Active network security defense method and system for distributed network information publishing system
By setting up decoy machines and listeners in a distributed network information publishing system to monitor and sniff packets for IP source tracing, construct feature vectors, and launch proactive attacks, the problems of high difficulty, low efficiency, and high cost in existing technologies are solved, achieving highly efficient security defense.
Patent Information
- Application Number
- CN202310042494.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-28
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-01-28
AI Technical Summary
Existing network security defense methods are difficult, inefficient, and costly in distributed network information publishing systems, and manual monitoring is limited by personnel skill levels, making it difficult to effectively respond to network attacks.
In a distributed network information publishing system, decoy machines are set up to listen to sniffing packets and trace IPs. Feature vectors of suspected hacker IPs are constructed, their danger level is calculated, and proactive attacks are launched. Unicast reverse routing lookup technology and custom communication protocols are used for defense.
It improves the preventive capabilities of distributed information publishing systems, reduces labor costs, achieves efficient and rapid security defense, and simplifies the implementation process.
Smart Images

Figure CN116055185B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of active network security defense technology, and in particular to an active network security defense method and system for a distributed network information publishing system. BACKGROUND
[0002] As a typical public network service system, the distributed network information publishing system has transparent IP and network service protocols, and is generally used as an information center platform of news and central units, and is also vulnerable to attacks by hackers or hostile forces. How to deal with network attacks is a huge technical knowledge system, such as 0day vulnerabilities, permission cracking, DDoS traffic attacks, etc.
[0003] The previous design methods have summarized firewall mode, internal network protocol mode, and real-time operation inspection mode. Among them, the firewall mode defines the access IP access, protocol type, and connection conditions of various network units, and blocks all that do not meet the rules. The permission cracking method is to decouple the front end, business logic, database, etc. by complex software engineering, and separate the permissions and even the hardware management, and establish multiple hot backups and cold backups to prevent being attacked at the same time. The third method is the white hat real-time operation monitoring mode, which is more flexible and efficient. Because 0day or system vulnerabilities may exceed the ability of the original software and hardware developers, professional white hat teams monitor traffic and network packet changes in real time, judge risks based on experience, shut down services or increase servers to respond to DDoS attacks, which is currently the most effective and highest level of network security protection.
[0004] However, the above three methods have great problems. First, the firewall setting is tedious, and any omission will cause attack vulnerabilities, and even the firewall itself may attract the interest of hackers because of the significant data resources it protects. Second, the permission cracking method requires a high-level design model, and the software modules are difficult to cooperate after decoupling, which may cause authorization confusion or even permission dead loop state, and if the highest permission account is attacked, there is still a risk of collapse. Third, the white hat manual monitoring is mainly limited by personnel level, and it is difficult for people who are not proficient in network attack and defense to judge abnormal changes from traffic and network packets, and manual work requires concentration of energy, and Internet information services are generally 24 hours, and if it is a global service, there is no distinction between busy and idle time, and whether it is a 3-shift or other way, it will increase the pressure on personnel and increase labor costs. SUMMARY
[0005] In view of the above analysis, the embodiments of the present application aim to provide an active network security defense method and system for a distributed network information publishing system to solve the problems of existing network security defense methods, such as difficulty in implementation, low efficiency, and high cost.
[0006] On one hand, embodiments of the present invention provide a proactive network security defense method for a distributed network information publishing system, comprising the following steps:
[0007] Decoy machines are set up in a distributed network information publishing system;
[0008] A listener is set up on the access port of an internal network machine accessible to the decoy machine. The listener listens for sniffing packets from the decoy machine and uses the sniffing packets to trace the IP to obtain the suspected hacker IP and construct the feature vector of the suspected hacker IP.
[0009] Calculate the risk level of suspected hacker IPs based on their feature vectors;
[0010] Actively attack suspected hacker IPs based on their perceived danger level.
[0011] Based on further improvements to the above technical solution, suspected hacker IPs are obtained through IP tracing based on sniffed packets, and feature vectors of suspected hacker IPs are constructed, including:
[0012] The source IP of each sniffing packet is obtained using unicast reverse routing lookup technology. The source IP, network traffic, and protocol version of each sniffing packet are recorded. The source IP is a suspected hacker IP.
[0013] The cumulative network traffic, cumulative number of protocol versions, and cumulative number of sniffing attempts for each suspected hacker IP constitute the feature vector of each suspected hacker IP.
[0014] Based on further improvements to the above technical solution, proactive attacks are launched against suspected hacker IPs according to their perceived danger level, including:
[0015] The attack frequency of each suspected hacker IP is calculated based on its perceived danger level.
[0016] Actively attack each suspected hacker IP based on its attack frequency.
[0017] Based on further improvements to the above technical solution, the following formula is used to calculate the risk level of each suspected hacker IP:
[0018]
[0019] Among them, R i W represents the danger level of the i-th suspected hacker IP. i B represents the danger weight of the i-th suspected hacker IP. i X represents the number of routing nodes from the i-th suspected hacker IP address to the internal network machine where the eavesdropper is located. ijLet m represent the j-th element of the feature vector of the i-th suspected hacker IP, and m represent the number of elements in the feature vector.
[0020] Based on further improvements to the above technical solution, the danger weight of suspected hacker IPs is calculated using the following formula:
[0021]
[0022] Among them, T current Tlast represents the current time. i ATT represents the last time the i-th suspected hacker IP was sniffed. i This represents the cumulative number of sniffing attempts on the i-th suspected hacker IP.
[0023] Based on further improvements to the above technical solution, the attack frequency of each suspected hacker IP is calculated using the following formula:
[0024]
[0025] Among them, R i T represents the danger level of the i-th suspected hacker IP. current T represents the current time. start Online information release time, W news This indicates the timeliness of the impact of the published information; Mod(·) indicates rounding down.
[0026] Based on further improvements to the above technical solution, the following formula is used to calculate the timeliness of the impact of the released information:
[0027] According to W news =a*P calculates the time-to-effect of the information's impact, where a represents the basic time of the information's impact;
[0028] in,
[0029] Where L represents the feature vector of the published information, W represents the feature weight, and P represents the importance of the published information.
[0030] On the other hand, embodiments of the present invention provide a proactive network security defense system for a distributed network information publishing system, comprising:
[0031] A decoy machine, wherein the decoy machine is installed in a distributed network information publishing system;
[0032] The listening module is set at the access port of the internal network machine accessible to the decoy machine. It is used to listen for sniffing packets from the decoy machine, trace the IP source based on the sniffing packets to obtain the suspected hacker IP, and construct the feature vector of the suspected hacker IP.
[0033] The risk assessment module is used to calculate the risk level of a suspected hacker IP based on its feature vector.
[0034] The proactive attack module is used to proactively attack suspected hacker IPs based on their perceived danger level.
[0035] Based on further improvements to the above technical solution, the listening module uses the following method to trace the IP source of suspected hacker IPs based on sniffed packets and constructs a feature vector of the suspected hacker IPs:
[0036] The source IP of each sniffing packet is obtained using unicast reverse routing lookup technology. The source IP, network traffic, and protocol version of each sniffing packet are recorded. The source IP is a suspected hacker IP.
[0037] The cumulative network traffic, cumulative number of protocol versions, and cumulative number of sniffing attempts for each suspected hacker IP constitute the feature vector of each suspected hacker IP.
[0038] Based on further improvements to the above technical solution, the active attack module actively attacks suspected hacker IPs according to their perceived danger level, including:
[0039] The attack frequency of each suspected hacker IP is calculated based on its perceived danger level.
[0040] Actively attack each suspected hacker IP based on its attack frequency.
[0041] Compared with existing technologies, this invention sets up decoy machines in a distributed network information publishing system to lure hackers into sniffing. By acquiring and analyzing sniffed data packets, it identifies suspected hacker IPs and launches proactive attacks before a full-scale attack, blocking the attacker's ability to act for a certain period of time. This proactive defense improves the preventive capabilities of the distributed information publishing system, enabling efficient and rapid security prevention. The method is simple, easy to implement, and reduces labor costs.
[0042] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description
[0043] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.
[0044] Figure 1 This is a flowchart of a proactive network security defense method for a distributed network information publishing system according to an embodiment of the present invention;
[0045] Figure 2 This is a block diagram of the proactive network security defense system of the distributed network information publishing system according to an embodiment of the present invention. Detailed Implementation
[0046] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.
[0047] The design goal of proactive network security defense in distributed network information publishing systems is to achieve maximum defense effectiveness with minimal resources. Based on this, we investigated the general process of hacker attacks, which can be summarized as follows:
[0048] 1. If it's a publicly accessible website, collect the list of IP addresses that hold DNS records.
[0049] 2. Perform a simple password test on each IP address.
[0050] 3. If complex passwords and robust firewalls prevent connection, then purchase one-day vulnerabilities in the operating system or other middleware to perform overflow attacks.
[0051] 4. If you can obtain the account, try upgrading it to the highest privilege level.
[0052] 5. Obtain all data information on this machine.
[0053] 6. This machine allows access to other machines in the distributed system because the internal network has higher connection privileges.
[0054] 7. Launch a full-scale attack at a specified time to paralyze the host or tamper with data for ransom.
[0055] Therefore, based on the above hacker attack process, it is clear that automatic defense is impossible against software and hardware zero-day vulnerabilities that are completely unpredictable. However, the discoverers of zero-day vulnerabilities, besides the developers themselves, are also highly skilled computer users. The international selling price of zero-day vulnerabilities has always been high, so for hackers whose primary goal is profit, zero-day attacks are not a priority.
[0056] Therefore, the approach considered in this invention is to anticipate and mitigate the level of a hacker's attack before it launches a full-scale attack.
[0057] Based on this, a specific embodiment of the present invention discloses a proactive network security defense method for a distributed network information publishing system, such as... Figure 1 As shown, it includes the following steps:
[0058] S1. Set up decoy machines in a distributed network information publishing system;
[0059] S2. Set up a listener on the access port of the internal network machine accessible to the decoy machine. The listener listens for sniffing packets from the decoy machine. Based on the sniffing packets, perform IP tracing to obtain the suspected hacker IP and construct the feature vector of the suspected hacker IP.
[0060] S3. Calculate the risk level of suspected hacker IPs based on their feature vectors;
[0061] S4. Launch proactive attacks on suspected hacker IPs based on their perceived danger level.
[0062] By setting up decoy machines in a distributed network information publishing system to lure hackers into sniffing, and by acquiring and analyzing sniffed data packets, suspected hacker IPs can be identified. This allows for proactive attacks before a full-scale attack, blocking the attacker's ability to act for a certain period of time, thus improving the preventative capabilities of the distributed information publishing system. This method is efficient, fast, simple, easy to implement, and reduces labor costs.
[0063] When implementing this, the decoy must be realistic enough. Therefore, the decoy bot must maintain the same static data (i.e., data from common websites without a database) such as HTML data and public access interfaces such as HTTP port 80, and be identical to other protected websites when refreshing or connecting directly via IP.
[0064] To ensure system security, the decoy machines must be sufficiently isolated. During implementation, the decoy machines maintain data publishing in only two ways: physically isolated hard copies or one-way data retrieval from other services. Data retrieval can only be achieved through a custom communication protocol, which can be implemented based on the TCP protocol. The communication collaboration includes the IP addresses of both communicating parties and the communication direction. The protocol restricts data communication to be initiated only by the decoy machine, and the communication data is confined to a fixed, independent, static folder on the server, thus ensuring that data can only be retrieved from a fixed location on the server and is not vulnerable to intrusive hacker attacks.
[0065] During implementation, the decoy bots should be widely publicized. The decoy bots' IP addresses need to be set at the top of all DNS lists for the published portal address, synchronized to all visible DNS servers.
[0066] For security reasons, no other data is stored on the decoy machine during implementation. All account passwords for the decoy machine are weak passwords that meet certain conditions.
[0067] According to current literature and cybersecurity attack and defense case studies, once a hacker gains access to a machine with an internal network address, they will actively sniff all machines on the internal network, which has become a standard attack procedure. In order to pinpoint the suspected hacker's IP address, listeners are set up on the access ports of internal network machines accessible by the decoy machine. For example, port listeners are set up on the standard network protocol interfaces of the internal network machines, such as TCP port 21 and HTTP port 80, and the access signal from the decoy machine is used as a trigger.
[0068] Specifically, the listener monitors sniffing packets from the decoy machine, does not respond to any requests from the decoy machine, and uses the sniffed packets to trace IPs to obtain suspected hacker IPs, constructing feature vectors for these suspected hacker IPs. This includes:
[0069] S21. Use unicast reverse routing lookup technology to obtain the source IP of each sniffing packet, and record the source IP, network traffic and protocol version of each sniffing packet; the source IP is a suspected hacker IP;
[0070] S22. The cumulative network traffic, cumulative number of protocol versions, and cumulative number of sniffing attempts for each suspected hacker IP constitute the feature vector of each suspected hacker IP.
[0071] In practice, Wireshark can be used to listen for and sniff data packets. Unicast reverse routing lookup technology can be used to trace the source IP of the sniffed packet (i.e., the sniffing source IP of the sniffed packet), the protocol name and version of the data packet, and the size of the data packet. The size of the data packet is the network traffic.
[0072] During implementation, if the protocol of the current sniffing packet is different from the protocol of the historical sniffing packets, or if the protocols are the same but the versions are different, the cumulative number of protocol versions will be incremented by one.
[0073] Network protocols are layered, and different protocols imply different levels of access. The more types of protocols a hacker uses, the greater the potential danger. Data packet size also reflects a hacker's intent and potential attack capability; larger packets indicate stronger potential attacks. More sniffing attempts also signify a stronger intent. Therefore, in practice, the cumulative network traffic, cumulative number of protocol versions, and cumulative number of accesses of the source IP are used as the feature vector of the source IP, i.e., the feature vector of a suspected hacker IP.
[0074] It should be noted that the elements of the feature vector of suspected hacker IPs are normalized data. For example, for the dimension of cumulative network traffic, the mean and variance of the cumulative network traffic of all suspected hacker IPs are first calculated, according to the formula... Calculate the normalized cumulative network traffic x for each suspected hacker IP address i , where x meanx represents the average cumulative network traffic of all suspected hacker IPs. std This represents the variance of the cumulative network traffic across all suspected hacker IPs.
[0075] Specifically, in step S3, the danger level of each suspected hacker IP is calculated using the following formula:
[0076]
[0077] Among them, R i W represents the danger level of the i-th suspected hacker IP. i B represents the danger weight of the i-th suspected hacker IP. i X represents the number of routing nodes from the i-th suspected hacker IP address to the internal network machine where the eavesdropper is located. ij Let m represent the j-th element of the feature vector of the i-th suspected hacker IP, and m represent the number of elements in the feature vector.
[0078] The closer a routing node is to the routing node of the publishing system server, the greater its risk level. Therefore, the reciprocal of the number of routing nodes from the suspected hacker IP to the internal network machine where the listener is located is added to the risk level calculation of the suspected hacker IP. This allows for a more accurate calculation of the risk level of each suspected hacker IP, facilitating proactive defense against attacks based on the risk level and thus improving the security of the information publishing system.
[0079] Specifically, the danger weight of a suspected hacker IP is calculated using the following formula:
[0080]
[0081] Among them, T current Tlast represents the current time. i ATT represents the last time the i-th suspected hacker IP was sniffed. i This represents the cumulative number of sniffing attempts on the i-th suspected hacker IP.
[0082] The more recent the attack, the more likely the hacker's server is in a hot state; the hotter the server, the more aggressive the attack is. Therefore, the above formula is used to calculate the danger weight of suspected hacker IPs.
[0083] After calculating the risk level of each suspected hacker IP, proactive attacks are launched against the suspected hacker IPs based on their risk levels. Specifically, step S4 includes:
[0084] S41. Calculate the attack frequency of each suspected hacker IP based on its risk level;
[0085] S42. Launch proactive attacks on each suspected hacker IP based on its attack frequency.
[0086] Specifically, in step S41, the attack frequency of each suspected hacker IP is calculated using the following formula:
[0087]
[0088] Among them, R i T represents the danger level of the i-th suspected hacker IP. current T represents the current time. start Online information release time, W news This indicates the timeliness of the impact of the published information; Mod(·) indicates rounding down.
[0089] Information is time-sensitive. Generally speaking, the newer and more timely the information, the higher its value. The value of information decreases over time. Therefore, the closer the information is to its release time, the higher the attack frequency; the further back in time the information is released, the lower the attack frequency.
[0090] Specifically, the duration of the impact of the published information is calculated using the following formula:
[0091] According to W news =a*P calculates the time-to-effect of the information's impact, where a represents the basic time of the information's impact and P represents the importance of the information.
[0092] Different types of information may have different basic impact periods. For example, news information can usually be set to 48 hours, while government announcements can be set to 720 hours.
[0093] Specifically, the importance of the published information is calculated using the following formula:
[0094]
[0095] Where L represents the feature vector of the published information, and W represents the feature weight.
[0096] In practice, the feature vector L of the publicly available information can be composed of the expected number of visits, the expected network traffic per unit time, the length of the publicly available information, and the type of the publicly available information.
[0097] Expected visit volume and expected network traffic per unit time can be obtained based on the average visit volume and average network traffic per unit time of similar information in the past.
[0098] The type of public information is the importance level of the public information. The more important the information, the higher the importance level. For example, there are a total of 6 importance levels, and the information at level 6 is more important.
[0099] In implementation, the elements of the feature weights W correspond one-to-one with the elements of the feature vector of the published information, and their values can be obtained from all historical published information. For example, for the visit volume feature, the mean and variance of the visit volume of historical published information in the information publishing system are calculated, and the variance is divided by the mean to obtain the weight of the visit volume dimension in the feature weights W.
[0100] After calculating the attack frequency of each suspected hacker IP, an active attack is launched on each suspected hacker IP based on its attack frequency.
[0101] Since the hacker's own ports are also in a standard protocol connection state when infiltrating the system, they can be actively attacked. This can be done by using standard protocols and port polling for a DDoS attack. The attack order can be based on the perceived danger level of the suspected hacker IPs, from highest to lowest. Active attacks should be launched against the suspected hacker IPs according to their perceived danger level.
[0102] It should be noted that the calculated attack frequency is the theoretical attack frequency. In practice, it is not necessary to strictly follow this frequency for subsequent active attacks. Attacks can be carried out according to this frequency, or the actual attack frequency can be calculated based on this theoretical attack frequency.
[0103] For example, if the overall attack capability of the attacking group is θ, then the actual attack frequency against each suspected hacker IP can be calculated using the formula... The calculation yields, where F i This represents the theoretical attack frequency of the i-th suspected hacker IP. This represents the actual attack frequency of the i-th suspected hacker IP.
[0104] During implementation, an attack stop threshold is set. If the actual attack frequency of a suspected hacker IP is less than the attack threshold, then attacks on that suspected hacker IP will be stopped.
[0105] A specific embodiment of the present invention discloses a proactive network security defense system for a distributed network information publishing system, such as... Figure 2 As shown, it includes:
[0106] A decoy machine, wherein the decoy machine is installed in a distributed network information publishing system;
[0107] The listening module is set at the access port of the internal network machine accessible to the decoy machine. It is used to listen for sniffing packets from the decoy machine, trace the IP source based on the sniffing packets to obtain the suspected hacker IP, and construct the feature vector of the suspected hacker IP.
[0108] The risk assessment module is used to calculate the risk level of a suspected hacker IP based on its feature vector.
[0109] The proactive attack module is used to proactively attack suspected hacker IPs based on their perceived danger level.
[0110] Preferably, the listening module uses the following method to perform IP tracing based on sniffed packets to obtain suspected hacker IPs and constructs a feature vector of the suspected hacker IPs:
[0111] The source IP of each sniffing packet is obtained using unicast reverse routing lookup technology. The source IP, network traffic, and protocol version of each sniffing packet are recorded. The source IP is a suspected hacker IP.
[0112] The cumulative network traffic, cumulative number of protocol versions, and cumulative number of sniffing attempts for each suspected hacker IP constitute the feature vector of each suspected hacker IP.
[0113] Preferably, the active attack module actively attacks suspected hacker IPs based on their perceived danger level, including:
[0114] The attack frequency of each suspected hacker IP is calculated based on its perceived danger level.
[0115] Actively attack each suspected hacker IP based on its attack frequency.
[0116] The above-described method and system embodiments are based on the same principles, and their related aspects can be referenced from each other to achieve the same technical effects. For specific implementation processes, please refer to the foregoing embodiments, which will not be repeated here.
[0117] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.
[0118] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
Claims
1. A proactive network security defense method for a distributed network information publishing system, characterized in that, Includes the following steps: Decoy machines are set up in a distributed network information publishing system; A listener is set up on the access port of an internal network machine accessible to the decoy machine. The listener listens for sniffing packets from the decoy machine and uses the sniffing packets to trace the IP to obtain the suspected hacker IP and construct the feature vector of the suspected hacker IP. Calculate the risk level of suspected hacker IPs based on their feature vectors; Actively attack suspected hacker IPs based on their perceived danger level. The danger level of each suspected hacker IP is calculated using the following formula: ; in, This indicates the danger level of the i-th suspected hacker IP. This represents the danger weight of the i-th suspected hacker IP. This represents the number of routing nodes from the i-th suspected hacker IP address to the internal network machine where the eavesdropper is located. Let represent the j-th element of the feature vector of the i-th suspected hacker IP, and m represent the number of elements in the feature vector; Proactive attacks are launched against suspected hacker IPs based on their perceived danger level, including: The attack frequency of each suspected hacker IP is calculated based on its perceived danger level. Based on the order of the suspected hacker IPs from most dangerous to least dangerous, proactive attacks are launched against each suspected hacker IP according to its attack frequency. The attack frequency of each suspected hacker IP is calculated using the following formula: ; in, This indicates the danger level of the i-th suspected hacker IP. Indicates the current time. Online information release time Indicates the timeliness of the impact of the published information. Indicates rounding down; The normalized cumulative network traffic, cumulative number of protocol versions, and cumulative number of sniffing attempts for each suspected hacker IP constitute the feature vector of each suspected hacker IP.
2. The proactive network security defense method for the distributed network information publishing system according to claim 1, characterized in that, Based on the sniffed packets, IP tracing was used to identify suspected hacker IPs, including: The source IP of each sniffing packet is obtained by using unicast reverse routing lookup technology, and the source IP, network traffic and protocol version of each sniffing packet are recorded; the source IP is a suspected hacker IP.
3. The proactive network security defense method for a distributed network information publishing system according to claim 1, characterized in that, The danger weight of a suspected hacker IP is calculated using the following formula: ; in, Indicates the current time. This indicates the time of the last sniffing attempt by the i-th suspected hacker IP. This represents the cumulative number of sniffing attempts on the i-th suspected hacker IP.
4. The proactive network security defense method for a distributed network information publishing system according to claim 1, characterized in that, The following formula is used to calculate the duration of the impact of published information: according to Calculate the timeliness of the impact of the published information, among which, This indicates the basic timeframe of the information's impact; in, ; Where L represents the feature vector of the published information, W represents the feature weight, and P represents the importance of the published information.
5. A proactive network security defense system for a distributed network information publishing system, characterized in that: include: A decoy machine, wherein the decoy machine is installed in a distributed network information publishing system; The listening module is set at the access port of the internal network machine accessible to the decoy machine. It is used to listen for sniffing packets from the decoy machine, trace the IP source based on the sniffing packets to obtain the suspected hacker IP, and construct the feature vector of the suspected hacker IP. The risk assessment module is used to calculate the risk level of a suspected hacker IP based on its feature vector. The proactive attack module is used to proactively attack suspected hacker IPs based on their perceived danger level. The danger level of each suspected hacker IP is calculated using the following formula: ; in, This indicates the danger level of the i-th suspected hacker IP. This represents the danger weight of the i-th suspected hacker IP. This represents the number of routing nodes from the i-th suspected hacker IP address to the internal network machine where the eavesdropper is located. Let represent the j-th element of the feature vector of the i-th suspected hacker IP, and m represent the number of elements in the feature vector; The proactive attack module initiates proactive attacks on suspected hacker IPs based on their perceived danger level, including: The attack frequency of each suspected hacker IP is calculated based on its perceived danger level. Based on the order of the suspected hacker IPs from most dangerous to least dangerous, proactive attacks are launched against each suspected hacker IP according to its attack frequency. The attack frequency of each suspected hacker IP is calculated using the following formula: ; in, This indicates the danger level of the i-th suspected hacker IP. Indicates the current time. Online information release time Indicates the timeliness of the impact of the published information. Indicates rounding down; The normalized cumulative network traffic, cumulative number of protocol versions, and cumulative number of sniffing attempts for each suspected hacker IP constitute the feature vector of each suspected hacker IP.
6. The proactive network security defense system of the distributed network information publishing system according to claim 5, characterized in that, The listening module uses the following method to trace the IP of suspected hackers based on sniffed packets: The source IP of each sniffing packet is obtained by using unicast reverse routing lookup technology, and the source IP, network traffic and protocol version of each sniffing packet are recorded; the source IP is a suspected hacker IP.
Citation Information
Patent Citations
Intelligent network security system based on big data analysis
CN112804204A
Monitoring analysis method, device and equipment of network terminal and storage medium
CN114363080A