Internal network threat hunting method, system, storage medium and electronic device

By deploying honeybeacons and honeyhole programs in cloud-native clusters, recording and analyzing attacker node information, and generating attack paths, the problem of the inability to hunt threat behaviors in a timely manner in existing technologies is solved, and real-time capture of threat behaviors and generation of detailed paths are achieved, thus avoiding the loss of cloud clusters.

CN119382978BActive Publication Date: 2025-09-30GUANGZHOU UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411507757.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-28
Publication Date
2025-09-30
Estimated Expiration
2044-10-28

AI Technical Summary

Technical Problem

Existing cloud-native security technologies are unable to promptly perceive and hunt threat actors' threat behaviors and attack paths in cloud-native scenarios in real time, resulting in the loss of cloud cluster administrator accounts and, in turn, the loss of the entire cloud cluster.

Method used

Deploy honeybeans in cloud-native clusters, record node information triggered by attackers and send early warning information, deliver honeyhole programs to collect information, generate attack paths through correlation analysis, and use honeyhole programs to collect device information, network information, and account information to capture threat actors in real time.

Benefits of technology

It achieves timely perception and real-time hunting of threat actors, generates detailed and accurate attack paths, avoids the loss of cloud cluster administrator accounts, and provides more macro threat intelligence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382978B_ABST
    Figure CN119382978B_ABST
Patent Text Reader

Abstract

The present invention provides an internal network threat hunting method, system, storage medium, and electronic device. The system includes: a honeytag for recording node information of the honeytag when an attacker triggers the honeytag on a node; an early warning module for forwarding the early warning information to a delivery module; the delivery module for retrieving a honeyhole program corresponding to the early warning information from a payload library and sending the honeyhole program and the location information of the honeyhole node to a management component in a cloud native cluster, so that the management component sends the honeyhole program to the honeyhole node based on the location information, and the honeyhole node receives and runs the honeyhole program; an association analysis module for receiving and analyzing the operation information returned by the honeyhole program and generating an attack path for the current threat hunting based on the operation information; and a payload library for storing multiple honeyhole programs. The present invention can timely perceive and generate attack paths related to threat hunting, effectively preventing cloud cluster administrator accounts from being compromised.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an internal network threat hunting method, system, storage medium and electronic device. Background Art

[0002] With the development of cloud computing technology, businesses and organizations are gradually realizing the advantages of migrating IT resources to the cloud. Cloud computing provides businesses with on-demand resources without the need for expensive hardware and infrastructure. Cloud-native architecture, a cutting-edge technology in cloud computing, aims to leverage the elasticity and scalability of cloud environments to enable collaborative software development and operations. With the increasing popularity of cloud-native architecture and applications, advanced cyber threat actors are targeting cloud devices. After infiltrating an enterprise / organization's local intranet, threat actors search for locally stored cloud credentials and attempt to access cloud hosts using local intranet devices to establish a foothold in the cloud. They then conduct large-scale lateral movement by scanning and probing for vulnerabilities in cloud hosts, enabling larger-scale and more complex information theft and sabotage activities.

[0003] Currently, security technologies for cloud-native applications fall into two main categories: those focused on container security and those focused on access control policies. Technologies focused on container security primarily ensure security within the container, such as detecting known vulnerabilities, malware, or incorrect configurations in container images, and detecting malicious behavior during container runtime. Technologies focused on access control policies ensure that each user and service account can only access the resources they need, reducing the risk of privilege abuse, by fine-grained control over API access permissions.

[0004] Within cloud platforms and cloud hosts, threat actors are more likely to use stolen or compromised cloud credentials to establish an initial foothold and use existing operational tools within the foothold host for reconnaissance and lateral movement, behaving similarly to benign users. Rather than conducting destructive activities within a single cloud host node, the threat actor's goal is to move laterally to more hosts until they gain cluster administrator privileges. Existing security technologies for cloud-native scenarios focus on the security of a single cloud host node (container) and the security of that container image, but fail to address anomalous behavior (e.g., lateral movement) across multiple nodes within a cloud cluster. Existing access control policies can only mitigate insecure permission configurations but are unable to detect and deny access to attackers with legitimate credentials. This makes existing security technologies unable to promptly detect and identify threat actors' threatening behaviors and attack paths in cloud-native scenarios. This asymmetry in attack and defense techniques ultimately leads to the compromise of cloud cluster administrator accounts and, ultimately, the entire cloud cluster. Summary of the Invention

[0005] The purpose of the present invention is to provide an internal network threat hunting method, system, storage medium and electronic device, aiming to solve the problem that traditional security technologies are unable to timely perceive and hunt the threat behaviors and attack paths of threat actors in cloud native scenarios in real time, resulting in the loss of cloud cluster administrator accounts and thus the loss of the entire cloud cluster.

[0006] In a first aspect, the present invention provides an internal network threat hunting system, applied to a cloud native cluster, comprising:

[0007] Honeytags are deployed on independent nodes or business nodes in the cloud native cluster. When an attacker triggers a honeytag on a node, they record the node information of the attacker and send an early warning message to the early warning module based on the node information.

[0008] The early warning module is used to forward the early warning information to the delivery module;

[0009] The delivery module is used to retrieve the honeyhole program corresponding to the warning information from the payload library and send the honeyhole program and the location information of the honeyhole node to the management component in the cloud native cluster. The management component sends the honeyhole program to the honeyhole node based on the location information, and the honeyhole node receives and runs the honeyhole program.

[0010] The correlation analysis module is used to receive and analyze the operation information returned by the honeyhole program, and generate the attack path of this threat hunting based on the operation information;

[0011] The payload library is used to store various honeyhole programs.

[0012] Furthermore, the warning information includes system type, version, architecture, location of the honey node, network location of the triggered honeybee, and attacker network information.

[0013] Furthermore, the honeymark is a simulated Web server, database server, file server, or a simulated service and port, or a file, database entry, key, password deployed on a normal business node, or a forged VPN configuration file;

[0014] When the honeybean simulates multiple services or opens multiple ports, the warning information also includes the services or ports accessed by the attacker;

[0015] When the honeytoken is a file-type honeytoken, the warning information further includes the path of the specific file or resource accessed by the attacker.

[0016] Furthermore, the delivery module is used to retrieve a matching honeyhole program from the load library according to the system type, version and architecture.

[0017] Furthermore, the operation information includes log information of the honey node, historical operation records, component logs of the cluster, and historical records of the gateway.

[0018] Furthermore, the association analysis module is also used to:

[0019] Based on the log information, historical operation records, cluster component logs, and gateway history of the honey node, check whether the honey node has been accessed by other nodes.

[0020] If the honey-stepping node has access from other nodes, then the other node will also be marked as a honey-stepping node, and the honeyhole program delivery and association analysis process will be repeated on the newly marked honey-stepping node to determine whether the newly marked honey-stepping node has access from other nodes. This process will be repeated until the newly marked honey-stepping node has no access from other nodes. At this time, the other node will be defined as the initial foothold.

[0021] If the first node that delivers the honeyhole program has no access from other nodes, the node that delivers the honeyhole program is marked as the initial foothold;

[0022] The link consisting of all honey-stepping nodes from the first honey-stepping node to which the honeyhole program is delivered to the initial foothold serves as the attack path for this threat hunting.

[0023] In a second aspect, the present invention provides an internal network threat hunting method, applied to a cloud native cluster, the method comprising:

[0024] When an attacker triggers a honeymark on a node, the node information of the node that triggered the honeymark is recorded, and an early warning message is sent based on the node information;

[0025] Forward warning information;

[0026] Retrieving the honeyhole program corresponding to the warning information from the payload library, and sending the honeyhole program and the location information of the honeyhole node to the management component in the cloud native cluster, so that the management component sends the honeyhole program to the honeyhole node according to the location information, and the honeyhole node receives and runs the honeyhole program. The payload library stores multiple honeyhole programs.

[0027] Receive and analyze the running information returned by the honeyhole program, and generate the attack path for this threat hunting based on the running information.

[0028] Furthermore, the step of receiving and analyzing the operation information returned by the honeyhole program and generating the attack path of this threat hunting according to the operation information includes:

[0029] Based on the log information, historical operation records, cluster component logs, and gateway history of the honey node, check whether the honey node has been accessed by other nodes.

[0030] If the honey-stepping node has access from other nodes, then the other node will also be marked as a honey-stepping node, and the honeyhole program delivery and association analysis process will be repeated on the newly marked honey-stepping node to determine whether the newly marked honey-stepping node has access from other nodes. This process will be repeated until the newly marked honey-stepping node has no access from other nodes. At this time, the other node will be defined as the initial foothold.

[0031] If the first node that delivers the honeyhole program has no access from other nodes, the node that delivers the honeyhole program is marked as the initial foothold;

[0032] The link consisting of all honey-stepping nodes from the first honey-stepping node to which the honeyhole program is delivered to the initial foothold serves as the attack path for this threat hunting.

[0033] In a third aspect, the present invention provides a storage medium storing one or more programs, which implement the above-mentioned internal network threat hunting method when executed by a processor.

[0034] In a fourth aspect, the present invention provides an electronic device, comprising a memory and a processor, wherein:

[0035] The memory is used to store computer programs;

[0036] When the processor is used to execute the computer program stored in the memory, the above-mentioned internal network threat hunting method is implemented.

[0037] Compared with the prior art, the present invention has the following advantages:

[0038] 1. According to the aforementioned internal network threat hunting system, when an attack is underway within a cloud native cluster, a large number of honeybees are deployed within the cloud cluster to detect threat actors entering the cloud. Benign users and system administrators only access / operate on components and files related to their business, not on the honeybees. Threat actors cannot accurately identify and avoid all honeybees. After a threat actor steps on a honeybee, the honeybee records the node where the step occurred. The management component then delivers a honeyhole program to that node. The honeyhole program is used to obtain information about the suspicious node, including system, device, network, and environmental characteristics. The collected information is analyzed and correlated with access logs to determine whether the node was the threat actor's initial access point to the cloud. Specifically, based on the access information, the system analyzes whether the suspicious node is associated with other suspicious nodes. If so, the honeyhole program is delivered to other nodes and the above process is repeated. If not, the node is considered the threat actor's initial foothold. This allows for timely detection and generation of threat hunting attack paths, effectively preventing cloud cluster administrator account compromise.

[0039] 2. The present invention proposes to detect threat actors entering the cloud-native environment through honeybeans when a network threat attack occurs, and use cloud-native cluster management components to deliver a honeyhole program for information collection to suspicious honeybean nodes. The program collects the device information, network information, account information, and service information of the honeybean nodes and transmits it back to the threat hunting system. The threat actor is unaware of this process, and the threat hunting system uses its control over the cluster to complete the real-time capture of the threat before it achieves its attack target. After detecting the threat actor, the present invention collects the most authentic attack scene information through active detection, and associates it with the information recorded in the log system for analysis, restoring the attacker's attack path during detection. Compared with existing cloud security technologies that focus on the security issues of a single node, the present invention can obtain more detailed, accurate, and macro threat intelligence. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 This is a schematic diagram of the structure of an internal network threat hunting system proposed in one embodiment of the present invention;

[0041] Figure 2 This is a schematic diagram of the operation of an internal network threat hunting system according to an embodiment of the present invention.

[0042] The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the invention belongs. The words "including" and similar words used in this article mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects.

[0044] See also Figure 1 One embodiment of the present invention provides an internal network threat hunting system, which is composed of a honeymark, an early warning module, a delivery module, a correlation analysis module, a payload library, etc., wherein:

[0045] The honeybean is deployed on an independent node or business node of the cloud native cluster. When an attacker triggers the honeybean on a node, it records the node information of the honeybean node and sends an early warning message to the early warning module based on the node information.

[0046] In some embodiments, a honeybean is a specific decoy designed to attract an attacker's attention and trick them into attacking, accessing, or manipulating the honeybean. A honeybean can be a standalone node deployed in a Kubernetes cluster, creating a simulated environment that emulates an enterprise's real business systems. This can attract and confuse attackers, making them believe they have entered a legitimate production environment. For example, simulated web servers, database servers, and file servers allow attackers to interact with these applications. Another example is simulating common services and ports, such as HTTP, FTP, SSH, and SQL, to entice attackers to perform port scans or attempt to exploit service vulnerabilities. A honeybean can also be a file, database entry, key, or password deployed on a legitimate business node. For example, a honeybean can be a forged sensitive file containing information about access tools required by system administrators, or a forged VPN configuration file containing the VPN product type and version required to access other devices. When an attacker uses these honeybean files or honeybean credentials, the corresponding parsing module identifies them as honeybeans and triggers the threat hunting system.

[0047] It should also be noted that the content of the warning information and the node information is basically the same. The difference is that the warning information also contains a prompt message that the honey node is attacked. In addition, the warning information also includes the system type, version, architecture, location of the honey node, the network location of the triggered honey, and the attacker's network information.

[0048] In some embodiments, the warning information also includes one or more of the following information, which can help the traceability system deliver the honeyhole program to the honey-stepping node and also help organize and record the scene where the threat was first discovered:

[0049] 1. Network location: Honeybeans are deployed in different locations on the network (such as subnets, DMZs, and internal networks). They record the network location from which the attacker accessed the honeybean. This helps determine whether the attacker entered directly from the outside or moved laterally within the internal network.

[0050] 2. Service or port trigger point: If the honeybean simulates multiple services or opens multiple ports (such as SSH, HTTP, SMB, etc.), the system will record which service or port the attacker accessed. By analyzing the type of service accessed, the attacker's target type or attack motivation can be inferred.

[0051] 3. File or resource trigger points: In file-based honeytokens (such as fake documents or databases), the honeytoken records the path to the specific file or resource accessed by the attacker. This helps understand what sensitive information or resources the attacker is trying to access in the system.

[0052] 4. Trigger location of bait data: If the honeytag contains bait data (such as a fake password or API key), when an attacker accesses or steals this data, the system will record the specific location where the data is triggered

[0053] 5. Attacker network-related content: Attacker's IP address - used to identify the attacker's source; Network traffic - records all communications with the honeybee, including protocol type (such as TCP / UDP), port, traffic size, packet content, and timestamp of the honeybee.

[0054] The early warning module is used to receive early warning information from the honey target. This early warning information includes the system type, version and architecture of the honey node. This information is related to the honeyhole program that will be delivered to the early warning node for operation. The early warning module then informs the delivery module of this information.

[0055] The delivery module is used to retrieve the honeyhole program corresponding to the warning information from the payload library, that is, to retrieve the matching honeyhole program from the payload library according to the system type, version and architecture, and send the location information of the honeyhole program and the honeyhole node to the management component in the cloud native cluster, so that the management component sends the honeyhole program to the honeyhole node according to the location information, and enables the honeyhole node to receive and run the honeyhole program. In some embodiments, the management component of the cloud cluster is used to enable administrators to remotely manage and automate the nodes / instances running in the operation and maintenance cluster; for example, Ansible is an agentless configuration management tool that allows administrators to use playbooks to automate code execution and deployment tasks on remote instances. By connecting to the target instance through SSH, Ansible can push scripts and applications and execute tasks; for another example, SaltStack is a flexible remote execution tool that supports the management of large-scale cloud instances. It can execute commands and scripts in instances by pushing tasks, supports parallel execution, and is suitable for code deployment and management of large-scale cloud clusters.

[0056] The association analysis module is used to receive and analyze the running information returned by the honeyhole program, and generate the attack path of this threat hunting based on the running information. In some embodiments, the association analysis module receives and analyzes the running information returned by the honeyhole program, and based on the log information, historical operation records, cluster log components, gateway history records, etc. of the honeyhole node, finds out whether the honeyhole node has access behavior from other nodes; if so, the node is also marked as a honeyhole node, and the honeyhole program delivery and association analysis process is repeated; if not, the honeyhole node is regarded as the initial foothold of the threat, and the link composed of all honeyhole nodes between the first honeyhole node to which the honeyhole program is delivered and the initial foothold is output as the attack path of this threat hunting. Specifically, the process of generating the attack path of threat hunting is as follows:

[0057] (1) Based on the log information, historical operation records of the honey node, cluster component logs, and gateway history records, find out whether the honey node has access behavior from other nodes;

[0058] (2) If the honey-stepping node has access from other nodes, then the other node is also marked as a honey-stepping node, and the honeyhole program delivery and association analysis process is repeated for the newly marked honey-stepping node to determine whether the newly marked honey-stepping node has access from other nodes. This process is repeated until the newly marked honey-stepping node has no access from other nodes. At this time, the other node is defined as the initial foothold;

[0059] (3) If the first node that delivers the honeyhole program has no access from other nodes, the node that delivers the honeyhole program is marked as the initial foothold;

[0060] (4) The link consisting of all honey-stepping nodes from the first honey-stepping node to which the honeyhole program is delivered to the initial foothold serves as the attack path for this threat hunting.

[0061] The payload library contains various types of honeyhole programs. Honeyhole programs can be executable script files or executable programs. They collect device information, network information, account information, service information, and other content from the attacker's device, such as the device model, MAC address, IP address, operating system information, network environment, device username, related credential storage, installed / started services, running programs, and historical operation records. This information can be used to trace the attack source of suspicious targets. The honeyhole program then transmits this information back to the threat hunting system.

[0062] For example, Figure 2 As shown in the figure, an example of the operation of the internal network threat hunting system for cloud native scenarios is listed, showing how the threat hunting system operates when an attacker triggers the honeymark in the cloud native cluster. This example only focuses on the operation process of the threat hunting system. The implementation details such as the program delivery method of the appropriate k8s cluster and the information content collected by the honeyhole program can be adjusted according to specific needs. Figure 2 In the example above, the threat hunting system operates as follows:

[0063] (1) The attacker triggers the honeypot in Pod1, which transmits container information such as Pod1 being compromised and the x86 Linux operating system installed on Pod1 to the threat hunting system;

[0064] (2) The threat hunting system (delivery module) prepares the corresponding x86 architecture-ELF format honeyhole program and informs the cluster management component of the location of the honeyhole program and the honey node Pod1. The cluster management component informs the kubelet component of the honey node Pod1 through kubectl, so that it receives and runs the honeyhole program from the threat hunting system;

[0065] (3) The honeyhole program runs on the node Pod1, collects information such as the programs running on Pod1, real-time system logs and application logs, and historical operation records, and transmits them back to the correlation analysis module;

[0066] (4) When analyzing the returned information, the correlation analysis module found that the SSH log of the Pod1 node showed that the current user's access connection came from the node Pod6, and the connection request from Pod6 to Pod1 was also found in the records of the cluster log component; therefore, Pod6 was marked as a node that stepped on the honeypot, and the warning module was notified;

[0067] (5) The early warning module checks the operating system installed on Pod6 and finds that it is a Windows system with x86 architecture. Therefore, a Powershell script file is delivered and run as a honeyhole program using a method similar to step 2.

[0068] (6) The Powershell script delivered to the Pod6 node runs and collects information such as the programs running on Pod6, real-time system logs and application logs, and historical operation records, and transmits it back to the correlation analysis module;

[0069] (7) The correlation analysis module did not find any other remote access behaviors from internal nodes in the returned logs. At the same time, it found that the access to Pod6 in the cluster's API gateway used VPN, that is, this access came from outside the cluster. Therefore, Pod6 was regarded as the initial foothold for network threats to enter the cluster; Pod6→Pod1 and related information were output as the attack path.

[0070] In summary, the aforementioned internal network threat hunting system, specifically designed for insider threat hunting in cloud-native scenarios, deploys a large number of honeybees within a cloud cluster to detect threat actors entering the cloud. Benign users and system administrators only access and operate components and files related to their business, not the honeybees. Threat actors cannot accurately identify and avoid all honeybees. After a threat actor steps on a honeybee, the honeybee records the node where the step occurred. The management component then delivers a honeyhole program to that node. The honeyhole program captures information about the suspicious node, including system, device, network, and environmental characteristics. This collected information is analyzed and correlated with access logs to determine whether the node was the threat actor's initial access point to the cloud. Specifically, based on the access information, the system analyzes whether the suspicious node is associated with other suspicious nodes. If so, the honeyhole program is delivered to other nodes, and the process repeats. If not, the node is considered the threat actor's initial foothold. This allows for timely detection and generation of attack paths for threat hunting, effectively preventing cloud cluster administrator account compromise.

[0071] An embodiment of the present invention further provides an internal network threat hunting method, which is applied to a cloud native cluster and includes:

[0072] When an attacker triggers a honeymark on a node, the node information of the node that triggered the honeymark is recorded, and an early warning message is sent based on the node information;

[0073] Forward warning information;

[0074] Retrieving the honeyhole program corresponding to the warning information from the payload library, and sending the honeyhole program and the location information of the honeyhole node to the management component in the cloud native cluster, so that the management component sends the honeyhole program to the honeyhole node according to the location information, and the honeyhole node receives and runs the honeyhole program. The payload library stores multiple honeyhole programs.

[0075] Receive and analyze the running information returned by the honeyhole program, and generate the attack path for this threat hunting based on the running information.

[0076] Furthermore, in some optional embodiments, the step of receiving and analyzing the operation information returned by the honeyhole program, and generating the attack path for this threat hunting according to the operation information includes:

[0077] Based on the log information, historical operation records, cluster component logs, and gateway history of the honey node, check whether the honey node has been accessed by other nodes.

[0078] If the honey-stepping node has access from other nodes, then the other node will also be marked as a honey-stepping node, and the honeyhole program delivery and association analysis process will be repeated on the newly marked honey-stepping node to determine whether the newly marked honey-stepping node has access from other nodes. This process will be repeated until the newly marked honey-stepping node has no access from other nodes. At this time, the other node will be defined as the initial foothold.

[0079] If the first node that delivers the honeyhole program has no access from other nodes, the node that delivers the honeyhole program is marked as the initial foothold;

[0080] The link consisting of all honey-stepping nodes from the first honey-stepping node to which the honeyhole program is delivered to the initial foothold serves as the attack path for this threat hunting.

[0081] Another aspect of the present invention further provides a storage medium having one or more programs stored thereon, which implement the above-mentioned internal network threat hunting method when executed by a processor.

[0082] On the other hand, the present invention further provides an electronic device, comprising a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory to implement the above-mentioned internal network threat hunting method.

[0083] Those skilled in the art will appreciate that the logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device), or in conjunction with such instruction execution system, apparatus, or device. For purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by an instruction execution system, apparatus, or device, or in conjunction with such instruction execution system, apparatus, or device.

[0084] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0085] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement the hardware: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0086] While the embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations of these embodiments are possible. However, it should be understood that such modifications and variations are within the scope and spirit of the present invention as set forth in the claims. Furthermore, the invention described herein is susceptible to other embodiments and may be practiced or implemented in a variety of ways.

Claims

1. An internal network threat hunting system, applied to cloud native clusters, characterized by: The system comprises: Honeytags are deployed on independent nodes or business nodes in the cloud native cluster. When an attacker triggers a honeytag on a node, they record the node information of the attacker and send an early warning message to the early warning module based on the node information. The early warning module is used to forward the early warning information to the delivery module; The delivery module is used to retrieve the honeyhole program corresponding to the warning information from the payload library and send the honeyhole program and the location information of the honeyhole node to the management component in the cloud native cluster. The management component sends the honeyhole program to the honeyhole node based on the location information, and the honeyhole node receives and runs the honeyhole program. The association analysis module is used to receive and analyze the operation information returned by the honeyhole program, and generate the attack path of this threat hunting based on the operation information; the association analysis module is also used to: based on the log information of the honeyhole node, historical operation records, cluster component logs, and gateway history records, find whether the honeyhole node has been accessed by other nodes; If the honey-stepping node has access from other nodes, then the other node will also be marked as a honey-stepping node, and the honeyhole program delivery and association analysis process will be repeated on the newly marked honey-stepping node to determine whether the newly marked honey-stepping node has access from other nodes. This process will be repeated until the newly marked honey-stepping node has no access from other nodes. At this time, the other node will be defined as the initial foothold. If the first node that delivers the honeyhole program has no access from other nodes, the node that delivers the honeyhole program is marked as the initial foothold; The chain of all honey-stepping nodes from the first honey-stepping node to the initial foothold serves as the attack path for this threat hunting. The payload library is used to store various honeyhole programs.

2. The internal network threat hunting system according to claim 1, characterized in that The warning information includes the system type, version, architecture, location of the honey node, the network location of the triggered honey, and the attacker's network information.

3. The internal network threat hunting system according to claim 2, characterized in that: The honeymark is a simulated web server, database server, file server, or a simulated service and port, or a file, database entry, key, password deployed on a normal business node, or a forged VPN configuration file; When the honeybean simulates multiple services or opens multiple ports, the warning information also includes the services or ports accessed by the attacker; When the honeytoken is a file-type honeytoken, the warning information further includes the path of the specific file or resource accessed by the attacker.

4. The internal network threat hunting system according to claim 2, characterized in that: The delivery module is used to retrieve the matching honeyhole program from the payload library according to the system type, version and architecture.

5. The internal network threat hunting system according to claim 3, characterized in that: The operation information includes the log information of the honey node, historical operation records, cluster component logs, and gateway history records.

6. An internal network threat hunting method, applied to a cloud native cluster, characterized in that: The method comprises: When an attacker triggers a honeymark on a node, the node information of the node that triggered the honeymark is recorded, and an early warning message is sent based on the node information; Forwarding warning information; Retrieving the honeyhole program corresponding to the warning information from the payload library, and sending the honeyhole program and the location information of the honeyhole node to the management component in the cloud native cluster, so that the management component sends the honeyhole program to the honeyhole node according to the location information, and the honeyhole node receives and runs the honeyhole program. The payload library stores multiple honeyhole programs. Receive and analyze the running information returned by the honeyhole program, and generate the attack path of this threat hunting based on the running information, including: according to the log information, historical operation records, cluster component logs, and gateway history records of the honeyhole node, find out whether the honeyhole node has access behavior from other nodes; if the honeyhole node has access behavior from other nodes, then the other node is also marked as a honeyhole node, and the honeyhole program delivery and association analysis process is repeated on the newly marked honeyhole node to determine whether the newly marked honeyhole node has access behavior from other nodes, and repeat it until the newly marked honeyhole node has no access from other nodes, at which time the other node is defined as the initial foothold; if the first honeyhole node to which the honeyhole program is delivered has no access behavior from other nodes, then the node to which the honeyhole program is first delivered is marked as the initial foothold; the link composed of all honeyhole nodes between the first honeyhole node to which the honeyhole program is delivered and the initial foothold is used as the attack path of this threat hunting.

7. A storage medium, characterized in that: The storage medium stores one or more programs, which, when executed by a processor, implement the internal network threat hunting method according to claim 6.

8. An electronic device comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor is used to execute the computer program stored in the memory, it implements the internal network threat hunting method according to claim 6.