Method, system, equipment and medium for trapping network attack behaviors in power information systems

By establishing a virtual honeynet network, formulating honey baits of different sweetness, and using collection probes to monitor and analyze, adjusting traffic, and actively attracting attackers into the virtual honeynet, the problem of insufficient capture of zero-day vulnerability exploits and advanced persistent threats by honeypot technology is solved, and efficient capture of attack behaviors on power information systems is achieved.

CN118784334BActive Publication Date: 2025-09-23STATE GRID ELECTRIC POWER RES INST +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411013736.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-26
Publication Date
2025-09-23
Estimated Expiration
2044-07-26

AI Technical Summary

Technical Problem

Existing honeypot technology has insufficient capture mechanisms when facing zero-day vulnerability exploits and advanced persistent threat attacks, making it difficult to fully capture attack behaviors. In addition, the deployment location affects the effect, making it impossible to fully analyze the attack steps and means.

Method used

Establish a virtual honeynet network, obtain network entity information of the power information system, formulate honey baits of different sweetness, use collection probes to monitor and analyze, adjust system traffic, and actively draw attackers into the virtual honeynet to achieve in-depth capture.

Benefits of technology

It effectively identifies and locks network attack behaviors, solves the technical problems existing in existing technologies, realizes the technical means of the cyberspace dimension, solves the technical problems existing in existing technologies, realizes the effect of network attacks, solves the existing technical problems, and realizes the in-depth capture system of the cyberspace dimension.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118784334B_ABST
    Figure CN118784334B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, system, device, and medium for trapping network attack behaviors in an electric power information system. The method comprises: obtaining network entity information of the electric power information system; establishing a network space topology map and a virtual simulation device based on the network entity information, deploying network simulation information in the virtual simulation device, and mirroring a virtual honeynet network with the same network structure as the electric power information system; formulating honey baits of varying sweetness based on the sensitivity of the electric power information system data and the degree of harm of network security vulnerabilities, and delivering the honey baits to the virtual honeynet network; monitoring and analyzing the physical network and the virtual honeynet network based on acquisition probes to determine whether the corresponding network is under network attack; and attracting attackers into the virtual honeynet network by adjusting the system traffic of the physical network and the honeynet network based on the network attack determination result. The method of the present invention can implement deception and trapping of network attacks under the premise of low coupling of business programs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a method, system, equipment and medium for trapping network attack behaviors in an electric power information system. Background Art

[0002] The power system, a critical national infrastructure crucial to energy security, has long been a key target of cyber warfare. Cyberattacks targeting power systems, due to their highly targeted, covert, and destructive nature, have become a global challenge affecting power network security. Zero-day vulnerability exploits and advanced persistent threat (APT) attacks pose the greatest threat. Once the power grid is attacked by such attacks, it can not only cause large-scale power outages, disrupting people's daily lives and production, but also lead to the leakage of sensitive power data.

[0003] The power industry has introduced honeypot systems as a proactive defense measure, but there have been instances where attackers have discovered and circumvented them. This is because while existing honeypot technology can provide an interactive environment for attackers, luring them into launching attacks, its attack capture mechanisms still suffer from limitations such as limited data collection, insufficient traceability, and strong integration with business systems. This makes it difficult to capture new attacks such as zero-day vulnerability exploits and APTs, and the capture of attack behavior is incomplete and lacks depth. Furthermore, existing honeypots are unable to fully analyze the attack steps and methods used by attackers in the face of new attacks like APTs. Furthermore, traditional honeypot deployment requires a combination of business system characteristics and technical expertise, and its deployment location significantly impacts the effectiveness of attack capture. Summary of the Invention

[0004] Purpose of the invention: In response to the deficiencies of the prior art, the present invention provides a method, system, device and storage medium for trapping network attack behaviors in a power information system, which can implement deception and trapping of network attacks under the premise of low coupling of business programs.

[0005] Technical solution: In the first aspect, a method for trapping network attack behaviors in a power information system comprises the following steps:

[0006] Acquiring network entity information of the power information system;

[0007] Based on the network entity information, a network space topology map and a virtual simulation device are established, network simulation information is deployed on the virtual simulation device, the network simulation information includes network entity information corresponding to the network entity device, and based on the network space topology map, the virtual simulation device and the network simulation information, a virtual honeynet network with the same network structure as the power information system is mirrored;

[0008] Combining the sensitivity of power information system data and the degree of harm of network security vulnerabilities, honey baits of different sweetness are formulated and delivered to the virtual honeynet network;

[0009] Based on the collection probe, the physical network and the virtual honeynet network with honey bait are monitored and analyzed, and the corresponding network is judged according to the monitoring and analysis results to determine whether it is under network attack;

[0010] According to the results of network attack judgment, the system traffic of the physical network and the virtual honeynet network is adjusted, and honey bait is continuously delivered to attract attackers into the virtual honeynet network.

[0011] Furthermore, obtaining network entity information of the power information system includes:

[0012] Based on the fact that the business system module of the power information system includes a database, a cloud platform, and a software system, and the network entity devices include business servers, terminal devices, network devices, and network security protection devices, a collection tool is deployed in the power information system to collect necessary network entity information, wherein the network entity information includes operating system-related information of the business server, application system-related information, terminal device-related information, network device-related information, and network security protection device-related information, as well as corresponding configuration data;

[0013] The network entity devices are scanned and traversed by a collection tool to determine whether the device type is a network control device or a non-network control device. The network control device is a network device with a routing function.

[0014] Furthermore, establishing a network space topology map based on the network entity information includes:

[0015] If the device type scanned by the collection tool is a network control device, then the relevant network control device connection is established in the network topology, and the physical device information under the network control device is scanned at the same time;

[0016] If the device type scanned by the collection tool is not a network control device, add the device to the corresponding network control device;

[0017] Based on a traversal scan of all network physical devices, a network space topology map with network control devices as nodes is established.

[0018] Furthermore, considering the sensitivity of power information system data and the degree of harm caused by network security vulnerabilities, different levels of sweetness of honey bait are formulated, including:

[0019] Based on the classification and grading method for power sensitive data, power data is divided into several sensitivity levels;

[0020] Based on the system vulnerability classification rules and published vulnerability information, vulnerabilities applicable to virtual simulation devices are selected and classified into several levels of damage;

[0021] The sensitivity of power data with different sensitivity levels and the harmfulness of vulnerabilities with different harmfulness levels are quantified and mapped to the same dimensional space. The power sensitive data and system vulnerabilities are combined to form files with different sweetness, which are called honey bait.

[0022] Furthermore, the sensitivity of power data with different sensitivity levels and the harmfulness of vulnerabilities with different harm levels are quantified and mapped into the same dimensional space, including:

[0023] Assign initial values ​​to the sensitivity of power data of different sensitivity levels and the vulnerability hazards of different hazard levels, where the values ​​assigned to high-level data are higher than those assigned to low-level data;

[0024] Calculate the mean and standard deviation of the sensitivity and vulnerability severity values ​​of power data respectively;

[0025] Quantify various sensitive data and vulnerability data based on mean and standard deviation;

[0026] The quantitative values ​​of power data sensitivity and vulnerability harm are mapped to the same dimensional space [0,1].

[0027] Furthermore, power-sensitive data is combined with system vulnerabilities to form files of varying sweetness, including:

[0028] Design the weights of power sensitive data and vulnerability hazard weights, and perform weighted summation on the quantified values ​​of power data sensitivity and vulnerability hazard in the same dimensional space to form a honey bait with corresponding sweetness value.

[0029] Furthermore, based on the acquisition probe, the physical network and the virtual honeynet network that delivered the honey bait are monitored and analyzed. Based on the monitoring and analysis results, it is determined whether the corresponding network is under network attack, including:

[0030] Based on the network physical devices and virtual simulation devices, deploy network collection probes and virtual network collection probes with traffic monitoring, log auditing and network information collection;

[0031] Based on the data collected by network collection probes and virtual network collection probes, analyze whether the corresponding network is under network attack.

[0032] Furthermore, based on the network attack judgment results, by adjusting the system traffic of the physical network and the honeynet network and continuously delivering honey bait, the attacker is attracted to enter the virtual honeynet network, including:

[0033] Determining whether a network attack is detected on the virtual honeynet network based on the operating data of the network collection probe deployed by the virtual simulation device;

[0034] If so, determining whether the network acquisition probe deployed by the physical network device detects a network attack;

[0035] If the physical network does not detect the network attack, the attacker is lured to continue attacking the virtual honeynet network by continuously delivering honey bait, and the attack behavior is traced and analyzed to create a profile of the attacker;

[0036] If a network attack is detected on the physical network, the attacker is actively drawn into the virtual honeynet network by reducing the data interaction of the physical network and increasing the interaction of the virtual honeynet network, and then the attacker is attacked.

[0037] After the attacker is drawn into the honeynet network, the physical network equipment is hardened.

[0038] In the second aspect, a network attack behavior trapping system for a power information system includes:

[0039] A device detection module, configured to obtain network entity information of the power information system;

[0040] A virtual simulation module is configured to establish a network space topology map and a virtual simulation device based on the network entity information, deploy network simulation information on the virtual simulation device, wherein the network simulation information includes network entity information corresponding to the network entity device, and mirror a virtual honeynet network with the same network structure as the power information system based on the network space topology map, the virtual simulation device, and the network simulation information;

[0041] The honey bait delivery module is used to formulate honey baits of different sweetness based on the sensitivity of power information system data and the degree of harm of network security vulnerabilities, and then deliver the honey baits to the virtual honeynet network;

[0042] The monitoring and analysis module is used to monitor and analyze the physical network and the virtual honeynet network that has delivered honey bait based on the collection probe, and determine whether the corresponding network is under network attack based on the monitoring and analysis results;

[0043] The traffic traction module is used to adjust the system traffic of the physical network and the virtual honeynet network according to the results of network attack judgment, and continuously deliver honey bait to attract attackers into the virtual honeynet network.

[0044] Furthermore, the device detection module includes:

[0045] A device information acquisition unit is configured to deploy a collection tool in the power information system to collect network entity information based on the power information system business system module including a database, a cloud platform, and a software system, and network entity devices including business servers, terminal devices, network devices, and network security protection devices, wherein the network entity information includes operating system-related information of the business server, application system-related information, terminal device-related information, network device-related information, and network security protection device-related information, as well as corresponding configuration data;

[0046] The device type acquisition unit is used to scan and traverse network entity devices through a collection tool to determine whether the device type is a network control device or a non-network control device, where the network control device is a network device with a routing function.

[0047] Furthermore, the virtual simulation module includes:

[0048] The network control device processing unit is used to establish a connection with the relevant network control device in the network topology if the device type scanned by the collection tool is a network control device, and scan the entity device information under the network control device at the same time;

[0049] The non-network control device processing unit is used to add the device to the corresponding network control device when the device type scanned by the acquisition tool is not a network control device;

[0050] The scanning control unit is used to establish a network space topology map with network control devices as nodes based on a traversal scan of all network entity devices.

[0051] Furthermore, the honey bait delivery model includes:

[0052] A power data classification unit, used to classify power data into several sensitivity levels based on the power sensitive data classification and grading method;

[0053] A vulnerability hazard classification unit is used to select vulnerabilities applicable to virtual simulation devices based on system vulnerability classification rules and published vulnerability information, and classify the vulnerabilities into several hazard levels;

[0054] The quantitative representation unit is used to quantify the sensitivity of power data with different sensitivity levels and the harmfulness of vulnerabilities with different harmfulness levels, and map them to the same dimensional space. It combines power sensitive data with system vulnerabilities to form files with different sweetness, called honey bait.

[0055] Furthermore, the quantitative representation unit quantifies the sensitivity of power data of different sensitivity levels and the harmfulness of vulnerabilities of different harmfulness levels, and maps them into the same dimensional space, including:

[0056] Assign initial values ​​to the sensitivity of power data of different sensitivity levels and the vulnerability hazards of different hazard levels, where the values ​​assigned to high-level data are higher than those assigned to low-level data;

[0057] Calculate the mean and standard deviation of the sensitivity and vulnerability severity values ​​of power data respectively;

[0058] Quantify various sensitive data and vulnerability data based on mean and standard deviation;

[0059] The quantitative values ​​of power data sensitivity and vulnerability harm are mapped to the same dimensional space [0,1].

[0060] Furthermore, the quantitative representation unit combines power-sensitive data with system vulnerabilities to form files of varying sweetness, including:

[0061] Based on the power sensitive data weight and vulnerability hazard weight, the quantitative values ​​of power data sensitivity and vulnerability hazard in the same dimensional space are weighted and summed to form a honey bait with corresponding sweetness value.

[0062] Furthermore, the monitoring and analysis module includes:

[0063] A probe deployment unit, configured to deploy network collection probes and virtual network collection probes capable of flow monitoring, log auditing, and network information collection based on the network entity devices and virtual simulation devices;

[0064] The data analysis unit is used to analyze whether the corresponding network is under network attack based on the data collected by the network collection probe and the virtual network collection probe.

[0065] Furthermore, the traffic traction module includes:

[0066] A first identification unit is configured to determine whether a network attack is detected in the virtual honeynet network based on the operation data of the network collection probe deployed by the virtual simulation device;

[0067] The second identification unit is used to determine whether the network collection probe deployed by the physical network device has detected a network attack when the virtual honeynet network detects a network attack;

[0068] The first processing unit is used to lure the attacker to continue attacking the virtual honeynet network by delivering honey bait when no network attack is detected on the physical network, and to trace and analyze the attack behavior and create a profile of the attacker;

[0069] The second processing unit is used to actively attract the attacker into the virtual honeynet network by reducing the data interaction of the physical network and increasing the interaction of the virtual honeynet network when a network attack is detected on the physical network, and to attack the virtual honeynet network;

[0070] The third processing unit is used to strengthen the security of the physical network equipment after the attacker is drawn into the virtual honeynet network.

[0071] In a third aspect, a computer device is provided, comprising one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the network traffic classification method as described in the first aspect of the present invention are implemented.

[0072] In a fourth aspect, a computer storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network traffic classification method as described in the first aspect of the present invention are implemented.

[0073] Beneficial effects: The present invention provides a method and system for trapping network attack behaviors in an electric power information system. Based on simulation technology, the method simulates a virtual honeynet network identical to the electric power information system. When facing network attacks such as advanced persistent threats, the present invention can be effectively used to identify and lock network attack behaviors. If the attacker is in the real electric power information system network at the time of the attack, the present invention can actively draw the attacker into the honeynet network through network traffic and honey bait delivery, effectively achieving the purpose of deceiving the attacker. In the electric power information system, the present invention constructs a virtual honeynet network to trick attackers into attacking, which does not affect the normal operation of the normal business system, has a low degree of coupling to the business program, and can effectively form a deep capture system in the cyberspace dimension. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] Figure 1 This is a flow chart of the method for trapping network attack behaviors in power information systems.

[0075] Figure 2 Schematic diagram of the relationship between cyberspace and device assets.

[0076] Figure 3 Flowchart for establishing network topology.

[0077] Figure 4 Flowchart for making honey pots of different sweetness. DETAILED DESCRIPTION

[0078] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings.

[0079] This embodiment provides a method for trapping network attack behaviors in a power information system. Figure 1 As shown, the method includes the following steps:

[0080] S101: Acquire network entity information of the power information system.

[0081] From the perspective of business systems, the business system modules of the power information system include databases, cloud platforms, and software systems; from the perspective of physical equipment, the network physical equipment of the power information system includes business servers, terminal equipment, network equipment, and network security protection equipment.

[0082] According to an embodiment of the present invention, obtaining network entity information of the power information system includes:

[0083] Deploy monitoring and collection tools in the power information system to collect necessary network entity information;

[0084] The network entity information includes the operating system associated information of the service server, the application system associated information, the terminal device associated information, the network device associated information and the network security protection device associated information, as well as the corresponding configuration data; the associated information includes, for example, the type and version of the operating system, the development language of the application system, the terminal device, the network device, the security manufacturer, the hardware and software framework of the device, etc.

[0085] Traverse the network physical devices through device scanning to determine the device type;

[0086] The device types include network control devices and non-network control devices; network control devices include switches, routers, firewalls, and other network devices with routing functions. Whether a device is a network control device can be determined by the subnet mask of the device's IP address, the device's function, and the port type.

[0087] In this embodiment, the device assets, network connection relationships and business interaction relationships in the physical network are detected by probes, and described by the three elements of "asset", "relationship" and "behavior", such as Figure 2 As shown in the figure, "assets" represent network nodes within the cyberspace, including network equipment, key servers, and security devices. "Relationships" indicate the network connectivity between assets, i.e., network reachability. By representing these relationships, a preliminary network topology is established. "Behaviors" represent the interactions between business systems operating within the cyberspace. The interaction information between business systems represents the access relationships and behaviors between them. The topology of the physical cyberspace is determined based on assets, relationships, and behaviors.

[0088] S102: Establish a network space topology based on the network entity information.

[0089] According to an embodiment of the present invention, based on the type of device scanned, if it is a network control device, a related network control device connection is established in the network topology, and the physical device information under the network control device is scanned at the same time; if it is not a network control device, the device is added under the corresponding network control device; based on a traversal scan of all network physical devices, a network space topology map with the network control device as the node is established.

[0090] like Figure 3 As shown in the figure, establishing the network space topology specifically includes:

[0091] The first step is to determine whether the scanned device is a network control device based on the scanned device type;

[0092] The second step is to establish a connection with the network control device in the network topology if it is a network control device, and obtain the forwarding database (FDB) and address resolution protocol (ARP) information of the switch under the network control device;

[0093] The third step is to traverse the device information directly connected to the network control device through the FDB table and ARP information;

[0094] The fourth step is to verify the type of the directly connected device according to the Link Layer Discovery Protocol (LLDP). If it is a network control device, return to the second step. If it is not a network control device, establish a directly connected non-network control asset under the network control device.

[0095] S103: Based on the network entity information, a virtual honeynet network with the same network structure as the business system is mirrored.

[0096] First, in the first step, corresponding virtual simulation devices are established based on the network entity information, including simulated service servers, simulated terminal devices, simulated network devices and simulated network security protection devices corresponding to the service servers, terminal devices, network devices and network security protection devices.

[0097] The second step is to deploy network simulation information on the virtual simulation device; the network simulation information includes network entity information corresponding to the network physical devices. Based on the network entity information scanned in step S101, such as the business server's operating system associated information, application system associated information, terminal device associated information, network device associated information, network security protection device associated information, and corresponding configuration data, information such as the business system logic, power network topology, and device interaction protocols in the physical network can be obtained, thus enabling simulation of business system modules and network physical devices.

[0098] The third step is to form a virtual honeynet network based on the virtual simulation equipment, network simulation information and network topology. The virtual honeynet network is a mirror image of the physical network.

[0099] S104. Combining the sensitivity of power data and the vulnerability severity scoring rules, formulate honey baits of different sweetness and deploy them to the virtual honeynet network through honeypots with interactive functions.

[0100] The importance of various data in the power information system and their sensitivity to attackers are different, and they can be treated differently by classifying and grading power sensitive data. The degree of harm caused by vulnerabilities is also different, so the vulnerabilities can be graded according to the degree of harm caused. According to an embodiment of the present invention, based on the power sensitive data classification and grading method, power data is divided into general data, important data and core data. General data includes telesignaling, telemetry data, etc., important data includes power transaction data, personal information, etc., and core data includes remote control, power generation plan, etc.; based on the system vulnerability grading rules and the published vulnerability information, vulnerabilities with high, medium and low hazard levels suitable for virtual simulation equipment are selected; the sensitivity of power data and the harm of vulnerability exploitation are quantified and mapped to the same dimensional space, and the power sensitive data and system vulnerabilities are combined to form files with different sweetness, called honey bait, which is used to attract attackers to further attack.

[0101] It should be understood that the classification of power-sensitive data into three levels and the classification of vulnerability hazard levels into three levels are merely examples and are not limitations on the implementation of the method of the present invention. This is because the purpose of grading power data sensitivity and vulnerabilities is to create baits with different degrees of utilization (different sweetness) based on different combinations, and the sweetness indicates the ability of the bait to attract attackers to attack. In other embodiments, power-sensitive data can be classified and graded differently according to business needs, and vulnerability hazards can also be divided into different levels.

[0102] like Figure 4 As shown, the formation of honey bait specifically includes:

[0103] S1041, classify the simulated power sensitive data into general data, important data, and core data; classify the selected vulnerabilities applicable to the virtual device into three levels: high, medium, and low; let the total number of sensitive data be n, and the total number of vulnerabilities be m;

[0104] S1042, quantify the sensitivity and vulnerability hazards of power data, and calculate the average value and standard deviation of the sensitivity and vulnerability hazards of power data respectively; the sensitivity of the i-th data is represented by S i Indicates the sensitivity S of data at different sensitivity levels i The values ​​are different. Generally, the sensitivity values ​​of general data, important data, and core data increase in turn. The harmfulness of the j-th vulnerability is expressed as Hj Indicates the severity of different vulnerability levels H j The values ​​are different. Generally, the higher the level, the greater the harmfulness value. The original values ​​of different levels of sensitivity and vulnerability harm can be specified manually. Different levels are assigned different values ​​to form honey baits of different sweetness according to needs. The average sensitivity value is used The average value of vulnerability severity is expressed as Indicates; the standard deviation is σ, and the standard deviation of sensitivity is σ S , the standard deviation of vulnerability severity is σ H ; then:

[0105]

[0106]

[0107] S1043, based on the mean and standard deviation, quantifies various types of sensitive data and vulnerability data, where SQ represents the quantified value of power sensitive data and HQ represents the quantified value of vulnerability damage.

[0108] The quantitative representation of sensitive data is as follows:

[0109]

[0110]

[0111] Among them, SQ i Represents the sensitivity quantification value of the i-th data;

[0112] Similarly, the vulnerability damage is quantitatively expressed as follows:

[0113]

[0114]

[0115] Among them HQ j Indicates the quantitative value of the harmfulness of the j-th vulnerability;

[0116] S1044 maps the quantitative values ​​of sensitive data and vulnerability hazards to the same dimensional space [0,1]. The mapping function is as follows:

[0117]

[0118]

[0119] Where exp represents the natural exponential function, then the mapping functions for quantifying the sensitivity of the i-th data and the harmfulness of the j-th vulnerability to the [0,1] space are:

[0120]

[0121]

[0122] S1045, combining the power sensitive data with the system vulnerability to form honey baits of different sweetness; the present invention uses a weighted average method to design honey baits of different sweetness, assuming that the weight of the power sensitive data is w S , the weight of the vulnerability is w H , the weight value can be adjusted as needed, and w S =1-w H , for the i-th data combined with the j-th vulnerability, the sweetness of the honey bait is expressed as C ij If it is expressed as follows:

[0123] C ij =f(S i )*w S +f(H j )*w H ,i∈[0,n-1],j∈[0,m-1].

[0124] Honey bait is a file format that can be delivered by honeypots as a means of attracting attackers. It is a file with vulnerabilities that defenders deliberately expose to lure attackers. Honey bait can be deployed on virtual device nodes in a virtual honeynet network using honeypot software. The aforementioned sweetness classification of content is also based on the sensitivity of the data. For example, for extremely sensitive data, a high-sweetness honey bait is set accordingly.

[0125] Since the business system logic simulation and protocol simulation are realized when mirroring the virtual honeynet network, honeypots with interactive functions can be deployed to improve the system's attack capture capability.

[0126] S105. Based on the collection probe, monitor and analyze the physical network and virtual network to monitor network attack behaviors.

[0127] According to an embodiment of the present invention, based on the network entity device and virtual simulation device, a network collection probe and a virtual network collection probe with traffic monitoring, log auditing and network information collection are deployed;

[0128] Based on network collection probes and virtual network collection probes, data is collected from the physical business network and virtual honeynet network, and based on the analysis of the collected network data, it is determined whether the corresponding network is under network attack.

[0129] As an example, data collection is performed on the physical business network and the virtual honeynet network. The collected content includes:

[0130] For network intrusion detection systems, the network attack data collected by the probe includes network attack traffic data (source IP address, target IP address, port number, protocol type, packet size), abnormal behavior patterns (mainly abnormal traffic), attack signatures, exploited vulnerability types, hijacked sessions, and tampered packets (attempts to insert malicious data into legitimate sessions or tamper with communication content), etc.

[0131] For host-type intrusion detection systems, the network attack data collected by the probe includes registry information collection (unauthorized addition, modification or deletion of registry entries), process information collection (whether there are malware, virus or worm processes), network connection monitoring (whether there are suspicious external connections or internal communications), memory monitoring (whether there is malicious code running) and user behavior monitoring (user login behavior, file access mode, system command execution, etc.).

[0132] For gateway devices, the network attack data collected by the probe includes network traffic data (IP data packets, TCP / UDP data segments, etc.), session data (source IP address, destination IP address, port number, protocol type, etc.), application layer data (HTTP requests, FTP transmissions, SMTP emails, etc.), metadata (data packet timestamps, source and destination MAC addresses, VLAN tags, etc.), threat intelligence data (malicious IP addresses, domain names, file hash values, etc.), etc.

[0133] For the judgment of collected data, the network security monitoring platform within the power system (such as the S6000 situational awareness platform) can be used to identify whether each collected content of each type of intrusion detection is abnormal.

[0134] S106. Attract attackers into the honeynet system by regulating the traffic between the real business system and the honeynet network system.

[0135] In this embodiment, step S106 attracts attackers to enter the honeynet system by regulating the traffic between the real business system and the honeynet network system, including:

[0136] In the first step, the attacker actively invades the network. The attacker does not know the type of network he is currently invading.

[0137] In the second step, the defender determines whether a network attack is detected on the corresponding network based on the operation data of the network collection probes deployed on the physical network device and the virtual simulation device;

[0138] In the third step, the attacker and defender engage in a game. The defender first determines whether the virtual honeynet network is under attack.

[0139] The fourth step is to determine whether the network acquisition probe deployed by the physical network device has detected a network attack; if the physical network has not detected a network attack, the attacker is lured to continue attacking the honeynet network by continuously delivering honey bait, and the attack behavior is traced and analyzed to profile the attacker; if the physical network detects a network attack, the attacker is actively drawn into the honeynet network by reducing the data interaction of the physical network and increasing the interaction of the honeynet network, and the attack is carried out on the honeynet network;

[0140] The fifth step is to lure the attacker into the honeynet network and then strengthen the security of the physical network equipment.

[0141] Based on the same technical concept as the method embodiment, the present invention also provides a power information system network attack behavior trapping system, comprising:

[0142] A device detection module, configured to obtain network entity information of the power information system;

[0143] A virtual simulation module is used to establish a network space topology map and a virtual simulation device based on the network entity information, deploy network simulation information on the virtual simulation device, and mirror a virtual honeynet network with the same network structure as the power information system based on the network space topology map, the virtual simulation device and the network simulation information;

[0144] The honey bait delivery module is used to formulate honey baits of different sweetness based on the sensitivity of power information system data and the severity of network security vulnerabilities, and deploy them to the virtual honeynet network through honeypots with interactive functions;

[0145] The monitoring and analysis module is used to monitor and analyze the physical network and virtual honeynet network based on the collection probe to determine whether the corresponding network is under network attack;

[0146] The traffic traction module is used to attract attackers into the virtual honeynet network by adjusting the system traffic of the physical network and the virtual honeynet network according to the network attack monitoring situation.

[0147] According to an embodiment of the present invention, the device detection module collects necessary network entity information through a collection tool, traverses network entity devices through a device scanning method, and determines the device type;

[0148] The network entity information includes the operating system associated information of the service server, the application system associated information, the terminal device associated information, the network device associated information and the network security protection device associated information, as well as the corresponding configuration data.

[0149] The device types include network-controlled devices and non-network-controlled devices;

[0150] The network control equipment mentioned above refers to network equipment such as switches, routers, firewalls, etc. with routing functions.

[0151] The device detection module includes:

[0152] A device information acquisition unit is configured to deploy a collection tool in the power information system to collect network entity information based on the power information system business system module including a database, a cloud platform, and a software system, and network entity devices including business servers, terminal devices, network devices, and network security protection devices, wherein the network entity information includes operating system-related information of the business server, application system-related information, terminal device-related information, network device-related information, and network security protection device-related information, as well as corresponding configuration data;

[0153] The device type acquisition unit is used to scan and traverse network entity devices through a collection tool to determine whether the device type is a network control device or a non-network control device, where the network control device is a network device with a routing function.

[0154] According to an embodiment of the present invention, the virtual simulation module, based on the device type scanned by the device detection module being a network control device, establishes a connection with the relevant network control device in the network topology and scans the physical device information under the network control device; if it is not a network control device, the device is added to the corresponding network control device;

[0155] Based on network physical devices, a network space topology map with network control devices as nodes is established.

[0156] The virtual simulation module includes:

[0157] The network control device processing unit is used to establish a connection with the relevant network control device in the network topology if the device type scanned by the collection tool is a network control device, and scan the entity device information under the network control device at the same time;

[0158] The non-network control device processing unit is used to add the device to the corresponding network control device when the device type scanned by the acquisition tool is not a network control device;

[0159] The scanning control unit is used to establish a network space topology map with network control devices as nodes based on a traversal scan of all network entity devices.

[0160] According to an embodiment of the present invention, after the virtual simulation module establishes the network space topology, it mirrors a virtual honeynet network with the same network structure as the business system, which mainly includes:

[0161] Based on the network entity information, a corresponding virtual simulation device is established; network simulation information is deployed in the virtual simulation device; wherein the virtual simulation device includes a simulated business server, simulated terminal device, simulated network device, and simulated network security protection device corresponding to the business server, terminal device, network device, and network security protection device; the network simulation information includes network entity information corresponding to the network entity device;

[0162] Based on virtual simulation devices, network simulation information and network topology, a virtual honeynet network is formed;

[0163] Based on the business system modules and network entity equipment, business system logic simulation, power network topology simulation and interaction protocol simulation are used to simulate the business system modules and network entity equipment.

[0164] The virtual simulation module also includes a virtual honeynet network establishment unit for completing the above operations.

[0165] According to an embodiment of the present invention, the honey bait delivery module formulates honeypots of different sweetness and with interactive functions, including the following steps:

[0166] Based on the classification and grading method for sensitive power data, some general data, important data and core data are simulated respectively. General data includes telesignaling and telemetering data, important data includes power transaction data and personal information, and core data includes remote control and power generation plan.

[0167] Select vulnerabilities applicable to virtual simulation devices based on system vulnerability classification rules and published vulnerability information;

[0168] The sensitivity of the power data and the harmfulness of the vulnerability exploit are quantified and mapped to the same dimensional space. The power-sensitive data is then combined with the system vulnerability to create files of varying sweetness, called honey bait. Honey bait is primarily used for honeypot delivery. Honeypots deployed at different nodes deliver honey bait of varying sweetness to attract attackers to further attacks.

[0169] Honey bait delivery module includes:

[0170] A power data classification unit, used to classify power data into several sensitivity levels based on the power sensitive data classification and grading method;

[0171] A vulnerability hazard classification unit is used to select vulnerabilities applicable to virtual simulation devices based on system vulnerability classification rules and published vulnerability information, and classify the vulnerabilities into several hazard levels;

[0172] The quantitative representation unit is used to quantify the sensitivity of power data with different sensitivity levels and the harmfulness of vulnerabilities with different harmfulness levels, and map them to the same dimensional space. It combines power sensitive data with system vulnerabilities to form files with different sweetness, called honey bait.

[0173] Furthermore, the quantitative representation unit quantifies the sensitivity of power data of different sensitivity levels and the harmfulness of vulnerabilities of different harmfulness levels, and maps them into the same dimensional space, including:

[0174] Assign initial values ​​to the sensitivity of power data of different sensitivity levels and the vulnerability hazards of different hazard levels, where the values ​​assigned to high-level data are higher than those assigned to low-level data;

[0175] Calculate the mean and standard deviation of the sensitivity and vulnerability severity values ​​of power data respectively;

[0176] Quantify various sensitive data and vulnerability data based on mean and standard deviation;

[0177] The quantitative values ​​of power data sensitivity and vulnerability harm are mapped to the same dimensional space [0,1].

[0178] Furthermore, the quantitative representation unit combines power-sensitive data with system vulnerabilities to form files of varying sweetness, including:

[0179] Based on the weight of power sensitive data and the weight of vulnerability hazard, the quantitative values ​​of power data sensitivity and vulnerability hazard in the same dimensional space are weighted and summed to form a honey bait with a corresponding sweetness value. According to an embodiment of the present invention, the monitoring and analysis module deploys network acquisition probes and virtual network acquisition probes with traffic monitoring, log auditing, and network information collection based on the network physical devices and virtual simulation devices;

[0180] Based on network collection probes and virtual network collection probes, data is collected from the physical business network and virtual honeynet network, and based on the analysis of the collected network data, it is determined whether the corresponding network is under network attack.

[0181] The monitoring and analysis modules include:

[0182] A probe deployment unit, configured to deploy network collection probes and virtual network collection probes capable of flow monitoring, log auditing, and network information collection based on the network entity devices and virtual simulation devices;

[0183] The data analysis unit is used to analyze whether the corresponding network is under network attack based on the data collected by the network collection probe and the virtual network collection probe.

[0184] According to an embodiment of the present invention, the traffic traction module comprises the following steps of attracting attackers into the virtual honeynet system:

[0185] Determining whether a network attack is detected on the honeynet network based on the operating data of the network collection probe deployed by the virtual simulation device;

[0186] If so, determining whether the network acquisition probe deployed by the physical network device detects a network attack;

[0187] If the physical network does not detect the network attack, it will continue to deliver honey bait to lure the attacker to attack the honeynet network, and then trace the attack behavior and analyze the attacker's behavior to create a profile.

[0188] If a network attack is detected on the physical network, the attacker is actively drawn into the honeynet network by reducing the data interaction of the physical network and increasing the interaction of the honeynet network, and then the attack is carried out on the honeynet network.

[0189] After the attacker is drawn into the honeynet network, the physical network equipment is hardened.

[0190] The traffic traction module includes:

[0191] A first identification unit is configured to determine whether a network attack is detected in the virtual honeynet network based on the operation data of the network collection probe deployed by the virtual simulation device;

[0192] The second identification unit is used to determine whether the network collection probe deployed by the physical network device has detected a network attack when the virtual honeynet network detects a network attack;

[0193] The first processing unit is used to lure the attacker to continue attacking the virtual honeynet network by continuously delivering honey bait when no network attack is detected on the physical network, and to trace and analyze the attack behavior and create a profile of the attacker;

[0194] The second processing unit is used to actively attract the attacker into the virtual honeynet network by reducing the data interaction of the physical network and increasing the interaction of the virtual honeynet network when a network attack is detected on the physical network, and to attack the virtual honeynet network;

[0195] The third processing unit is used to strengthen the security of the physical network equipment after the attacker is drawn into the virtual honeynet network.

[0196] It should be understood that the power information system network attack behavior trapping system in the embodiment of the present invention can implement all the technical solutions in the above method embodiment, and the functions of its various functional modules can be specifically implemented according to the methods in the above method embodiment. The specific implementation process can refer to the relevant description in the above embodiment, and will not be repeated here.

[0197] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus (systems), computer devices, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0198] The present invention is described with reference to flowcharts of methods according to embodiments of the present invention. It should be understood that each process in the flowcharts and combinations of processes in the flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts. Figure 1 A device that specifies functions in a process or multiple processes.

[0199] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A function specified in a process or multiple processes.

[0200] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 The steps of a specified function in a process or multiple processes.

Claims

1. A method for trapping network attack behaviors in a power information system, characterized in that: The method comprises the following steps: Acquiring network entity information of the power information system; Based on the network entity information, a network space topology map and a virtual simulation device are established, network simulation information is deployed on the virtual simulation device, the network simulation information includes network entity information corresponding to the network entity device, and based on the network space topology map, the virtual simulation device and the network simulation information, a virtual honeynet network with the same network structure as the power information system is mirrored; Combining the sensitivity of power information system data and the degree of harm of network security vulnerabilities, honey baits of different sweetness are formulated and delivered to the virtual honeynet network; wherein, combining the sensitivity of power information system data and the degree of harm of network security vulnerabilities, formulating honey baits of different sweetness includes: based on the classification and grading method of power sensitive data, dividing power data into several sensitivity level data; based on the system vulnerability grading rules and the published vulnerability information, selecting vulnerabilities applicable to virtual simulation equipment, and dividing the vulnerabilities into several harm levels; quantifying the sensitivity of power data of different sensitivity levels and the harm of vulnerabilities of different harm levels, and mapping them to the same dimensional space, combining power sensitive data with system vulnerabilities to form files of different sweetness, which are called honey baits; wherein, combining power sensitive data with system vulnerabilities to form files of different sweetness includes: designing power sensitive data weights and vulnerability harm weights, and weighted summing the quantized values ​​of power data sensitivity and vulnerability harm in the same dimensional space to form honey baits with corresponding sweetness values; Based on the collection probe, the physical network and the virtual honeynet network with honey bait are monitored and analyzed, and the corresponding network is judged according to the monitoring and analysis results to determine whether it is under network attack; According to the results of network attack judgment, the system traffic of the physical network and the virtual honeynet network is adjusted, and the attacker is attracted to enter the virtual honeynet network by delivering honey bait, which specifically includes: judging whether the virtual honeynet network has detected a network attack based on the operation data of the network collection probe deployed by the virtual simulation device; if so, judging whether the network collection probe deployed by the network physical device has detected a network attack; if the physical network has not detected a network attack, the attacker is lured to continue attacking the virtual honeynet network by delivering honey bait, and the attack behavior is traced and analyzed to profile the attacker; if the physical network detects a network attack, the attacker is actively drawn into the virtual honeynet network by reducing the data interaction of the physical network and increasing the interaction of the virtual honeynet network, and the virtual honeynet network is attacked; after the attacker is drawn to the virtual honeynet network, the network physical device is security reinforced.

2. The method according to claim 1, characterized in that Acquiring network entity information of the power information system includes: Based on the fact that the business system module of the power information system includes a database, a cloud platform, and a software system, and the network entity devices include business servers, terminal devices, network devices, and network security protection devices, a collection tool is deployed in the power information system to collect network entity information, wherein the network entity information includes operating system-related information of the business server, application system-related information, terminal device-related information, network device-related information, and network security protection device-related information, as well as corresponding configuration data; The network entity devices are scanned and traversed by a collection tool to determine whether the device type is a network control device or a non-network control device. The network control device is a network device with a routing function.

3. The method according to claim 2, characterized in that Establishing a network space topology map based on the network entity information includes: If the device type scanned by the collection tool is a network control device, then the relevant network control device connection is established in the network topology, and the physical device information under the network control device is scanned at the same time; If the device type scanned by the collection tool is not a network control device, add the device to the corresponding network control device; Based on a traversal scan of all network physical devices, a network space topology map with network control devices as nodes is established.

4. The method according to claim 1, wherein The sensitivity of power data with different sensitivity levels and the harmfulness of vulnerabilities with different harm levels are quantified and mapped into the same dimensional space, including: Assign initial values ​​to the sensitivity of power data of different sensitivity levels and the vulnerability hazards of different hazard levels, where the values ​​assigned to high-level data are higher than those assigned to low-level data; Calculate the mean and standard deviation of the sensitivity and vulnerability severity values ​​of power data respectively; Quantify various sensitive data and vulnerability data based on mean and standard deviation; The quantitative values ​​of power data sensitivity and vulnerability harm are mapped to the same dimensional space [0,1].

5. The method according to claim 1, wherein Based on the collection probe, the physical network and the virtual honeynet network with the honey bait are monitored and analyzed. Based on the monitoring and analysis results, it is determined whether the corresponding network is under network attack, including: Based on the network physical devices and virtual simulation devices, deploy network collection probes and virtual network collection probes with traffic monitoring, log auditing and network information collection; Based on the data collected by network collection probes and virtual network collection probes, analyze whether the corresponding network is under network attack.

6. A network attack behavior trapping system for power information systems, characterized in that: include: A device detection module, configured to obtain network entity information of the power information system; A virtual simulation module is configured to establish a network space topology map and a virtual simulation device based on the network entity information, deploy network simulation information on the virtual simulation device, wherein the network simulation information includes network entity information corresponding to the network entity device, and mirror a virtual honeynet network with the same network structure as the power information system based on the network space topology map, the virtual simulation device, and the network simulation information; The honey bait delivery module is used to formulate honey baits of different sweetness based on the sensitivity of power information system data and the degree of harm of network security vulnerabilities, and then deliver the honey baits to the virtual honeynet network; The monitoring and analysis module is used to monitor and analyze the physical network and the virtual honeynet network that has delivered honey bait based on the collection probe, and determine whether the corresponding network is under network attack based on the monitoring and analysis results; The traffic traction module is used to adjust the system traffic of the physical network and the virtual honeynet network according to the results of the network attack judgment, and to attract attackers into the virtual honeynet network by delivering honey bait; Among them, the honey bait delivery module includes: A power data classification unit, used to classify power data into several sensitivity levels based on the power sensitive data classification and grading method; A vulnerability hazard classification unit is used to select vulnerabilities applicable to virtual simulation devices based on system vulnerability classification rules and published vulnerability information, and classify the vulnerabilities into several hazard levels; The quantitative representation unit is used to quantify the sensitivity of power data of different sensitivity levels and the harmfulness of vulnerabilities of different harm levels, and map them into the same dimensional space. The power sensitive data and system vulnerabilities are combined to form files of different sweetness levels, called honey bait. The quantitative representation unit combines power-sensitive data with system vulnerabilities to form files of different sweetness levels, including: based on the power-sensitive data weight and the vulnerability hazard weight, the quantized values ​​of power data sensitivity and vulnerability hazard in the same dimensional space are weighted and summed to form honey bait with corresponding sweetness values; The traffic traction module includes: A first identification unit is configured to determine whether a network attack is detected in the virtual honeynet network based on the operation data of the network collection probe deployed by the virtual simulation device; The second identification unit is used to determine whether the network collection probe deployed by the network entity device has detected a network attack when the virtual honeynet network detects a network attack; The first processing unit is used to lure the attacker to continue attacking the virtual honeynet network by delivering honey bait when no network attack is detected on the physical network, and to trace and analyze the attack behavior and create a profile of the attacker; The second processing unit is used to actively attract the attacker into the virtual honeynet network by reducing the data interaction of the physical network and increasing the interaction of the virtual honeynet network when a network attack is detected on the physical network, and to attack the virtual honeynet network; The third processing unit is used to perform security reinforcement on the network entity devices after the attacker is drawn into the virtual honeynet network.

7. The system according to claim 6, characterized in that The device detection module includes: A device information acquisition unit is configured to deploy a collection tool in the power information system to collect network entity information based on the power information system business system module including a database, a cloud platform, and a software system, and network entity devices including business servers, terminal devices, network devices, and network security protection devices, wherein the network entity information includes operating system-related information of the business server, application system-related information, terminal device-related information, network device-related information, and network security protection device-related information, as well as corresponding configuration data; The device type acquisition unit is used to scan and traverse network entity devices through a collection tool to determine whether the device type is a network control device or a non-network control device, where the network control device is a network device with a routing function.

8. The system according to claim 7, characterized in that The virtual simulation module includes: The network control device processing unit is used to establish a connection with the relevant network control device in the network topology if the device type scanned by the collection tool is a network control device, and scan the entity device information under the network control device at the same time; The non-network control device processing unit is used to add the device to the corresponding network control device when the device type scanned by the acquisition tool is not a network control device; The scanning control unit is used to establish a network space topology map with network control devices as nodes based on a traversal scan of all network entity devices.

9. The system according to claim 6, wherein: The quantitative representation unit quantifies the sensitivity of power data with different sensitivity levels and the harmfulness of vulnerabilities with different harmfulness levels, and maps them to the same dimensional space, including: Assign initial values ​​to the sensitivity of power data of different sensitivity levels and the vulnerability hazards of different hazard levels, where the values ​​assigned to high-level data are higher than those assigned to low-level data; Calculate the mean and standard deviation of the sensitivity and vulnerability severity values ​​of power data respectively; Quantify various sensitive data and vulnerability data based on mean and standard deviation; The quantitative values ​​of power data sensitivity and vulnerability harm are mapped to the same dimensional space [0,1].

10. The system according to claim 6, wherein: The monitoring and analysis modules include: A probe deployment unit, configured to deploy network collection probes and virtual network collection probes capable of flow monitoring, log auditing, and network information collection based on the network entity devices and virtual simulation devices; The data analysis unit is used to analyze whether the corresponding network is under network attack based on the data collected by the network collection probe and the virtual network collection probe.

11. A computer device, characterized in that: The device includes one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the method for trapping network attack behaviors in a power information system are implemented as described in any one of claims 1 to 5.

12. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for trapping network attack behaviors in a power information system according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Power industry network security secret network system

    CN115694965A

  • Honeynet-based high-sweetness deception defense method and system

    CN117294532A