IP reputation calculation method, device and medium integrating honey spot perception
By integrating the IP reputation calculation method of honey dot-aware, using open source intelligence and network logs to build a reputation model, the problem of insufficient IP reputation in the existing technology is solved, and higher attacker recognition rate and lower latency are achieved.
Patent Information
- Application Number
- CN202311104346.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-29
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2043-08-29
AI Technical Summary
In the prior art, relying solely on local data to calculate IP credibility is not enough to discover new attackers, and external open source intelligence data is vulnerable to attacks, resulting in low recognition rate and latency problems.
The IP reputation calculation method that integrates honey point perception is used to obtain open source intelligence data, behavior logs of WAF servers and honey point servers, build an IP-based reputation model, combine physical attributes and behavioral data to calculate the IP's reputation score, and use weight ratios to aggregate multiple reputation scores to improve the judgment accuracy.
When the behavioral data is insufficient, the attacker can be detected in advance, the recognition rate can be improved and the delay can be reduced, combining the accuracy of internal and external data.
Smart Images

Figure CN117061199B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an IP reputation calculation method, device and medium integrating honeypot perception. Background Art
[0002] In today's information society, the Internet acts as a communication bridge between virtual characters on the Internet. Many network servers provide a variety of services to users around the world. Currently, most network servers adopt a centralized mechanism. The advantage of this is that it is convenient for authoritative agencies to manage. It is precisely because of the design mechanism of centralized servers that these servers have become attractive targets.
[0003] Honeypot technology is a type of active defense technology. It attempts to simulate normal business while introducing some vulnerable hosts and services to attract attackers, capture attack traffic and samples, and waste attackers' time and resources. The honeypot technology mentioned in this system is another active defense technology that is related to but different from honeypot technology. It is a deception program designed based on the concept of containerization. It has the characteristics of lightweight container applications, easy orchestration, and fast deployment. It can be easily adapted to both local networks and cloud scenarios. It is characterized by diversity, deception, and dynamism. It can be flexibly and seamlessly integrated into the real network environment, creating a mixed environment of false and real for attackers.
[0004] Reputation systems are common in everyday life, designed to model trust between entities. They attempt to determine the trust levels of these entities by collecting mutual opinions and evaluations from these entities. Functionally, reputation systems are very similar to recommendation systems, but they are fundamentally different. The former involves arbitrary entities and focuses on trust, with entities recommending highly trusted entities to each other. The latter, on the other hand, typically involves service providers and users, focusing on user preferences, with service providers making recommendations to users.
[0005] The common open-source cyber threat intelligence platforms currently on the market can essentially be classified as reputation systems. Users in the platform forums regularly upload threat intelligence. This data, usually in units of IP addresses, records the malicious behavior of the IP addresses, such as sending malicious emails, launching DDoS attacks, and setting up fraudulent websites. This intelligence ensures that the platform's data is updated in a timely manner and also makes the platform data more comprehensive.
[0006] IP reputation technologies based on local data generally include the following:
[0007] 1. Spam blacklist technology: A spam blacklist is maintained locally. This method checks whether an IP address appears on a list of known spammers and evaluates it based on the frequency and volume of appearances. If an IP address appears frequently on the spammer list, its reputation will be affected.
[0008] 2. Sending volume control technology: This method prevents spam and malware by monitoring the number of emails sent by an IP address. If the IP address frequently sends a large number of emails, its reputation will be affected.
[0009] 3. User complaint rating technology: This method tracks the frequency and number of user complaints about IP addresses and rates them based on their specific circumstances. If an IP address receives a large number of user complaints, its credibility will also be reduced.
[0010] Simply using third-party open source threat intelligence will bring about data trust issues, because anyone can submit data to the platform, and the platform's audit data capabilities are limited. Therefore, over-reliance on external data will make it vulnerable to attacks.
[0011] If only local data is used to calculate IP reputation, its ability to detect new attackers will be insufficient, and spam blacklist technology will lead to delays in list updates; sending volume control technology will cause delays, as it takes time to obtain sufficient data and information to make an accurate assessment. During this process, malicious behavior may have already caused losses; user complaint ratings require the collection of a large amount of user-related data, which may bring privacy issues. Summary of the Invention
[0012] In order to overcome the problems existing in the related art, the present disclosure provides an IP reputation calculation method, device and medium integrating honey spot perception to solve the technical problems of the related art.
[0013] One or more embodiments of this specification provide an IP reputation calculation method integrating honeypot awareness, including the following steps:
[0014] Obtain open-source intelligence data and filter out intelligence data containing attack behaviors; obtain all first-action logs that access the WAF server and second-action logs that access the honeypot server;
[0015] Extract blacklisted IP addresses from open-source intelligence data as a blacklist. Build a reputation model based on the physical attributes of the IP by constructing the blacklist to calculate the reputation score based on the physical attributes of the IP.
[0016] For any IP address, the R1, R2, and R3 scores are calculated based on the first and second behavior logs and open-source intelligence data within a preset time period. The calculation includes:
[0017] Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the first and second weights for the IP, and normalize them to obtain the R1 score for the IP;
[0018] Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the third and fourth weights for the IP, and normalize them to obtain the R2 score for the IP.
[0019] Determine the physical attribute type of the IP record in the open source intelligence data and the weight of the corresponding physical attribute type to calculate the physical attribute reputation score of the IP. Then determine the attack behavior of the IP record in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the behavioral reputation score of the IP. Aggregate the physical attribute reputation score and the behavioral reputation score to obtain the R3 score of the IP.
[0020] Aggregate the R1 score, R2 score, and R3 score corresponding to each IP according to the set weight ratio to obtain the corresponding IP reputation score and record it;
[0021] Get and return the reputation score of the specified IP within the target period.
[0022] One or more embodiments of this specification provide an IP reputation calculation device integrating honeypot awareness, including:
[0023] Data acquisition module: used to obtain open source intelligence data and filter out intelligence data containing attack behaviors; obtain the first behavior logs of all visits to the WAF server and the second behavior logs of visits to the honeypot server;
[0024] Reputation score calculation model construction module: This module is used to extract blacklist IP addresses from open source intelligence data as a blacklist, build a reputation model based on the physical attributes of the IP, and calculate the reputation score based on the physical attributes of the IP;
[0025] Reputation Score Calculation Module: This module calculates the R1, R2, and R3 scores for any IP address based on the first and second behavior logs and open-source intelligence data within a preset time period. The calculation includes:
[0026] Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the first and second weights for the IP, and normalize them to obtain the R1 score for the IP;
[0027] Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the third and fourth weights for the IP, and normalize them to obtain the R2 score for the IP.
[0028] Determine the physical attribute type of the IP record in the open source intelligence data and the weight of the corresponding physical attribute type to calculate the physical attribute reputation score of the IP. Then determine the attack behavior of the IP record in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the behavioral reputation score of the IP. Aggregate the physical attribute reputation score and the behavioral reputation score to obtain the R3 score of the IP.
[0029] Reputation score determination module: used to aggregate the R1 score, R2 score and R3 score corresponding to each IP according to the set weight ratio to obtain the corresponding IP's reputation score and record it;
[0030] Search module: Based on the specified IP, obtain and return the reputation score of the IP within the corresponding target period.
[0031] One or more embodiments of this specification provide a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the steps of the above-described method for calculating IP reputation integrating honeyspot awareness are implemented.
[0032] The method of this embodiment can calculate the reputation score based on the similarity between the IP address and the blacklisted IP addresses when insufficient behavioral data is available for the specified IP address, that is, when there is no access record for the IP address in either the WAF server or the honeypot server. This method can also fully exploit the log data from the honeypot server to detect attackers in advance. Moreover, this method can simultaneously combine the system's internal behavioral logs and external real-time threat intelligence data to improve the accuracy of the judgment. The periodic update calculation method also avoids the problem of excessive delay caused by directly retrieving all logs for calculation in a single query. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate one or more embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0034] Figure 1 A flowchart of a complex honeypot-aware IP reputation calculation method provided in one or more embodiments of this specification;
[0035] Figure 2 A block diagram of a complex honeypot-aware IP reputation calculation device provided in one or more embodiments of this specification;
[0036] Figure 3 A schematic diagram of the structure of a computer provided for one or more embodiments of this specification. DETAILED DESCRIPTION
[0037] In order to help those skilled in the art better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below in conjunction with the drawings in one or more embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this invention.
[0038] The present invention will be described in detail below with reference to specific implementation methods and the accompanying drawings.
[0039] Method Example
[0040] According to an embodiment of the present invention, a method for calculating IP reputation based on complex honeypot perception is provided. Figure 1 FIG. 1 is a flowchart of the IP reputation calculation method integrating honey spot awareness provided in this embodiment. The IP reputation calculation method integrating honey spot awareness according to the embodiment of the present invention includes:
[0041] Step S1: Obtain open source intelligence data and filter out intelligence data containing attack behaviors; obtain the first behavior logs of all visits to the firewall (WAF) server and the second behavior logs of visits to the honeypot server; wherein,
[0042] In this embodiment, a script can be written to regularly access third-party open-source threat intelligence data and convert some of this data into access logs, recording the source IP address, attack type, and attack event time. Some IP addresses from the open-source intelligence can also be extracted as a blacklist. The physical attributes of all IP addresses in the open-source intelligence are stored locally, including information such as country, city, autonomous system number, and coordinates. When crawling IP objects, priority is given to crawling information related to IPs in the same network segment as those that appear in honey spots and WAFs.
[0043] In this embodiment, a program is run periodically to request honeyspot servers and Web application firewall (WAF) servers deployed on the intranet and public network, parse the obtained access logs into a fixed format, and obtain all first-behavior logs of all visits to the firewall (WAF) server and second-behavior logs of all visits to the honeyspot server required for calculating IP reputation.
[0044] Step S2: extract blacklist IP addresses from the open source intelligence data as a blacklist list, and build a reputation model based on the physical attributes of the IP through the blacklist list to calculate the reputation score based on the physical attributes of the IP.
[0045] In this embodiment, the blacklist obtained above is modeled. First, for the IP addresses in the blacklist, the corresponding physical attribute values are obtained. For an m-type attribute space, for an m-type physical attribute space, the i-th IP address is represented as:
[0046] IP x =x i,1 ,x i,2 ,…,x i,m ;
[0047] Normalize the attribute values of each type of physical attribute of each IP address to obtain the normalized value, and obtain the reputation model parameters based on the physical attributes of each IP address. The normalized value is calculated as:
[0048]
[0049] Where, Represents the physical property value x i,j The number of occurrences, x i,j represents the jth attribute of the i-th IP, N total Indicates the number of IP addresses in the blacklist.
[0050] Traverse all IPs on the blacklist, applying the above formula to each IP, ultimately obtaining model data consisting of several NFs. Step S3: For any IP, calculate the R1, R2, and R3 scores corresponding to that IP based on the first and second behavior logs and open-source intelligence data within a preset time period. The preset time period is a time window of a specified length, and the first and second behavior logs and open-source intelligence data within the preset time window are obtained based on the preset time period.
[0051] In this embodiment, the reputation score that integrates physical attribute data and access logs can be divided into three dimensions, represented by R1, R2, and R3 respectively. The R1 score is calculated using WAF log data, the R2 score is calculated using honeypot log data, and the R3 score is calculated using third-party threat intelligence data. The final reputation score is then calculated using a preset aggregation method; the details are as follows.
[0052] In this embodiment, the IP sets that appear in the WAF log data and the honey spot log data within a preset period are respectively recorded as S WAF and S hnp , and denote the union of the two as S IP For S IP For each IP in the , calculate its R1, R2 and R3 scores, which are calculated as follows:
[0053] The calculation of R1, R2, and R3 scores includes:
[0054] 1) Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of the attack type in this update cycle, calculate the product of the first weight and the second weight of the IP, and normalize them to obtain the R1 score of the IP.
[0055] Specifically, the calculation of the R1 score refers to the access log of the WAF server within a preset period of time. In this log, the attack type and attack launch time of the corresponding IP are recorded in detail. Different attack types have different weights. In addition, to prevent the threat level of some low-threat attacks from being easily greater than that of other attack types due to the accumulation of attacks, a weight is given to the number of attacks. The product of the threat level of each attack type and the weight corresponding to the number of attacks is summed and normalized to form the R1 score. The detailed calculation method is as follows:
[0056]
[0057] Among them, A is the complete set of attack types, W type() is the first weight corresponding to the attack type, W n,aIt is the second weight corresponding to the number of attacks of the attack type in this update cycle; the closer it is to 1, the more dangerous it is.
[0058] 2) Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of the attack type in this update cycle, calculate the weight product of the third weight and the fourth weight for the IP, and normalize them to obtain the R2 score of the IP.
[0059] Specifically, the R2 score is calculated by referring to the access log of the honeypot server within a preset period. In this log, relevant information such as the attack type initiated by the IP, the time when the request was initiated, and the payload of the request is recorded in detail. Referring to the calculation method of R1, each request and the corresponding number of attacks are given a corresponding weight, and then the sum of the products is calculated and normalized to obtain the R2 score. The detailed calculation method is as follows:
[0060]
[0061] Among them, A is the complete set of attack types, W type() is the weight corresponding to the attack type, W n, The weight of the attack is the number of attacks in this update cycle. The difference between the calculation of R2 and R1 is that the attack type is different and the corresponding weight is also different.
[0062] 3) Determine the physical attribute type of the IP recorded in the open source intelligence data and the weight of the corresponding physical attribute type, calculate the reputation score of the IP's physical attribute through the reputation model, then determine the attack behavior of the IP recorded in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the IP's behavioral reputation score, aggregate the physical attribute reputation score and the behavioral reputation score to obtain the IP's R3 score.
[0063] Specifically, the R3 score calculation consists of two parts: physical attribute-based and behavioral data-based. The significance of the reputation score based on physical attributes is that for a new IP, the internal access logs are relatively few, or even non-existent. Therefore, it is necessary to measure the threat of the IP by calculating the similarity between the IP and the blacklisted IP. The reputation score based on physical attributes can be performed according to the following steps:
[0064] Query the properties of the IP and express them as:
[0065] IP x =x i,1 ,x i,2 ,…,x i,m
[0066] Use step S2 to obtain the reputation model of each IP, solve the normalized value corresponding to the attribute value of the IP, and use the following formula to calculate the reputation score based on physical attributes:
[0067]
[0068]
[0069] Among them, NF i is the normalized value of the i-th attribute, w i is the corresponding weight, ED max The maximum normalized value of each attribute in the blacklist is used for calculation. Since different types of attribute values provide different meanings, this reputation model tends to give greater weight to coordinate-type attributes and smaller weight to country-type attributes.
[0070] After obtaining the reputation score based on physical attributes, you can use the data containing attack behaviors in third-party threat intelligence to calculate the behavior-based reputation score. When calculating this part of the reputation, the calculation is mainly based on the behavior type issued by the IP. Assuming that the IP to be calculated is src_ip, you can first retrieve the behavior log with the source IP src_ip. To avoid excessive calculation time caused by too many logs, filter out logs within a specified time window. Assuming the current time is t, the IP's behavior reputation score based on external data can be calculated using the following formula:
[0071]
[0072] Among them, the attenuation is to be more in line with the laws of nature, arctan is to map the infinite interval to the finite interval, S i is the threat level of the log behavior, w is the time window, and Dec(t′,t) is the decay function, which is expressed as follows:
[0073] Dec(t′,t)= -K*(t-t′)
[0074] The next step is aggregation, which combines the attribute-based and behavior-based reputation scores:
[0075] Rep=C1*Rep beh +C2*Rep attr ;
[0076] Among them, C1 and C2 are preset constant coefficients;
[0077] Finally, a score will be obtained, and then the score will be normalized to obtain the R3 score. The normalization calculation formula is as follows:
[0078]
[0079] Step S4: Aggregate the R1 score, R2 score, and R3 score corresponding to each IP according to the set weight ratio to obtain the reputation score of the corresponding IP and record and save it, for example, update these reputation values to the IP reputation database.
[0080] In this embodiment, since the internal data of the system (i.e., logs of accessed firewall (WAF) servers and logs of accessed honeypot servers) is more detailed, the aggregation process of this embodiment gives greater weight to R1 and R2, and then synchronizes the aggregated score as the reputation score for the current time interval to the IP reputation system database. The specific aggregation formula is as follows:
[0081]
[0082] Step S5: According to the specified IP, obtain and return the reputation score of the corresponding IP within the target period. In this embodiment, the object to be obtained is a search initiated by a protection system such as a firewall, so the returned object is also the protection system.
[0083] The method of this embodiment can calculate the reputation score based on the similarity between the IP address and the blacklisted IP addresses when insufficient behavioral data is available for the specified IP address, that is, when there is no access record for the IP address in either the WAF server or the honeypot server. This method can also fully exploit the log data from the honeypot server to detect attackers in advance. Moreover, this method can simultaneously combine the system's internal behavioral logs and external real-time threat intelligence data to improve the accuracy of the judgment. The periodic update calculation method also avoids the problem of excessive delay caused by directly retrieving all logs for calculation in a single query.
[0084] In this embodiment, preferably, obtaining and returning the reputation score of the corresponding IP according to the specified IP is specifically as follows:
[0085] According to the instruction, the reputation score of the specified IP within the target time period is obtained. If there is a corresponding reputation score record, the average, minimum and maximum values are calculated for all reputation score records of the IP within the target time period, and the corresponding reputation score is returned according to the preset return policy. If the IP reputation score record does not exist in the database, the IP reputation score is recalculated. The reason why the average, minimum and maximum values are calculated separately is because the effects brought about in the three cases are different; because there may be multiple records for an IP within a specified time period; for example, for the maximum and minimum values, if the system has very high security requirements, a threshold will be set. If the minimum value in an IP reputation score record is smaller than the threshold, then the IP will be denied access. If the security requirements are not high, if the maximum value exceeds this threshold, then the IP can be released. In some embodiments, the recalculation of the IP reputation score is specifically as follows:
[0086] Determine the corresponding open source intelligence data of the IP within the target time period, the first behavior log of the IP accessing the WAF server and the second behavior log of the IP accessing the honeypot server. If there is no first behavior log of the IP accessing the WAF server and the second behavior log of the IP accessing the honeypot server, the R1 and R2 scores of the IP are the preset default values. Then, calculate the R3 score of the IP based on the open source intelligence data, aggregate the R1, R2 and R3 scores to obtain and return the final IP reputation score; if there is no open source intelligence data at the same time, the R1, R2 and R3 scores of the IP are all the preset default values, aggregate the R1, R2 and R3 scores and return the final IP reputation score.
[0087] Device embodiment
[0088] According to an embodiment of the present invention, an IP reputation calculation device integrating honeypot perception is provided. Figure 2 FIG. 1 is a block diagram of an IP reputation calculation device integrating honey spot awareness according to an embodiment of the present invention. The IP reputation calculation device integrating honey spot awareness according to an embodiment of the present invention includes:
[0089] Data acquisition module 10: used to obtain open source intelligence data and filter out intelligence data containing attack behaviors; obtain all first behavior logs that have accessed the WAF server and second behavior logs that have accessed the honeypot server;
[0090] Reputation score calculation model construction module 20: used to extract blacklist IP addresses from open source intelligence data as a blacklist list, build a reputation model based on the physical attributes of the IP through the blacklist list, and calculate the reputation score based on the physical attributes of the IP;
[0091] Reputation score calculation module 30: for calculating the R1, R2, and R3 scores corresponding to any IP address based on the first behavior log, the second behavior log, and open source intelligence data within a preset time period; wherein the calculation includes:
[0092] Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the first and second weights for the IP, and normalize them to obtain the R1 score for the IP;
[0093] Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the third and fourth weights for the IP, and normalize them to obtain the R2 score for the IP.
[0094] Determine the physical attribute type of the IP record in the open source intelligence data and the weight of the corresponding physical attribute type to calculate the physical attribute reputation score of the IP. Then determine the attack behavior of the IP record in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the behavioral reputation score of the IP. Aggregate the physical attribute reputation score and the behavioral reputation score to obtain the R3 score of the IP.
[0095] Reputation score determination module 40: used to aggregate the R1 score, R2 score and R3 score corresponding to each IP according to the set weight ratio to obtain the reputation score of the corresponding IP and record and save it;
[0096] Search module 50: Based on the specified IP, obtain and return the reputation score of the IP within the corresponding target time period.
[0097] The embodiment of the present invention is an apparatus embodiment corresponding to the above-mentioned method embodiment. The specific operations of the processing steps of each module can be understood by referring to the description of the method embodiment, and will not be repeated here.
[0098] like Figure 3 As shown, the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the IP reputation calculation method integrating honey spot awareness in the above embodiment is implemented. Alternatively, when the computer program is executed by a processor, the IP reputation calculation method integrating honey spot awareness in the above embodiment is implemented. When the computer program is executed by the processor, the following method steps are implemented:
[0099] Step S1: Obtain open source intelligence data and filter out intelligence data containing attack behaviors; obtain all first behavior logs that have accessed the WAF server and second behavior logs that have accessed the honeypot server.
[0100] Step S2: extract blacklist IP addresses from the open source intelligence data as a blacklist list, and build a reputation model based on the physical attributes of the IP by constructing the blacklist list to calculate the reputation score based on the physical attributes of the IP.
[0101] Step S3: For any IP, calculate the R1, R2, and R3 scores corresponding to the IP based on the first behavior log, the second behavior log, and the open source intelligence data within a preset time period;
[0102] Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the first and second weights for the IP, and normalize them to obtain the R1 score for the IP;
[0103] Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the third and fourth weights for the IP, and normalize them to obtain the R2 score for the IP.
[0104] Determine the physical attribute type of the IP record in the open source intelligence data and the weight of the corresponding physical attribute type to calculate the physical attribute reputation score of the IP. Then determine the attack behavior of the IP record in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the behavioral reputation score of the IP. Aggregate the physical attribute reputation score and the behavioral reputation score to obtain the R3 score of the IP.
[0105] Step S4: Aggregate the R1 score, R2 score, and R3 score corresponding to each IP according to the set weight ratio to obtain the reputation score of the corresponding IP and record and save it, for example, update these reputation values to the IP reputation database.
[0106] Step S5: According to the specified IP, obtain and return the corresponding IP reputation score.
[0107] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0108] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments. The device and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative efforts.
[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. The IP reputation calculation method integrating honeypot perception is characterized by: The following steps are involved: Obtain open-source intelligence data and filter out intelligence data containing attack behaviors; obtain all first-action logs that access the WAF server and second-action logs that access the honeypot server; Extract blacklisted IP addresses from open-source intelligence data as a blacklist, and use the blacklist to build a reputation model based on the physical attributes of the IP to calculate the reputation score based on the physical attributes of the IP; For any IP address, the R1, R2, and R3 scores are calculated based on the first and second behavior logs and open-source intelligence data within a preset time period. The calculation includes: Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the first and second weights for the IP, and normalize them to obtain the R1 score for the IP; Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the third and fourth weights for the IP, and normalize them to obtain the R2 score for the IP. Determine the physical attribute type of the IP recorded in the open source intelligence data and the weight of the corresponding physical attribute type, calculate the reputation score of the IP's physical attribute through the reputation model, then determine the attack behavior of the IP recorded in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the IP's behavioral reputation score, aggregate the physical attribute reputation score and the behavioral reputation score to obtain the IP's R3 score; Aggregate the R1 score, R2 score, and R3 score corresponding to each IP according to the set weight ratio to obtain the corresponding IP reputation score and record it; Get and return the reputation score of the specified IP within the target period.
2. The IP reputation calculation method integrating honeypot perception as claimed in claim 1, characterized in that: The specific steps of obtaining and returning the reputation score of the corresponding IP according to the specified IP are as follows: According to the instructions, the reputation score of the specified IP within the target time period is obtained. If the corresponding reputation score record exists, the average, minimum and maximum values are calculated for all reputation score records of the IP within the target time period, and the corresponding reputation score is returned according to the preset return strategy. If the IP reputation score record does not exist in the database, the IP reputation score is recalculated.
3. The IP reputation calculation method integrating honeypot perception as claimed in claim 2, characterized in that: The recalculation of the IP reputation score is specifically as follows: Determine the corresponding open source intelligence data of the IP within the target time period, the first behavior log of the IP accessing the WAF server and the second behavior log of the IP accessing the honeypot server. If there is no first behavior log of the IP accessing the WAF server and the second behavior log of the IP accessing the honeypot server, the R1 and R2 scores of the IP are the preset default values. Then, calculate the R3 score of the IP based on the open source intelligence data, aggregate the R1, R2 and R3 scores to obtain and return the final IP reputation score; if there is no open source intelligence data at the same time, the R1, R2 and R3 scores of the IP are all the preset default values, aggregate the R1, R2 and R3 scores and return the final IP reputation score.
4. The IP reputation calculation method integrating honeypot perception as claimed in claim 1, characterized in that: The specific steps of building a reputation model based on the physical attributes of IP are as follows: According to each IP address in the blacklist, obtain its physical attribute value. For m types of physical attribute space, the i-th IP address is expressed as: IP x =x i,1 ,x i,2 ,…,x i,m ; Normalize the attribute values of each type of physical attribute of each IP address to obtain the normalized value, and obtain the reputation model parameters based on the physical attributes of each IP address. The normalized value is calculated as: Where, Represents the physical property value x i,j The number of occurrences, x i,j represents the jth attribute of the i-th IP, N total Indicates the number of IP addresses in the blacklist.
5. The IP reputation calculation method integrating honeypot perception as claimed in claim 1, characterized in that: The R1 score of the IP is calculated as follows: Determine the attack type and number of attacks recorded by the IP in the first line of the log, and determine the IP's R1 score based on the following calculation: Among them, A is the complete set of attack types, W type(a) is the first weight corresponding to the attack type, W n,a It is the second weight corresponding to the number of attacks of the attack type in this update cycle.
6. The IP reputation calculation method integrating honeypot perception as claimed in claim 1, characterized in that: The R2 score of the IP is calculated as follows: Determine the attack type and number of attacks recorded by the IP in the second line of the log, and determine the IP's R2 score based on the following calculation: Among them, A is the complete set of attack types, W type(a) is the third weight corresponding to the attack type, W n,a It is the fourth weight corresponding to the number of attacks of the attack type in this update cycle.
7. The IP reputation calculation method integrating honeypot perception as described in claims 1-3 is characterized in that: The physical attribute type of the IP record in the open source intelligence data and the weight of the corresponding physical attribute type are determined to calculate the physical attribute reputation score of the IP. Then, the attack behavior of the IP record in the open source intelligence data and the threat level of the corresponding attack behavior are determined to calculate the behavior reputation score of the IP. The physical attribute reputation score and the behavior reputation score are aggregated to obtain the R3 score of the IP. The physical attribute reputation score is calculated as follows: Query the properties of the IP and express them as: IP x =x i,1 ,x i,2 ,…,x i,m ; Through the reputation model of physical attributes, solve the normalized value corresponding to the attribute value of the IP, and calculate the reputation score Rep based on the physical attributes of the IP through the following formula attr : Among them, NF i is the normalized value of the i-th attribute, w i is the weight of the normalized value of the corresponding attribute, ED max The maximum normalized value of each attribute in the blacklist is used for calculation. The larger the ED value, the more dangerous it is. Determine the data containing attack behaviors in the target period in the open source intelligence data, and calculate the IP behavior-based reputation score Rep according to the threat level of the IP corresponding to the attack behavior and the attenuation function using the following formula beh : Among them, S i is the threat level of the log behavior, w is the time window, t is the current time, and Dec(t′,t) is the decay function, which is expressed as follows: Dec(t′,t)=e -K*(t-t′) ; Aggregate IP reputation scores based on physical attributes and behavior: Rep=C1*Rep beh +C2*Rep attr ; Among them, C1 and C2 are preset constant coefficients; Finally, a score will be obtained, and then the score will be normalized to obtain the R3 score. The normalization calculation formula is as follows:
8. The IP reputation calculation method integrating honeypot perception as claimed in claim 1, characterized in that: The R1 score, R2 score and R3 score corresponding to each IP are aggregated according to the set weight ratio to obtain the corresponding IP reputation score calculation as follows:
9. An IP reputation calculation device integrating honeypot perception, characterized in that: include: Data acquisition module: used to obtain open source intelligence data and filter out intelligence data containing attack behaviors; Obtain all first-action logs that access the WAF server and all second-action logs that access the honeypot server; Reputation score calculation model construction module: This module is used to extract blacklist IP addresses from open source intelligence data as a blacklist, build a reputation model based on the physical attributes of the IP, and calculate the reputation score based on the physical attributes of the IP; Reputation Score Calculation Module: This module calculates the R1, R2, and R3 scores for any IP address based on the first and second behavior logs and open-source intelligence data within a preset time period. The calculation includes: Determine the attack type and number of attacks recorded by the IP in the first behavior log, determine the first weight corresponding to each attack type and the second weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the first and second weights for the IP, and normalize them to obtain the R1 score for the IP; Determine the attack type and number of attacks recorded by the IP in the second behavior log, determine the third weight corresponding to each attack type and the fourth weight corresponding to the number of attacks of that attack type in the current update cycle, calculate the product of the third and fourth weights for the IP, and normalize them to obtain the R2 score for the IP. Determine the physical attribute type of the IP record in the open source intelligence data and the weight of the corresponding physical attribute type to calculate the physical attribute reputation score of the IP. Then determine the attack behavior of the IP record in the open source intelligence data and the threat level of the corresponding attack behavior to calculate the behavioral reputation score of the IP. Aggregate the physical attribute reputation score and the behavioral reputation score to obtain the R3 score of the IP. Reputation score determination module: used to aggregate the R1 score, R2 score and R3 score corresponding to each IP according to the set weight ratio to obtain the corresponding IP's reputation score and record it; Search module: Based on the specified IP, obtain and return the reputation score of the IP within the corresponding target period.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the IP reputation calculation method integrating honeyspot perception are implemented as claimed in any one of claims 1 to 8.
Citation Information
Patent Citations
Internet protocol (IP) credibility library generation method and device
CN106790041A
Whole-ship computing environment cloud honeypot and attack event perception and behavior analysis method
CN115694928A