains the target attack data packet of the corresponding honeypot simulation asset type, and forwards the target attack data packet to the intermediate component, so that the intermediate component can complete the data interaction between the network edge device and the honeypot simulation asset.
[0033] Specifically, the target attack traffic data is obtained by filtering and classifying the attack traffic received by the monitoring port through the boundary device. The basis for filtering and classification can be the type identifier of the honeypot asset.
[0034] The border device filters and classifies received attack traffic, which may include: extracting threat type identifiers carried in the attack traffic data packets. These threat type identifiers may include, for example, the destination IP address, port number, protocol type, access frequency within a predetermined time period, code characteristics, etc., and determining the attack type of the attack traffic based on these threat type identifiers. For example, if the extracted attack traffic data carries port numbers 21 / 22 / 69, corresponding to the FTP / TFTP file transfer protocol, it generally represents attack types such as upload, download, brute-force, and sniffing. Based on the types of honeypot simulation assets in the honeypot simulation asset list, the attack traffic data corresponding to the attack type is identified as the target attack data packet and forwarded to an intermediate component, which then forwards it to the honeypot simulation asset deployed in the internal network.
[0035] Of course, for simple border device traffic filtering, the common method is to use ports as the basis for traffic filtering. This method defaults to using the port numbers of common network services. For example, port 80 is usually used as the web service port, so the border device can initiate a forwarding process when it detects access to port 80. Similarly, SSH services typically use port 22 as the traffic exchange port, so when the border device receives access traffic to port 22, it can initiate a forwarding process to redirect the access to the intermediate module.
[0036] For advanced border devices with traffic identification capabilities, more effective traffic identification and extraction methods, such as code signature information, can be used to selectively filter malicious traffic and deliver it to backend middleware modules. For example, in website vulnerability attacks, in addition to accessing port 80 as mentioned above, the attack packet will include a Proof of Concept (PoC) in the payload. When the border device detects the code signature of this PoC, the packet can be accurately delivered to a honeypot in the backend that contains this vulnerability.
[0037] Furthermore, when deploying honeypot emulation assets, it is often necessary to expose the working ports of these assets to the external network environment. For security reasons, border devices are required to forward or map traffic to the corresponding working ports. However, although the forwarded traffic passes through the border devices, these devices do not actually filter the attack traffic content. This results in too many potentially uncontrolled attack traffic packets flowing to the honeypot emulation assets, which increases the potential attack risk of the entire network system. Once a honeypot emulation asset is compromised, it can be used as a stepping stone to attack internal network hosts.
[0038] Therefore, in this embodiment of the invention, by filtering attack traffic data at the boundary device to obtain the target attack traffic, it is possible to prevent some attack traffic data outside the control scope from entering the honeypot simulation asset, thereby improving the security of the internal network asset during the process of the honeypot simulation asset capturing attackers.
[0039] For details, please refer to Figure 2 As shown, taking the border device as a firewall as an example, in this embodiment of the invention, firstly, in the internal network controlled by the firewall that supports the forwarding of attack packets from simulated targets, after deploying a honeypot and honeypot simulation assets, an intermediate module is deployed in a dedicated device, and the intermediate module performs a series of subsequent operations (see the description below for details) to realize data interaction between the network border device and the honeypot simulation assets.
[0040] S120. The target attack data packet is forwarded to the corresponding honeypot asset according to the attack type; there are multiple honeypot assets deployed, and each honeypot asset deploys a honeypot for attack data packets of at least one attack type.
[0041] Please continue reading. Figure 2As shown, the intermediate module first needs to establish a trusted communication connection with the boundary device. In this embodiment, the firewall needs to provide complete data and operation documents to establish a trusted communication connection with the intermediate module. After the intermediate module establishes a connection with the firewall, it obtains the information of the backend honeypot device and establishes a trusted connection with it. The intermediate module sends a list of deployed honeypot simulation asset information to the firewall. When the firewall obtains the list, the intermediate module enters a waiting sequence, waiting for the firewall to send back the target attack data packet. When the firewall detects that the port of the corresponding network segment is accessed, or after that, the firewall will forward the target attack data packet to the intermediate module. After receiving the target attack data packet sent back by the firewall, the intermediate module will have two possible forwarding methods.
[0042] Firstly, the intermediate module acquires the target attack data packet returned by the firewall, which includes receiving a complete target attack data packet sent by the border device. This complete target attack data packet contains the data information required to complete a full data packet transmission process. Specifically, the intermediate module receives a complete IP (Internet Protocol Address, a method of addressing hosts on the Internet, also known as an Internet Protocol address) or TCP (Transmission Control Protocol) data packet returned by the firewall, which contains the data information required to complete a full data packet transmission process.
[0043] The intermediate module forwards the received target attack data packet to the corresponding honeypot asset according to the attack type, including: determining each honeypot asset corresponding to the attack type of the target attack data packet, and distributing the complete target attack data packet to the corresponding honeypot asset.
[0044] In this embodiment, the border device forwards complete IP or TCP data packets. In this case, the intermediate module does not need to modify the target attack data packet and can directly transmit the target attack data packet to the honeypot asset. Since the data packet is complete, the honeypot asset will directly replace the information and then enter the honeypot replay stage to trace the source of the attack traffic data.
[0045] The step of determining each honeypot asset corresponding to the attack type of the target attack data packet includes: detecting the feature identifier carried in the target attack data packet; determining the honeypot asset corresponding to the attack type of the target attack data packet based on the feature identifier; wherein the feature identifier is used to indicate the honeypot asset corresponding to the attack type of the target attack data packet.
[0046] Secondly, the intermediate module's acquisition of the target attack data packets returned by the firewall also includes: receiving the target attack data packets transmitted by the border device based on application layer protocols; the target attack data packets are sent in one or more communication data packets, and the first communication data packet that makes up the target attack data packet carries four-tuple information, while subsequent communication data packets starting from the second one carry data payloads. For example, if the firewall returns the target attack data packets using a private application layer protocol, for instance, it only sends four-tuple information consisting of source IP, destination IP, source port, and destination port in the first packet, and then from the second packet onwards, it only sends TCP data payloads and no longer sends TCP or IP header information.
[0047] The step of forwarding the target attack data packet to the corresponding honeypot asset according to the attack type includes: determining each honeypot asset corresponding to the attack type of the target attack data packet; constructing and simulating a TCP protocol stack based on the four-tuple information carried in the first target attack data packet, and establishing a TCP connection with the honeypot asset; and concatenating the data payload into the TCP protocol stack and sending it to the corresponding honeypot asset.
[0048] In the first forwarding method mentioned above, since the complete attack data packet is forwarded from the border device to the intermediate module and then to the honeypot asset, the destination IP and destination port are modified, but the source IP and source port do not need to be modified. The attacker's source IP can be retained. After the backend honeypot asset receives it, it can successfully trace the attack data packet. Therefore, it can be forwarded directly.
[0049] In this embodiment, the incomplete attack data packet occurs when the border device cannot forward the complete attack data packet to the intermediate module and splits the attack data packet. At this time, the source IP of the data packet sent by the border device is the border device itself, and the information of the attack data packet is carried in the payload of the data packet sent by the border device (for example, the payload of the first data packet is the four-tuple information of the attack data packet, and the payload of the subsequent data packets is part of the payload of the attack data packet).
[0050] Then, after the intermediate module receives an incomplete data packet, if it directly establishes a TCP connection with the honeypot, or if it sends the data packet after parsing the attack data packet, and the source IP of the sent data packet is the intermediate device, or if it directly forwards the data packet forwarded by the border device, and the source IP is the border device, the honeypot asset may have the problem of not being able to trace the attack data packet.
[0051] Therefore, in order to ensure that the data packets sent by the intermediate module are easy to replay and trace the source of the honeypot assets and to avoid errors in the source tracing, in this embodiment, by establishing a simulated TCP connection, based on the case that the current attack data packet only has a payload, the attack data packet from the IP layer all the way to the application layer can be constructed through the four-tuple information in the first communication data packet. Thus, after the honeypot assets receive the forwarded target attack data packet, it is easy to successfully replay and trace the source of the attack data packet.
[0052] Therefore, depending on the different target attack data packets received by the intermediate module from the firewall, the intermediate module can choose one of the two processing methods mentioned above to process the attack traffic data.
[0053] S130: Receive a response packet from at least one honeypot asset returning the target attack packet, and forward it to the border device so that the border device forwards the response packet to the attacking host.
[0054] For details, please refer to Figure 2 As shown, receiving a response data packet of the target attack data packet returned by at least one honeypot asset and forwarding it to the border device includes: receiving response data packets of different attack types of target attack data packets returned by the honeypot asset; and sending the corresponding response data packet to the border device according to the attack type of the obtained target attack data packet, so that the border device sends it to the attacking host.
[0055] In this embodiment, after the intermediate module obtains the response data packet of the honeypot asset receipt, it replies to the firewall with the corresponding data traffic packet according to the different types of target attack data packet traffic. The firewall then takes over and completes communication interaction with the external attack end.
[0056] The method for honeypot-attacking host interaction provided in this invention reduces the amount of meaningless traffic data processed by the intermediate module and / or honeypot assets by the boundary device before forwarding it to the intermediate module for processing, thus improving the interaction efficiency between the honeypot and the attacker host. This is because the boundary device filters the attack traffic data in advance before forwarding it to the intermediate module for processing.
[0057] Furthermore, by filtering attack traffic data at the border device to obtain the target attack traffic, some attack traffic data outside the control scope can be prevented from entering the honeypot simulation asset. This improves the security of internal network assets during the process of the honeypot simulation asset luring attackers. This also solves the security risk problem of interactive traffic from high-interaction honeypots being forwarded through the border device.
[0058] Example 2
[0059] See Figure 3 As shown, an embodiment of the present invention provides a honeypot and attack host interaction device, comprising:
[0060] The acquisition module 21 is used to acquire target attack data packets forwarded by the border device; the target attack data packets are obtained by the border device after filtering the received attack traffic;
[0061] Forwarding module 22 is used to forward the target attack data packets to the corresponding honeypot assets according to the attack type; there are multiple honeypot assets deployed, and each honeypot asset is configured for attack traffic data packets of at least one attack type;
[0062] The transceiver module 23 is used to receive a response packet of the target attack packet returned by at least one honeypot asset, and forward it to the border device so that the border device forwards the response packet to the attacking host.
[0063] The honeypot and attack host interaction device provided in this embodiment of the invention can be used to execute the technical solution of any of the disclosed method embodiments in Embodiment 1. Its implementation principle and technical effect are similar, and will not be repeated here.
[0064] Example 3
[0065] Please refer to Figure 4 As shown, this embodiment of the invention provides a honeypot and attack host interaction system, including: a border device 31, an intermediate program unit 32, and a honeypot asset 33; wherein, the honeypot asset is associated with a honeypot, and the border device stores honeypot information of the honeypot asset; the honeypot information may include IP, MAC, port number, type of attack data packet targeted by the honeypot, etc.; the border device is used to obtain attack traffic sent by the attack host, filter the attack traffic to obtain target attack traffic, and send the target attack traffic to the intermediate program unit; the intermediate program unit is used to interact with the border device and the honeypot asset to implement the method described in any of the embodiments.
[0066] The honeypot and attack host interaction system provided in this embodiment of the invention can be used to execute the technical solutions of the method embodiments disclosed in Embodiment 1. Its implementation principle and technical effects are similar, and will not be repeated here.
[0067] Example 4
[0068] Figure 5 This is a schematic block diagram of the architecture of an embodiment of the electronic device of the present invention; based on the same technical concept as the foregoing Embodiment 1, the electronic device provided by the embodiments of the present invention, such as... Figure 5As shown, the process can be implemented according to any of the embodiments described in Embodiment 1 of the present invention.
[0069] The aforementioned electronic device may include: a housing 41, a processor 42, a memory 43, a circuit board 44, and a power supply circuit 45, wherein the circuit board 44 is disposed inside the space enclosed by the housing 41, and the processor 42 and the memory 43 are disposed on the circuit board 44; the power supply circuit 45 is used to supply power to the various circuits or devices of the aforementioned electronic device; the memory 43 is used to store executable program code; the processor 42 runs a program corresponding to the executable program code by reading the executable program code stored in the memory 43, for executing the method of honeypot and attack host interaction described in any of the aforementioned embodiments.
[0070] For details on the specific execution process of the above steps by the processor 42 and the steps further executed by the processor 42 by running executable program code, please refer to the description of Embodiment 1 of the present invention, which will not be repeated here.
[0071] The electronic device exists in various forms, including but not limited to:
[0072] (1) Mobile communication devices: These devices are characterized by their mobile communication capabilities and primarily aim to provide voice and data communication. These terminals include: smartphones (e.g., iPhones), multimedia phones, feature phones, and low-end phones, etc.
[0073] (2) Ultra-mobile personal computer devices: These devices fall under the category of personal computers, possessing computing and processing capabilities, and generally also have mobile internet access features. These terminals include PDAs, MIDs, and UMPCs, such as the iPad.
[0074] (3) Portable entertainment devices: These devices can display and play multimedia content. This category includes: audio and video players (such as iPods), handheld game consoles, e-books, as well as smart toys and portable car navigation devices.
[0075] (4) Server: A device that provides computing services. The components of a server include a processor, hard disk, memory, system bus, etc. Servers are similar to general computer architectures, but because they need to provide highly reliable services, they have higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.
[0076] (5) Other electronic devices with data interaction functions.
[0077] Example 5
[0078] This invention also provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the honeypot-attacking host interaction method described in any of the preceding embodiments. Therefore, it can also achieve the corresponding technical effects, as has been described in detail above and will not be repeated here.
[0079] In summary, the method, apparatus, system, electronic device, and storage medium for honeypot-attacking host interaction provided by this invention, and the method for honeypot-attacking host interaction provided in the embodiments of this invention, reduce the processing of meaningless traffic data received by the intermediate module and / or honeypot assets by the boundary device before forwarding it to the intermediate module for processing, thus reducing the amount of data processing and improving the interaction efficiency between the honeypot and the attacking host. This further solves the data communication and data filtering problems between network boundary devices and honeypot assets (including honeypot proxy assets, such as virtual switches).
[0080] Furthermore, by filtering attack traffic data at the border device to obtain the target attack traffic, some attack traffic data outside the control scope can be prevented from entering the honeypot simulation asset. This improves the security of internal network assets during the process of the honeypot simulation asset luring attackers. This also solves the security risk problem of interactive traffic from high-interaction honeypots being forwarded through the border device.
[0081] Furthermore, the solution provided by this invention allows for the construction of an intermediate module that utilizes automated packet capture and fully simulates the TCP protocol stack. This expands the methods and detection techniques for redirecting traffic from edge devices to honeypot assets, increasing the data acquisition sources for honeypots. It also adds specific schemes for honeypots to send response packets back to edge devices, and by deploying this intermediate module, data can be provided to other platforms. This removes technical barriers to data and functional interaction between honeypots and other network security devices; it enables redirection of traffic to honeypot assets from edge devices of different vendors and topology locations, and supports high-interaction responses from honeypots to incoming traffic.
[0082] It should be noted that in this article, relational terms such as first and second are only used to refer to...
[0083] Distinguishing one entity or operation from another does not necessarily require or imply any such actual relationship or order between those entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0084] The various embodiments in this specification are described in a related manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
[0085] For ease of description, if systems, servers, etc., are involved, they may be described separately as various units / modules based on their functions. Of course, in implementing this invention, the functions of each unit / module can be implemented in one or more software and / or hardware.
[0086] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0087] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for interaction between a honeypot and an attacking host, characterized in that, Including the following steps: The target attack data packet forwarded by the border device is obtained; the target attack data packet is obtained by the border device after filtering the received attack traffic. The target attack data packets are forwarded to the corresponding honeypot assets according to the attack type. Multiple honeypot assets are deployed, each targeting at least one type of attack data packet. Specifically, when the edge device transmits the target attack data packets based on an application layer protocol, and the first communication data packet containing the target attack data packet carries a four-tuple, while subsequent communication data packets carry data payloads, a TCP protocol stack is constructed and simulated based on the four-tuple information carried in the first target attack data packet, and a TCP connection is established with the honeypot asset. The data payload is then concatenated into the TCP protocol stack and sent to the corresponding honeypot asset. The system receives a response packet from at least one honeypot asset that returns the target attack packet, and forwards it to the border device so that the border device forwards the response packet to the attacking host.
2. The method for interaction between the honeypot and the attacking host as described in claim 1, characterized in that, The process of acquiring the target attack data packet forwarded by the border device includes: receiving the complete target attack data packet sent by the border device; the complete target attack data packet contains the data information required to complete a complete data packet transmission process. The step of forwarding the target attack data packet to the corresponding honeypot assets according to the attack type includes: determining each honeypot asset corresponding to the attack type of the target attack data packet, and distributing the complete target attack data packet to the corresponding honeypot assets.
3. The method for interaction between the honeypot and the attacking host as described in claim 1, characterized in that, Before acquiring the target attack data packet forwarded by the border device, the method further includes: establishing a trusted communication connection with the border device; Send the list of deployed honeypot assets to the edge devices; Waiting for the border device to transmit the target attack data packet; When the border device detects that the port of the corresponding network segment is accessed, or afterward, it receives the target attack data packet transmitted by the border device.
4. The method for interaction between the honeypot and the attacking host as described in claim 1, characterized in that, The step of receiving a response packet of the target attack packet returned by at least one honeypot asset and forwarding it to the border device includes: Receive response packets from the honeypot assets, representing different types of target attack packets. Based on the attack type of the acquired target attack data packet, the corresponding response data packet is sent to the border device, so that the border device sends it to the attacking host.
5. The method for interaction between the honeypot and the attacking host as described in claim 2, characterized in that, The process of determining each honeypot asset corresponding to the attack type of the target attack data packet includes: Detect the feature identifiers carried in the target attack data packets; The honeypot asset corresponding to the attack type of the target attack data packet is determined based on the feature identifier; wherein, the feature identifier is used to indicate the honeypot asset corresponding to the attack type of the target attack data packet.
6. A honeypot and attack host interaction device, characterized in that, include: The acquisition module is used to acquire target attack data packets forwarded by the border device; the target attack data packets are obtained by the border device after filtering the received attack traffic; The forwarding module is used to forward the target attack data packets to the corresponding honeypot assets according to the attack type. Multiple honeypot assets are deployed, each designed for at least one type of attack traffic data packet. Specifically, when the edge device transmits the target attack data packets based on an application layer protocol, and the first communication data packet containing the target attack data packet carries a four-tuple information while subsequent communication data packets carry data payloads, a TCP protocol stack is constructed and simulated based on the four-tuple information carried in the first target attack data packet, and a TCP connection is established with the honeypot asset. The data payload is then concatenated into the TCP protocol stack and sent to the corresponding honeypot asset. The transceiver module is used to receive a response packet of the target attack packet returned by at least one honeypot asset, and forward it to the border device so that the border device forwards the response packet to the attacking host.
7. A honeypot and attack host interaction system, characterized in that, include: The boundary device, intermediate program unit, and honeypot assets; wherein, the honeypot assets are associated with honeypots, and the honeypot information of the honeypot assets is stored on the boundary device; The boundary device is used to acquire the attack traffic sent by the attacking host, filter the attack traffic to obtain the target attack traffic, and send the target attack traffic to the intermediate program unit. The intermediate program unit is used to interact with the boundary device and honeypot assets to implement the method described in any one of claims 1 to 5.
8. An electronic device, characterized in that, The electronic device includes: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed inside the space enclosed by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, for executing the method of honeypot and attack host interaction as described in any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more programs, which can be executed by one or more processors to implement the method for honeypot and attack host interaction as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Honeypot cluster detection method and system based on directional drainage
CN113992368A