A honeypot drainage method, device, target machine, storage medium and program product
By integrating honeypot probes into host security, the system automatically identifies and associates idle ports, solving the problem of insufficient honeypot traffic and maximizing honeypot traffic, thereby improving the attack traffic coverage and security of the honeypot.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2024-09-29
- Publication Date
- 2026-05-15
AI Technical Summary
Current honeypot technology has limited traffic generation capacity and cannot maximize it.
Integrating honeypot probes into host security automatically identifies and associates idle ports with the honeypot probes, maximizing honeypot traffic redirection.
By automatically identifying and associating idle ports, the honeypot maximizes traffic redirection, increases attack traffic coverage, and reduces the risk of being detected.
Smart Images

Figure CN119210864B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a honeypot diversion method, apparatus, target machine, storage medium, and program product. Background Technology
[0002] With the continuous advancement of network technology, cyberattacks on the internet are becoming increasingly common. In response, to ensure network security, technologies such as deploying honeypots on machines and using honeypots for traffic redirection have emerged.
[0003] In the process of realizing this invention, the inventors discovered the following technical problem in the prior art: the access traffic introduced into the honeypot is limited, that is, it is impossible to maximize the traffic diversion of the honeypot. Summary of the Invention
[0004] This invention provides a honeypot referral method, apparatus, target machine, storage medium, and program product to maximize honeypot referrals.
[0005] According to one aspect of the present invention, a honeypot redirection method is provided. This method is applied to host security, where the host security is deployed on a target machine. The host security integrates a honeypot probe, and a target port on the target machine is associated with the honeypot probe. The target port is in an idle state before being associated with the honeypot probe. The method may include:
[0006] Monitor traffic access on the target port;
[0007] Upon detecting the first access traffic on the target port, the honeypot probe is used to direct the first access traffic into the target honeypot mapped to the target port.
[0008] According to another aspect of the present invention, a honeypot referral device is provided, which can be configured on a host security device deployed on a target machine. The host security device integrates a honeypot probe, and a target port in the target machine is associated with the honeypot probe. The target port is in an idle state before being associated with the honeypot probe. The device may include:
[0009] The first traffic detection module is used to detect traffic access on the target port;
[0010] The honeypot redirection module is used to redirect the first access traffic to the honeypot mapped by the honeypot probe when the first access traffic is detected on the target port.
[0011] According to another aspect of the present invention, a target machine is provided, on which host security is deployed, and the host security integrates a honeypot probe. A target port in the target machine is associated with the honeypot probe, and the target port is in an idle state before being associated with the honeypot probe. The host security includes a computer program, and the target machine includes:
[0012] At least one processor; and
[0013] A memory that is communicatively connected to at least one processor; wherein,
[0014] The memory stores a computer program that can be executed by at least one processor, such that when the at least one processor executes the program, it implements the honeypot referral method provided in any embodiment of the present invention.
[0015] According to another aspect of the present invention, a computer-readable storage medium is provided having computer instructions stored thereon for causing a processor to execute and implement the honeypot redirection method provided in any embodiment of the present invention.
[0016] According to another aspect of the present invention, a computer program product is provided, on which a computer program is stored, which, when executed by a processor, implements the honeypot referral method provided in any embodiment of the present invention.
[0017] The honeypot redirection method described in this invention is applied to host security. The host security is deployed on a target machine and integrates a honeypot probe. A target port on the target machine is associated with the honeypot probe. Before association, the target port is idle. This method detects traffic access on the target port, and upon detecting the first access traffic on the target port, it redirects the first access traffic to the target honeypot mapped to the target port via the honeypot probe, thus completing the honeypot redirection. This technical solution, by integrating the honeypot probe into the host security, leverages the host security's ability to automatically identify idle ports on the target machine and associate these idle ports with the honeypot probe for honeypot redirection, maximizing honeypot redirection.
[0018] It should be understood that the description in this section is not intended to identify key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a schematic diagram of an optional example of various honeypot referral methods provided according to embodiments of the present invention;
[0021] Figure 2 A flowchart of a honeypot diversion method provided in an embodiment of the present invention;
[0022] Figure 3 This is a flowchart of another honeypot diversion method provided by an embodiment of the present invention;
[0023] Figure 4 This is a flowchart of another honeypot diversion method provided by an embodiment of the present invention;
[0024] Figure 5 This is a structural block diagram of a honeypot diversion device provided according to an embodiment of the present invention;
[0025] Figure 6 This is a schematic diagram of the target machine for implementing the honeypot referral method of this invention. Detailed Implementation
[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. The same applies to "target," "original," etc., and will not be repeated here. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0028] It should be noted that the collection, gathering, updating, analysis, processing, use, transmission, and storage of user personal information involved in the technical solution of this invention all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken to prevent unauthorized access to user personal information data and to maintain user personal information security and network security.
[0029] Before introducing the embodiments of the present invention, the relevant technologies for using honeypots for traffic generation described above will be explained by way of example in order to better understand the honeypot traffic generation method described in the embodiments of the present invention.
[0030] For example, related technologies reserve machines within the business network to deploy honeypot probes, and use these honeypot probes to introduce attack traffic into the honeynet. However, this has at least two problems: First, to deploy more honeypot probes, more machines need to be reserved, which obviously leads to a waste of resources and makes it difficult to achieve coverage of a large number of honeypot probes; Second, only one honeypot probe service is deployed on the machine, which is only used to map one or more web applications or services that disguise themselves as big data services, databases, or web content management systems (CMS) that appear to be normal business operations but have obvious vulnerabilities. There are no other identifiers associated with normal business operations, making it very easy for attackers to identify this as a honeypot trap.
[0031] Here are two technical concepts explained: First, the honeypot probe mentioned above can also be called a honeypot agent. A honeypot agent is a special network service that allows a terminal (usually a client) to establish an indirect connection with another terminal (usually a server) through itself (i.e., the network service). Second, a honeypot is a deception technique used to detect, analyze, and trace attack behavior. It has no business application. All traffic flowing into and out of the honeypot indicates scanning or attack behavior, thus allowing for a better focus on attack traffic. It is frequently used in network security.
[0032] For another example, to address the two issues mentioned above, for business machines with normal business operations deployed within the business network, the relevant technology directly deploys honeypot probes on the business machines and associates a specific port on the business machine with the honeypot probe, thereby diverting attack traffic destined for that port into the honeynet. This approach avoids resource waste and achieves extensive coverage of the honeypot probe; secondly, because both the honeypot probe and normal business operations are deployed on the business machine simultaneously, it effectively confuses attackers and prevents the honeypot trap from being detected.
[0033] However, once this technology associates a port with a honeypot probe, it will not associate other ports with the honeypot probe, resulting in a limited amount of attack traffic introduced into the honeynet, that is, a limited amount of attack traffic introduced into the honeypot, which cannot maximize the honeypot's traffic diversion.
[0034] Based on this, in order to bring more attack traffic into the honeypot, this embodiment of the invention takes into account that host security has been deployed on most or even all business machines in the business network, and that the host security can automatically identify idle ports on the business machines. Therefore, this embodiment of the invention integrates the honeypot probe into the host security, so that after the host security identifies an idle port, it automatically associates the idle port with the honeypot probe, thereby associating more interfaces with the honeypot probe. As a result, more attack traffic can be brought into the honeypot using these more interfaces, thereby maximizing the honeypot's traffic diversion.
[0035] For example, see Figure 1Ten business machines are deployed in the business network. Each of these ten machines has a host security module deployed on it. This host security module monitors the accounts, processes, and network traffic files of the corresponding business machines (i.e., hosts) to detect and block potential network threats. Honeypot probes are integrated into each host security module to improve their coverage. Taking the host security module deployed on business machine A and its integrated honeypot probe as an example, the host security module can automatically identify idle ports on business machine A (e.g., 8080 and 7001) and associate each idle port with the honeypot probe. This ensures that attack traffic destined for these idle ports is directed to honeypot A, thereby maximizing the traffic redirection from honeypot A.
[0036] This will be explained in detail below.
[0037] Figure 2 This is a flowchart of a honeypot referral method provided in an embodiment of the present invention. This embodiment is applicable to honeypot referral scenarios. The method can be executed by the honeypot referral device provided in this embodiment of the present invention. This device can be implemented in software and / or hardware. The device can be integrated on the target machine, which has host security deployed on it. The host security integrates a honeypot probe. The target port on the target machine is associated with the honeypot probe, and the target port is idle before being associated with the honeypot probe.
[0038] See Figure 2 The method of this invention specifically includes the following steps:
[0039] S110. Detect traffic access on the target port.
[0040] The target machine can be a machine with host security deployed. Depending on the application scenarios that may be involved in the embodiments of the present invention, the machine can optionally be a business machine used to provide business services. On this basis, the business services can optionally be big data services, databases, and Web CMS, etc., which are related to the actual situation and are not specifically limited here.
[0041] The target machine exposes at least two ports. Typically, some of these ports are occupied (called occupied ports), while the other is idle (called idle ports). As explained above, host security can identify the idle port and associate it with a honeypot probe to redirect traffic to the honeypot. Understandably, the port associated with the honeypot probe is no longer idle but occupied. To distinguish it from the occupied port, this port is referred to as the target port. The number of target ports can be one or more, depending on the specific situation, and is not specifically limited here. Therefore, before being associated with the honeypot probe, the target port is an idle port.
[0042] It should be noted that, for the real service deployed on the target machine corresponding to the honeypot probe, the target honeypot (i.e., the virtual service corresponding to the real service) proxied by the honeypot probe is more vulnerable to attack. Therefore, the probability of attack traffic hitting the target port is greater than the probability of hitting the port occupied by the real service.
[0043] The host security system monitors traffic access on the target port. This traffic access information indicates whether there is any traffic reaching the target port. This traffic may be abnormal (i.e., attack traffic) or normal (i.e., non-attack traffic), depending on the actual situation, and is not limited here. It should be noted that, for ease of distinction from traffic reaching an occupied port, traffic reaching the target port is referred to here as the first access traffic.
[0044] S120. Upon detecting the first access traffic on the target port, the first access traffic is introduced into the target honeypot mapped to the target port via a honeypot probe.
[0045] In this context, a target honeypot can be understood as the honeypot proxies the honeypot probe, specifically the honeypot mapped to the target port associated with the honeypot probe. Upon detecting the first access traffic on the target port, host security can use the honeypot probe to redirect this first access traffic into the target honeypot. This is achieved through port mapping, preventing the first access traffic, which is highly likely to be attack traffic, from impacting the target machine.
[0046] Optionally, the target machine is located within the target network, and the target honeypot is located within a honeynet. This honeynet is communicatively connected to the target machine, and at least two honeypots are deployed within the honeynet, including the target honeypot. Therefore, after detecting the first access traffic, the host security system can determine the target honeypot mapped to the target port from among these at least two honeypots. Using a honeypot probe, the first access traffic is then directed to the correct honeypot (i.e., the target honeypot), thus ensuring the correctness of the honeypot redirection and preventing the first access traffic, which is highly likely to be attack traffic, from impacting the target network.
[0047] The honeypot redirection method described in this invention is applied to host security. The host security is deployed on a target machine and integrates a honeypot probe. A target port on the target machine is associated with the honeypot probe. Before association, the target port is idle. This method detects traffic access on the target port, and upon detecting the first access traffic on the target port, it redirects the first access traffic to the target honeypot mapped to the target port via the honeypot probe, thus completing the honeypot redirection. This technical solution, by integrating the honeypot probe into the host security, leverages the host security's ability to automatically identify idle ports on the target machine and associate these idle ports with the honeypot probe for honeypot redirection, maximizing honeypot redirection.
[0048] Figure 3 This is a flowchart of another honeypot referral method provided in this embodiment of the invention. This embodiment is an optimization based on the above-described technical solutions. In this embodiment, optionally, the target machine includes at least two ports, and the honeypot referral method may further include: collecting the occupancy status of at least two ports; and, if, based on the occupancy status, an idle port is identified among the at least two ports, as the idle port is used as the target port and associated with the honeypot probe. The explanations of terms that are the same as or corresponding to those in the above embodiments will not be repeated here.
[0049] See Figure 3 The method in this embodiment may specifically include the following steps:
[0050] S210. Collect the occupancy status of at least two ports, and if an idle port is identified among the at least two ports based on the occupancy status, use the idle port as the target port and associate it with the honeypot probe.
[0051] The target machine exposes at least two ports. The host security system can automatically collect the occupancy status of each of these two ports, indicating whether the port is occupied or idle. Furthermore, if the host security system determines that there is an idle port among the at least two ports based on the collected occupancy status, it can designate that idle port as the target port and associate it with the honeypot probe for subsequent honeypot traffic redirection.
[0052] In practical applications, optionally, the occupancy status of at least two ports can be collected at preset time intervals, i.e., the occupancy status can be collected repeatedly. In this way, newly added idle ports can be discovered in a timely manner, and the idle ports can be associated with the honeypot probe, thereby increasing the number of target ports that can be used for honeypot traffic redirection. This helps to bring more first-access traffic to the target honeypot and further maximize honeypot traffic redirection.
[0053] S220. Detect traffic access on the target port.
[0054] S230. Upon detecting the first access traffic on the target port, the first access traffic is introduced into the target honeypot mapped to the target port via a honeypot probe.
[0055] The technical solution of this invention automatically collects the occupancy status of each port in the host security system, and when an idle port is found, it is used as the target port to associate with the honeypot probe. This realizes the automatic identification and association of idle ports, and prepares for subsequent honeypot traffic redirection.
[0056] Figure 4 This is a flowchart of another honeypot traffic redirection method provided in this embodiment of the invention. This embodiment is based on and optimized from the above-mentioned technical solutions. In this embodiment, optionally, a real service corresponding to the target honeypot is deployed on the target machine, and at least two ports include the occupied port occupied by the real service. The honeypot traffic redirection method further includes: detecting the traffic access on the occupied port; and forwarding the second access traffic to the real service when a second access traffic is detected on the occupied port. The explanations of terms that are the same as or corresponding to those in the above embodiments are not repeated here.
[0057] See Figure 4 The method in this embodiment may specifically include the following steps:
[0058] S310. Collect the occupancy status of at least two ports, and if, based on the occupancy status, there is an idle port among the at least two ports, use the idle port as the target port and associate it with the honeypot probe.
[0059] S320. Detect traffic access on the target port.
[0060] S330. Upon detecting the first access traffic on the target port, the first access traffic is introduced into the target honeypot mapped to the target port via a honeypot probe.
[0061] S340. Detect the traffic access on the occupied port, wherein the target machine has a real service corresponding to the target honeypot deployed on it, and the occupied port is the port occupied by the real service among at least two ports.
[0062] In this context, a target honeypot can be understood as a fake service simulating a real service deployed on the target machine. The ports occupied by the real service are referred to as occupied ports. Host security checks the traffic access to the occupied ports. It should be noted that, for clarity, to distinguish it from the first access traffic, traffic hitting the occupied port is referred to as second access traffic.
[0063] S350. If a second access traffic is detected on a port that is occupying the port, the second access traffic is forwarded to the real service.
[0064] In this case, when host security detects a second access traffic on a port that is being used, it forwards the second access traffic to the real service for a response because the port being used corresponds to the real service.
[0065] For example, such as Figure 1 As shown, when access traffic reaches ports 80, 443, or 22, the access traffic is forwarded to the real service for response; similarly, when access traffic reaches ports 8080 or 7001, the access traffic is introduced into honeypot A through the port mapping function of the honeypot probe.
[0066] The technical solution of this invention can forward the second access traffic that is blocked on the port occupied by the real service to the real service, so as to ensure the effective response of the second access traffic.
[0067] Optionally, the target honeypot is located within the honeynet, while the real service and the honeypot probe (which serves as the entry point for the target honeypot) are located within the target network. This ensures that the network interconnection protocol of the honeypot entry point is the same as that of the real service. In other words, the target honeypot and the real service are located in different networks, resulting in different Internet Protocol (IP) protocols. However, the advantage is that the honeypot entry point (i.e., the honeypot probe) shares the same IP address as the real service. This allows for better disguise of the honeypot, reducing attackers' awareness and thus lowering the probability of it being identified as a honeypot trap.
[0068] Figure 5 This is a structural block diagram of a honeypot diversion device provided in an embodiment of the present invention. This device is used to execute the honeypot diversion method provided in any of the above embodiments. This device and the honeypot diversion methods of the above embodiments belong to the same inventive concept. Details not described in detail in the embodiments of the honeypot diversion device can be found in the embodiments of the honeypot diversion methods described above. See also... Figure 5 This device can be configured for host security, which is deployed on the target machine. The host security integrates a honeypot probe. The target port on the target machine is associated with the honeypot probe. Before being associated with the honeypot probe, the target port is in an idle state. This device may include: a traffic first detection module 410 and a honeypot diversion module 420.
[0069] The traffic detection module 410 is used to detect the traffic access on the target port;
[0070] The honeypot redirection module 420 is used to redirect the first access traffic into the honeypot mapped by the honeypot probe when the first access traffic is detected on the target port.
[0071] Optionally, the target machine includes at least two ports, and the honeypot diversion device described above may further include:
[0072] The occupancy status acquisition module is used to collect the occupancy status of at least two ports;
[0073] The association module is used to identify at least two idle ports based on port occupancy and then associate the idle port with the honeypot probe as the target port.
[0074] Based on this, an optional occupancy data collection module is specifically used for:
[0075] Based on a preset time interval, collect the occupancy status of at least two ports.
[0076] Alternatively, the target machine may have a real service corresponding to the target honeypot deployed on it, with at least two ports including those occupied by the real service. The honeypot redirection device may also include:
[0077] The second traffic detection module is used to detect the traffic access on the occupied port;
[0078] The traffic forwarding module is used to forward the second access traffic to the real service when it detects that the second access traffic is occupying the port.
[0079] Optionally, the target honeypot is located within the honeynet, while the real service and the honeypot probe, which serves as the honeypot's entry point, are located within the target network, ensuring that the network interconnection protocol of the honeypot's entry point is the same as that of the real service.
[0080] Optionally, at least two honeypots are deployed within the honeynet that communicates with the target machine, and the honeypot diversion device further includes:
[0081] The target honeypot determination module is used to determine the target honeypot mapped to the target port from at least two honeypots.
[0082] Optionally, based on any of the above devices, the target machine is a business machine.
[0083] The honeypot redirection device provided in this embodiment of the invention is configured on a host security system deployed on a target machine. The host security system integrates a honeypot probe, and a target port on the target machine is associated with the honeypot probe. Before association, the target port is idle. The device, through the cooperation of a first traffic detection module and a honeypot redirection module, detects traffic access on the target port. Upon detecting first access traffic on the target port, the honeypot probe redirects this first access traffic into the target honeypot mapped to the target port, thus completing the honeypot redirection. By integrating the honeypot probe into the host security system, this device leverages the host security system's ability to automatically identify idle ports on the target machine and associate these idle ports with the honeypot probe for honeypot redirection, maximizing honeypot redirection.
[0084] The honeypot diversion device provided in the embodiments of the present invention can execute the honeypot diversion method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0085] It is worth noting that in the embodiments of the honeypot diversion device described above, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.
[0086] Figure 6A schematic diagram of a target machine 10, which can be used to implement embodiments of the present invention, is shown. The target machine is equipped with host security, on which a honeypot probe is integrated. A target port in the target machine is associated with the honeypot probe and is idle before being associated with it. The host security includes computer programs. The target machine is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The target machine can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0087] like Figure 6 As shown, the target machine 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 and a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer programs stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the target machine 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0088] Multiple components in the target machine 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, optical disk, etc.; and a communication unit 19, such as a network card, modem, wireless transceiver, etc. The communication unit 19 allows the target machine 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0089] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as honeypot referral methods.
[0090] In some embodiments, the honeypot redirection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the target machine 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the honeypot redirection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to execute the honeypot redirection method by any other suitable means (e.g., by means of firmware).
[0091] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0092] Computer programs used to implement the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0093] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0094] To provide interaction with a user, the systems and techniques described herein can be implemented on a target machine having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the target machine. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0095] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0096] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0097] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0098] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A honeypot diversion method, characterized in that, Applied to host security, the host security is deployed on a target machine, the target machine includes at least two ports, and the host security integrates a honeypot probe; the method includes: Collect the occupancy status of at least two ports; If, based on the occupancy status, it is determined that there is an idle port among the at least two ports, the idle port is associated with the honeypot probe to obtain the target port in an occupied state; Detect the traffic access status on the target port; Upon detecting the first access traffic on the target port, the first access traffic is introduced into the target honeypot mapped to the target port via the honeypot probe.
2. The method according to claim 1, characterized in that, The collection of occupancy status of the at least two ports includes: Based on a preset time interval, the occupancy status of the at least two ports is collected.
3. The method according to claim 1, characterized in that, The target machine has a real service corresponding to the target honeypot deployed on it, and the at least two ports include ports occupied by the real service. The method further includes: The traffic access status on the occupied port is detected; Upon detecting a second access traffic on the occupied port, the second access traffic is forwarded to the real service.
4. The method according to claim 3, characterized in that, The target honeypot is located within the honeynet, and the real service and the honeypot probe, which serves as the honeypot entry point for the target honeypot, are located within the target network, such that the network interconnection protocol of the honeypot entry point is the same as the network interconnection protocol of the real service.
5. The method according to claim 1, characterized in that, The honeynet, which is communicatively connected to the target machine, has at least two honeypots deployed within it. The method further includes: From the at least two honeypots, determine the target honeypot that the target port maps to.
6. The method according to any one of claims 1-5, characterized in that, The target machine is a business machine.
7. A honeypot diversion device, characterized in that, Configured for host security, the host security is deployed on a target machine, the target machine includes at least two ports, and the host security integrates a honeypot probe; the device includes: The occupancy status acquisition module is used to collect the occupancy status of the at least two ports; The association module is used to associate the idle port with the honeypot probe when it is identified that there is an idle port among the at least two ports based on the occupancy status, so as to obtain the target port in the occupancy state; The traffic detection module is used to detect the traffic access status on the target port; The honeypot redirection module is used to, upon detecting first access traffic on the target port, redirect the first access traffic into the honeypot mapped by the honeypot probe via the honeypot probe.
8. A target machine, characterized in that, The target machine is equipped with host security, which integrates honeypot probes. The host security includes computer programs. The target machine includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores the computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to cause the at least one processor to perform the honeypot referral method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the honeypot redirection method as described in any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the honeypot referral method as described in any one of claims 1-6.