A honeypot-based network attack protection method and system
By performing risk classification and honeypot evaluation of cyber attacks, and optimizing honeypot deployment with trapping rate and defense success rate, the problem of insufficient dynamic adjustment of honeypots in the existing technology is solved, and the comprehensiveness and accuracy of cyberattack protection is improved.
Patent Information
- Application Number
- CN202310591632.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2043-05-24
AI Technical Summary
The existing technology fails to effectively adjust honeypot dynamically in combination with factors such as trapping rate and defense success rate, resulting in more types of cyberattacks or higher potential dangers that may lead to network information leakage.
By dividing cyberattacks into high-risk and low-risk types, determining important cyberattacks based on the number of attacks, methods and targets, and evaluating them in combination with the trapping rate and defense success rate of honeypots, optimizing the deployment and analysis scope of honeypots.
Dynamic adjustment of honeypots has been achieved, comprehensive and accurate in risk screening and evaluation of network attacks, and ensure the security and protection of network communications.
Smart Images

Figure CN116599733B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a network attack protection method and system based on a honeypot. Background Art
[0002] In order to achieve the protection against network attacks, in the invention patent publication number CN114448731B, "Honeypot Deployment Method, Device, Equipment and Computer Readable Medium", by analyzing attack data and packet capture data, obtaining the attack characteristics of attack behaviors, and storing the attack characteristics in a database; when the attack characteristics in the database meet the first preset condition and the current honeypot resources meet the second preset condition, adding a honeypot that matches the attack characteristics, but there are the following technical problems:
[0003] It does not consider determining the actual operation situation of the honeypot by combining the trapping rate and the defense success rate, etc. For network attack types with a large number of attacks or greater potential risks, if dynamic adjustment cannot be carried out in combination with the analysis results, a series of problems such as network information leakage may occur.
[0004] In view of the above technical problems, the present invention provides a network attack protection method and system based on a honeypot. Summary of the Invention
[0005] To achieve the object of the present invention, the present invention adopts the following technical solutions:
[0006] According to one aspect of the present invention, a network attack protection method based on a honeypot is provided.
[0007] A network attack protection method based on a honeypot, characterized in that it specifically includes:
[0008] S11 Based on the attack mode and attack target of the network attack, dividing the network attack into high-risk network attacks and low-risk network attacks, and determining important network attacks based on the number of attacks, attack mode, and attack target of the low-risk network attacks;
[0009] S12 Based on the number of attacks of the high-risk network attacks, the number of attacks of the important network attacks, and the number of attacks of the low-risk network attacks, determining whether it is necessary to analyze all the honeypots. If so, go to step S14; if not, go to step S13;
[0010] S13 Based on the decoy rate and defense success rate of honeypots, the running states of the honeypots for high-risk network attacks and the honeypots for important network attacks are respectively evaluated to obtain evaluation results, and based on the evaluation results, the number of attacks of high-risk network attacks, important network attacks, and low-risk network attacks, it is determined whether it is necessary to analyze the honeypots for low-risk network attacks. If so, go to step S14; if not, determine the problem honeypots and the deployment quantity of honeypots according to the evaluation results;
[0011] S14 Analyze all honeypots based on the decoy rate and defense success rate of honeypots to obtain analysis results, and determine the problem honeypots and the deployment quantity of honeypots according to the analysis results.
[0012] By determining important network attacks based on the number of attacks, attack methods, and attack targets of low-risk network attacks, the screening of important network attacks with relatively high risks in low-risk network attacks is realized from multiple perspectives, and it also lays a foundation for further determining the scope of honeypot analysis.
[0013] By first determining whether it is necessary to analyze all honeypots based on the number of attacks of high-risk network attacks, important network attacks, and low-risk network attacks, the judgment of running risks is realized from the perspective of the number of attacks of different types. On the basis of ensuring the running efficiency, the comprehensiveness of honeypot analysis is also ensured.
[0014] By further combining the running states of the honeypots for high-risk network attacks and the honeypots for important network attacks to obtain evaluation results, and based on the evaluation results, the number of attacks of high-risk network attacks, important network attacks, and low-risk network attacks, it is determined whether it is necessary to analyze the honeypots for low-risk network attacks, thereby further realizing the further confirmation of the risks of network attacks and further combining the evaluation results of honeypots, ensuring the comprehensiveness and accuracy of the evaluation.
[0015] A further technical solution is that the attack methods include message tampering, message forgery, denial of service, and data eavesdropping; the attack targets include network ports, network messages, and user data.
[0016] A further technical solution is that the high-risk network attacks and low-risk network attacks are determined according to the threat degree of the attack methods and attack targets of the network attacks to the normal operation of network operation servers or terminals.
[0017] A further technical solution is that the specific steps for determining whether it is necessary to analyze all honeypots are as follows:
[0018] S21 determines a high - risk coefficient based on the number of attacks of the high - risk network attack, and determines whether it is necessary to analyze all honeypots based on the high - risk coefficient. If so, analyze all honeypots; if not, proceed to step S22;
[0019] S22 determines an important - risk coefficient based on the number of attacks of the important network attack, and determines whether it is necessary to analyze all honeypots based on the important - risk coefficient and the high - risk coefficient. If so, analyze all honeypots; if not, proceed to step S23;
[0020] S23 determines the weights of the high - risk network attack, the important network attack, and the low - risk network attack based on the threat level of the network attack. Then, it corrects the number of attacks of the high - risk network attack based on the weight of the high - risk network attack to obtain the corrected number of attacks of the high - risk network attack, corrects the number of attacks of the important network attack based on the weight of the important network attack to obtain the corrected number of attacks of the important network attack, and corrects the number of attacks of the low - risk network attack based on the weight of the low - risk network attack to obtain the corrected number of attacks of the low - risk network attack;
[0021] S24 determines the risk coefficient of the network attack based on the corrected number of attacks of the high - risk network attack, the important network attack, and the low - risk network attack, and determines whether it is necessary to analyze all honeypots based on the risk coefficient.
[0022] Furthermore, the technical solution lies in that the threat level of the network attack is determined according to the attack method and the attack target of the network attack, and specifically, the entropy value method is used for determination.
[0023] Furthermore, the specific steps for determining whether it is necessary to analyze the honeypots of the low - risk network attack are as follows:
[0024] S31 determines the proportion of the honeypots with problems in the honeypots for the high - risk network attack as the high - risk problem honeypot proportion based on the evaluation result, and obtains a high - risk evaluation factor based on the high - risk problem honeypot proportion and the number of attacks of the high - risk network attack;
[0025] S32 determines the proportion of the honeypots with problems in the honeypots for the important network attack as the important - problem honeypot proportion based on the evaluation result, and obtains an important evaluation factor based on the important - problem honeypot proportion and the number of attacks of the important network attack;
[0026] S33 uses the sum of the number of attacks of the high-risk cyber attacks and the number of attacks of the important cyber attacks as the evaluated attack count sum, and uses the ratio of the evaluated attack count sum to the number of attacks of the low-risk cyber attacks as the evaluated count ratio;
[0027] S34 determines the evaluated risk of the cyber attacks based on the evaluated count ratio, the high-risk evaluation factor, and the important evaluation factor, and determines whether it is necessary to analyze the honeypot of the low-risk cyber attacks based on the evaluated risk.
[0028] A further technical solution is that when the evaluated risk is greater than the set value, analyze the honeypot of the low-risk cyber attacks, where the set value is determined according to the number of the honeypots and the number of attacks of the cyber attacks, and the more the number of the honeypots and the more the number of attacks of the cyber attacks, the greater the set value.
[0029] A further technical solution is to determine the problem honeypots and the deployment quantity of the honeypots according to the evaluation result, specifically including:
[0030] Optimize the problem honeypots, and use the optimized problem honeypots and the existing non-problematic honeypots as alternative honeypots, and determine the quantity of the alternative honeypots for the cyber attacks of different attack methods based on the attack methods and the number of attacks of the cyber attacks.
[0031] On the other hand, an embodiment of the present application provides a computer system, including: a memory and a processor connected by communication, and a computer program stored on the memory and capable of running on the processor, wherein: when the processor runs the computer program, it executes the above-mentioned method for protecting cyber attacks based on honeypots.
[0032] On the other hand, the present invention provides a computer storage medium, on which a computer program is stored, and when the computer program is executed in a computer, the computer is made to execute the above-mentioned method for protecting cyber attacks based on honeypots.
[0033] Other features and advantages will be described in the following description, and some will become obvious from the description, or will be understood by implementing the present invention. The objectives and other advantages of the present invention are achieved and obtained by the structure specifically pointed out in the description and the drawings.
[0034] To make the above objectives, features, and advantages of the present invention more obvious and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, makes a detailed description as follows. Description of the Drawings
[0035] By referring to the drawings and describing its exemplary embodiments in detail, the above and other features and advantages of the present invention will become more obvious.
[0036] Figure 1 is a flowchart of a honeypot-based network attack protection method according to Embodiment 1.
[0037] Figure 2 is a framework diagram of a computer storage medium according to Embodiment 2. Detailed implementation manners
[0038] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Like reference numerals in the figures denote like or similar structures, and thus their detailed description will be omitted.
[0039] The terms "a", "an", "the", and "said" are used to denote the presence of one or more elements / components / etc.; the terms "comprising" and "having" are used to mean an open inclusion and mean that there may be additional elements / components / etc. in addition to the listed elements / components / etc.
[0040] Embodiment 1
[0041] To solve the above problems, according to one aspect of the present invention, as Figure 1 shown, a honeypot-based network attack protection method is provided, which specifically includes:
[0042] S11 Based on the attack method and attack target of the network attack, divide the network attack into high-risk network attacks and low-risk network attacks, and determine important network attacks based on the number of attacks, attack methods, and attack targets of the low-risk network attacks;
[0043] Specifically, for example, the attack methods include message tampering, message forgery, denial of service, and data eavesdropping; the attack targets include network ports, network messages, and user data.
[0044] Specifically, the high-risk network attacks and low-risk network attacks are determined according to the threat degree of the attack method and attack target of the network attack to the normal operation of the network operation server or terminal.
[0045] Specifically, for example, the high-risk network attacks and low-risk network attacks are scored respectively according to the attack methods and attack targets of the network attacks to obtain the attack method scoring results and attack target scoring results, and according to the attack formula scoring results and attack target scoring results, a classification result of the high-risk network attacks and low-risk network attacks is obtained by using a mathematical model based on the entropy method.
[0046] Specifically, for example, the important network attacks are determined by using the analytic hierarchy process, formula or look-up table according to the number of attacks, attack methods, and attack targets of the low-risk network attacks. Generally speaking, the proportion of the important network attacks in the low-risk network attacks is not higher than 20%.
[0047] In this embodiment, by determining the important network attacks based on the number of attacks, attack methods, and attack targets of the low-risk network attacks, the screening of the important network attacks with relatively high risks in the low-risk network attacks is realized from multiple perspectives, and a foundation is laid for further determining the scope of honeypot analysis.
[0048] S12 Determine whether it is necessary to analyze all honeypots based on the number of attacks of the high-risk network attacks, the number of attacks of the important network attacks, and the number of attacks of the low-risk network attacks. If so, enter step S14; if not, enter step S13.
[0049] Specifically, the specific steps for determining whether it is necessary to analyze all honeypots are as follows:
[0050] S21 Determine a high-risk coefficient based on the number of attacks of the high-risk network attacks, and determine whether it is necessary to analyze all honeypots based on the high-risk coefficient. If so, analyze all honeypots; if not, enter step S22.
[0051] Specifically, for example, the high-risk coefficient is positively correlated with the number of attacks of the high-risk network attacks. The more the number of attacks, the higher the high-risk coefficient. The specific value range is between 0 and 1. When the value of the high-risk coefficient is 0.7 and the set value is 0.5, if it is greater than the set value at this time, it is necessary to analyze all honeypots.
[0052] S22 Determine an important risk coefficient based on the number of attacks of the important network attacks, and determine whether it is necessary to analyze all honeypots based on the important risk coefficient and the high-risk coefficient. If so, analyze all honeypots; if not, enter step S23.
[0053] Specifically, for example, a comprehensive proportionality factor is constructed based on the important risk factor and the high-risk factor, and it is determined whether all honeypots need to be analyzed based on the magnitude of the comprehensive proportionality factor.
[0054] S23 Based on the threat level of network attacks, determine the weights of the high-risk network attacks, important network attacks, and low-risk network attacks, and based on the weight of the high-risk network attacks, correct the number of attack times of the high-risk network attacks to obtain the corrected number of attack times of the high-risk network attacks. Based on the weight of the important network attacks, correct the number of attack times of the important network attacks to obtain the corrected number of attack times of the important network attacks. Based on the weight of the low-risk network attacks, correct the number of attack times of the low-risk network attacks to obtain the corrected number of attack times of the low-risk network attacks;
[0055] It should be noted that the high-risk factor or the comprehensive proportionality factor can also be directly corrected based on the weight, and it is determined whether all honeypots need to be analyzed according to the correction result.
[0056] S24 Based on the corrected number of attack times of the high-risk network attacks, important network attacks, and low-risk network attacks, determine the risk factor of the network attacks, and based on the risk factor, determine whether all honeypots need to be analyzed.
[0057] Specifically, the risk factor of the network attacks is predicted according to a prediction model based on the CSO-BP neural network, and the specific steps for constructing the prediction model are as follows:
[0058] (1) Randomly initialize the cat population, set the population size m, the maximum number of iterations k, and the grouping rate, and randomly set the positions of the cat population in the interval [-1, 1];
[0059] (2) By calculating the fitness values of all cats in the population, select the cat with the optimal fitness value for recording;
[0060] (3) Randomly group the cat patterns according to the grouping rate;
[0061] (4) When the cat is in the search group, copy its position for the individual cat according to the improved individual replication formula, execute the selection operation label, and replace the current position of the individual with the candidate point with the highest fitness value of the individual cat, and replace and update the optimal value;
[0062] (5) The cat with the optimal fitness value is saved and recorded;
[0063] (6) Determine whether the optimization process of the algorithm meets the termination condition. If it meets, output the optimal solution and transfer it to the BP neural network to determine the initial weights and thresholds of the network;
[0064] (7) Input the training sample data to train the BP neural network. After the training is completed, input the test sample data and comprehensively analyze the data test results.
[0065] It should be noted that in the optimization problem, most algorithms basically generate the next individual through the iteration of an optimal individual. This behavior of sacrificing the optimal individual is different from the cat swarm algorithm. Instead, it randomly assigns patterns according to the value of the grouping rate, and obtains the optimal individual through the coordinated work of two modes. In the algorithm, every time an iteration is performed, the fitness values of all individual cats are compared to select the optimal cat, and then compared with the optimal cat in the iterative history process, and the information is saved therein. In this way, the optimal solution of the optimization target can be transformed into the problem of obtaining the optimal cat.
[0066] Like other intelligent algorithms, the unique pattern allocation of CSO provides a basis for the algorithm to achieve global search. While improving the search efficiency of the algorithm to a certain extent, there are also some deficiencies: for example, in the later stage of iteration, the search efficiency will gradually decrease as the number of iterations increases, which will affect the accuracy of the output results and reduce the accuracy of the local and global optimal solutions. Therefore, while retaining the original advantages of CSO, optimize the allocation mode and search mode by improving the value-taking method of the grouping rate and the individual replication formula in the search mode, so as to improve the search efficiency and accuracy of the algorithm.
[0067] If the value of the grouping rate is set too low, the global search ability of the system is poor in the early stage of calculation, which will increase the response time; while when the value of the grouping rate is set too high, it will reduce the local search effect in the later stage of the system, and let too many cats join the global search, that is, it occupies the computing memory of the computer and also increases the ambiguity of the system output. We improve the system stability and result parameters in the state delegation of the system by correcting the size of the grouping rate. When the system grouping rate is set too high, it will greatly improve the global search ability of the system in the early stage, and the set value of the grouping rate will linearly decrease as the amount of calculation increases, and the size of the cat swarm in the search mode will also linearly increase as the amount of calculation increases, and finally make the local search of the system in the later stage achieve better results and also greatly improve the accuracy of the optimal solution. The calculation formula of the grouping rate at the kth iteration is:
[0068]
[0069] In the formula, MR max is the initial value of the mixing rate, a is a constant, k is the current iteration number, k max is the maximum number of iterations, is a random number, and its value range is between and
[0070] It should be noted that the threat level of the network attack is determined according to the attack method and attack target of the network attack, and specifically, the entropy value method is used for determination.
[0071] In this embodiment, by first determining whether it is necessary to analyze all honeypots based on the number of attacks of high-risk network attacks, the number of attacks of important network attacks, and the number of attacks of low-risk network attacks, the judgment of the operation risk is realized from the perspective of the number of attacks of different types. On the basis of ensuring the operation efficiency, the comprehensiveness of honeypot analysis is also ensured.
[0072] S13 Based on the trapping rate and defense success rate of the honeypots, evaluate the running states of the honeypots for high-risk network attacks and the honeypots for important network attacks respectively to obtain evaluation results, and determine whether it is necessary to analyze the honeypots for low-risk network attacks based on the evaluation results, the number of attacks of the high-risk network attacks, the number of attacks of important network attacks, and the number of attacks of low-risk network attacks. If so, enter step S14; if not, determine the problematic honeypots and the deployment quantity of the honeypots according to the evaluation results;
[0073] Specifically, for example, the specific steps to determine whether it is necessary to analyze the honeypots for low-risk network attacks are as follows:
[0074] S31 Based on the evaluation results, determine the proportion of the problematic honeypots in the honeypots for the high-risk network attacks as the high-risk problematic honeypot proportion, and obtain a high-risk evaluation factor based on the high-risk problematic honeypot proportion and the number of attacks of the high-risk network attacks;
[0075] S32 Based on the evaluation results, determine the proportion of the problematic honeypots in the honeypots for the important network attacks as the important problematic honeypot proportion, and obtain an important evaluation factor based on the important problematic honeypot proportion and the number of attacks of the important network attacks;
[0076] S33 Take the sum of the number of attacks of the high-risk network attacks and the number of attacks of the important network attacks as the evaluation attack number sum, and take the ratio of the evaluation attack number sum to the number of attacks of the low-risk network attacks as the evaluation number proportion;
[0077] S34 Based on the evaluation number proportion, the high-risk evaluation factor, and the important evaluation factor, determine the evaluation risk of the network attack, and determine whether it is necessary to analyze the honeypots for low-risk network attacks based on the evaluation risk.
[0078] Specifically, when the evaluated risk is greater than the set value, analyze the honeypots for low-risk network attacks, where the set value is determined based on the number of the honeypots and the number of attack times of the network attacks. The more the number of the honeypots and the more the number of attack times of the network attacks, the greater the set value.
[0079] In this embodiment, the evaluation result is obtained by further combining the operation status of the honeypots for high-risk network attacks and the honeypots for important network attacks, and it is determined whether to analyze the honeypots for low-risk network attacks based on the evaluation result, the number of attack times of high-risk network attacks, the number of attack times of important network attacks, and the number of attack times of low-risk network attacks. Thus, the risk of network attacks is further confirmed, and the evaluation result of the honeypots is further combined, ensuring the comprehensiveness and accuracy of the evaluation.
[0080] S14 Analyze all the honeypots based on the trapping rate and defense success rate of the honeypots to obtain an analysis result, and determine problem honeypots and the deployment quantity of the honeypots according to the analysis result.
[0081] Specifically, determining problem honeypots and the deployment quantity of the honeypots according to the evaluation result specifically includes:
[0082] Optimize the problem honeypots, and use the optimized problem honeypots and the existing non-problematic honeypots as alternative honeypots, and determine the quantity of alternative honeypots for network attacks with different attack methods based on the attack methods and attack times of the network attacks.
[0083] Embodiment 2
[0084] An embodiment of the present application provides a computer system, including: a memory and a processor connected by communication, and a computer program stored on the memory and capable of running on the processor, characterized in that: when the processor runs the computer program, it executes the above-mentioned network attack protection method based on honeypots.
[0085] Embodiment 3
[0086] As Figure 2 shown, the present invention provides a computer storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is made to execute the above-mentioned network attack protection method based on honeypots.
[0087] In several embodiments provided in this application, it should be understood that the disclosed systems and methods can also be implemented in other ways. The system embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of systems, methods, and computer program products according to multiple embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and a module, a program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0088] In addition, each functional module in various embodiments of the present invention can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0089] If the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program code.
[0090] Based on the above inspiration from the ideal embodiments of the present invention, through the above description, relevant staff can completely make various changes and modifications without departing from the technical idea of this invention. The technical scope of this invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.
Claims
1. A honeypot-based network attack protection method, characterized in that Specifically, it includes: S11 Classify the network attacks into high-risk network attacks and low-risk network attacks based on the attack methods and targets of the network attacks, and determine important network attacks based on the number of attacks, attack methods, and attack targets of the low-risk network attacks; S12 Determine whether it is necessary to analyze all honeypots based on the number of attacks of the high-risk network attacks, the number of attacks of the important network attacks, and the number of attacks of the low-risk network attacks. If so, go to step S14; if not, go to step S13; S13 Evaluate the running status of the honeypots for high-risk network attacks and the honeypots for important network attacks respectively based on the trapping rate and defense success rate of the honeypots to obtain an evaluation result, and determine whether it is necessary to analyze the honeypots for low-risk network attacks based on the evaluation result, the number of attacks of the high-risk network attacks, the number of attacks of the important network attacks, and the number of attacks of the low-risk network attacks. If so, go to step S14; if not, determine the problematic honeypots and the deployment quantity of the honeypots according to the evaluation result; S14 Analyze all honeypots based on the trapping rate and defense success rate of the honeypots to obtain an analysis result, and determine the problematic honeypots and the deployment quantity of the honeypots according to the analysis result.
2. The network attack prevention method according to claim 1, characterized in that, The attack methods include message tampering, message forgery, denial of service, and data eavesdropping; the attack targets include network ports, network messages, and user data.
3. The network attack protection method according to claim 1, characterized in that The high-risk network attacks and low-risk network attacks are determined according to the threat degree of the network attacks' attack methods and attack targets to the normal operation of the network operation server or terminal.
4. The network attack prevention method according to claim 1, wherein The specific steps for determining whether it is necessary to analyze all honeypots are: S21 Determine a high-risk coefficient based on the number of attacks of the high-risk network attacks, and determine whether it is necessary to analyze all honeypots based on the high-risk coefficient. If so, analyze all honeypots; if not, go to step S22; S22 Determine an important risk coefficient based on the number of attacks of the important network attacks, and determine whether it is necessary to analyze all honeypots based on the important risk coefficient and the high-risk coefficient. If so, analyze all honeypots; if not, go to step S23; S23 Determine the weights of the high-risk network attacks, the important network attacks, and the low-risk network attacks based on the threat degree of the network attacks, and correct the number of attacks of the high-risk network attacks based on the weight of the high-risk network attacks to obtain the corrected number of attacks of the high-risk network attacks, correct the number of attacks of the important network attacks based on the weight of the important network attacks to obtain the corrected number of attacks of the important network attacks, and correct the number of attacks of the low-risk network attacks based on the weight of the low-risk network attacks to obtain the corrected number of attacks of the low-risk network attacks; S24 Determine the risk coefficient of the network attacks based on the corrected number of attacks of the high-risk network attacks, the important network attacks, and the low-risk network attacks, and determine whether it is necessary to analyze all honeypots based on the risk coefficient.
5. The network attack protection method according to claim 4, characterized in that The threat level of the network attack is determined according to the attack method and attack target of the network attack, and specifically, the entropy value method is used for determination.
6. The network attack protection method according to claim 1, characterized in that, The specific steps for determining whether it is necessary to analyze the honeypots for low-risk network attacks are as follows: S31 Based on the evaluation result, determine the proportion of the honeypots with problems in the honeypots for the high-risk network attacks as the high-risk problem honeypot proportion, and obtain the high-risk evaluation factor based on the high-risk problem honeypot proportion and the number of attacks of the high-risk network attacks; S32 Based on the evaluation result, determine the proportion of the honeypots with problems in the honeypots for the important network attacks as the important problem honeypot proportion, and obtain the important evaluation factor based on the important problem honeypot proportion and the number of attacks of the important network attacks; S33 Take the sum of the number of attacks of the high-risk network attacks and the number of attacks of the important network attacks as the evaluation attack number sum, and take the ratio of the evaluation attack number sum to the number of attacks of the low-risk network attacks as the evaluation number proportion; S34 Based on the evaluation number proportion, high-risk evaluation factor, and important evaluation factor, determine the evaluation risk of the network attack, and determine whether it is necessary to analyze the honeypots for low-risk network attacks based on the evaluation risk.
7. The network attack prevention method according to claim 6, wherein When the evaluation risk is greater than the set value, analyze the honeypots for the low-risk network attacks, where the set value is determined according to the number of the honeypots and the number of attacks of the network attack. The more the number of the honeypots and the more the number of attacks of the network attack, the greater the set value.
8. The network attack protection method according to claim 1, wherein Determine the problem honeypots and the deployment quantity of the honeypots according to the evaluation result, specifically including: Optimize the problem honeypots, and use the optimized problem honeypots and the existing honeypots without problems as alternative honeypots, and determine the quantity of the alternative honeypots for the network attacks with different attack methods based on the attack method and the number of attacks of the network attack.
9. A computer system, comprising: A memory and a processor in communication connection, and a computer program stored on the memory and capable of running on the processor, characterized in that: when the processor runs the computer program, it executes a network attack protection method according to any one of claims 1-8.
10. A computer storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is made to execute a network attack protection method according to any one of claims 1-8.
Citation Information
Patent Citations
Honeypot deployment methods, apparatus, equipment and computer-readable media
CN114448731B
Deception trapping method and device, computer equipment and readable storage medium
CN113949520A
Honeypot deployment method, apparatus and device, and computer readable medium
CN114448731A