Honeypot protection methods, devices, storage media and electronic equipment
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-21
- Publication Date
- 2026-08-14
AI Technical Summary
[0004]本说明书实施例提供了一种蜜罐防护方法、装置、存储介质及电子设备,可以解决高交互蜜罐的安全性问题
[0016] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following:
Smart Images

Figure CN116800525B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of network security technology, and in particular to a honeypot protection method, device, storage medium and electronic device. Background Technology
[0002] A honeypot is a security resource used to lure intruders. Its value lies in being detected, attacked, or compromised. Honeypot technology is a deceptive technique that uses fake resources to trick intruders, thereby collecting intruder attack data and analyzing intruder behavior to protect the real host target. In other words, a honeypot is a pre-configured system designed to deceive hackers into attacking and compromising it. The very purpose of a honeypot is to be compromised; any interaction with the honeypot can be considered an intrusion. Therefore, honeypots allow for the collection and analysis of intruder attack data and behavior.
[0003] High-interaction honeypots are typically set up on a real host, while a decoy service is deployed on the same host to deceive attackers into intrusion. Compared to low-interaction honeypots, high-interaction honeypots solve the problems of insufficient interaction and poor camouflage capabilities of low-interaction honeypots by directly deploying a real service, but they also introduce security issues. Summary of the Invention
[0004] This specification provides a honeypot protection method, device, storage medium, and electronic device, which can solve the security problem of highly interactive honeypots. The technical solution is as follows:
[0005] Firstly, this specification provides a honeypot protection method, applicable to honeypot servers, the method comprising:
[0006] Based on the target role type corresponding to the attack request, a target prompt word template is matched among multiple preset prompt word templates, and the multiple prompt word templates correspond to multiple role types respectively;
[0007] Generate target prompts based on the attack request and the target prompt template;
[0008] Based on the target prompts, an AI chat model generates a dialogue result, and the dialogue result is sent to the device corresponding to the attack request.
[0009] Secondly, this specification provides a honeypot protection device, applicable to honeypot servers, comprising:
[0010] The role matching module is used to match a target prompt word template among multiple preset prompt word templates based on the target role type corresponding to the attack request. The multiple prompt word templates correspond to multiple role types respectively.
[0011] The prompt generation module is used to generate target prompts based on the attack request and the target prompt template;
[0012] The dialogue sending module is used to generate a dialogue result based on the target prompt words using an artificial intelligence chat model, and to send the dialogue result to the device corresponding to the attack request.
[0013] Thirdly, embodiments of this specification provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the above-described method steps.
[0014] Fourthly, embodiments of this specification provide a computer program product that stores multiple instructions adapted for loading by a processor and executing the above-described method steps.
[0015] Fifthly, embodiments of this specification provide an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the above-described method steps.
[0016] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following:
[0017] In the embodiments of this specification, the honeypot server stores multiple role types and corresponding prompt word templates for each role type. It matches the target prompt word template with the target role type corresponding to the attack request and generates the target prompt word. Furthermore, it generates a dialogue result using an artificial intelligence chat model based on the target prompt word. The honeypot server provided in this embodiment has high interactivity and ensures its own security by generating and returning dialogue results. Since the collected data comes from external attack requests, it will not compromise the security of internal privacy data in the data transaction server where the honeypot server is deployed. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1This is a schematic diagram of the architecture of a honeypot protection method provided in the embodiments of this specification;
[0020] Figure 2 This is a schematic flowchart of a honeypot protection method provided in the embodiments of this specification;
[0021] Figure 3 This is a schematic diagram of a role type and prompt word template provided in the embodiments of this specification;
[0022] Figure 4 This is a schematic flowchart of a honeypot protection method provided in the embodiments of this specification;
[0023] Figure 5 This is a schematic diagram of a process for generating target prompt words provided in an embodiment of this specification;
[0024] Figure 6 This is a schematic flowchart of a honeypot protection method provided in the embodiments of this specification;
[0025] Figure 7 This is a schematic diagram of the structure of a honeypot protection device provided in the embodiments of this specification;
[0026] Figure 8 This is a schematic diagram of the structure of an electronic device provided in the embodiments of this specification. Detailed Implementation
[0027] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0028] In the description of this specification, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise expressly specified and limited, "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. Those skilled in the art can understand the specific meaning of the above terms in this specification based on the specific circumstances. Furthermore, in the description of this specification, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0029] The present specification will now be described in detail with reference to specific embodiments.
[0030] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the object characteristics, interactive behavior characteristics, and user information involved in this specification were all obtained under full authorization.
[0031] The internet has always been subject to various cybersecurity threats, with attack methods constantly evolving, their tactics changing, and their targets diverse. In the process of attack and defense, even a minor design oversight can create serious system vulnerabilities, which attackers can exploit to cause severe damage. Defenders, on the other hand, must ensure the defense of their systems or nodes is absolutely flawless to guarantee complete security. Simultaneously, defenders are completely unaware of attackers who can come from anywhere on the network, while their systems or nodes are entirely exposed to attackers. In this attack-defense game, attackers hold the dominant, proactive position, while defenders are relegated to a passive role.
[0032] Therefore, proactive defense technologies have gradually attracted widespread attention and importance from academia and industry. The strategic goal of proactive real-time protection models and technologies is to assess the current network security situation through situational awareness, risk assessment, and security detection, and then implement proactive network defense based on the assessment results—a proactive security protection system. Proactive defense technology is not merely a single type or category of defense technology, but rather a defense system designed to predict and identify unknown attack behaviors and methods, automatically respond to defenses, or proactively strengthen potential vulnerabilities to achieve forward-looking defense. Common proactive defense technologies include intrusion detection technology, honeypot technology, mimicry defense technology, and moving target defense.
[0033] Intrusion detection technology can be divided into two categories of proactive defense technologies: rule-based anomaly detection and anomaly detection-based detection. Rule-based anomaly detection technology primarily targets the characteristics or behaviors of known malicious programs by matching rules to enable blocking and attribution defenses before an attack occurs. Anomaly detection-based intrusion detection technology, on the other hand, can detect unknown attacks. Mimicry defense technology is an inherent security architecture technology that possesses natural immunity to unknown vulnerabilities, backdoors, and even some unknown viruses and Trojans within its architecture. Effective integration with existing passive defense methods can create a capability to combat both known and unknown attacks in cyberspace. In conclusion, mimicry defense is complementary, integrative, and controllable to existing cyberspace security defense systems.
[0034] A honeypot is a mainstream proactive defense technology used to lure attackers into probing, attacking, or compromising fake network resources. It's a collection of network resources combining a honeypot system with firewalls, intrusion detection devices, alarm modules, and intrusion behavior logging modules, enabling proactive capture of attackers. The value of a honeypot lies in being detected, attacked, or compromised. In other words, a honeypot is a pre-configured system designed to deceive hackers into attacking and compromising it. Its very existence is defined by being compromised; any interaction with the honeypot can be considered an intrusion. Therefore, honeypots allow for the collection and analysis of attacker data and behavior.
[0035] In one embodiment, such as Figure 1 The diagram shown illustrates the architecture of a honeypot protection method provided in an embodiment of this specification. The architecture includes: a data transaction server 101, a honeypot server 102, and multiple electronic devices. The multiple electronic devices include at least electronic device 1031, electronic device 1032, and electronic device 1033. It is understood that... Figure 1 The number of data transaction server 101, honeypot server 102 and multiple electronic devices shown are for illustrative purposes only, and the embodiments in this specification do not impose any limitations on them.
[0036] Data transaction server 101 can be understood as one server or a cluster of multiple servers. Data transaction server 101 is used to receive requests or information through multiple configured interfaces, and to provide corresponding data or services based on the request content. For example, data transaction server 101 checks the legitimacy of the identity information provided by the user, or collects and saves the running logs of the target application at a preset period. The aforementioned multiple servers can be multiple physical servers, which are hardware-independent; or multiple servers can be multiple virtual servers, which are deployed in the same hardware resource pool. The deployment methods of virtual servers include, but are not limited to, VMware, VirtualBox, and Virtual PC.
[0037] Honeypot server 102 can be understood as a server that provides honeypot services or has a honeypot system configured. In other words, honeypot server 102 executes the honeypot protection method provided in this specification. Honeypot server 102 can be a virtual server or a decoy host located within data transaction server 101. In one embodiment, since honeypot service 102 is deployed within the decoy host of data transaction server 101, the decoy host is also at risk of being compromised if an attacker breaches it. Therefore, in this embodiment, honeypot server 102 is located in a container and / or virtual machine, and interacts with the attacker through a proxy module. On the one hand, even if the attacker exploits a vulnerability in honeypot server 102 to gain access, they can only obtain the highest level of access to the container and / or virtual machine where honeypot server 102 resides, not the complete access to the entire data transaction server 101. This prevents the attacker from escaping from honeypot server 102 and ensures the security of data transaction server 101.
[0038] It is understood that the data transaction server 101 and honeypot server 102 also possess other service capabilities and functions to complete the tasks described in the following embodiments. For example, the data transaction server 101 also provides portal services, resource management services, and CI / CD services. The honeypot server 102 also provides behavior capture services, threat analysis services, and decoy situation analysis servers. Among them, the behavior capture service refers to capturing relevant data from illegal external attack behaviors, specifically including honeypot access, command execution, raw traffic, and file changes; the threat analysis service refers to deeply analyzing all attack sessions captured by the honeypot through a behavior analysis engine, displaying the interaction commands between the honeypot server 102 and the attacker in an attack timeline; the decoy situation analysis service refers to using correlation analysis technology to build a decoy analysis model and monitor the overall decoy attack situation in real time.
[0039] Data transaction server 101, honeypot server 102, and multiple electronic devices can communicate via communication links established based on communication protocols, such as gRPC. gRPC is a high-performance, general-purpose, open-source Remote Procedure Call (RPC) framework primarily designed for mobile application development and based on the HTTP / 2 protocol standard. It is developed using Protocol Buffers (PB) serialization and supports numerous programming languages. Furthermore, the communication link can be a wireless or wired communication link. For example, wired communication links include fiber optic cables, twisted-pair cables, or coaxial cables, while wireless communication links include Bluetooth, Wi-Fi, or microwave communication links.
[0040] Non-attackers communicate with data transaction server 101 via electronic devices, while attackers attempt to attack data transaction server 101 via electronic devices and are lured by honeypot server 102. Electronic devices include, but are not limited to, physical or virtual servers, mobile stations (MS), mobile terminals, mobile phones, handsets, portable devices, Bluetooth headsets, smartwatches, etc. These electronic devices can communicate with one or more core networks via a Radio Access Network (RAN). It is understood that the embodiments in this specification do not limit the types of electronic devices described above. For example, a non-attacker communicates with data transaction server 101 via electronic device 1031 or electronic device 1032 and receives services or data provided by data transaction server 101. An attacker, through electronic device 1033, is lured by honeypot server 102 and sends an attack request to honeypot server 102.
[0041] In the embodiments of this specification, a display device may also be installed on the electronic device. This display device can be any device capable of displaying functions, such as a cathode ray tube display (CR), a light-emitting diode display (LED), an electronic ink screen, a liquid crystal display (LCD), or a plasma display panel (PDP). Both non-attackers and attackers can use the display device on the electronic device to view information from the data transaction server 101 or the honeypot server 102, and to send instructions to the electronic device via the display device. For example, instructions can be sent to the electronic device by long-pressing, clicking, or double-clicking on the display device. These instructions may include sending a request for target data to the data transaction server 101 or an attack request to the honeypot server 102.
[0042] In one embodiment, such as Figure 2 The diagram shown is a flowchart illustrating a honeypot protection method proposed in an embodiment of this specification. This method can be implemented using a computer program and can run on a honeypot protection device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application.
[0043] Specifically, the honeypot protection method includes:
[0044] S102. Match the target prompt word template from multiple preset prompt word templates according to the target role type corresponding to the attack request.
[0045] An attack request can be understood as an abnormal request sent by an attacker to a honeypot server via an electronic device. The attack request includes attack information such as the attack time, target, method, attacker's IP address, and specific actions taken. Attack methods can include vulnerability exploitation, password brute-force attacks, and anti-fraud attacks. The target can be a gateway or a container; for example, the target of the attack request can be determined based on the IP address and / or name and / or service of the honeypot server targeted by the attack request.
[0046] In this specification, the honeypot server's storage unit includes multiple role types and corresponding prompt word templates. In other words, there is a relationship between the multiple role types and the multiple prompt word templates. A role type can be understood as a certain role identity based on which the AI chat model interacts with the honeypot server. A prompt word can be understood as instructing the AI chat model to switch to a certain role type. A prompt word template can be understood as a fixed format for generating prompt words based on that role type. The template is the result of fixing and standardizing the structural rules of a prompt word; it embodies the standardization of structural form.
[0047] In one embodiment, the multiple role types include at least one of the following role types: command-line role, gateway role, container role, and vulnerability role. For example... Figure 3 The diagram shown illustrates a role type and prompt word template provided in an embodiment of this specification. In this embodiment, the honeypot server includes multiple preset role types 101, which at least include a command-line role 1011, a gateway role 1012, a container role 1013, and a vulnerability role 1014. The honeypot server also includes prompt word templates corresponding to the multiple role types, such as... Figure 3 As shown, there are prompt word templates 1021 corresponding to the command line role 1011, 1022 corresponding to the gateway role 1012, 1023 corresponding to the container role 1013, and 1024 corresponding to the vulnerability role 1014. It is understood that this specification may also include other role types and corresponding prompt word templates. Figure 3 The illustrations shown are for illustrative purposes only and do not constitute any limitation in this manual.
[0048] The content of the prompt word templates corresponds to the role type. For example, for role type 101 of command line role 1011, the prompt word template 1021 corresponding to command line role 1011 contains the content "Assuming you are a command line, here are some commands for you to execute and return the results." For role type 101 of gateway role 1012, the prompt word template 1022 corresponding to gateway role 1012 contains the content "Assuming you are a gateway, carrying out load balancing functions, here are some inputs for you to execute and return the results." For role type 101 of container role 1013, the prompt word template 1023 corresponding to container role 1013 contains the content "Assuming you are a cloud-native container, here are some inputs for you to execute and return the results." For role type 101 of vulnerability role 1014, the prompt word template 1024 corresponding to vulnerability role 1014 contains the content "Assuming you have the CVE-2023-0001 vulnerability, the vulnerability details are as follows, here are some inputs for you to execute and return the results." It is understood that the content of the above prompt template is for illustrative purposes only and is not intended to limit the scope of this instruction manual.
[0049] Specifically, the honeypot server receives an attack request and, based on the content of the attack request, matches the target role type from a set of preset role types. Then, based on the target role type, it matches the corresponding target prompt word template from a set of preset prompt word templates. For example, based on the attack method and / or target in the attack request, the type of the attack request is determined, and the target role type is matched from a set of preset role types. For instance, if the attack target of the attack request is a container, the target role type is determined to be container role 1014, and the target prompt word template corresponding to container role 1014 is determined to be prompt word template 1024; that is, the target prompt word template for this attack request is 1024. Similarly, if the attack method of the attack request is a command line, the target role type is determined to be command line role 101, and the target prompt word template corresponding to command line role 101 is determined to be prompt word template 1021; that is, the target prompt word template for this attack request is prompt word template 1011.
[0050] S104. Generate target prompts based on the attack request and target prompt template.
[0051] Based on the attack request and the corresponding target prompt template, the target prompt is filled in to generate the target prompt for the attack request. The target prompt template can be filled in according to the specific operations carried in the attack request; that is, the characters representing multiple operations carried in the attack request are extracted and filled into the corresponding positions of the prompt template to obtain the target prompt.
[0052] For example, when an attack request corresponds to a command-line role, the prompt template for that role is populated based on the command-line information carried in the attack request. When an attack request corresponds to a gateway role, the prompt template for that role is populated based on the gateway information and command-line information carried in the attack request; the gateway information may include the gateway identifier corresponding to the attack request. When an attack request corresponds to a container role, the prompt template for that role is populated based on the container information and command-line information carried in the attack request; the container information may include the container type and container identifier corresponding to the attack request, such as a web container or a Docker container. When an attack request corresponds to a vulnerability role, the prompt template for that role is populated based on the vulnerability information and command-line information carried in the attack request; the vulnerability information may include the type of vulnerability and / or the details and / or the address of the vulnerability.
[0053] S106. Generate dialogue results using an AI chat model based on template prompts, and send the dialogue results to the device corresponding to the attack request.
[0054] AI chatbot models can include Convolutional Neural Networks (CNNs), Recurrent Neural Networks (RNNs), or Transformer networks based on the attention mechanism, along with a classification layer. CNNs, RNNs, and Transformers are used to semantically encode the input prompt words, and the classification layer maps the encoded vectors to the label dimension. For example, an AI chatbot model can be a BERT pre-trained model. BERT (Bidirectional Encoder Representation from Transformers) pre-trained models are models that retrieve at least one dialogue result corresponding to a prompt word by running a self-supervised learning method on massive amounts of corpus data. Self-supervised learning refers to supervised learning performed on unlabeled data. It is understood that the AI chatbot models in the embodiments of this specification are not limited to the aforementioned BERT pre-trained models and other models; other multi-label classification models for Natural Language Processing (NLP) are also applicable.
[0055] In one embodiment, the honeypot server sends an Application Programming Interface (API) request, including target prompts, to the AI chat model to obtain the dialogue results generated by the AI chat model corresponding to the target prompts, and then sends the dialogue results to the device corresponding to the attack request. An Application Programming Interface (API) is an agreement between different components of a software system. Due to the complex structure of the AI chat model module, this embodiment rationally divides the AI chat model module into smaller components and sets up programming interfaces. Furthermore, by obtaining the dialogue results generated by the AI chat model based on the target prompts through API requests, the interdependence between the modules including the AI chat model in the honeypot server system can be reduced, thereby improving the maintainability and scalability of the honeypot server.
[0056] In one embodiment, the process of an AI chat model generating dialogue results based on target prompt words is as follows: The characters of the target prompt word are converted into numbers through mapping, and then the numbers are vectorized to obtain an initial vector for the target prompt word. For example, word embedding can be used to achieve the vectorization process. The initial vector is input into an encoding module for semantic encoding to obtain the encoding result. For example, the encoding module uses the Encoder module in the Transformer architecture to extract features from the initial vector and obtain an encoded vector sequence. For example, the semantically encoded output vector dimension is 768×2048, where 2048 is the length of the input vector. Further, the encoded result is input into a dialogue generation module for linear transformation to obtain the dialogue result corresponding to the target prompt word. The dialogue generation module can be a linear transformation layer that transforms the encoding result to other dimensions. Alternatively, a dropout layer can be added before the dialogue generation module to randomly discard some neurons with a preset probability (e.g., 0.1), and then the encoding result is linearly transformed to obtain the dialogue result. For example, the AI chat model can be a Chat Generative Pre-trained Transformer (chatGPT) or other models; this specification does not impose any limitations on this.
[0057] After obtaining the dialogue result corresponding to the attack request, the honeypot server sends the dialogue result to the device corresponding to the attack request. Before sending the dialogue result, it can be processed, such as by replacement, trimming, or concatenation. For example, if the attack request is web code, the dialogue result can be sent to the device corresponding to the attack request by concatenating it with the attack request. The dialogue result can be sent to the device corresponding to the attack request by displaying it on the device's display screen; this specification does not impose any restrictions on this.
[0058] In the embodiments of this specification, the honeypot server stores multiple role types and corresponding prompt word templates for each role type. It matches the target prompt word template with the target role type corresponding to the attack request and generates the target prompt word. Furthermore, it generates a dialogue result using an artificial intelligence chat model based on the target prompt word. The honeypot server provided in this embodiment has high interactivity and ensures its own security by generating and returning dialogue results. Since the collected data comes from external attack requests, it will not compromise the security of internal privacy data in the data transaction server where the honeypot server is deployed.
[0059] In one embodiment, such as Figure 4 The diagram shown is a flowchart illustrating a honeypot protection method proposed in an embodiment of this specification. This method can be implemented using a computer program and can run on a honeypot protection device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application.
[0060] Specifically, the honeypot protection method includes:
[0061] S202. Accept and store multiple role types and prompt word templates corresponding to each role type.
[0062] The honeypot server receives multiple role types and corresponding prompt word templates from other electronic devices, or the developer sets multiple role types and corresponding prompt word templates through the honeypot server and stores them in the honeypot server's memory.
[0063] Because of the complex internal code structure and numerous interrelationships within honeypot servers, developers often spend a significant amount of time modifying or adding even small parts. Furthermore, honeypot servers require real-time updates to adapt to rapidly changing transaction requirements. This embodiment, however, only modifies the pre-stored role types and their corresponding prompt word templates within the honeypot server, without altering the honeypot server itself. This allows for flexible application to various transaction needs while reducing developer time and development costs.
[0064] S204, Receive attack request.
[0065] An attack request can be understood as an abnormal request sent by an attacker to a honeypot server via an electronic device. The attack request includes attack information such as the attack time, target, method, attacker's IP address, and specific actions taken. Attack methods can include vulnerability exploitation, password brute-force attacks, and anti-fraud attacks. The target can be a gateway or a container; for example, the target of the attack request can be determined based on the IP address and / or name and / or service of the honeypot server targeted by the attack request.
[0066] S206. Based on the content of the attack request, match the target role type among multiple preset role types.
[0067] Attack requests include attack information and other content. The honeypot server matches the target role type among several preset role types based on the content of the attack request. For example, the type of attack request is determined based on the attack method and / or target in the attack request, thereby matching the target role type among several preset role types.
[0068] like Figure 5 As shown, Figure 5 This is a schematic diagram illustrating a process for generating target prompts provided in an embodiment of this specification. The honeypot server receives an attack request 200 and determines the target role type from multiple role types 201 based on the content of the attack request 200. The multiple role types 201 include at least a command-line role 2011, a gateway role 2012, a container role 2013, and a vulnerability role 2014. For example, the attack request 200 includes command-line information, which can be transaction code for a specific application, test code, configuration changes, POM (Project Object Model) modifications, or any other content, or code data generated based on any development framework. The application can be an application built based on any development framework, or an application providing any service or possessing any function. Based on the content of the attack request 200, the target role type corresponding to the attack request 200 is determined to be the command-line role 2011.
[0069] S208. Based on the target role type, match the corresponding prompt word template from multiple preset prompt word templates.
[0070] Based on the target role type and the pre-defined mapping between multiple role types and multiple prompt word templates, the corresponding template prompt word for the target role type is determined. For example, to check whether there are request-response conditions corresponding to a matching request for a target role type in the honeypot server's storage, the matching can be performed by matching the Uniform Resource Locator (URL), request headers, sensitive keywords, development language, middleware version, special protocols, etc. carried in the matching request, thereby determining the prompt word template corresponding to the target role type in the storage.
[0071] like Figure 5 As shown, the honeypot server includes multiple prompt word templates, including at least prompt word template 2021, prompt word template 2022, prompt word template 2023, and prompt word template 2024. Attack request 200 corresponds to a target role type of command line role 2011. Prompt word template 2021, corresponding to command line role 2011, is selected from the multiple prompt word templates and used as the target prompt word template for attack request 200.
[0072] S210. Based on the content of the attack request, fill in the template prompt words to generate template prompt words.
[0073] Based on the attack request and the corresponding target prompt template, the target prompt is filled in to generate the target prompt for the attack request. The target prompt template can be filled in according to the specific operations carried in the attack request; that is, the characters representing multiple operations carried in the attack request are extracted and filled into the corresponding positions of the prompt template to obtain the target prompt.
[0074] like Figure 5 As shown, based on the content of attack request 200 and prompt template 2021, target prompt 203 is generated. For example, for role type 201, which is command line role 2011, the content of prompt template 2021 corresponding to command line role 2011 is "Assuming you are a command line, here are some commands for you to execute and return the results." Based on the prompt template 2021 and the content of attack request 200, template prompt 203 is generated.
[0075] S212. Generate dialogue results using an AI chat model based on template prompts, and send the dialogue results to the device corresponding to the attack request.
[0076] See S104 above, which will not be repeated here.
[0077] In the embodiments of this specification, the honeypot server stores multiple role types and corresponding prompt word templates for each role type. It matches the target prompt word template with the target role type corresponding to the attack request and generates the target prompt word. Furthermore, it generates a dialogue result using an artificial intelligence chat model based on the target prompt word. The honeypot server provided in this embodiment has high interactivity and ensures its own security by generating and returning dialogue results. Since the collected data comes from external attack requests, it will not compromise the security of internal privacy data in the data transaction server where the honeypot server is deployed.
[0078] In one embodiment, such as Figure 6 The diagram shown is a flowchart illustrating a honeypot protection method proposed in an embodiment of this specification. This method can be implemented using a computer program and can run on a honeypot protection device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application.
[0079] Specifically, the honeypot protection method includes:
[0080] S302. Based on the target role type corresponding to the attack request, match the target prompt word template from among multiple preset prompt word templates.
[0081] See S102 above, which will not be repeated here.
[0082] S304. Generate target prompts based on the attack request and the target prompt template.
[0083] See S104 above; it will not be repeated here.
[0084] S306. Generate dialogue results using an AI chat model based on target prompts, and detect whether the dialogue results are harmful.
[0085] When using an AI-powered chatbot to generate dialogue based on target prompts, it's necessary to detect whether the content of the dialogue is harmful; in other words, whether the dialogue is legal or meets preset output conditions. For example, if the dialogue contains private information, negative emotions, or biased information, it's judged as harmful or illegal. Another example is when developers preset output conditions in a honeypot server; if the dialogue doesn't meet these conditions, it's judged as harmful. Yet another example is when the dialogue involves private data from a data transaction server, it's judged as harmful.
[0086] S308. If the dialogue result is harmless, the dialogue request is sent to the device corresponding to the attack request.
[0087] When the dialogue result is determined to be harmless, it is sent to the device corresponding to the attack request. Before sending the dialogue result, it can be processed, such as by replacement, trimming, or concatenation. For example, if the attack request is web code, the dialogue result can be sent to the device corresponding to the attack request by concatenating it with the attack request. The dialogue result can be sent to the device corresponding to the attack request by displaying it on the display device of that device; this specification does not impose any restrictions on this.
[0088] S310. If the dialogue result is harmful, then intercept the dialogue result.
[0089] If a conversation outcome is deemed harmful, it is blocked; that is, the outcome is not sent to the device corresponding to the attack request, thereby preventing the harmful outcome from causing adverse effects. For example, harmful conversation outcomes containing private data can be blocked to prevent privacy leaks.
[0090] In the embodiments of this specification, the honeypot server stores multiple role types and corresponding prompt word templates for each role type. It matches the target prompt word template with the target role type corresponding to the attack request and generates the target prompt word. Furthermore, it generates a dialogue result using an artificial intelligence chat model based on the target prompt word. The honeypot server provided in this embodiment has high interactivity and ensures its own security by generating and returning dialogue results. Since the collected data comes from external attack requests, it will not compromise the security of internal privacy data in the data transaction server where the honeypot server is deployed.
[0091] The following are embodiments of the apparatus described in this specification, which can be used to execute the embodiments of the methods described in this specification. For details not disclosed in the apparatus embodiments of this specification, please refer to the embodiments of the methods described in this specification.
[0092] Please see Figure 7 This diagram illustrates a structural schematic of a honeypot protection device provided in an exemplary embodiment of this specification. The honeypot protection device can be implemented as all or part of a device through software, hardware, or a combination of both. The honeypot protection device includes a role matching module 701, a prompt generation module 702, and a dialogue sending module 703.
[0093] The role matching module 701 is used to match a target prompt word template among multiple preset prompt word templates according to the target role type corresponding to the attack request. The multiple prompt word templates correspond to multiple role types respectively.
[0094] The prompt generation module 702 is used to generate a target prompt word based on the attack request and the target prompt word template;
[0095] The dialogue sending module 702 is used to generate a dialogue result based on the target prompt words using an artificial intelligence chat model, and to send the dialogue result to the device corresponding to the attack request.
[0096] In one embodiment, the plurality of role types includes at least one of the following role types: command line role, gateway role, container role, and vulnerability role.
[0097] In one embodiment, the prompt generation module 702 includes:
[0098] A request receiving unit is used to receive the attack request;
[0099] A type matching unit is used to match a target role type among the preset plurality of role types based on the content of the attack request;
[0100] The matching prompt unit is used to match the target prompt word template corresponding to the target role type among the preset plurality of prompt word templates, based on the target role type.
[0101] In one embodiment, the prompt generation module 702 includes:
[0102] The prompt generation unit is used to fill in the target prompt word template according to the content of the attack request and generate the target prompt word.
[0103] In one embodiment, the honeypot protection device includes:
[0104] The receiving and storage module is used to receive and store the multiple role types and the prompt word templates corresponding to the multiple role types.
[0105] In one embodiment, the dialogue sending module 702 includes:
[0106] The dialogue sending unit is configured to send an application programming interface (API) request including the target prompt word to the AI chat model, so as to obtain the dialogue result corresponding to the target prompt word generated by the AI chat model, and to send the dialogue result to the device corresponding to the attack request.
[0107] In one embodiment, the dialogue sending module 702 includes:
[0108] The harmfulness detection module is used to generate dialogue results based on the target prompt words using an artificial intelligence chat model, and to detect whether the dialogue results are harmful.
[0109] The harmless determination module is used to send the dialogue result to the device corresponding to the attack request when the dialogue result is harmless.
[0110] In one embodiment, the dialogue sending module 702 further includes:
[0111] A harmful module is identified and used to intercept the dialogue result when the result is harmful.
[0112] In the embodiments of this specification, the honeypot server stores multiple role types and corresponding prompt word templates for each role type. It matches the target prompt word template with the target role type corresponding to the attack request and generates the target prompt word. Furthermore, it generates a dialogue result using an artificial intelligence chat model based on the target prompt word. The honeypot server provided in this embodiment has high interactivity and ensures its own security by generating and returning dialogue results. Since the collected data comes from external attack requests, it will not compromise the security of internal privacy data in the data transaction server where the honeypot server is deployed.
[0113] It should be noted that the honeypot protection device provided in the above embodiments is only illustrated by the division of the above functional modules when performing the honeypot protection method. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the honeypot protection device and the honeypot protection method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.
[0114] The example numbers in this specification are for descriptive purposes only and do not represent the superiority or inferiority of the examples.
[0115] This specification also provides a computer storage medium that can store multiple instructions adapted to be loaded and executed by a processor as described above. Figure 1 - Figure 6 The honeypot protection method described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figure 1 - Figure 6 The specific details of the illustrated embodiments will not be elaborated here.
[0116] This specification also provides a computer program product that stores at least one instruction, said at least one instruction being loaded and executed by the processor as described above. Figure 1 - Figure 6 The honeypot protection method described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figure 1 - Figure 6 The specific details of the illustrated embodiments will not be elaborated here.
[0117] Please see Figure 8 This document provides a schematic diagram of the structure of an electronic device as an embodiment of the present specification. Figure 8 As shown, the electronic device 800 may include: at least one processor 801, at least one network interface 804, a user interface 803, a memory 805, and at least one communication bus 802.
[0118] The communication bus 802 is used to enable communication between these components.
[0119] The user interface 803 may include a display screen and a camera. Optionally, the user interface 803 may also include a standard wired interface and a wireless interface.
[0120] The network interface 804 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0121] The processor 801 may include one or more processing cores. The processor 801 connects to various parts of the server 800 via various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 805, and by calling data stored in the memory 805. Optionally, the processor 801 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 801 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed on the screen; and the modem handles wireless communication. It is understood that the modem may also be implemented as a separate chip without being integrated into the processor 801.
[0122] The memory 805 may include random access memory (RAM) or read-only memory. Optionally, the memory 805 may include a non-transitory computer-readable storage medium. The memory 805 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 805 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 805 may also be at least one storage device located remotely from the aforementioned processor 801. Figure 8 As shown, the memory 805, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a honeypot protection application.
[0123] exist Figure 8 In the illustrated electronic device 800, the user interface 803 is mainly used to provide an input interface for the user and to obtain user input data; while the processor 801 can be used to call the honeypot protection application stored in the memory 805 and specifically perform the following operations:
[0124] Based on the target role type corresponding to the attack request, a target prompt word template is matched among multiple preset prompt word templates, and the multiple prompt word templates correspond to multiple role types respectively;
[0125] Generate target prompts based on the attack request and the target prompt template;
[0126] Based on the target prompts, an AI chat model generates a dialogue result, and the dialogue result is sent to the device corresponding to the attack request.
[0127] In one embodiment, the processor 801 executes at least one of the following role types: command line role, gateway role, container role, and vulnerability role.
[0128] In one embodiment, the processor 801 executes the step of matching a target prompt word template among a plurality of preset prompt word templates based on the target role type corresponding to the attack request. Specifically, the following steps are performed:
[0129] Receive the attack request;
[0130] Based on the content of the attack request, the target role type is matched among the preset multiple role types;
[0131] Based on the target role type, match the target prompt word template corresponding to the target role type among the preset plurality of prompt word templates.
[0132] In one embodiment, the processor 801 executes the step of generating a target prompt word based on the attack request and the target prompt word template, specifically:
[0133] Based on the content of the attack request, the target prompt word template is filled in to generate the target prompt word.
[0134] In one embodiment, before the processor 801 executes the step of matching the target prompt word template among a plurality of preset prompt word templates according to the target role type corresponding to the attack request, it also executes:
[0135] Receive and store the multiple character types and the corresponding prompt word templates for each of the multiple character types.
[0136] In one embodiment, the processor 801 executes the process of generating a dialogue result based on the target prompt word using an artificial intelligence chat model, and sending the dialogue result to the attacker, specifically:
[0137] Send an application programming interface (API) request, including the target prompt word, to the AI chat model to obtain the dialogue result corresponding to the target prompt word generated by the AI chat model, and send the dialogue result to the device corresponding to the attack request.
[0138] In one embodiment, the processor 801 executes the process of generating a dialogue result based on the target prompt word using an artificial intelligence chat model, and sending the dialogue result to the attacker, specifically:
[0139] Based on the target prompts, an AI chat model generates dialogue results, and the system detects whether the dialogue results are harmful.
[0140] If the dialogue result is harmless, the dialogue result is sent to the device corresponding to the attack request.
[0141] In one embodiment, after the processor 801 generates a dialogue result based on the target prompt word using an artificial intelligence chat model and detects whether the dialogue result is harmful, it further performs the following:
[0142] If the outcome of the dialogue is harmful, intercept the dialogue outcome.
[0143] In the embodiments of this specification, the honeypot server stores multiple role types and corresponding prompt word templates for each role type. It matches the target prompt word template with the target role type corresponding to the attack request and generates the target prompt word. Furthermore, it generates a dialogue result using an artificial intelligence chat model based on the target prompt word. The honeypot server provided in this embodiment has high interactivity and ensures its own security by generating and returning dialogue results. Since the collected data comes from external attack requests, it will not compromise the security of internal privacy data in the data transaction server where the honeypot server is deployed.
[0144] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.
[0145] The above-disclosed embodiments are merely preferred embodiments of this specification and should not be construed as limiting the scope of this specification. Therefore, any equivalent variations made in accordance with the claims of this specification shall still fall within the scope of this specification.
Claims
1. A honeypot protection method, applicable to honeypot servers, the method comprising: Based on the target role type corresponding to the attack request, a target prompt word template is matched among multiple preset prompt word templates, and the multiple prompt word templates correspond to multiple role types respectively; The step of matching a target prompt word template from multiple preset prompt word templates based on the target role type corresponding to the attack request includes: Receive the attack request; Based on the content of the attack request, the target role type is matched among the preset multiple role types; Based on the target role type, match the target prompt word template corresponding to the target role type among the preset plurality of prompt word templates; Generate target prompts based on the attack request and the target prompt template; Based on the target prompt words, a dialogue result is generated using an artificial intelligence chat model, and the dialogue result is sent to the device corresponding to the attack request; The step of generating a dialogue result using an AI chat model based on the target prompt words, and sending the dialogue result to the attacker, includes: Based on the target prompts, an AI chat model generates dialogue results, and the system detects whether the dialogue results are harmful. If the dialogue result is harmless, the dialogue result is sent to the device corresponding to the attack request; If the outcome of the dialogue is harmful, intercept the dialogue outcome.
2. The honeypot protection method according to claim 1, wherein the plurality of role types includes at least one of the following role types: command line role, gateway role, container role, and vulnerability role.
3. The honeypot protection method according to any one of claims 1-2, wherein generating the target prompt word based on the attack request and the target prompt word template includes: Based on the content of the attack request, the target prompt word template is filled in to generate the target prompt word.
4. The honeypot protection method according to any one of claims 1-2, before matching the target prompt word template among a plurality of preset prompt word templates according to the target role type corresponding to the attack request, further comprising: Receive and store the multiple character types and the corresponding prompt word templates for each of the multiple character types.
5. The honeypot protection method according to any one of claims 1-2, wherein generating a dialogue result based on the target prompt word using an artificial intelligence chat model and sending the dialogue result to the attacker comprises: Send an application programming interface (API) request, including the target prompt word, to the AI chat model to obtain the dialogue result corresponding to the target prompt word generated by the AI chat model, and send the dialogue result to the device corresponding to the attack request.
6. A honeypot protection device, suitable for honeypot servers, the device comprising: The role matching module is used to match a target prompt word template among multiple preset prompt word templates based on the target role type corresponding to the attack request. The multiple prompt word templates correspond to multiple role types respectively. The role matching module is also used to receive the attack request; and to match the target role type among the preset plurality of role types according to the content of the attack request. Based on the target role type, match the target prompt word template corresponding to the target role type among the preset plurality of prompt word templates; The prompt generation module is used to generate target prompts based on the attack request and the target prompt template; The dialogue sending module is used to generate a dialogue result based on the target prompt words using an artificial intelligence chat model, and to send the dialogue result to the device corresponding to the attack request; The dialogue sending module is also used to generate a dialogue result based on the target prompt words using an artificial intelligence chat model, and to detect whether the dialogue result is harmful; if the dialogue result is harmless, the dialogue result is sent to the device corresponding to the attack request. If the outcome of the dialogue is harmful, intercept the dialogue outcome.
7. A computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 5.
8. A computer program product storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 5.
9. An electronic device, comprising: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 8.
Citation Information
Patent Citations
Social engineering interaction method and device and storage medium
CN112398793A
Dialogue generation method, dialogue model training method and device
CN115309877A