Method and device for evaluating attack ability of attacker, electronic equipment and storage medium
Through multi-level and multi-gradient honeypot network deployment and data evaluation methods, the problem that honeypot technology is difficult to evaluate the attacker's capabilities is solved, detailed evidence collection and capability evaluation of the attacker are achieved, and the protection effect of the honeypot network is improved.
Patent Information
- Application Number
- CN202211652572.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-21
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-12-21
AI Technical Summary
Existing honeypot technology is difficult to effectively assess the attack capabilities of attackers. The focus of the simulation bait system is on systems with no/low protection and systems containing vulnerabilities, which makes it impossible for attackers to distinguish between honeypot bait and real machines, and cannot meet functional indicators such as attack assessment.
By deploying a multi-level, multi-gradient honeypot network, including the first honeypot without vulnerabilities, the second honeypot with vulnerabilities but no protection system, and the third honeypot with vulnerabilities and a protection system, the simulation degree and vulnerability release time are gradually increased, attack data is collected and evaluation scores are calculated, and a weighted evaluation is performed using the attack capability assessment database.
It achieves all-round evidence collection and profiling of the attacker's attack capabilities, improves the protection capabilities of the honeypot network, and can accurately assess the attacker's threat level and capabilities.
Smart Images

Figure CN116015836B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of network security technology, and in particular to a method, device, electronic device, and storage medium for evaluating an attacker's attack capability. Background Art
[0002] Honeypot technology is a deceptive defense technology that tricks intruders into attacking, thereby monitoring and tracking the intruder's behavior and recording it in the form of logs. It then uses certain tools to analyze the intruder's tools, strategies, and methods, so that corresponding defensive measures can be taken to improve defense capabilities.
[0003] However, in related technologies, it is difficult for simulation defense systems using honeypot technology to evaluate the attack capabilities of attackers.
[0004] Based on this, there is an urgent need for an attacker's attack capability assessment method, device, electronic device and storage medium to solve the above technical problems. Summary of the Invention
[0005] In order to evaluate the attack capability of an attacker, embodiments of this specification provide a method, device, electronic device, and storage medium for evaluating the attack capability of an attacker.
[0006] In a first aspect, embodiments of this specification provide a method for evaluating an attacker's attack capability, including:
[0007] Deploy the honeypot network in the target network to be protected according to the preset deployment rules;
[0008] Obtain attack data generated by attackers on the honeypot network;
[0009] The attack capability of the attacker is evaluated based on the attack data.
[0010] In one possible design, the honeypot network includes multiple first honeypot sub-networks deployed at different gradient levels, and the first honeypot sub-network at each gradient level includes at least two second honeypot sub-networks of different types, and each of the second honeypot sub-networks includes a first honeypot without vulnerabilities, a second honeypot with vulnerabilities and no protection system, and a third honeypot with vulnerabilities and a protection system.
[0011] In one possible design, the deployment rules include:
[0012] As the gradient levels move from shallow to deep, the degree of simulation of the first honeypot sub-network gradually increases.
[0013] In one possible design, the deployment rules include:
[0014] According to the direction of the gradient level from shallow to deep, the release time of the vulnerability of the first honeypot sub-network gradually approaches the current evaluation time.
[0015] In one possible design, the attack data includes the following items: the gradient level of the attacked first honeypot network, the type and number of attacked second honeypot sub-networks, the release time of the attacked vulnerability, the protection products included in the attacked protection system, and the number of attacked first honeypots, second honeypots and third honeypots; wherein the protection products include firewalls, WAFs, IPSs and HIPSs.
[0016] In one possible design, the evaluating the attacker's attack capability based on the attack data includes:
[0017] Obtaining a target assessment score corresponding to the attack data based on the items included in the attack data;
[0018] An assessment of the attacker's attack capability based on the target assessment score and preset grading rules.
[0019] In one possible design, obtaining a target assessment score corresponding to the attack data based on items included in the attack data includes:
[0020] Determining, based on the items included in the attack data, an attack identifier corresponding to each item;
[0021] Determining an evaluation score corresponding to each attack identifier based on each attack identifier and a preset attack capability evaluation database; wherein the attack capability evaluation database includes multiple attack identifiers and evaluation scores corresponding to each attack identifier;
[0022] The evaluation scores corresponding to the attack identifiers are weightedly calculated to obtain a target evaluation score corresponding to the attack data; wherein the attack capability evaluation database also includes a weight value corresponding to each attack identifier.
[0023] In a second aspect, the embodiments of this specification further provide a device for evaluating an attacker's attack capability, including:
[0024] A deployment module is used to deploy the honeypot network in the target network to be protected according to the preset deployment rules;
[0025] The acquisition module is used to obtain the attack data generated by the attacker on the honeypot network;
[0026] An evaluation module is used to evaluate the attack capability of the attacker based on the attack data.
[0027] In a third aspect, an embodiment of this specification further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method described in any embodiment of this specification is implemented.
[0028] In a fourth aspect, an embodiment of this specification further provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method described in any embodiment of this specification.
[0029] The embodiments of this specification provide a method, device, electronic device and storage medium for evaluating the attack capability of an attacker. By deploying a honeypot network in a target network to be protected according to preset deployment rules, and then obtaining the attack data generated by the attacker on the honeypot network, the attacker's attack capability can be evaluated based on the attack data. In this way, the attacker's attack capability can be evaluated based on the honeypot network. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0031] Figure 1 This is a flow chart of a method for evaluating an attacker's attack capability provided in one embodiment of this specification;
[0032] Figure 2 This is a hardware architecture diagram of an electronic device provided in an embodiment of this specification;
[0033] Figure 3 This is a structural diagram of an attacker's attack capability assessment device provided in an embodiment of this specification;
[0034] Figure 4 This is a deployment architecture diagram of a honeypot network provided in an embodiment of this specification. DETAILED DESCRIPTION
[0035] In order to make the purpose, technical solutions and advantages of the embodiments of this specification clearer, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are part of the embodiments of this specification, not all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this specification.
[0036] In related technologies, honeypot deployment solutions are only used to protect or lure attacks against systems or intranets, and the only purpose achieved is to protect the system or obtain preliminary attack data. This does play a protective role in the initial protection of the intranet, but traditional honeypot systems and their deployment solutions cannot fully meet the needs of attack capability testing for educational purposes, security personnel evidence collection, and attacker capability profiling.
[0037] Since traditional honeypot defense systems mainly focus on lure, and simulated decoy systems focus on systems with no / low protection and systems containing vulnerabilities, most simulations of services are still in the low-interaction simulation stage, which allows attackers to distinguish between honeypot baits and real machines at no cost, resulting in defense failure; on the other hand, since most vulnerabilities in simulated decoy systems are easy to attack, it is impossible to distinguish the attacker's capabilities and cannot meet functional indicators such as attack assessment.
[0038] In order to solve this technical problem, the inventors took into consideration during the research and development process: by expanding the simulation capabilities of existing honeypots and innovating the existing honeypot-to-honeynet deployment plan, while fully ensuring the basic protection capabilities of the honeypot, the ability requirements of the honeypot-honeynet environment for attacker capability assessment, attacker capability profiling, and security personnel evidence collection can be met. That is, based on the honeynet, all-round evidence collection can be performed on the attacker's attack capabilities, tool profiling, etc.
[0039] The inventive concepts of the embodiments of this specification are introduced below.
[0040] Please refer to Figure 1 , an embodiment of this specification provides a method for evaluating an attacker's attack capability, the method comprising:
[0041] Step 100: Deploy the honeypot network in the target network to be protected according to the preset deployment rules;
[0042] Step 102: Obtain attack data generated by the attacker on the honeypot network;
[0043] Step 104: Evaluate the attacker's attack capability based on the attack data.
[0044] In the embodiments of this specification, a honeypot network is deployed in the target network to be protected according to preset deployment rules, and then the attack data generated by the attacker on the honeypot network is obtained. In this way, the attack capability of the attacker can be evaluated based on the attack data. In this way, the attack capability of the attacker can be evaluated based on the honeypot network.
[0045] Described below Figure 1 How to perform the steps shown.
[0046] For step 100:
[0047] See also Figure 4 In one embodiment of the present specification, a honeypot network includes multiple first honeypot sub-networks deployed at different gradient levels, each first honeypot sub-network at each gradient level includes at least two second honeypot sub-networks of different types, and each second honeypot network includes a first honeypot without vulnerabilities, a second honeypot with vulnerabilities and no protection system, and a third honeypot with vulnerabilities and a protection system.
[0048] In the present embodiment, by configuring the environment within the honeypot and the network between honeypots, different levels of protection (i.e., forming a tree-like honeypot network of protection) can be formed, so that a capability assessment portrait can be made for network attackers in the region. That is, the service entrance of the protection object (i.e., the guarded target) is simulated, and multiple honeypots with different attack difficulties are deployed in a multi-angle and multi-level manner after the entrance probe, and they constitute a honeypot network. When the attacker breaks into the honeypot entrance, what will be scanned will be honeypots of different types and attack difficulties, and there will be a honeypot network with rich topology, and the honeypot network is completely isolated from the main working network (i.e., the network where the protection object is located). This not only ensures the security of the target network to be protected, but also can obtain detailed attack data of the attacker based on the degree of penetration of the attacker into the entire honeynet, and obtain rich attack data information for subsequent evidence collection and scoring.
[0049] In some implementations, the type of the second honeypot sub-network may be an application vulnerability type, a system vulnerability type, a mailbox type, etc., which is not specifically limited herein.
[0050] A honeypot refers to a bait network asset that is used to lure attackers into attacking it. The bait includes virtual assets such as hosts, services, and information. A honeynet (i.e., a honeypot network) refers to a bait network composed of multiple honeypots of different types deployed in cyberspace and interconnected with each other. A vulnerability refers to a system weakness that allows access to network assets through unauthorized means.
[0051] Protection systems may include, for example, firewalls, WAFs (Web Application Firewalls), IPSs, and HIPSs (Host Intrusion Prevent Systems). WAFs are firewalls specifically customized for web applications and designed with security policies tailored to HTTP / HTTPS protocols. These firewalls are used to protect web applications. HIPSs are host-monitoring defense systems that monitor system runtime and file changes to prevent malicious programs from invading or tampering with system information without permission.
[0052] To improve the simulation level of the decoy system, the simulation capabilities of existing honeypots have been expanded, for example, by converting low-interaction service simulation to medium- and high-interaction simulation. Simultaneously, the simulation of honeypots without vulnerabilities and those with protection systems has been increased. This approach addresses the technical issue of being unable to distinguish attacker capabilities and meet functional indicators such as attack assessment, as most vulnerabilities in simulated decoy systems are low-attack.
[0053] In one embodiment of this specification, the deployment rules include:
[0054] According to the direction of gradient level from shallow to deep, the simulation degree of the first honeypot sub-network gradually increases.
[0055] For example, the degree of honeypot simulation can be divided into three levels. During deployment, the simulation degree of the first honeypot sub-network of the third level can be set to the highest. In this way, the hacker's ability can be determined by detecting which honeypot the hacker can distinguish. The higher the level of the honeypot that the hacker can distinguish, the higher the hacker's ability.
[0056] In another embodiment of the present specification, the deployment rules include:
[0057] According to the gradient hierarchy from shallow to deep, the release time of the vulnerability of the first honeypot network gradually approaches the current evaluation time.
[0058] For example, honeynets can be deployed in levels according to the time when vulnerabilities are released. In this way, the newness of hackers' attack weapons can be confirmed by detecting which levels of vulnerabilities hackers can exploit to attack honeypots.
[0059] It is understandable that the above two deployment methods can be used in the same honeynet. The gradient level mentioned in the embodiments of this specification can be equivalent to the depth. The deployment method can use the Docker internal network protocol to build a honeypot virtual local area network, or to build a honeypot physical local area network.
[0060] Regarding step 102:
[0061] In one embodiment of the present specification, the attack data includes the following items: the gradient level of the attacked first honeypot network, the type and number of attacked second honeypot sub-networks, the release time of the attacked vulnerability, the protection products included in the attacked protection system, and the number of attacked first honeypots, second honeypots and third honeypots; wherein, the protection products include firewalls, WAFs, IPSs and HIPSs.
[0062] In this embodiment, by setting the items of attack data, it is possible to facilitate quantitative analysis of the attack data to accurately evaluate the attack capability of the attacker.
[0063] Of course, the attack capability can also be assessed manually, taking Table 1 as an example.
[0064] Table 1
[0065]
[0066]
[0067] For example, by using a fakeweb honeypot to simulate external web services within a protected network environment and deploying them on nodes at the same level, attackers cannot distinguish between real web services and, due to fakeweb's real-time simulation capabilities, do not impact service operations. At the same time, fakeweb intentionally exposes vulnerabilities in the honeypot or intercepts abnormal access traffic from legitimate web services, directing it to the backend honeypot network.
[0068] In the back-end honeypot network, virtual network device honeypots are purposefully deployed, including routing honeypots, firewalls, honeypots with obvious vulnerabilities, and honeypots with firewalls but without vulnerabilities. By observing the attackers' attacks on different types of honeypots in the honeynet, the attacker's data can be clearly collected.
[0069] Regarding step 104:
[0070] In one embodiment of this specification, step 104 may specifically include:
[0071] Based on the items included in the attack data, obtain the target assessment score corresponding to the attack data;
[0072] An assessment of the attacker's attack capability based on the target assessment score and preset grading rules.
[0073] In this embodiment, the target evaluation score corresponding to the attack data is obtained based on the items included in the attack data, and then the attacker's attack capability can be evaluated based on the target evaluation score and the preset grade scoring rules, thereby completing the rating of the attacker's threat.
[0074] In one embodiment of this specification, the step of “obtaining a target assessment score corresponding to the attack data based on the items included in the attack data” may specifically include:
[0075] Based on the items included in the attack data, determine the attack identifier corresponding to each item;
[0076] Determine an evaluation score corresponding to each attack identifier based on each attack identifier and a preset attack capability evaluation database; wherein the attack capability evaluation database includes multiple attack identifiers and evaluation scores corresponding to each attack identifier;
[0077] The evaluation scores corresponding to the attack identifiers are weighted and calculated to obtain the target evaluation scores corresponding to the attack data; wherein the attack capability evaluation database also includes the weight values corresponding to the attack identifiers.
[0078] In this embodiment, by using the attack identifier and attack capability assessment database, the assessment score of each item included in the attack data can be easily obtained, and then the assessment score corresponding to each attack identifier is weightedly calculated according to the weight value corresponding to each attack identifier to obtain the target assessment score corresponding to the attack data, thereby making the target assessment score more reasonable and standardized.
[0079] In summary, the above method, based on a rich honeypot simulation decoy system, effectively protects target network services by constructing a deeply scalable tree-like honeypot network at the same level as the protected network. By building network portals at the same level as the protected target services (or embedded in the target services), the honeynet system can guide attacks to the honeynet at the initial stage, deceiving attackers into believing that their network space is the protected target network space. At the same time, it guides and records the attacker's attack behavior within the honeynet, and based on the detailed data records of the attacker's attack process, it is possible to rank, collect evidence, and profile the attacker.
[0080] like Figure 2 、 Figure 3 As shown, the embodiment of this specification provides an attacker's attack capability assessment device. The device embodiment can be implemented by software, hardware, or a combination of software and hardware. From the hardware level, such as Figure 2 The figure shows a hardware architecture diagram of an electronic device where an attacker attack capability assessment device provided by an embodiment of this specification is located, except Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown, the electronic device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing messages, etc. Taking software implementation as an example, Figure 3 As shown, as a device in a logical sense, it is formed by the CPU of the electronic device in which it is located reading the corresponding computer program in the non-volatile memory into the internal memory and running it.
[0081] like Figure 3 As shown, this embodiment provides an attacker attack capability assessment device, which is applied to a detection node deployed in an intranet environment. The device includes:
[0082] A deployment module 300 is used to deploy the honeypot network in the target network to be protected according to preset deployment rules;
[0083] An acquisition module 302 is used to obtain attack data generated by an attacker on the honeypot network;
[0084] The evaluation module 304 is configured to evaluate the attack capability of the attacker based on the attack data.
[0085] In the embodiment of this specification, the deployment module 300 can be used to execute step 100 in the above method embodiment, the acquisition module 302 can be used to execute step 102 in the above method embodiment, and the evaluation module 304 can be used to execute step 104 in the above method embodiment.
[0086] In one embodiment of the present specification, the honeypot network includes multiple first honeypot sub-networks deployed at different gradient levels, and the first honeypot sub-network at each gradient level includes at least two second honeypot sub-networks of different types, and each of the second honeypot sub-networks includes a first honeypot without vulnerabilities, a second honeypot with vulnerabilities and no protection system, and a third honeypot with vulnerabilities and a protection system.
[0087] In one embodiment of the present specification, the deployment rules include:
[0088] As the gradient levels move from shallow to deep, the degree of simulation of the first honeypot sub-network gradually increases.
[0089] In one embodiment of the present specification, the deployment rules include:
[0090] According to the direction of the gradient level from shallow to deep, the release time of the vulnerability of the first honeypot sub-network gradually approaches the current evaluation time.
[0091] In one embodiment of the present specification, the attack data includes the following items: the gradient level of the attacked first honeypot network, the type and number of attacked second honeypot sub-networks, the release time of the attacked vulnerability, the protection products included in the attacked protection system, and the number of attacked first honeypots, second honeypots and third honeypots; wherein, the protection products include firewalls, WAFs, IPSs and HIPSs.
[0092] In one embodiment of this specification, the evaluation module is configured to perform the following operations:
[0093] Obtaining a target assessment score corresponding to the attack data based on the items included in the attack data;
[0094] An assessment of the attacker's attack capability based on the target assessment score and preset grading rules.
[0095] In one embodiment of the present specification, when executing the items included in the attack data to obtain the target evaluation score corresponding to the attack data, the evaluation module is configured to perform the following operations:
[0096] Determining, based on the items included in the attack data, an attack identifier corresponding to each item;
[0097] Determining an evaluation score corresponding to each attack identifier based on each attack identifier and a preset attack capability evaluation database; wherein the attack capability evaluation database includes multiple attack identifiers and evaluation scores corresponding to each attack identifier;
[0098] The evaluation scores corresponding to the attack identifiers are weightedly calculated to obtain a target evaluation score corresponding to the attack data; wherein the attack capability evaluation database also includes a weight value corresponding to each attack identifier.
[0099] It should be understood that the structures illustrated in the embodiments of this specification do not constitute a specific limitation on an attacker capability assessment device. In other embodiments of this specification, an attacker capability assessment device may include more or fewer components than illustrated, or may combine or separate certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0100] The information interaction, execution process, etc. between the modules in the above-mentioned device are based on the same concept as the method embodiments of this specification. For specific contents, please refer to the description in the method embodiments of this specification and will not be repeated here.
[0101] An embodiment of this specification further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, a method for evaluating the attack capability of an attacker in any embodiment of this specification is implemented.
[0102] An embodiment of this specification further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the processor executes a method for evaluating an attacker's attack capability according to any embodiment of this specification.
[0103] Specifically, a system or device equipped with a storage medium can be provided, on which software program codes that implement the functions of any of the above-mentioned embodiments are stored, and a computer (or CPU or MPU) of the system or device can be enabled to read and execute the program codes stored in the storage medium.
[0104] In this case, the program code read from the storage medium itself can realize the function of any one of the above embodiments, and thus the program code and the storage medium storing the program code constitute part of this specification.
[0105] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, the program code can be downloaded from a server computer via a communication network.
[0106] In addition, it should be clear that the functions of any of the above embodiments can be achieved not only by executing the program code read by the computer, but also by enabling the operating system operating on the computer to complete part or all of the actual operations based on the instructions of the program code.
[0107] In addition, it can be understood that the program code read from the storage medium is written into a memory provided in an expansion board inserted into the computer or into a memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or expansion module is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above embodiments.
[0108] It should be noted that, in this article, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical factors in the process, method, article or device comprising the elements.
[0109] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk, etc. Various media that can store program codes.
[0110] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this specification, rather than to limit them. Although this specification has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of this specification.
Claims
1. A method for evaluating an attacker's attack capability, characterized in that: include: Deploy the honeypot network in the target network to be protected according to the preset deployment rules; Obtain attack data generated by attackers on the honeypot network; Based on the attack data, evaluating the attack capability of the attacker; The honeypot network includes a plurality of first honeypot sub-networks deployed at different gradient levels, each first honeypot sub-network at each gradient level includes at least two second honeypot sub-networks of different types, each second honeypot network includes a first honeypot without vulnerabilities, a second honeypot with vulnerabilities and no protection system, and a third honeypot with vulnerabilities and a protection system; According to the gradient hierarchy from shallow to deep, the release time of the vulnerability of the first honeypot sub-network gradually approaches the current evaluation time; The attack data includes the following items: the gradient level of the attacked first honeypot network, the type and number of attacked second honeypot sub-networks, the release time of the attacked vulnerability, the protection products included in the attacked protection system, and the number of attacked first honeypots, second honeypots, and third honeypots; wherein the protection products include firewalls, WAFs, IPSs, and HIPSs; The evaluating the attack capability of the attacker based on the attack data includes: Obtaining a target assessment score corresponding to the attack data based on the items included in the attack data; An assessment of the attacker's attack capability based on the target assessment score and a preset grading rule; Obtaining a target assessment score corresponding to the attack data based on the items included in the attack data includes: Determining, based on the items included in the attack data, an attack identifier corresponding to each item; Determining an evaluation score corresponding to each attack identifier based on each attack identifier and a preset attack capability evaluation database; wherein the attack capability evaluation database includes multiple attack identifiers and evaluation scores corresponding to each attack identifier; The evaluation scores corresponding to the attack identifiers are weightedly calculated to obtain a target evaluation score corresponding to the attack data; wherein the attack capability evaluation database also includes a weight value corresponding to each attack identifier.
2. The method according to claim 1, characterized in that The deployment rules include: As the gradient levels move from shallow to deep, the degree of simulation of the first honeypot sub-network gradually increases.
3. A device for evaluating an attacker's attack capability, characterized in that: include: A deployment module is used to deploy the honeypot network in the target network to be protected according to the preset deployment rules; The acquisition module is used to obtain the attack data generated by the attacker on the honeypot network; An evaluation module, configured to evaluate the attack capability of the attacker based on the attack data; The honeypot network includes a plurality of first honeypot sub-networks deployed at different gradient levels, each first honeypot sub-network at each gradient level includes at least two second honeypot sub-networks of different types, each second honeypot network includes a first honeypot without vulnerabilities, a second honeypot with vulnerabilities and no protection system, and a third honeypot with vulnerabilities and a protection system; According to the gradient hierarchy from shallow to deep, the release time of the vulnerability of the first honeypot sub-network gradually approaches the current evaluation time; The attack data includes the following items: the gradient level of the attacked first honeypot network, the type and number of attacked second honeypot sub-networks, the release time of the attacked vulnerability, the protection products included in the attacked protection system, and the number of attacked first honeypots, second honeypots, and third honeypots; wherein the protection products include firewalls, WAFs, IPSs, and HIPSs; The evaluation module is used to perform the following operations: Obtaining a target assessment score corresponding to the attack data based on the items included in the attack data; An assessment of the attacker's attack capability based on the target assessment score and a preset grading rule; When executing the items included in the attack data to obtain the target evaluation score corresponding to the attack data, the evaluation module is configured to perform the following operations: Determining, based on the items included in the attack data, an attack identifier corresponding to each item; Determining an evaluation score corresponding to each attack identifier based on each attack identifier and a preset attack capability evaluation database; wherein the attack capability evaluation database includes multiple attack identifiers and evaluation scores corresponding to each attack identifier; The evaluation scores corresponding to the attack identifiers are weightedly calculated to obtain a target evaluation score corresponding to the attack data; wherein the attack capability evaluation database also includes a weight value corresponding to each attack identifier.
4. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method according to any one of claims 1 to 2 is implemented.
5. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed in a computer, the computer is caused to execute the method according to any one of claims 1 to 2.
Citation Information
Patent Citations
Vulnerability simulation overload honeypot method
CN101567887A
Attacker threat scoring method and related device
CN114357447A