Honeypot-based APT attack capture and detection method, device, and medium
By deploying IoT honeypots on cloud servers, using reinforcement learning and graph matching technology to build a deep trapping environment, the problem of IoT honeypots being easily detected and attack logs being difficult to identify APT attacks in the existing technology is solved, and efficient APT attack capture and rapid detection are achieved.
Patent Information
- Application Number
- CN202410899351.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-05
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-07-05
AI Technical Summary
When existing IoT honeypots capture and detect APT attacks, they are easily visible by attackers, and the captured attack logs are difficult to quickly identify APT attack behavior.
By deploying IoT honeypots on cloud servers, collecting network-layer operating system fingerprint data and application-layer HTTP response data of IoT devices, using the model-free SARSA algorithm for reinforcement learning to learn response strategies online to build a deep trapping environment. At the same time, graph matching technology is used to compare the traceability map and threat intelligence data sets to identify the traceability map of APT attacks.
It realizes a low-cost simulated IoT deep trapping environment, improves the capture efficiency of APT attack behavior, and enables rapid detection of advanced persistent threats.
Smart Images

Figure CN118802341B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security and relates to a honeypot-based APT attack capture and detection method, device and medium. Background Art
[0002] In recent years, with the rapid development and widespread application of IoT technology, the number of IoT devices has increased dramatically. While these devices bring convenience to people, they also pose new security challenges. The widespread security vulnerabilities and vulnerabilities of IoT devices make them an ideal target for advanced persistent threat (APT) attackers in networks. APT attackers are typically highly organized, persistent, and stealthy. They use advanced attack methods and strategies to maintain long-term lurking and deep penetration into specific targets to achieve their goals of stealing sensitive information, damaging critical infrastructure, or conducting other malicious activities. Faced with the current severe challenges in IoT security, there is an urgent need to research technologies to capture and detect IoT APT attack behaviors to help security personnel promptly identify security threats and prevent attackers from further infiltrating the network, thereby improving the security of the entire IoT environment.
[0003] Honeypot technology is playing an increasingly important role in addressing the challenges posed by APT attacks in the IoT sector. Essentially, a honeypot is a security tool that simulates vulnerable systems to lure attackers into launching attacks, capturing attack data as they occur and providing a controlled environment for analyzing attacker behavior. IoT honeypots, in particular, built from real devices, can simulate a deep entrapment environment to capture APT attacks. However, cyber attackers may infect these honeypots with malware and use them as a launching pad to further attack other systems on the network.
[0004] Reinforcement learning methods can avoid this problem because they don't rely on real IoT devices. By learning and adapting to the behavior of network attackers, reinforcement learning honeypots can adaptively learn optimal response strategies to simulate deep entrapment environments. However, existing IoT honeypots using reinforcement learning methods do not consider simulating network-layer operating system fingerprints. This makes the honeypot's disguise easily deciphered by experienced network attackers, making it difficult to capture APT attack behavior. Furthermore, while the attack logs captured by honeypots record low-level information about attackers' activities within the system, it remains challenging to quickly and accurately identify potential APT attacks from them. Summary of the Invention
[0005] The purpose of the present invention is to provide a honeypot-based APT attack detection method, device, and medium to address the shortcomings in current APT attack capture and detection.
[0006] The object of the present invention is achieved through the following technical solutions:
[0007] The present invention provides a honeypot-based APT attack capture and detection method, which includes the following steps:
[0008] (1) Deploy an IoT honeypot on a cloud server to collect network layer operating system fingerprint data and application layer HTTP response data of real IoT devices connected to the public network, and capture application layer HTTP request data from network attackers;
[0009] (2) Based on the fingerprint data of the network layer operating system of the real IoT device collected in step (1), the IoT honeypot automatically detects the TCP SYN scan data packet and uses the personalization engine of Honeyd to modify the fingerprint data of the cloud server operating system to simulate the operating system of the real IoT device;
[0010] (3) Based on the application layer HTTP response data collected in step (1), the application layer HTTP interaction process between the IoT honeypot and the network attacker is modeled as a Markov decision process;
[0011] (4) Based on the Markov decision process modeled in step (3), the IoT honeypot uses the reinforcement learning model-free SARSA algorithm to learn the response strategy to the network attacker online, so that the IoT honeypot can adaptively return the best HTTP response to the attacker; all the captured attack behaviors during the online interaction process are saved in the attack log;
[0012] (5) constructing a traceability graph based on the attack log saved in step (4), wherein the traceability graph consists of nodes and directed edges, wherein the nodes represent the system entities recorded in the attack log, and the directed edges record the causal relationship between the nodes;
[0013] (6) constructing a query graph based on the open source threat intelligence dataset, wherein the query graph consists of nodes and directed edges, where the nodes represent system entities in the real attack process recorded in the threat intelligence dataset, and the directed edges record the causal relationship between the nodes;
[0014] (7) Based on the provenance graph constructed in step (5) and the query graph constructed in step (6), the nodes in the provenance graph and the query graph are aligned using graph matching technology to match multiple provenance subgraphs similar to the query graph;
[0015] (8) Based on the multiple traceability subgraphs matched in step (7), a path scoring function is introduced to calculate the traceability subgraph with the highest matching degree with the query graph to obtain the final ATP attack traceability graph.
[0016] Furthermore, in step (1), the application layer HTTP request data is captured by the HTTP service provided by the IoT honeypot, the application layer HTTP response data is obtained by the IoT honeypot forwarding the captured application layer HTTP request data to the IoT device, and the network layer operating system fingerprint data is obtained from the IoT device by the IoT honeypot using Nmap and Wireshark tools.
[0017] Furthermore, in step (2), when the IoT honeypot detects six TCPSYN scanning packets with an interval of 100ms from the Nmap tool, the network layer operating system fingerprint data of the IoT device collected in step (1) is first extracted through the personalization engine of Honeyd; then, a response initialization sequence number that is similar to the distribution of the initialization sequence number in the IoT device fingerprint is generated based on the TCP initialization sequence number in the scanning packet; finally, the extracted fingerprint data and the generated initialization sequence number are used to introduce modifications in each response packet returned to the network attacker; through this process, it is ensured that the network attacker misjudges the operating system fingerprint of the IoT honeypot as the operating system fingerprint of a real IoT device, thereby resisting the attacker's network layer fingerprint recognition and enhancing the ability of the IoT honeypot to trap APT attacks.
[0018] Furthermore, in step (3), the application layer HTTP response data collected from the IoT device is the action set in the Markov decision process; the public network environment in which the IoT honeypot is located is the environment; the application layer HTTP request sent by the network attacker is the state; the IoT honeypot is the intelligent agent; and the distribution of the reward depends on the specific content of the next HTTP request captured from the network attacker after the IoT honeypot returns an HTTP response to the network attacker.
[0019] Furthermore, in step (4), the model-free SARSA algorithm is applied to online interactions with network attackers, aiming to help the IoT honeypot learn how to dynamically formulate the best response strategy in the network environment; when the IoT honeypot interacts online, it first initializes a Q table, in which rows represent different HTTP responses and columns represent different HTTP requests; when the network attacker sends an HTTP request to the IoT honeypot, the IoT honeypot first selects an HTTP response from the action set based on the ∈-greedy strategy and returns it to the network attacker; then, the IoT honeypot observes the network attacker's next HTTP request, the corresponding reward, and the IoT honeypot's next action to update the Q value; this process is repeated continuously, allowing the honeypot to gradually optimize its response strategy; this method can realize the construction of a deep trapping environment for the IoT honeypot to attract attackers to launch more attacks and capture deep-level APT attack behaviors; all captured attack behaviors will be recorded in detail and saved in the attack log.
[0020] Furthermore, the provenance graph depicts potential APT attack behaviors captured by the IoT honeypot, and the nodes in the provenance graph represent different types of system entities recorded in the attack log; the query graph depicts real ATP attack behaviors, and the nodes in the query graph represent different types of system entities in the real attack process; the node types in the provenance graph and the query graph include processes, malware, sockets, files and registry entries, different graphs are used to represent different types of entities, and the specific information of the entities is marked in the graphs; the directed edges in the provenance graph and the query graph both mark the specific actions performed by a node on other nodes, and record the information flow and the causal relationship between entities.
[0021] Furthermore, in step (7), based on the constructed provenance graph and query graph, first, all possible candidate alignment sets are identified according to the specific information of different nodes in the two graphs; then, among these aligned nodes, a group of seed nodes with the least number of adjacent aligned nodes in the provenance graph and query graph are screened out; finally, with the seed node as the center, the matching search range is expanded to find more aligned nodes, and all provenance subgraphs in the provenance graph with a similar structure to the query graph are matched.
[0022] Furthermore, in step (8), the path scoring function scores according to the matching of different aligned nodes and the consistency of the causal relationship between different aligned nodes; by accumulating the scores of each path, the tracing subgraph with the highest score is identified, namely the APT attack tracing subgraph; the APT attack tracing subgraph contains detailed information on the APT attack behavior captured by the IoT honeypot, including each stage of the attack and related activities. This detailed record enables APT attack behavior to be quickly detected and analyzed.
[0023] The present invention also provides a honeypot-based APT attack capture and detection device, comprising a memory and one or more processors, wherein the memory stores executable code, and when the processor executes the executable code, it is used to implement the above-mentioned honeypot-based APT attack capture and detection method.
[0024] The present invention also provides a computer-readable storage medium having a program stored thereon, wherein when the program is executed by a processor, the above-mentioned honeypot-based APT attack capture and detection method is implemented.
[0025] The beneficial effects of the present invention are as follows: First, an IoT honeypot is deployed to collect network-layer operating system fingerprint data and application-layer HTTP response data from IoT devices, and to capture application-layer HTTP request data. Then, using Honeyd's personalization engine, the IoT honeypot extracts the collected network-layer fingerprint data and modifies the cloud server's operating system fingerprint to resist attackers' network-layer fingerprinting. Simultaneously, the application-layer HTTP interaction between the IoT honeypot and the attacker is modeled as a Markov decision process. Based on this, the IoT honeypot uses the model-free SARSA algorithm based on reinforcement learning to online learn and optimize its response strategy to attackers. This strategy aims to build a deep entrapment environment that simulates a real system and effectively captures APT attacks. Finally, the attack logs recorded by the IoT honeypot are used to generate a traceability graph, and open-source threat intelligence data is used to generate a query graph. Using graph matching technology, these two graphs are compared and analyzed in detail to obtain an APT attack traceability graph, enabling detection of APT attacks. This method can cost-effectively simulate an IoT deep entrapment environment, capture APT attacks, and rapidly detect highly organized and covert APT attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0027] Figure 1 This is a flow chart of a honeypot-based APT attack capture and detection method provided by an embodiment of the present invention;
[0028] Figure 2 This is a schematic diagram of a honeypot simulating an IoT device operating system fingerprint according to an embodiment of the present invention;
[0029] Figure 3 This is a schematic diagram of an APT attack source tracing diagram based on path scoring provided by an embodiment of the present invention;
[0030] Figure 4 This is a structural diagram of a honeypot-based APT attack capture and detection device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0031] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0032] This embodiment provides a honeypot-based APT attack capture and detection method, including the following steps:
[0033] (1) An IoT honeypot is deployed on a cloud server to collect network layer operating system fingerprint data and application layer HTTP response data of real IoT devices connected to the public network, and to capture application layer HTTP request data from network attackers. The IoT honeypot is implemented based on Python programming. The capture and response of application layer HTTP data are implemented by using the socket library to listen to port 80. In addition, the IoT honeypot uses the scapy library to listen to port 22 to identify the scanning data packets generated by network attackers when they scout the IoT honeypot, and returns simulated IoT device operating system fingerprint data packets. When the IoT honeypot is running, it uses the application layer HTTP service to capture HTTP requests from network attackers and forwards the requests to real IoT devices connected to the public network to collect HTTP responses; in addition, the IoT honeypot uses the python-nmap library to integrate the functions of the Nmap tool, which can actively perform operating system fingerprint identification operations on IoT devices connected to the public network, and then determine the operating system types of these devices. At the same time, the IoT honeypot uses pyshark to execute the functions of Wireshark to capture fingerprint data related to these operating system types. The fingerprint data will then be saved in the pcap file format.
[0034] (2) Based on the real IoT device operating system fingerprint data collected in step (1), the IoT honeypot on the cloud server simulates the operating system fingerprint of the IoT device. The IoT honeypot is able to achieve this simulation using Honeyd's Personality Engine. Specifically, when the IoT honeypot detects six TCP SYN scan packets with a 100ms interval from the Nmap tool, Honeyd's Personality Engine first reads the fingerprint data of the IoT device from the pcap file. These fingerprint data include Identification and Flags in the IP stack, Flags, Window, and Options in the TCP stack, Type, Code, and Data in the ICMP stack, and Data in the UDP stack. Then, the Personality Engine tracks the TCP Initial Sequence Number (ISN) in the scan packet and generates a response Initial Sequence Number that approximates the distribution of the initial sequence number in the IoT device fingerprint. Finally, the Personality Engine uses the extracted fingerprint data and the generated initial sequence number to introduce modifications in each response packet returned to the network attacker. Through this process, the IoT honeypot is able to return data that matches the operating system fingerprint of the IoT device. This allows the IoT honeypot to be identified as a real IoT device by network attackers at the network layer, thereby effectively enhancing the IoT honeypot's deception effect on network attackers.
[0035] (3) Based on the application layer HTTP response data collected from real IoT devices connected to the public network in step (1), the application layer HTTP interaction process between the IoT honeypot and the attacker is modeled as a Markov decision process. The HTTP response data is the set of actions in the Markov decision process; the public network environment where the IoT honeypot is located is the environment; the application layer HTTP request data sent by the network attacker is the state; the IoT honeypot is the agent; the reward setting is based on the result after the IoT honeypot replies to the network attacker with an HTTP response: if the network attacker continues to send HTTP requests, it means that the honeypot's response has successfully attracted the attacker, and the IoT honeypot is given a positive reward. Specifically, if the HTTP request contains Linux instructions, the honeypot will receive 5 points; if it does not contain Linux instructions, it will receive 2 points. On the contrary, if the network attacker no longer sends HTTP requests, it means that the honeypot's response has failed to attract the attacker, and the IoT honeypot is given a negative reward of -2 points.
[0036] (4) Based on the Markov decision process modeled in step (3), the IoT honeypot uses the model-free SARSA algorithm to interact with the attacker online to train the IoT honeypot to learn and formulate the best response strategy in the network environment. The update rules of the SARSA algorithm are as follows:
[0037] Q (s,a) =Q (s,a) +α*[R+γ*Q (s′,a′) -Q (s,a) ]
[0038] In the above formula, Q (s,a) represents the Q value of taking action a in state s; α is the learning rate, which is used to adjust the rate of response policy updates; R is the reward obtained immediately after taking action a; γ is the discount factor, which is used to measure the importance of future rewards; s and a are the current state and action, namely HTTP request and HTTP response, respectively; s′ is the new state obtained after taking action a, namely HTTP request at the next moment; a′ is the next action selected in the new state s′, namely HTTP response at the next moment. (s′,a′) It represents the Q value of taking action a′ in state s′.
[0039] When an IoT honeypot interacts online, it creates a Q-table, where rows represent different HTTP responses and columns represent different HTTP requests. When an attacker sends an HTTP request to the IoT honeypot, the IoT honeypot first selects an HTTP response from a set of actions based on the ∈-greedy strategy and returns it to the attacker. It then observes the attacker's next HTTP request and its corresponding reward. It then selects the next HTTP response based on the ∈-greedy strategy and uses this observed data to update the corresponding Q-value in the Q-table. During online interactions, the IoT honeypot repeats this process, learning the optimal response strategy that attracts the attacker to conduct sustained attacks. This allows it to build a deep entrapment environment and capture advanced APT attack behaviors. All captured attack behaviors are stored in an attack log.
[0040] (5) Based on the attack logs captured by the IoT honeypot in step (4), a traceability graph is constructed. It depicts the potential attack behaviors performed by a network attacker in the IoT honeypot. The traceability graph consists of nodes and directed edges, where the nodes represent the system entities recorded in the attack logs, including processes, malware, sockets, files, and registry entries. In order to clearly distinguish them, different graphs are used to represent these entities: ovals represent processes or malware, diamonds represent sockets, rectangles correspond to files, and pentagons are used to represent registry entries. At the same time, the nodes of different graphs are also marked with more detailed information about the node entity. Directed edges record the information flow between different entities and the causal relationship between entities. Each directed edge is marked with the specific operation performed, such as "write", to clarify the action performed by one node on another node. For example, if there is an edge from an elliptical node (representing malware) to a rectangular node (representing a file) and is marked with "write", it clearly indicates that the malware is performing the action of writing a file.
[0041] (6) Based on the open source threat intelligence data Engagement 3 from the DARPA TC project, a query graph is constructed. The query graph also consists of nodes and directed edges, where the nodes represent the key entities in the real attack process recorded in the dataset, including processes, malware, sockets, files, and registry entries. In the process of constructing the query graph, the Tokenizer is first used to segment the long sentences according to the symbol boundaries of the sentences, and the short sequences containing complete sentence components (subject, predicate, and object) are screened out. Then, the passive sentences in the short sequences are converted to active sentences to more easily discover the causal relationship between entities. Next, according to the node differentiation method in step (5), the nodes in the query graph are represented by different graphs according to different entity types, and directed edges are used to represent the causal relationship between different entities. Finally, a query graph containing the real attack process is obtained.
[0042] (7) Based on the provenance graph and query graph constructed in steps (5) and (6), the provenance graph and the query graph are aligned using graph matching technology to find multiple provenance subgraphs similar to the query graph. When performing graph matching, first determine all possible candidate alignment sets A = {(i1, j1), (i2, j2), (i3, j3), ..., (i n ,j n)}, each element in the set represents a set of aligned nodes, where i and j in the aligned nodes come from entities in the provenance graph and query graph respectively, and the specific information annotated by these two entities is the same, for example, i and j are both nodes of the Firefox browser. Next, a set of seed nodes is identified from the candidate alignment set, which has the least number of adjacent aligned nodes in the provenance graph and the query graph. This set of nodes is chosen as seeds because attack activities usually show a lower alignment frequency in graph matching than benign activities, which is a common phenomenon in security analysis. Finally, the search is expanded with the seed node as the center to find more node alignments, matching all provenance subgraphs in the provenance graph that have similar structures to the query graph.
[0043] (8) Based on the multiple traceability subgraphs similar to the query graph matched in step (7), a path scoring function is introduced to determine the APT attack traceability graph that is most similar to the query graph. The path scoring function scores according to the matching of different aligned nodes and the consistency of the causal relationship between different aligned nodes. The specific scoring rules are as follows: If a group of aligned nodes points to another group of identical aligned nodes, and the causal relationship between them is the same, then the path is scored as 1 point in the scoring function. By accumulating the scores of each path, the traceability subgraph with the highest score can be identified. This traceability subgraph is the traceability graph that is most likely to contain APT attack behavior, so it can be used as the traceability graph of APT attack behavior to achieve the detection of APT attacks.
[0044] Figure 1 The flow chart of the present invention is mainly divided into two stages.
[0045] In the first stage, the core role of IoT honeypots is to capture APT attacks.
[0046] At the application layer, the IoT honeypot provides HTTP services to capture HTTP requests from attackers and forwards them to real IoT devices connected to the public network to collect the corresponding HTTP responses. Furthermore, the HTTP interaction between the IoT honeypot and the attacker is modeled as a Markov decision process. Using the model-free SARSA algorithm based on reinforcement learning, the IoT honeypot can learn online response strategies to attackers, returning the optimal response that can deceive the attacker, thereby enhancing the IoT honeypot's ability to simulate real IoT devices.
[0047] At the network layer, the IoT honeypot integrates Honeyd's personalization engine, Nmap, and Wireshark. Nmap actively scans real IoT devices for operating system information, while Wireshark captures the returned OS fingerprint traffic. The personalization engine simulates the IoT device's OS fingerprint, making the IoT honeypot appear like a real IoT device at the network layer.
[0048] By combining application-layer HTTP response strategy learning with network-layer OS fingerprint simulation, IoT honeypots can create a deep entrapment environment to more effectively capture application-layer APT attacks launched by attackers. All captured APT attacks are recorded in detail in attack logs, providing data support for further construction of traceability maps.
[0049] In the second phase, the attack logs captured in the first phase are used to construct a provenance graph. This graph details all behaviors captured by the IoT honeypot, including both benign and APT attacks. Simultaneously, the open source threat intelligence Engagement 3 dataset is used to construct a query graph containing labeled APT attack behaviors. Graph matching techniques are then applied to identify multiple provenance subgraphs with similar structures to the query graph. Furthermore, a path scoring function is introduced to calculate the similarity between different provenance subgraphs and the query graph, and the subgraph with the highest similarity is identified as the APT attack provenance graph. Finally, the resulting APT attack provenance graph enables rapid identification of the entire phase of an APT attack and related activities, enabling rapid detection of APT attack behaviors.
[0050] Figure 2 This paper demonstrates how an IoT honeypot simulates the operating system fingerprint of an IoT device. When the IoT honeypot detects six TCP SYN scan packets from the Nmap tool, spaced 100ms apart, Honeyd's personalization engine first reads the IoT device's fingerprint data from the pcap file. This fingerprint data includes the identifier and flags from the IP stack, the flags, window size, and options from the TCP stack, the type, code, and data from the ICMP stack, and the data from the UDP stack. The personalization engine then tracks the TCP initial sequence numbers in the scan packets and generates a response initial sequence number that approximates the initial sequence number distribution in the IoT device's fingerprint. Finally, the personalization engine uses the extracted fingerprint data and the generated initial sequence number to modify each response packet returned to the attacker. Through this process, the IoT honeypot provides the attacker with an operating system fingerprint that matches that of a real IoT device. This allows the attacker to mistakenly identify the IoT honeypot as a real IoT device at the network level, rather than the cloud server it is intended to be. This enhanced camouflage allows the IoT honeypot to more effectively deceive attackers, thereby attracting more application-layer attacks.
[0051] Figure 3This article demonstrates the process of identifying APT attack tracing graphs based on path scoring. The query graph recreates a fragment of a Firefox backdoor attack scenario. In this scenario, the attacker first launches various processes using cmd.exe, including commands such as whoami, netstat, and hostname, and then writes the data into the thumbs.db file to hide the malicious data.
[0052] Provenance subgraphs A and B simulate potential attack behaviors captured by an IoT honeypot. When calculating the similarity between different provenance subgraphs and the query graph, the path scoring function uses the matching of aligned nodes and the consistency of the causal relationships between them. For example, in provenance subgraph A, the attacker launches the hostname process using cmd.exe. In the query graph, the attacker also launches the hostname process using cmd.exe, and the causal relationship between the two is consistent. In this case, the path receives a score of 1. Similarly, in provenance subgraph A, there are four paths that can receive a score of 1, for a total of 4 points. However, in provenance subgraph B, only three paths are identical to the query graph, resulting in a score of 3. Therefore, the final result is provenance subgraph A, which has the highest match with the attack activity in the query graph and can be used as the provenance graph for APT attack behavior, enabling APT attack detection.
[0053] Corresponding to the aforementioned embodiment of the honeypot-based APT attack capture and detection method, the present invention also provides an embodiment of the honeypot-based APT attack capture and detection device.
[0054] See also Figure 4 The honeypot-based APT attack capture and detection device provided in an embodiment of the present invention includes a memory and one or more processors. The memory stores executable code. When the processor executes the executable code, it is used to implement the honeypot-based APT attack capture and detection method in the above embodiment.
[0055] The embodiment of the honeypot-based APT attack capture and detection device of the present invention can be applied to any device with data processing capabilities, and the device with data processing capabilities can be a device or apparatus such as a computer. The device embodiment can be implemented through software, or through hardware or a combination of software and hardware. Taking software implementation as an example, as a device in a logical sense, it is formed by the processor of any device with data processing capabilities in which it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for execution. From the hardware level, if Figure 4 The figure shows a hardware structure diagram of any device with data processing capability where the honeypot-based APT attack capture and detection device of the present invention is located. Figure 4In addition to the processor, memory, network interface, and non-volatile memory shown, any device with data processing capabilities in which the apparatus in the embodiment is located may also include other hardware, generally based on the actual functions of the device with data processing capabilities, which will not be described in detail.
[0056] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.
[0057] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present invention. A person of ordinary skill in the art can understand and implement the present invention without inventive work.
[0058] An embodiment of the present invention further provides a computer-readable storage medium having a program stored thereon. When the program is executed by a processor, the honeypot-based APT attack capture and detection method in the above embodiment is implemented.
[0059] The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the aforementioned embodiments, such as a hard disk or memory. The computer-readable storage medium may also be an external storage device of any device with data processing capabilities, such as a plug-in hard disk, a smart media card (SMC), an SD card, a flash card, etc. equipped on the device. Furthermore, the computer-readable storage medium may also include both an internal storage unit and an external storage device of any device with data processing capabilities. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and may also be used to temporarily store data that has been output or is to be output.
[0060] The above description is merely a preferred embodiment of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of this specification shall be included in the scope of protection of one or more embodiments of this specification.
Claims
1. A honeypot-based APT attack capture and detection method, characterized in that: The following steps are involved: (1) Deploy an IoT honeypot on the cloud server to collect network layer operating system fingerprint data and application layer HTTP response data of real IoT devices connected to the public network, and capture application layer HTTP request data from network attackers; (2) Based on the network layer operating system fingerprint data of the real IoT device collected in step (1), the IoT honeypot automatically detects the TCP SYN scan data packet and uses Honeyd's personalization engine to modify the fingerprint data of the cloud server operating system to simulate the operating system of the real IoT device; (3) Based on the application layer HTTP response data collected in step (1), the application layer HTTP interaction process between the IoT honeypot and the network attacker is modeled as a Markov decision process; (4) Based on the Markov decision process modeled in step (3), the IoT honeypot uses the reinforcement learning model-free SARSA algorithm to learn online the response strategy to network attackers, so that the IoT honeypot can adaptively return the best HTTP response to the attacker; all captured attack behaviors during the online interaction process are saved in the attack log; (5) constructing a traceability graph based on the attack log saved in step (4), wherein the traceability graph consists of nodes and directed edges, wherein the nodes represent system entities recorded in the attack log, and the directed edges record the causal relationship between the nodes; (6) constructing a query graph based on the open source threat intelligence dataset, wherein the query graph consists of nodes and directed edges, wherein the nodes represent system entities in the real attack process recorded in the threat intelligence dataset, and the directed edges record the causal relationship between the nodes; (7) Based on the provenance graph constructed in step (5) and the query graph constructed in step (6), the nodes in the provenance graph and the query graph are aligned using graph matching technology to match multiple provenance subgraphs similar to the query graph; (8) Based on the multiple traceability subgraphs matched in step (7), a path scoring function is introduced to calculate the traceability subgraph with the highest matching degree with the query graph to obtain the final ATP attack traceability graph.
2. A honeypot-based APT attack capture and detection method according to claim 1, characterized in that: In step (1), the application layer HTTP request data is captured by the HTTP service provided by the IoT honeypot, the application layer HTTP response data is obtained by the IoT honeypot forwarding the captured application layer HTTP request data to the IoT device, and the network layer operating system fingerprint data is obtained from the IoT device by the IoT honeypot using Nmap and Wireshark tools.
3. The method for capturing and detecting APT attacks based on honeypot according to claim 1, characterized in that: In step (2), when the IoT honeypot detects 6 TCP SYN scanning packets with an interval of 100ms from the Nmap tool, the network layer operating system fingerprint data of the IoT device collected in step (1) is first extracted through the personalization engine of Honeyd; then, a response initialization sequence number that approximates the distribution of the initialization sequence number in the fingerprint of the IoT device is generated according to the TCP initialization sequence number in the scanning packet; finally, the extracted fingerprint data and the generated initialization sequence number are used to introduce modifications in each response packet returned to the network attacker; This process ensures that network attackers will mistake the operating system fingerprint of the IoT honeypot for the operating system fingerprint of a real IoT device, thereby resisting the attacker's network layer fingerprint recognition and enhancing the ability of the IoT honeypot to trap APT attacks.
4. The method for capturing and detecting APT attacks based on honeypot according to claim 1, characterized in that: In step (3), the application layer HTTP response data collected from the IoT device is the action set in the Markov decision process; the public network environment where the IoT honeypot is located is the environment; the application layer HTTP request sent by the network attacker is the state; the IoT honeypot is the intelligent agent; the distribution of rewards depends on the specific content of the next HTTP request captured from the network attacker after the IoT honeypot returns an HTTP response to the network attacker.
5. The method for capturing and detecting APT attacks based on honeypot according to claim 1, characterized in that: In step (4), the model-free SARSA algorithm is applied to the online interaction with the network attacker, aiming to help the IoT honeypot learn how to dynamically formulate the best response strategy in the network environment; When the IoT honeypot interacts online, it first initializes a Q table, where rows represent different HTTP responses and columns represent different HTTP requests; When a network attacker sends an HTTP request to the IoT honeypot, the IoT honeypot first selects an HTTP response from the action set based on the ∈-greedy strategy and returns it to the network attacker; Then, the IoT honeypot observes the attacker's next HTTP request, the corresponding reward, and the IoT honeypot's next action to update the Q value; This process is repeated over and over, allowing the honeypot to gradually optimize its response strategy.
6. The method for capturing and detecting APT attacks based on honeypot according to claim 1, characterized in that: The provenance graph depicts potential APT attack behaviors captured by the IoT honeypot, and the nodes in the provenance graph represent different types of system entities recorded in the attack log; the query graph depicts real ATP attack behaviors, and the nodes in the query graph represent different types of system entities in the real attack process; the node types in the provenance graph and the query graph include processes, malware, sockets, files, and registry entries, and different graphs are used to represent different types of entities, and the specific information of the entities is marked in the graphs; the directed edges in the provenance graph and the query graph both mark the specific actions performed by a node on other nodes, and record the information flow and the causal relationship between entities.
7. The method for capturing and detecting APT attacks based on honeypot according to claim 1, characterized in that: In step (7), based on the constructed provenance graph and query graph, firstly, all possible candidate alignment sets are identified according to the specific information of different nodes in the two graphs; then, among these aligned nodes, a set of seed nodes with the least number of adjacent aligned nodes in the provenance graph and query graph are screened out; finally, with the seed nodes as the center, the matching search range is expanded to find more aligned nodes, and all provenance subgraphs in the provenance graph with similar structures to the query graph are matched.
8. The method for capturing and detecting APT attacks based on honeypot according to claim 1, characterized in that: In step (8), the path scoring function scores according to the matching of different aligned nodes and the consistency of causal relationships between different aligned nodes; by accumulating the scores of each path, the tracing subgraph with the highest score is identified, namely, the APT attack tracing subgraph; the APT attack tracing subgraph contains detailed information on the APT attack behavior captured by the IoT honeypot, including each stage of the attack and related activities.
9. A honeypot-based APT attack capture and detection device, comprising a memory and one or more processors, wherein the memory stores executable code, characterized in that: When the processor executes the executable code, it is used to implement the honeypot-based APT attack capture and detection method as described in any one of claims 1-8.
10. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the honeypot-based APT attack capture and detection method as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Intelligent self-evolution generation method for network threat disposal strategy based on DRL model
CN116319060A
High-interaction Internet of Things honeypot deployment method and system based on firmware simulation
CN116502226A