Honey spot anti-aging method and system based on digital twin
By building a digital twin model and dynamically deploying honeypots, combined with SDN technology, the flexibility and adaptability issues of network security systems in the face of rapidly changing environments and complex attacks are solved, automated management and efficient defense are achieved, and the intelligence level of network security is improved.
Patent Information
- Application Number
- CN202411270155.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-11
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-09-11
AI Technical Summary
Existing network security technologies lack flexibility and adaptability when faced with rapidly changing network environments and new and complex attack methods, resulting in cumbersome maintenance processes and the easy introduction of new security vulnerabilities, inefficient resource utilization, and difficulty in achieving continuous and efficient defense.
By collecting historical raw data from the network and devices, building and training the initial digital twin model, generating and deploying honey spots, analyzing network traffic and user behavior in real time, dynamically adjusting the honey spot configuration to cope with aging, and using SDN technology to achieve centralized control and automated management of network resources, reducing manual intervention.
It has improved the flexibility and adaptability of the network security system, reduced maintenance complexity, and can automatically detect and respond to new threats, thereby improving resource utilization efficiency and overall defense capabilities, ensuring continuous and efficient protection.
Smart Images

Figure CN119402216B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a honey spot anti-aging method and system based on digital twins. Background Art
[0002] As security threats continue to evolve and become more complex, security teams must develop new defense systems and solutions to protect cyber assets. This requires security systems to be more intelligent and flexible to effectively identify and defend against emerging attacks. This need is particularly pressing in digital twin systems, as these systems rely on the continuous collection and analysis of large amounts of real-time data from their physical counterparts, including sensitive operational information and personal data. Without appropriate encryption and protection measures during transmission or storage, this data is at risk of unauthorized access or leakage, potentially leading to serious consequences. Furthermore, digital twin systems consist of multiple interconnected components and services, and each expansion of the system can introduce new security vulnerabilities. For example, flaws in interface or API design or configuration can become potential attack vectors. Therefore, ensuring the security of digital twin systems requires a series of maintenance measures, such as regular technical updates, system testing, and security audits. While these measures are crucial for maintaining system security, they can also introduce new vulnerabilities or expose existing risks during implementation. Technical updates may involve software patches, system upgrades, or hardware replacements to address known vulnerabilities, improve system performance, or add new functionality.
[0003] However, existing network security measures mainly rely on static protection mechanisms and manual maintenance, which are difficult to adapt to the rapidly changing network environment and new and complex attack methods. At the same time, since manual intervention is required for system updates and configuration management, the process is cumbersome and prone to operational errors, resulting in low resource utilization and new security vulnerabilities, making it difficult to achieve continuous and efficient defense. Summary of the Invention
[0004] The purpose of the present invention is to provide a honey spot anti-aging method and system based on digital twins, aiming to solve the problem that due to the static nature and lack of flexibility of traditional network security technology, it is difficult to adapt to the rapidly changing network environment and new and complex attack methods. At the same time, the maintenance and update process is cumbersome and prone to introduce new security vulnerabilities, resource utilization efficiency is low, and it is difficult to achieve continuous and efficient defense.
[0005] In a first aspect, the present invention provides a sweet spot anti-aging method based on digital twins, the method comprising:
[0006] Collecting historical raw data of the target network and devices, the historical raw data including at least one of network traffic data, system and application logs, device status information, and user behavior data;
[0007] Constructing an initial digital twin model, and training the initial virtual model based on the historical original data to obtain a trained digital twin model;
[0008] Obtaining current raw data of the target network and device, and inputting the current raw data into the current raw data to output an event analysis result corresponding to the current raw data, and generating and deploying a honey spot according to the event analysis result corresponding to the current raw data;
[0009] Determine whether the deployed honey spots meet the preset conditions for aging honey spots;
[0010] If the preset conditions of the aging honey spot are met, the anti-aging operation is performed on the aging honey spot.
[0011] Furthermore, after the step of collecting historical raw data of the target network and device, the step further includes:
[0012] Denoising and formatting the historical original data in sequence to obtain formatted historical original data;
[0013] Extract key fields from the formatted historical raw data, including timestamp, user name, IP address, and event description;
[0014] The historical original data is analyzed according to the key fields to obtain event analysis results.
[0015] Furthermore, the steps of constructing an initial digital twin model and training the initial virtual model according to the historical original data to obtain a trained digital twin model include:
[0016] The event description is annotated according to the event analysis result, and a data set is constructed according to the annotated result. The initial digital twin model is trained according to the data set to obtain a trained digital twin model.
[0017] Furthermore, the steps of obtaining current raw data of the target network and device, inputting the current raw data into the current raw data to output an event analysis result corresponding to the current raw data, and generating and deploying a honey spot according to the event analysis result corresponding to the current raw data include:
[0018] Obtain network traffic patterns, user behavior patterns, and attack pattern characteristics based on the event analysis results;
[0019] Identifying suspicious traffic based on the network traffic pattern, generating a honey spot corresponding to the suspicious traffic, and deploying the honey spot corresponding to the suspicious traffic at a location close to a target of the suspicious traffic;
[0020] Identifying abnormal users with abnormal behavior based on the user behavior pattern, and deploying honey spots near the systems or resources that the abnormal users attempt to access;
[0021] Generate corresponding honey spots according to the attack pattern characteristics, and deploy the honey spots corresponding to the attack pattern characteristics in areas that the attacker is concerned about.
[0022] Furthermore, the preset conditions include that the service corresponding to the original sweet spot is modified, or the difference in attack frequency of the sweet spot in adjacent monitoring cycles is less than a first preset threshold, or the difference in attack frequency of the sweet spot in adjacent monitoring cycles is greater than a second preset threshold.
[0023] Furthermore, if the preset conditions of the aging sweet spot are met, the step of performing an anti-aging operation on the aging sweet spot includes:
[0024] If the deployed honey point meets the service modification requirement, the service image with the same version as the current digital twin model is searched and downloaded to the local server. The service image is modified using a script, and a new honey point is generated using the bu ild instruction. The new honey point is stored in the honey point warehouse, and the new honey point is called from the honey point warehouse for deployment.
[0025] Furthermore, if the preset conditions of the aging sweet spot are met, the step of performing an anti-aging operation on the aging sweet spot includes:
[0026] If the attack frequency of the deployed honey spot is significantly reduced, the honey spot is deleted and the same service image is re-called from the honey spot warehouse as a new honey spot for replenishment;
[0027] If the frequency of attacking and being attacked at the honey spot after deployment increases significantly, the service of the honey spot is modified every first preset time.
[0028] In a second aspect, the present invention provides a sweet spot anti-aging system based on digital twins, the system comprising:
[0029] A data collection module is used to collect historical raw data of the target network and devices, wherein the historical raw data includes at least one of network traffic data, system and application logs, device status information, and user behavior data;
[0030] A model building module is used to build an initial digital twin model and train the initial virtual model based on the historical original data to obtain a trained digital twin model;
[0031] a honeyspot deployment module, configured to obtain current raw data of target networks and devices, input the current raw data into current raw data, output event analysis results corresponding to the current raw data, and generate and deploy honeyspots based on the event analysis results corresponding to the current raw data;
[0032] Aging honey spot detection module, used to determine whether the deployed honey spots meet the preset conditions for aging honey spots;
[0033] The anti-aging operation execution module is used to execute the anti-aging operation on the aging sweet spot if the preset conditions of the aging sweet spot are met.
[0034] In a third aspect, the present invention provides a readable storage medium, which stores one or more programs, and when the program is executed by a processor, it implements the above-mentioned digital twin-based honey spot anti-aging method.
[0035] In a fourth aspect, the present invention provides a computer device, comprising a memory and a processor, wherein:
[0036] The memory is used to store computer programs;
[0037] When the processor is used to execute the computer program stored in the memory, the above-mentioned digital twin-based honey spot anti-aging method is implemented.
[0038] In summary, the embodiments of the present invention significantly improve the flexibility, adaptability, and resource utilization efficiency of network security systems by combining deception defense theory, Docker technology, and SDN technologies, while reducing maintenance complexity and achieving intelligent defense against advanced persistent threats. The embodiments of the present invention have high innovation and practical value. The beneficial effects of the embodiments of the present invention include:
[0039] 1. The embodiments of the present invention can automatically adjust and optimize defense strategies. This dynamic adaptive capability enables the system to not only respond to currently known threats, but also predict and prevent potential risks that are about to emerge. In addition, the honey spot anti-aging method in the embodiments of the present invention does not require frequent manual intervention and can continuously learn and adapt to new attack patterns, thereby ensuring continuous and efficient protection in the face of unknown and ever-changing attacks. In addition, through this adaptive mechanism, the system can also better manage and allocate security resources, ensuring a rapid response when needed, thereby significantly improving the security and stability of the entire network.
[0040] 2. In traditional network security frameworks, system maintenance often involves complex manual processes such as regular software updates, patching, and configuration management. These processes are not only time-consuming but also prone to introducing new security vulnerabilities due to human error. The honeyspot anti-aging method of the present invention utilizes an automated update and configuration management mechanism that enables the system to automatically detect new security vulnerabilities and necessary system upgrades, and automatically apply the corresponding patches and updates without manual intervention.
[0041] 3. The present invention adopts digital twin technology to create and maintain dynamic virtual images (digital twin models), which can reflect the status of the physical network environment in real time. This makes the system more flexible than traditional static security measures and can better adapt to changes in the network environment and new attack methods, thereby improving overall defense capabilities.
[0042] 4. The present invention realizes the centralized control and automated management of network resources by utilizing SDN technology, which reduces the need for manual intervention, reduces the complexity of system maintenance, and reduces the risk of manual operation errors. At the same time, the honey spot anti-aging method of the present invention generates and deploys honey spots based on real-time data, avoiding the waste of resources and identification risks caused by the long-term static existence of traditional honey spots. By dynamically generating and adjusting the configuration of honey spots, the system can more efficiently utilize network resources and ensure continuous and efficient security protection. In addition, by collecting and analyzing various data in the network environment, accurate real-time intelligence is provided to the system. Combined with the anti-aging technology of honey spots, the system can quickly respond to potential threats, automatically generate and deploy honey spots, and achieve effective defense against unknown threats.
[0043] 5. This invention dynamically adjusts the configuration and deployment strategies of sweet spots, maintaining their effectiveness and freshness. This enables the system to intelligently respond to advanced persistent threats and other complex attacks, enhancing the overall intelligence level of security protection. By utilizing a sweet spot repository and automated generation technology, this invention can also create complex entrapment environments to attract and capture attacker behavior, reducing the risk exposure of real assets. It also provides security teams with detailed attack behavior data, helping to improve defense strategies and enhance threat detection capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 This is a flow chart of a sweet spot anti-aging method based on digital twins proposed in one embodiment of the present invention;
[0045] Figure 2 This is a structural diagram of a sweet spot anti-aging system based on digital twins proposed in one embodiment of the present invention.
[0046] The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the invention belongs. The words "including" and similar words used in this article mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects.
[0048] The term "digital twin" refers to an advanced simulation technology that creates a virtual model of a physical object, process, or system to mimic its real-world counterpart. This virtual model integrates real-time and historical data from its physical twin, allowing users to test, analyze, and predict in a safe virtual environment, thereby optimizing operations, improving efficiency, predicting maintenance needs, and enhancing understanding of real-world systems. Digital twins are widely used in a variety of fields, including manufacturing, construction, healthcare, and urban planning, providing decision makers with a powerful tool to monitor, maintain, and improve the performance of systems or products in real time, efficiently, and accurately.
[0049] The technical term "deception defense" refers to an advanced network security strategy that creates decoys (such as honeypots, virtual services, fake files, etc.) to deceive and lure attackers into a controlled environment rather than actual system resources. This approach actively tricks attackers into revealing their behavioral patterns and attack techniques, allowing security teams to monitor, analyze, and understand attacker behavior and gather critical security intelligence without compromising the primary system. By establishing these seemingly vulnerable but closely monitored resources, deception defense not only reduces the risk exposure of real assets but also provides real-time data for counterattack strategies, improving the intelligence and responsiveness of the overall security architecture. Through this strategy, organizations can more proactively defend against complex threats such as APTs and insider threats, enhancing the proactiveness and adaptability of their security posture.
[0050] The technical term "SDN" refers to an innovative network architecture that separates the network control layer from traditional physical devices and centralizes control functions into a central control point: the SDN controller. This design allows network administrators to dynamically configure, manage, and optimize network resources through software applications without directly intervening in hardware devices, thereby increasing network flexibility and programmability. SDN significantly simplifies network design and operation, enabling more flexible traffic management and efficient data flow, while also providing strong technical support for network virtualization and automation. Through centralized control and automated network management, SDN helps better address rapidly changing network demands and complex network security challenges.
[0051] The technical term "honeypot" refers to a security mechanism that sets up seemingly attractive, but actually controlled and monitored, network or system resources with the goal of luring and analyzing unauthorized or malicious network behavior. As a proactive defense tool, honeypots are designed in various forms, such as simulating vulnerable operating systems, databases, websites, or other network services to attract hackers or automated malware. Honeypots appear to be valuable targets to attackers, but are actually isolated and contain no production data, unknowingly exposing attackers' attack techniques and strategies. In this way, honeypots help security teams gather detailed information on attack sources, methods, and behaviors, thereby improving security measures, enhancing threat detection capabilities, and optimizing response strategies. Honeypots provide a risk-free environment for studying new and unknown threats and are an indispensable tool in cybersecurity practices.
[0052] Honeypots can be categorized into three types based on the level of interaction with attackers: low-interaction, medium-interaction, and high-interaction. Each type has its own unique characteristics and uses:
[0053] 1. Low-interaction honeypot
[0054] Low-interaction honeypots are simple in design and primarily used to simulate vulnerable network services or ports, such as open FTP, Telnet, or Web services. These honeypots are designed to attract attackers and collect basic attack information, such as attack type, source, and tools used. Low-interaction honeypots typically do not run actual operating systems or applications, but instead use network monitoring and logging capabilities to track attacker activity. This allows for efficient recording of attack activity while maintaining low system complexity and high efficiency.
[0055] 2. Medium-interaction honeypot
[0056] Medium-interaction honeypots offer more complex interaction capabilities, typically simulating a complete operating system and various application environments to attract attackers to conduct in-depth probing and attack activities. These honeypots are equipped with a variety of services and resources that attackers may target, such as email servers, databases, or file sharing systems. Compared to low-interaction honeypots, medium-interaction honeypots can provide richer information, revealing attackers' intentions and strategies in greater detail, effectively inducing and recording complex attack behaviors.
[0057] 3. High-interaction honeypot
[0058] High-interaction honeypots represent the most complex and realistic form of honeypot technology, completely recreating a real operating environment, including a fully functional operating system, applications, and data. These honeypots provide users with an experience that closely resembles a live environment, making it difficult for attackers to distinguish between them and the real system. Within such honeypots, attackers can conduct full attack campaigns, including penetration testing, exploiting security vulnerabilities, and stealing data. Because high-interaction honeypots provide extremely detailed attack data and behavioral analysis, they are considered invaluable network security tools.
[0059] See also Figure 1 , which is a flow chart of a sweet spot anti-aging method based on digital twins provided by an embodiment of the present invention, includes steps S101 to S105, wherein:
[0060] Step S101: Collecting historical raw data of the target network and device, wherein the historical raw data includes at least one of network traffic data, system and application logs, device status information, and user behavior data;
[0061] It should be noted that this historical raw data is key real-time data collected from various network environments and devices. This data includes, but is not limited to, network traffic data, system and application logs, device status information, and user behavior data. For example, application logs may include the operating status and events of software such as the operating system and applications. For example, the system log of a Linux server records a user login: Aug 10 12:34:56 myserver sshd
[12345] : Accepted password for user1 from 192.168.1.101 port 34567 ssh2. This records that user user1 successfully logged into the server via SSH from IP address 192.168.1.101 at 12:34:56.
[0062] Specifically, data collection is performed using advanced monitoring tools and sensor technology to ensure comprehensiveness and accuracy. The collected data undergoes preprocessing, such as noise removal and formatting, to produce formatted historical raw data. Key fields are extracted from this formatted historical raw data, including timestamps, usernames, IP addresses, and event descriptions. The historical raw data is then analyzed based on these key fields to produce event analysis results.
[0063] For example, the collected historical raw data is: Aug 10 12:34:56 myserver sshd
[12345] : Accepted password for user1 from 192.168.1.101 port 34567 ssh2
[0064] Aug 10 12:34:57myserver kerne l:[123.456]Debug:System check comp lete
[0065] Aug 10 12:34:58myserver sshd
[12345] :Accepted password for user1from192.168.1.101port 34567ssh2
[0066] We can see that a debug log is inserted between the two login events. We can delete it during the denoising process and only keep the key login events.
[0067] The purpose of formatting is to standardize log data and make it more consistent in structure for easier analysis. For example, you can extract key fields from the original data, such as timestamps, usernames, IP addresses, etc., and convert them into structured data. For example:
[0068]
[0069] After formatting, log entries are parsed into structured JSON format, and all key information is extracted as independent fields for subsequent analysis and query.
[0070] The accurate collection and effective management of this data are key to ensuring that the entire network security system can accurately reflect the network status and effectively respond to security threats.
[0071] Step S102: constructing an initial digital twin model, and training the initial virtual model according to the historical original data to obtain a trained digital twin model;
[0072] In this step, a base model corresponding to the physical entity is first created in the virtual environment. Initially, this base model is a simple virtualized replica, similar to a static snapshot of the physical network. This initial digital twin model is then continuously updated using collected data to ensure it accurately reflects the current state of the physical network environment. Over time, more historical raw data is continuously fed into the digital twin model.
[0073] Specifically, the event description is annotated according to the event analysis result, and a data set is constructed according to the annotation result, and the initial digital twin model is trained according to the data set to obtain a trained digital twin model.
[0074] For example, a sensor's temperature readings might be rising, indicating a potential overheating issue. This data is then integrated into a virtual model (digital twin) to update the device's status. This highly synchronized data replication allows the module to simulate and analyze potential security threats in a secure virtual environment, predict the potential impact of an attack, and test different defense strategies without risking the actual network.
[0075] In addition, digital twin models support complex data analysis and machine learning algorithms, which can provide an in-depth understanding of network behavior and anomalies, thereby identifying and responding to potential security incidents in advance, greatly enhancing the system's prevention and response capabilities.
[0076] For example, an event description might read: The temperature of controller A has gradually risen from 70°C to 90°C over the past hour (normal temperature should be below 60°C). Sensor data is transmitted to the digital twin module in real time, updating the virtual model's status of controller A to "high temperature warning." Malicious traffic from IP address 192.168.1.50 initiates a large number of login attempts to controller B. This anomalous behavior is recorded and analyzed, resulting in an event analysis result of "attacked." Therefore, the virtual model marks controller B's network status as "attacked."
[0077] In some embodiments, after obtaining the trained digital twin model, in order to achieve continuous optimization of the trained digital twin model, data generated in real time by the target network and device will be collected every second preset time. This data also includes but is not limited to network traffic data, system and application logs, device status information, and user behavior data. These data are then processed according to the preprocessing method of historical original data, and then input into the trained digital twin model for iterative update, thereby completing the fine-tuning optimization of the digital twin model. It should be noted that the purpose of setting the second preset time is to be able to continuously collect training data, and then continuously update the digital twin model over time to further improve the model's ability to recognize abnormal behavior.
[0078] Step S103: obtaining current raw data of the target network and device, and inputting the current raw data into the current raw data to output an event analysis result corresponding to the current raw data, and generating and deploying a honey spot according to the event analysis result corresponding to the current raw data;
[0079] It should be noted that during the honeyspot deployment process, the event analysis results also include the following three key characteristics:
[0080] Network traffic patterns: Analyze information including the source, target, protocol type, and traffic magnitude of the traffic. By observing normal traffic patterns in the network, identify which traffic sources may represent potential threats (such as a certain IP frequently accessing multiple different ports). At the same time, analyze whether there is abnormal traffic in the network, such as a surge in traffic in a short period of time or abnormal access frequency of certain IP addresses. Determine which traffic is suspicious or potentially malicious, and mark possible attack paths. For suspicious traffic, you can generate honey spots suitable for inducing the traffic (such as simulating vulnerable web servers). During deployment, the honey spot can be placed in a location close to the target of the suspicious traffic to increase the attacker's chance of contacting the honey spot.
[0081] User behavior patterns: Analyze information including user login behavior, access frequency, and operation types. This analyzes normal user behavior (e.g., typical login times, frequently used devices, etc.) and identifies operations that do not conform to normal behavior patterns (e.g., logins at unusual times, frequent failed login attempts, etc.). This ultimately identifies possible internal threats or signs of external attackers impersonating users. For abnormal user behavior, honeypots can be deployed near systems or resources these users may attempt to access, such as by tricking attackers into entering fake databases or file systems, and their operational behavior can be recorded.
[0082] Attack pattern characteristics: This system extracts characteristics of known attack behaviors (such as SQL injection and brute force cracking) as well as historical attack records to analyze attack behavior data in the digital twin model, identifying activities that match known attack characteristics (such as frequent failed login attempts and abnormal access to specific ports). Based on the identified attack patterns, it generates highly targeted honey spots (such as a fake database honey spot for SQL injection attacks) and deploys them in areas that attackers may target.
[0083] Step S104: determining whether the deployed honey spot meets the preset conditions of the aging honey spot;
[0084] It should be pointed out that, in some embodiments, the preset conditions include that the service corresponding to the original sweet spot is modified (the service is modified), or the difference in attack frequency of the sweet spot in adjacent monitoring periods is less than a first preset threshold (the attack frequency is significantly reduced), or the difference in attack frequency of the sweet spot in adjacent monitoring periods is greater than a second preset threshold (the attack frequency is significantly increased). In other words, as long as the honey spot after deployment meets one of the preset conditions, the honey spot is considered to be an aging sweet spot. Conversely, if the honey spot after deployment does not meet any of the three preset conditions, the honey spot is considered not to be an aging sweet spot.
[0085] Step S105: If the preset conditions of the aging sweet spot are met, an anti-aging operation is performed on the aging sweet spot.
[0086] It should be noted that in the actual process of detecting honey spots, different anti-aging operations will be performed according to the preset conditions of different aging honey spots, as follows:
[0087] 1. For honey points whose corresponding digital twin modules have changed, if the old honey point is no longer applicable to the new service, the old honey point needs to be deleted. At the same time, a Python script is used to search for a service image from Dockerhub that is the same version as the latest digital twin model and download it to the local server. The script is then used to modify the image so that it can become a honey point. Finally, a new honey point is generated using the build command and stored in the honey point warehouse. The honey point can then be directly called from the warehouse for deployment. For example, in the digital twin model, a database honey point was originally deployed near a database. However, after the real system is modified, the virtual database in the digital twin also needs to be deleted. At this time, the original database honey point will be judged to be no longer valid, and the system will delete it and add a new honey point.
[0088] 2. For honeypots whose attack frequency has significantly decreased recently, the system will determine that they have been compromised and are no longer useful for reconnaissance. The system will then delete the honeypot and re-use the same service image from the honeypot repository as a new honeypot. For example, an enterprise network has deployed multiple honeypots to trap and analyze attackers. The system continuously monitors the attack logs and activity of all honeypots and discovers that the attack frequency of a particular honeypot has significantly decreased over the past few weeks. For example, there used to be dozens of attack attempts per day, but now there are only a few sporadic attempts. The system will analyze the attack logs of the honeypot to determine whether the decrease in attack frequency is normal (such as during holidays or during the attacker's activity cycle) or an anomaly (perhaps indicating that the honeypot has been compromised). If the decrease is sustained and accompanied by signs of attackers attempting to circumvent the honeypot (such as attempts to access specific interfaces on the honeypot), it can be preliminarily determined that the honeypot has been compromised. The system will then disconnect the honeypot from the network, stop its services, and clear any related configurations. For example, a fake database service or a disguised server may be shut down. The system will select an identical service image from the honeypot repository and configure a new honeypot as needed, such as setting up a new fake database structure or updating the disguised server configuration.
[0089] 3. For hotspots experiencing a significant increase in attack frequency, the system will regularly modify the hotspot's services to provide different responses to attackers during different time periods, slowing down the attacker's detection. For example, a corporate network may deploy multiple hotspots to trap and analyze attackers. Recently, certain hotspots have experienced frequent attacks, necessitating regular modifications to their services to slow down the attacker's detection. For example, the system can regularly update the data in a fake database. For example, fake product information, prices, or user data can be changed weekly or daily. This variation can confuse attackers, making it difficult for them to determine the authenticity of the data. Alternatively, the hotspot's service configuration can be regularly modified. For example, the simulated device status of the hotspot can be adjusted to display different temperatures, vibrations, or operating parameters.
[0090] It should also be noted that to automatically and continuously detect the aging of deployed sweetspots, they must be deployed accordingly after they are created. Typically, aging sweetspots are deleted and replaced with new ones. However, for networks frequently attacked, to prevent the rapid aging of sweetspots, more sweetspots are automatically assigned to the network segment, thereby slowing the aging of individual sweetspots. After deployment is complete, the system continues to collect and analyze sweetspot logs, reassessing whether a sweetspot has aged, and then re-enters a cycle of creating new, unaged sweetspots.
[0091] In addition, in some optional embodiments, after the de-aging operation is completed, the SDN controller is initialized and the network management and control functions are started. Subsequently, data from the digital twin model and the sweet spot de-aging operation is received, including device status information, network traffic data, system logs, and sweet spot information. This data will be transmitted to the SDN controller for parsing. The system will then analyze the input traffic and use the parsed data to identify potential threats and traffic characteristics that need to be directed to the sweet spot. Based on the traffic analysis results, the SDN controller dynamically adjusts the network configuration, redirects potential attack traffic to the corresponding sweet spot, and ensures that the traffic is effectively captured by modifying traffic routing rules and adjusting access control policies.
[0092] For example, high-frequency requests, abnormal data packet content, etc. Potential attackers or malicious traffic are identified based on traffic characteristics. Normal request traffic does not need to be redirected to the honeypot, but identified abnormal traffic will be redirected to the honeypot.
[0093] Traffic routing rules, for example, redirecting traffic with source IP 192.168.1.10 to the honeypot 192.168.1.100, can be set using the flow table rules of the SDN controller. The flow table is updated in the SDN controller to indicate that traffic needs to be directed to the honeypot. Rules may include matching specific traffic characteristics (such as IP address, port number) and forwarding them to the honeypot. For example: if (src_ip == 192.168.1.10 and dest_port == 80) then redi rect to 192.168.1.100;
[0094] For access control policies, for example, you can set up whitelists to filter and redirect traffic. For firewall rules, you can configure rules to allow traffic from specific IP addresses into the honeypot while blocking all other traffic: Allow src_ip 192.168.1.10, dest_ip 192.168.1.100, protocol TCP; Deny src_ip 10.0.0.0 / 8.
[0095] Furthermore, by re-directing the deployment and configuration of sweet spots based on real-time analysis, the system ensures that they are always in optimal capture locations, preventing attackers from identifying them. Finally, the system continuously monitors sweet spots and network traffic, collects attacker behavior data, and uses this data to optimize sweet spot configuration and traffic control strategies, forming an adaptive and dynamic defense mechanism to enhance network security.
[0096] In summary, by using SDN controllers and monitoring tools to analyze network traffic in real time, we can understand the attacker's range of activity, attack patterns, targets, and the distribution of network traffic across various areas. Based on these real-time analysis results, we can identify traffic hotspots within the network, such as those with high inbound traffic or frequent attack attempts. We can also determine possible attack paths, such as those that could access sensitive services or bypass defense zones.
[0097] Deploy honeypots to traffic hotspots or potential attack paths. For example, if analysis shows that attackers are concentrated in a certain subnet, deploy honeypots within that subnet.
[0098] In summary, the above-mentioned honey spot anti-aging method based on digital twins has the following advantages:
[0099] 1. The embodiments of the present invention can automatically adjust and optimize defense strategies. This dynamic adaptive capability enables the system to not only respond to currently known threats, but also predict and prevent potential risks that are about to emerge. In addition, the honey spot anti-aging method in the embodiments of the present invention does not require frequent manual intervention and can continuously learn and adapt to new attack patterns, thereby ensuring continuous and efficient protection in the face of unknown and ever-changing attacks. In addition, through this adaptive mechanism, the system can also better manage and allocate security resources, ensuring a rapid response when needed, thereby significantly improving the security and stability of the entire network.
[0100] 2. In traditional network security frameworks, system maintenance often involves complex manual processes such as regular software updates, patching, and configuration management. These processes are not only time-consuming but also prone to introducing new security vulnerabilities due to human error. The honeyspot anti-aging method of the present invention utilizes an automated update and configuration management mechanism that enables the system to automatically detect new security vulnerabilities and necessary system upgrades, and automatically apply the corresponding patches and updates without manual intervention.
[0101] 3. The present invention adopts digital twin technology to create and maintain dynamic virtual images (digital twin models), which can reflect the status of the physical network environment in real time. This makes the system more flexible than traditional static security measures and can better adapt to changes in the network environment and new attack methods, thereby improving overall defense capabilities.
[0102] 4. The present invention realizes the centralized control and automated management of network resources by utilizing SDN technology, which reduces the need for manual intervention, reduces the complexity of system maintenance, and reduces the risk of manual operation errors. At the same time, the honey spot anti-aging method of the present invention generates and deploys honey spots based on real-time data, avoiding the waste of resources and identification risks caused by the long-term static existence of traditional honey spots. By dynamically generating and adjusting the configuration of honey spots, the system can more efficiently utilize network resources and ensure continuous and efficient security protection. In addition, by collecting and analyzing various data in the network environment, accurate real-time intelligence is provided to the system. Combined with the anti-aging technology of honey spots, the system can quickly respond to potential threats, automatically generate and deploy honey spots, and achieve effective defense against unknown threats.
[0103] 5. This invention dynamically adjusts the configuration and deployment strategies of sweet spots, maintaining their effectiveness and freshness. This enables the system to intelligently respond to advanced persistent threats and other complex attacks, enhancing the overall intelligence level of security protection. By utilizing a sweet spot repository and automated generation technology, this invention can also create complex entrapment environments to attract and capture attacker behavior, reducing the risk exposure of real assets. It also provides security teams with detailed attack behavior data, helping to improve defense strategies and enhance threat detection capabilities.
[0104] See also Figure 2 , which is a schematic structural diagram of a honey spot anti-aging system based on digital twins in one embodiment of the present invention, includes:
[0105] A data collection module 10 is configured to collect historical raw data of target networks and devices, wherein the historical raw data includes at least one of network traffic data, system and application logs, device status information, and user behavior data;
[0106] A model building module 20 is used to build an initial digital twin model and train the initial virtual model based on the historical original data to obtain a trained digital twin model;
[0107] a honeyspot deployment module 30 for acquiring current raw data of target networks and devices, inputting the current raw data into current raw data, outputting event analysis results corresponding to the current raw data, and generating and deploying honeyspots according to the event analysis results corresponding to the current raw data;
[0108] An aging honey spot detection module 40 is used to determine whether a deployed honey spot meets the preset conditions for an aging honey spot;
[0109] The anti-aging operation execution module 50 is configured to execute an anti-aging operation on the aging sweet spot if a preset condition of the aging sweet spot is met.
[0110] On the other hand, the present invention also proposes a readable storage medium having one or more programs stored thereon, which, when executed by a processor, implements the above-mentioned honey spot anti-aging method based on digital twins.
[0111] On the other hand, the present invention also proposes a computer device, including a memory and a processor, wherein the memory is used to store computer programs, and the processor is used to execute the computer programs stored in the memory to implement the above-mentioned digital twin-based honey spot anti-aging method.
[0112] Those skilled in the art will appreciate that the logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device), or in conjunction with such instruction execution system, apparatus, or device. For purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by an instruction execution system, apparatus, or device, or in conjunction with such instruction execution system, apparatus, or device.
[0113] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0114] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement the hardware: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0115] While the embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations of these embodiments are possible. However, it should be understood that such modifications and variations are within the scope and spirit of the present invention as set forth in the claims. Furthermore, the invention described herein is susceptible to other embodiments and may be practiced or implemented in a variety of ways.
Claims
1. A honey spot anti-aging method based on digital twins, characterized in that: The method comprises: Collecting historical raw data of the target network and devices, the historical raw data including at least one of network traffic data, system and application logs, device status information, and user behavior data; Constructing an initial digital twin model, and training the initial digital twin model based on the historical original data to obtain a trained digital twin model; Obtain current raw data of the target network and device, and input the current raw data into the current digital twin model to output event analysis results corresponding to the current raw data, and generate and deploy honey spots based on the event analysis results corresponding to the current raw data; Determine whether the deployed honey spots meet the preset conditions for aging honey spots; If the preset conditions of the aging honey spot are met, the anti-aging operation is performed on the aging honey spot; The steps of obtaining the current raw data of the target network and device, inputting the current raw data into the current digital twin model to output event analysis results corresponding to the current raw data, and generating and deploying honey spots according to the event analysis results corresponding to the current raw data include: Obtain network traffic patterns, user behavior patterns, and attack pattern characteristics based on the event analysis results; Identifying suspicious traffic based on the network traffic pattern, generating a honey spot corresponding to the suspicious traffic, and deploying the honey spot corresponding to the suspicious traffic at a location close to a target of the suspicious traffic; Identifying abnormal users with abnormal behavior based on the user behavior pattern, and deploying honey spots near the systems or resources that the abnormal users attempt to access; Generate corresponding honey spots according to the attack pattern characteristics, and deploy the honey spots corresponding to the attack pattern characteristics in areas that the attacker is concerned about.
2. The honey spot anti-aging method based on digital twin according to claim 1 is characterized in that: After the step of collecting historical raw data of the target network and device, the following steps are further included: Denoising and formatting the historical original data in sequence to obtain formatted historical original data; Extract key fields from the formatted historical raw data, including timestamp, user name, IP address, and event description; The historical original data is analyzed according to the key fields to obtain event analysis results.
3. The honey spot anti-aging method based on digital twin according to claim 2 is characterized in that: The steps of constructing an initial digital twin model and training the initial digital twin model according to the historical original data to obtain a trained digital twin model include: The event description is annotated according to the event analysis result, and a data set is constructed according to the annotated result. The initial digital twin model is trained according to the data set to obtain a trained digital twin model.
4. The honey spot anti-aging method based on digital twin according to any one of claims 1 to 3, characterized in that: The preset conditions include that the service corresponding to the original sweet spot is modified, or the difference in attack frequency of the sweet spot in adjacent monitoring cycles is less than a first preset threshold, or the difference in attack frequency of the sweet spot in adjacent monitoring cycles is greater than a second preset threshold.
5. The honey spot anti-aging method based on digital twin according to claim 4 is characterized in that: If the preset conditions of the aging sweet spot are met, the step of performing the anti-aging operation on the aging sweet spot includes: If the honey point after deployment meets the service modification requirements, search for the service image with the same version as the current digital twin model and download it to the local server. Use the script to modify the service image, use the build instruction to generate a new honey point, store the new honey point in the honey point warehouse, and call the new honey point from the honey point warehouse for deployment.
6. The honey spot anti-aging method based on digital twin according to claim 4 is characterized in that: If the preset conditions of the aging sweet spot are met, the step of performing the anti-aging operation on the aging sweet spot includes: If the attack frequency of the deployed honey spot is significantly reduced, the honey spot is deleted and the same service image is re-called from the honey spot warehouse as a new honey spot for replenishment; If the deployed honey spot meets the requirement that the attack frequency increases significantly, the service of the honey spot is modified every first preset time.
7. A honey spot anti-aging system based on digital twins, characterized in that: The system comprises: A data collection module is used to collect historical raw data of the target network and devices, wherein the historical raw data includes at least one of network traffic data, system and application logs, device status information, and user behavior data; A model building module is used to build an initial digital twin model and train the initial digital twin model based on the historical original data to obtain a trained digital twin model; A honeyspot deployment module is used to obtain the current raw data of the target network and device, input the current raw data into the current digital twin model, output the event analysis results corresponding to the current raw data, and generate and deploy honeyspots based on the event analysis results corresponding to the current raw data; Aging honey spot detection module, used to determine whether the deployed honey spots meet the preset conditions for aging honey spots; an anti-aging operation execution module, configured to execute an anti-aging operation on an aging sweet spot if a preset condition of the aging sweet spot is met; The steps of obtaining the current raw data of the target network and device, inputting the current raw data into the current digital twin model to output event analysis results corresponding to the current raw data, and generating and deploying honey spots according to the event analysis results corresponding to the current raw data include: Obtain network traffic patterns, user behavior patterns, and attack pattern characteristics based on the event analysis results; Identifying suspicious traffic based on the network traffic pattern, generating a honey spot corresponding to the suspicious traffic, and deploying the honey spot corresponding to the suspicious traffic at a location close to a target of the suspicious traffic; Identifying abnormal users with abnormal behavior based on the user behavior pattern, and deploying honey spots near the systems or resources that the abnormal users attempt to access; Generate corresponding honey spots according to attack pattern characteristics, and deploy the honey spots corresponding to the attack pattern characteristics in areas of concern to the attacker.
8. A readable storage medium, characterized in that: The readable storage medium stores one or more programs, which, when executed by a processor, implement the honey spot anti-aging method based on digital twins as described in any one of claims 1 to 6.
9. A computer device comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor is used to execute the computer program stored in the memory, it implements the digital twin-based honey spot anti-aging method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Service simulation method and device, computer equipment and storage medium
CN117596087A
Twin trapping network design method
CN117938440A