Active trapping method and device based on network feature analysis, equipment and medium

By identifying and trapping suspected malicious traffic through network feature analysis and dynamic simulation modules, the passive nature of honeypot technology is solved, enabling proactive trapping of attackers and threat intelligence empowerment, thereby improving network security and defense efficiency.

CN119520092BActive Publication Date: 2026-01-06CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411648494.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2026-01-06
Estimated Expiration
2044-11-18

AI Technical Summary

Technical Problem

Honeypot technology is passive, which limits its effectiveness and coverage. It cannot actively guide attackers into the trapping system and relies on attackers to actively select targets, resulting in uncertain capture results.

Method used

The network feature analysis module detects traffic mirroring data, uses malicious IP intelligence database and attack feature intelligence database to identify suspected malicious traffic, and redirects it to a highly realistic honeypot in the dynamic simulation module for trapping. Combined with honeynet management and threat intelligence modules, the system performs summary analysis and intelligence updates to form a closed-loop proactive trapping defense system.

Benefits of technology

It enables precise and proactive targeting of suspected malicious traffic, timely detection and blocking of real attack behaviors, improves the security of business systems and the efficiency of threat handling, and forms a highly accurate defense system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520092B_ABST
    Figure CN119520092B_ABST
Patent Text Reader

Abstract

The application discloses a method and device for active trapping based on network feature analysis, equipment and medium, comprising: obtaining traffic mirror data by traffic mirroring of access traffic data through a traffic arrangement module; performing traffic detection on the traffic mirror data according to a malicious IP intelligence database and an attack feature intelligence database through a network feature analysis module; performing traffic arrangement on the traffic mirror data according to a traffic detection result through the traffic arrangement module; redirecting suspected malicious traffic to a dynamic simulation module through an attack trapping module; trapping the suspected malicious traffic through the dynamic simulation module; obtaining local intelligence data by collecting and analyzing trapping results through a honeynet management module; generating intelligence empowerment data according to cloud intelligence data and local intelligence data through a threat intelligence module, and updating the malicious IP intelligence database and the attack feature intelligence database according to the intelligence empowerment data. The application improves the security of the business system and can be widely applied in the field of network security technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an active trapping method, apparatus, device, and medium based on network feature analysis. Background Technology

[0002] Honeypots, as a proactive cybersecurity technology, are primarily used to lure and analyze the behavior of cyber attackers, thereby enhancing the effectiveness of defense strategies. In the current cybersecurity field, honeypot technology has been widely applied and developed. Honeypot systems attract potential attackers by simulating real network environments and systems, and record their activities for analysis and research by security experts. This technology has significant application value at multiple levels, including detecting and defending against advanced persistent threats, analyzing malware behavior, acquiring attack patterns and methods, and improving overall cybersecurity situational awareness.

[0003] Honeypot technology excels in defense against advanced persistent threats (APTs). APT attacks are typically highly stealthy and persistent, making them difficult to detect and respond to effectively with traditional security measures. By deploying advanced honeypots, these sophisticated attackers can be effectively lured in, their intrusion methods and behavioral paths recorded, providing valuable data for subsequent threat intelligence analysis. This not only helps in the timely detection and blocking of attacks but also improves the overall security defense level of an organization. Honeypot technology also plays a crucial role in malware analysis. Security researchers can use honeypots to capture malware samples in transit and conduct detailed analysis in a controlled environment. By observing the behavior of malware within a honeypot, researchers can understand its propagation methods, infection mechanisms, and specific malicious behaviors. This information is essential for developing effective malware defense strategies, enabling security vendors and organizations to update and improve their protective measures more quickly.

[0004] Honeypots are also widely used for acquiring attack patterns and methods. By analyzing attackers' behavior within a honeypot system, we can understand the tools, techniques, and tactics they use. This information provides direct data support for threat intelligence collection and analysis. Especially for novel attacks and unknown threats, honeypots can provide firsthand attack intelligence, enabling security experts to quickly understand and respond to emerging security threats. Furthermore, honeypot technology has significant advantages in enhancing network security situational awareness. By deploying multiple honeypot nodes across the network, security teams can monitor and analyze suspicious activity in real time. Attack data captured by honeypots can be correlated with other security events, providing a more comprehensive threat situational view. This integrated threat awareness capability is crucial for timely detection and response to cyberattacks and ensuring network security.

[0005] Meanwhile, with the development of cloud computing and the Internet of Things (IoT), honeypot technology is also expanding into these emerging fields. In cloud environments, honeypots can be deployed on virtualization platforms to simulate various cloud services and applications, trapping attacks targeting the cloud platform. In IoT environments, honeypots can simulate various smart devices to capture attack behaviors targeting IoT devices. These new application scenarios further expand the scope of honeypot technology, enabling it to play a role in a wider range of network environments.

[0006] However, current industry solutions for active trapping still have significant limitations, a notable one being the passivity of honeypot technology. Specifically, honeypots can only passively wait for attackers to initiate attacks and fall into their traps; they cannot actively guide attackers into the honeypot. This passivity limits the effectiveness and coverage of honeypots to some extent. Because honeypots require attackers to actively launch attacks, their effectiveness in capturing attacks depends on the attacker's chosen target. If the attacker avoids the honeypot or becomes aware of its existence, the honeypot will struggle to fulfill its intended purpose. While highly realistic honeypots can attract attackers by masquerading as high-value targets, this method still has limitations and cannot guarantee that all attackers will fall for it. Summary of the Invention

[0007] The purpose of this invention is to at least partially solve one of the technical problems existing in the prior art.

[0008] Therefore, one objective of this invention is to provide an active trapping method based on network feature analysis. This method can more accurately target suspected malicious traffic, thereby promptly detecting and blocking real attack behaviors and improving the security of business systems.

[0009] Another objective of this invention is to provide an active trapping device based on network feature analysis.

[0010] To achieve the above-mentioned technical objectives, the technical solutions adopted in the embodiments of the present invention include:

[0011] On one hand, embodiments of the present invention provide an active trapping method based on network feature analysis, comprising the following steps:

[0012] The access traffic data is mirrored by the traffic orchestration module to obtain traffic mirror data, and the traffic mirror data is sent to the network feature analysis module.

[0013] The network feature analysis module performs traffic detection on the traffic mirroring data based on the malicious IP intelligence database and the attack feature intelligence database, and returns the traffic detection results to the traffic orchestration module.

[0014] The traffic orchestration module orchestrates the traffic mirroring data based on the traffic detection results, so that suspected malicious traffic is forwarded to the attack trapping module.

[0015] The attack trapping module redirects the suspected malicious traffic to the dynamic simulation module.

[0016] The suspected malicious traffic is captured by the dynamic simulation module, and the capture results are output to the honeynet management module.

[0017] The honeynet management module summarizes and analyzes the trapping results to obtain local intelligence data, and then sends the local intelligence data to the threat intelligence module.

[0018] The threat intelligence module generates intelligence-enhancing data based on cloud-based intelligence data and local intelligence data, and updates the malicious IP intelligence database and the attack signature intelligence database based on the intelligence-enhancing data.

[0019] Furthermore, in one embodiment of the present invention, the step of performing traffic detection on the traffic mirroring data based on the malicious IP intelligence database and the attack signature intelligence database specifically includes:

[0020] The source IP of the traffic mirroring data is determined, and the source IP is matched and searched according to the malicious IP intelligence database to determine whether the source IP is a malicious IP;

[0021] When the source IP is a malicious IP, attack feature detection is performed on the traffic mirroring data according to the attack feature intelligence database. If the traffic mirroring data has attack features, it is determined that the traffic mirroring data is malicious traffic. If the traffic mirroring data does not have attack features, it is determined that the traffic mirroring data is suspected malicious traffic.

[0022] When the source IP is not a malicious IP, the traffic mirroring data is subjected to attack feature detection based on the attack feature intelligence database. If the traffic mirroring data has attack features, it is determined that the traffic mirroring data is suspected malicious traffic. If the traffic mirroring data does not have attack features, it is determined that the traffic mirroring data is real access traffic.

[0023] Furthermore, in one embodiment of the present invention, the step of orchestrating the traffic mirroring data based on the traffic detection result specifically includes:

[0024] Forward the actual access traffic to the actual business system;

[0025] The suspected malicious traffic is forwarded to the attack trapping module;

[0026] The malicious traffic is blocked, and the malicious IPs corresponding to the malicious traffic are banned.

[0027] Furthermore, in one embodiment of the present invention, the dynamic simulation module includes multiple highly realistic honeypots, which are obtained by simulating a real business system. Each highly realistic honeypot has multiple exploitable vulnerabilities built in, and the multiple highly realistic honeypots form a honeycomb by imitating a real business topology. The attack trapping module is bound to the service port of the highly realistic honeypot to redirect the suspected malicious traffic to the highly realistic honeypot.

[0028] Furthermore, in one embodiment of the present invention, the step of intercepting the suspected malicious traffic specifically includes:

[0029] The highly realistic honeypot uses exploitable vulnerabilities to lure and capture suspected malicious traffic, and monitors whether the suspected malicious traffic exhibits any attack behavior.

[0030] When the suspected malicious traffic exhibits attack behavior, an alarm log is recorded, and sample analysis and attack traffic tracing are performed on the suspected malicious traffic to obtain analysis logs and raw traffic logs.

[0031] Furthermore, in one embodiment of the present invention, the step of summarizing and analyzing the trapping results to obtain local intelligence data specifically includes:

[0032] The alarm logs output by multiple high-fidelity honeypots are merged to obtain the attack start time, attack end time, attack target IP, and attack type.

[0033] By performing correlation analysis on the analysis logs output by multiple high-fidelity honeypots, the attack source IP and the attack tools used by the attacker can be obtained.

[0034] By tracing the original traffic logs output by multiple highly realistic honeypots, the attacker's personal ID, device fingerprint, and device MAC address can be obtained.

[0035] An attacker profile is generated based on the personal ID, device fingerprint, device MAC address, attack source IP address, attack tool, attack start time, attack end time, attack target IP address, and attack type, and the attacker profile is used as the local intelligence data.

[0036] Furthermore, in one embodiment of the present invention, intelligence-enabling data is generated based on cloud-based intelligence data and the local intelligence data, and the malicious IP intelligence database and the attack signature intelligence database are updated based on the intelligence-enabling data, specifically including:

[0037] Real-time acquisition of intelligence data from the cloud;

[0038] The attacker's source IP and attack characteristics are determined based on the cloud-based intelligence data and the local intelligence data.

[0039] The attacker's source IP and the attack feature data are sent to the network feature analysis module as intelligence empowerment data, so that the network feature analysis module updates the malicious IP intelligence database according to the attacker's source IP and updates the attack feature intelligence database according to the attack feature data.

[0040] On the other hand, embodiments of the present invention provide an active trapping device based on network feature analysis, including a traffic orchestration module, a network feature analysis module, an attack trapping module, a dynamic simulation module, a honeynet management module, and a threat intelligence module, wherein:

[0041] The traffic orchestration module is used to mirror the access traffic data to obtain traffic mirror data, and send the traffic mirror data to the network feature analysis module. It is also used to orchestrate the traffic mirror data according to the traffic detection results returned by the network feature analysis module, so that suspected malicious traffic is forwarded to the attack trapping module.

[0042] The network feature analysis module is used to perform traffic detection on the traffic mirroring data based on the malicious IP intelligence database and the attack feature intelligence database, and return the traffic detection results to the traffic orchestration module.

[0043] The attack trapping module is used to redirect the suspected malicious traffic to the dynamic simulation module;

[0044] The dynamic simulation module is used to capture the suspected malicious traffic and output the capture results to the honeynet management module.

[0045] The honeynet management module is used to summarize and analyze the trapping results to obtain local intelligence data, and send the local intelligence data to the threat intelligence module;

[0046] The threat intelligence module is used to generate intelligence empowerment data based on cloud-based intelligence data and local intelligence data, and to update the malicious IP intelligence database and the attack feature intelligence database based on the intelligence empowerment data.

[0047] On the other hand, embodiments of the present invention provide an electronic device, which includes a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for enabling communication between the processor and the memory. When the program is executed by the processor, it implements the active trapping method based on network feature analysis as described above.

[0048] On the other hand, embodiments of the present invention also provide a storage medium, which is a computer-readable storage medium for computer-readable storage. The storage medium stores one or more programs, which can be executed by one or more processors to implement the active trapping method based on network feature analysis as described above.

[0049] The advantages and beneficial effects of the present invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention:

[0050] In this embodiment of the invention, a traffic orchestration module performs traffic mirroring on access traffic data to obtain traffic mirror data, which is then sent to a network feature analysis module. The network feature analysis module performs traffic detection on the traffic mirror data based on a malicious IP intelligence database and an attack feature intelligence database, and returns the detection results to the traffic orchestration module. The traffic orchestration module then orchestrates the traffic mirror data based on the detection results, causing suspected malicious traffic to be forwarded to an attack trapping module. The attack trapping module redirects the suspected malicious traffic to a dynamic simulation module, which traps the suspected malicious traffic and outputs the trapping results to a honeynet management module. The honeynet management module summarizes and analyzes the trapping results to obtain local intelligence data, which is then sent to a threat intelligence module. The threat intelligence module generates intelligence empowerment data based on cloud-based and local intelligence data, and updates the malicious IP intelligence database and attack feature intelligence database based on the intelligence empowerment data. This invention utilizes a network feature analysis module for proactive targeting, combined with traffic orchestration to guide suspected malicious traffic to a dynamic simulation honeypot for attack targeting. This enables attack forensics and attacker profiling. By summarizing and analyzing the targeting results, threat intelligence data is generated, empowering the network feature analysis module with threat intelligence and forming an automated traffic orchestration and handling script, thus improving threat handling efficiency. Through a layered design of traffic orchestration, network feature analysis, attack targeting, dynamic simulation, honeypot management, and threat intelligence modules, a closed-loop, sustainable, and highly accurate proactive targeting defense system is formed. This improves upon the situation where defenders can only passively wait for attackers to fall into the trap. It allows for more precise proactive targeting of suspected malicious traffic, enabling timely detection and blocking of real attack behaviors, protecting real business systems from harm, and improving the security of business systems. Attached Figure Description

[0051] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the embodiments of the present invention are described below. It should be understood that the drawings described below are only for the convenience of clearly describing some embodiments of the technical solutions of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1 A flowchart illustrating the steps of an active trapping method based on network feature analysis provided in an embodiment of the present invention;

[0053] Figure 2 A schematic diagram of data interaction for the active trapping method based on network feature analysis provided in an embodiment of the present invention;

[0054] Figure 3 A flowchart of step S102 provided in an embodiment of the present invention;

[0055] Figure 4 A flowchart of step S103 provided in an embodiment of the present invention;

[0056] Figure 5 A flowchart of step S105 provided in an embodiment of the present invention;

[0057] Figure 6 A flowchart of step S106 provided in an embodiment of the present invention;

[0058] Figure 7 A flowchart of step S107 provided in an embodiment of the present invention;

[0059] Figure 8 A schematic diagram of the active trapping device based on network feature analysis provided in an embodiment of the present invention;

[0060] Figure 9 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention;

[0061] Figure 10 This is a schematic diagram of the structure of the storage medium provided in an embodiment of the present invention. Detailed Implementation

[0062] The embodiments of the present invention are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application. It should be noted that although functional modules are divided in the system schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system schematic diagram or the order in the flowchart. The step numbers in the following embodiments are only set for ease of explanation and do not limit the order between steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.

[0063] In the description of this invention, "multiple" means two or more. The use of "first" and "second" is for distinguishing technical features only and should not be construed as indicating or implying relative importance, the number of indicated technical features, or the order of the indicated technical features. Furthermore, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0064] The active trapping method based on network feature analysis provided in this application can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, set-top box, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the active trapping method based on network feature analysis, etc., but is not limited to the above forms.

[0065] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0066] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards of the relevant countries and regions. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirects to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data for the normal operation of the embodiments of this application obtained.

[0067] like Figure 1 The diagram shows a flowchart of an active trapping method based on network feature analysis provided in an embodiment of the present invention. (Refer to...) Figure 1 This invention provides an active trapping method based on network feature analysis, specifically including the following steps:

[0068] S101. The access traffic data is mirrored by the traffic orchestration module to obtain traffic mirror data, and the traffic mirror data is sent to the network feature analysis module.

[0069] S102. The network feature analysis module performs traffic detection on the traffic mirroring data based on the malicious IP intelligence database and the attack feature intelligence database, and returns the traffic detection results to the traffic orchestration module.

[0070] S103. The traffic orchestration module performs traffic orchestration on the traffic mirroring data based on the traffic detection results, so that suspected malicious traffic is forwarded to the attack trapping module.

[0071] S104. Redirect suspected malicious traffic to the dynamic simulation module through the attack trapping module;

[0072] S105. The dynamic simulation module is used to capture suspected malicious traffic, and the capture results are output to the honeynet management module.

[0073] S106. The trapping results are summarized and analyzed through the honeynet management module to obtain local intelligence data, and the local intelligence data is sent to the threat intelligence module.

[0074] S107. Generate intelligence empowerment data based on cloud-based intelligence data and local intelligence data through the threat intelligence module, and update the malicious IP intelligence database and attack signature intelligence database based on the intelligence empowerment data.

[0075] like Figure 2 The diagram shown is a data interaction schematic of the active trapping method based on network feature analysis provided in an embodiment of the present invention. Figure 2 The relevant modules are explained below:

[0076] The traffic orchestration module is responsible for traffic mirroring, traffic orchestration, and blocking. By mirroring access traffic to the network feature analysis module and then judging based on the results of the network feature analysis module, it actively forwards suspected malicious traffic to the attack trapping module or blocks malicious IPs, thereby achieving proactive threat trapping and handling.

[0077] The network feature analysis module performs network feature analysis on access traffic based on threat intelligence and attack feature database, realizing proactive threat feature analysis.

[0078] The attack trapping module serves as the honeynet entry point and is mapped and bound to the dynamic simulation module. It redirects suspected malicious traffic to the dynamic simulation module, thereby achieving proactive threat trapping and diversion.

[0079] The dynamic simulation module is a honeycomb composed of multiple highly realistic honeypots. It performs attack forensics and profiling on attackers who enter the honeycomb area, enabling proactive source tracing and evidence collection.

[0080] The honeynet management module summarizes and analyzes the trapping results from the dynamic simulation module, generates threat intelligence data, and sends it to the threat intelligence module to achieve proactive threat intelligence data production.

[0081] The threat intelligence module produces intelligence and empowers the network feature analysis module, thereby enabling proactive threat intelligence.

[0082] This invention utilizes a network feature analysis module for proactive targeting, combined with traffic orchestration to guide suspected malicious traffic to a dynamic simulation honeypot for attack targeting. This enables attack forensics and attacker profiling. By summarizing and analyzing the targeting results, threat intelligence data is generated, empowering the network feature analysis module with threat intelligence and forming an automated traffic orchestration and handling script, thus improving threat handling efficiency. Through a layered design of traffic orchestration, network feature analysis, attack targeting, dynamic simulation, honeypot management, and threat intelligence modules, a closed-loop, sustainable, and highly accurate proactive targeting defense system is formed. This improves upon the situation where defenders can only passively wait for attackers to fall into the trap. It allows for more precise proactive targeting of suspected malicious traffic, enabling timely detection and blocking of real attack behaviors, protecting real business systems from harm, and improving the security of business systems.

[0083] like Figure 3 The diagram shown is a flowchart of step S102 provided in an embodiment of the present invention. (Refer to...) Figure 3 As an optional implementation, traffic detection is further performed on the traffic mirroring data based on a malicious IP intelligence database and an attack signature intelligence database, specifically including:

[0084] S1021. Determine the source IP of the traffic mirroring data, match and search the source IP according to the malicious IP intelligence database, and determine whether the source IP is a malicious IP.

[0085] S1022. When the source IP is a malicious IP, attack feature detection is performed on the traffic mirroring data according to the attack feature intelligence database. If the traffic mirroring data has attack features, it is determined that the traffic mirroring data is malicious traffic. If the traffic mirroring data does not have attack features, it is determined that the traffic mirroring data is suspected malicious traffic.

[0086] S1023. When the source IP is not a malicious IP, attack feature detection is performed on the traffic mirroring data according to the attack feature intelligence database. If the traffic mirroring data has attack features, it is determined that the traffic mirroring data is suspected malicious traffic. If the traffic mirroring data does not have attack features, it is determined that the traffic mirroring data is real access traffic.

[0087] Specifically, the network feature analysis module performs the following tasks:

[0088] Threat Intelligence Update: Update the IP intelligence database of the network feature analysis module based on malicious IPs enabled by the threat intelligence module;

[0089] Attack signature database update: The attack signature database of the network signature analysis module is updated based on the attack signatures enabled by the threat intelligence module;

[0090] Threat intelligence matching: The source IP of the access traffic sent by the traffic orchestration module is compared. If a malicious IP is found in the IP intelligence database, the access traffic is marked as suspected malicious traffic. Then, attack feature analysis and detection are performed. If the detection rules are matched, the access traffic is marked as malicious traffic; otherwise, it is marked as suspected malicious traffic. If no malicious IP is found in the IP intelligence database, attack feature analysis and detection are performed. If the detection rules are matched, the access traffic is marked as suspected malicious traffic; otherwise, it is marked as real access traffic.

[0091] Attack signature database matching: Analyze the access traffic sent by the traffic orchestration module, and label the access traffic (real access traffic, suspected malicious traffic, malicious traffic) by analyzing the comparison results between the attack payload and the attack signature database.

[0092] like Figure 4 The diagram shown is a flowchart of step S103 provided in an embodiment of the present invention. (Refer to...) Figure 4 As an optional implementation, traffic orchestration is performed on the traffic mirroring data based on the traffic detection results, specifically including:

[0093] S1031. Forward real access traffic to the real business system;

[0094] S1032. Forward suspected malicious traffic to the attack trapping module;

[0095] S1033. Block malicious traffic and ban the malicious IPs corresponding to the malicious traffic.

[0096] Specifically, the traffic orchestration module has the following capabilities:

[0097] Traffic mirroring: By configuring the system, access traffic is copied to a mirror service and sent to the network feature analysis module for analysis;

[0098] Traffic forwarding: By configuring access traffic to be forwarded to a specific destination, such as a real business system or an attack trapping module;

[0099] One-click blocking: Block high-confidence malicious IPs by setting up ACL access control lists;

[0100] Orchestration script generation: Based on SOAR technology, an automated handling script is generated based on the traffic marking situation and sent to the traffic orchestration module. Traffic marked as real access traffic is forwarded to the real business system, traffic marked as suspected malicious traffic is forwarded to the attack trapping module, and traffic marked as malicious traffic is blocked.

[0101] Script execution: Based on the analysis results of the network feature analysis module, SOAR script execution can choose to forward real access traffic to the real business system, or to trap malicious traffic attacks, or to block high-confidence malicious IPs with one click.

[0102] As an optional implementation, the dynamic simulation module includes multiple highly realistic honeypots. These honeypots are simulated based on real business systems and contain multiple exploitable vulnerabilities. The multiple honeypots mimic the real business topology to form a honeycomb. The attack trapping module is bound to the service port of the highly realistic honeypots to redirect suspected malicious traffic to the honeypots.

[0103] Specifically, the attack trapping module achieves the following capabilities:

[0104] Port mapping: As a port mapping node in the high-fidelity honeypot in the dynamic simulation module, it is bound to the service port of the high-fidelity honeypot;

[0105] Traffic redirection: redirects suspected malicious traffic forwarded by the traffic orchestration module to a highly realistic honeypot in the dynamic simulation module;

[0106] Micro-segmentation: As the entry point for active trapping, the attack trapping module should be subject to strict access control, with fine-grained micro-segmentation based on traffic flow, allowing access only to the highly realistic honeypot in the dynamic simulation module.

[0107] like Figure 5 The diagram shown is a flowchart of step S105 provided in an embodiment of the present invention. (Refer to...) Figure 5 As an optional implementation method, suspected malicious traffic can be intercepted, specifically including:

[0108] S1051. By exploiting the built-in vulnerabilities of the highly realistic honeypot, suspected malicious traffic is captured and monitored to see if there are any attack behaviors in the suspected malicious traffic.

[0109] S1052. When suspected malicious traffic exhibits attack behavior, record alarm logs, and perform sample analysis and attack traffic tracing on the suspected malicious traffic to obtain analysis logs and raw traffic logs.

[0110] Specifically, the dynamic simulation module has the following characteristics:

[0111] High simulation: The honeypots in the dynamic simulation module are highly simulated 1:1 based on real business systems, and multiple high simulation honeypots form a honeycomb by imitating the real business topology.

[0112] High sweetness: The honeypot in the dynamic simulation module contains a high sweetness decoy to induce attackers to reveal their true attack intentions;

[0113] Attack signature extraction: The honeypot in the dynamic simulation module has multiple exploitable vulnerabilities built in, which induce attackers to exploit the vulnerabilities and record the attacker's exploitation process.

[0114] Attack behavior collection: For attackers who enter the honeypot in the dynamic simulation module, it supports reproducing the attacker's attack behavior through command line playback or screen recording.

[0115] like Figure 6 The diagram shown is a flowchart of step S106 provided in an embodiment of the present invention. (Refer to...) Figure 6 As an optional implementation method, the trapping results are summarized and analyzed to obtain local intelligence data, which specifically includes:

[0116] S1061. Merge the alarm logs output by multiple high-fidelity honeypots to obtain the attack start time, attack end time, attack target IP, and attack type.

[0117] S1062. Perform correlation analysis on the analysis logs output by multiple high-fidelity honeypots to obtain the attack source IP and the attack tools used by the attacker;

[0118] S1063. Perform information tracing on the raw traffic logs output by multiple high-fidelity honeypots to obtain the attacker's personal ID, device fingerprint, and device MAC address;

[0119] S1064. Generate an attacker profile based on personal ID, device fingerprint, device MAC, attack source IP, attack tool, attack start time, attack end time, attack target IP, and attack type, and use the attacker profile as local intelligence data.

[0120] Specifically, the honeynet management module can uniformly manage multiple highly realistic honeypots in the dynamic simulation module, including:

[0121] Honeypot deployment: Manage the generation, deployment, editing, deletion, and honeypot orchestration of honeypots;

[0122] Decoy Deployment: Manages the generation, format, type, content, deletion, and placement path of decoy files in honeypots;

[0123] Countermeasure monitoring: For countermeasure decoys, such as remote control malware decoys, the attacker's terminal can be remotely controlled or monitored for proactive source tracing and countermeasures.

[0124] Information tracing: For tracing-type baits, the attacker's social account ID is obtained through the JSONP interface of social networking sites, and proactive tracing is carried out.

[0125] Attacker Profile: Combining the trapping information from multiple honeypots, a high-precision attacker profile is compiled. The attacker's information includes social account ID, device fingerprint, device MAC, attack start time, attack end time, attack target IP, attack source IP, attack tools used, attack type, attack characteristics, etc.

[0126] like Figure 7 The diagram shown is a flowchart of step S107 provided in an embodiment of the present invention. (Refer to...) Figure 7 As an optional implementation, intelligence-enhancing data is generated based on cloud-based intelligence data and local intelligence data, and the malicious IP intelligence database and attack signature intelligence database are updated based on the intelligence-enhancing data. Specifically, this includes:

[0127] S1071, Real-time acquisition of cloud intelligence data;

[0128] S1072. Determine the attacker's source IP and attack characteristics based on cloud intelligence data and local intelligence data;

[0129] S1073. The attacker's source IP and attack feature data are sent as intelligence-enabling data to the network feature analysis module, so that the network feature analysis module updates the malicious IP intelligence database according to the attacker's source IP and updates the attack feature intelligence database according to the attack feature data.

[0130] Specifically, the threat intelligence module generates threat intelligence based on the intelligence data from the honeynet management module, including:

[0131] Attack characteristics: The attack techniques and vulnerability exploitation methods used by attackers in the honeypot are formed into attack characteristics;

[0132] Malicious Sample MD5: The MD5 hashes of samples identified as malicious after execution within the honeypot sandbox will be summarized.

[0133] Malicious IPs: The source IPs of attacker profiles are merged and included in the IP intelligence database.

[0134] The method steps of the embodiments of the present invention have been described above.

[0135] A specific process of an embodiment of the present invention is as follows.

[0136] Step 1: The traffic orchestration module mirrors the access traffic to the network feature analysis module, which analyzes and detects the traffic through various methods such as attack feature detection, semantic analysis, rule matching, and intelligence matching, and marks the analysis results.

[0137] Step 2: The network feature analysis module detects access traffic based on the intelligence empowered by the threat intelligence module and the attack feature database, and returns the detection results to the traffic orchestration module. The analysis results are divided into real access traffic, suspected malicious traffic, and malicious traffic.

[0138] Step 3: The traffic orchestration module makes a judgment based on the detection results returned by the network feature analysis module. Traffic marked as real access traffic is forwarded to the real business system, traffic marked as suspected malicious traffic is forwarded to the attack trapping module, and traffic marked as malicious traffic is directly blocked.

[0139] Step 4: The attack trapping module redirects suspected malicious traffic to the dynamic simulation module, which then performs attack monitoring, sample analysis, and attack traffic source tracing and storage on the traffic.

[0140] Step 5: The dynamic simulation module outputs the trapping results to the honeynet management module, including alarm logs, analysis logs, raw traffic logs, and other information;

[0141] Step Six: The honeynet management module summarizes and analyzes the trapping results output by multiple honeypots in the dynamic simulation module, merges alarms and performs correlation analysis of multiple honeypots, generates an attack profile, forms local intelligence data, and sends it to the threat intelligence module.

[0142] Step 7: The threat intelligence module combines cloud-based intelligence with local intelligence produced by the honeynet management module, and periodically sends information such as the source IP, MD5 hash, and attack characteristics of the suspected malicious traffic to the network feature analysis module as intelligence data, thus completing the intelligence empowerment of the network feature analysis module.

[0143] It can be recognized that the embodiments of the present invention actively lure and capture attacks based on the network feature analysis module, and guide suspected malicious traffic to a dynamic simulation honeypot for attack capture in conjunction with traffic orchestration. This enables attack evidence collection and profile reconstruction of attackers. By summarizing and analyzing the capture results, threat intelligence data is obtained, which empowers the network feature analysis module with threat intelligence, forming an automated traffic orchestration and handling script, thus improving the efficiency of threat handling. By utilizing the nested design of the traffic orchestration module, network feature analysis module, attack capture module, dynamic simulation module, honeypot management module, and threat intelligence module, a closed-loop, sustainable, and highly accurate active capture and defense system is formed. This improves the situation where the defender can only passively wait for attackers to fall into the trap. It can more accurately actively capture suspected malicious traffic, thereby timely detecting and blocking real attack behaviors, protecting real business systems from harm, and improving the security of business systems.

[0144] Compared with the prior art, the embodiments of the present invention also have the following advantages:

[0145] 1) Form a multi-module collaborative active trapping system. The system discovers malicious traffic based on network feature analysis, actively traps malicious traffic by combining a highly realistic honeynet, and processes malicious traffic using traffic orchestration technology.

[0146] 2) Enable network feature analysis with high-confidence threat intelligence. Empower the network feature analysis module with high-confidence threat intelligence, drive the network feature analysis module to continuously improve the malicious traffic identification rate, and achieve efficient and proactive threat detection.

[0147] 3) Achieve proactive trapping of high-sweetness honeypots. Utilize traffic orchestration and redirection technology to divert suspected malicious traffic identified by the network feature analysis module to a honeypot composed of multiple highly simulated honeypot nodes. Record attackers' attack behaviors, methods, tools, etc. in detail to form a multi-dimensional attacker profile, thereby achieving proactive trapping and attack behavior tracing and evidence collection.

[0148] 4) By integrating multiple functional modules such as network feature analysis, traffic orchestration, attack trapping, dynamic simulation, honeynet management, and threat intelligence, it is not only more technologically advanced, but also demonstrates significant effects in many aspects of practical applications.

[0149] 5) By monitoring network traffic in real time, abnormal behavior and potential threats can be identified. Unlike the passive waiting of traditional honeypots, network signature analysis utilizes attack signature databases and threat intelligence to dynamically analyze network traffic characteristics and proactively discover potential attackers. This method can identify the attacker's intent and take trapping measures before the attacker gets close to the real target. By guiding and redirecting suspicious traffic, attackers are directed to the honeypot system. Traditional honeypots require attackers to actively make contact, but traffic orchestration can proactively intervene and divert attack traffic to the honeypot.

[0150] 6) Create fake high-value targets, such as disguised databases, applications, and servers, to lure attackers into further operations. By simulating real operating systems and application environments, the attack decoy module can record every step of the attacker's actions and analyze their methods and tools in detail. By integrating multiple honeypot nodes, a complex and multi-layered decoy network is formed. This networked management approach allows the honeypot system to cover a wider attack surface and provide more comprehensive monitoring and defense capabilities. The attacker's behavioral trajectory across different nodes can be fully recorded and analyzed, providing more detailed attack paths and strategy data.

[0151] 7) The system can acquire and apply the latest attack intelligence data in real time, maintaining the advancement of network signature analysis strategies. Its dynamic adjustment capabilities enable the proactive decoy system to respond quickly to new threats and provide more effective defense. Compared to existing proactive decoy solutions, it is more proactive and flexible, capable of more effectively capturing and analyzing advanced persistent threats, and providing more comprehensive and timely protection for network security.

[0152] like Figure 8 The diagram shown is a structural schematic of an active trapping device based on network feature analysis provided in an embodiment of the present invention. (Refer to...) Figure 8 This invention provides an active trapping device based on network feature analysis, comprising a traffic orchestration module, a network feature analysis module, an attack trapping module, a dynamic simulation module, a honeynet management module, and a threat intelligence module, wherein:

[0153] The traffic orchestration module is used to mirror access traffic data to obtain traffic mirror data, and send the traffic mirror data to the network feature analysis module. It is also used to orchestrate the traffic mirror data based on the traffic detection results returned by the network feature analysis module, so that suspected malicious traffic is forwarded to the attack trapping module.

[0154] The network feature analysis module is used to perform traffic detection on traffic mirroring data based on the malicious IP intelligence database and the attack feature intelligence database, and return the traffic detection results to the traffic orchestration module.

[0155] The attack decoy module is used to redirect suspected malicious traffic to the dynamic simulation module;

[0156] The dynamic simulation module is used to trap suspected malicious traffic and output the trapping results to the honeynet management module;

[0157] The honeynet management module is used to summarize and analyze the trapping results to obtain local intelligence data, and then send the local intelligence data to the threat intelligence module;

[0158] The threat intelligence module is used to generate intelligence-enhancing data based on cloud-based and local intelligence data, and to update the malicious IP intelligence database and attack signature intelligence database based on the intelligence-enhancing data.

[0159] The content of the above method embodiments is applicable to the device embodiments. The specific functions implemented by the device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0160] This invention also provides an electronic device, comprising: a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for communication between the processor and the memory. When the program is executed by the processor, it implements the aforementioned active trapping method based on network feature analysis. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0161] like Figure 9 The diagram shown is a hardware structure schematic of an electronic device provided in an embodiment of the present invention. (Refer to...) Figure 9 This invention provides an electronic device, comprising:

[0162] The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present invention.

[0163] The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 to execute the active trapping method based on network feature analysis of the embodiments of this invention.

[0164] The input / output interface 903 is used to implement information input and output;

[0165] The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0166] Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904);

[0167] The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0168] like Figure 10The diagram shown is a structural schematic of the storage medium provided in an embodiment of the present invention. (Refer to...) Figure 10 The present invention also provides a storage medium, which is a computer-readable storage medium for computer-readable storage. The storage medium stores one or more programs 1001, which can be executed by one or more processors to implement the above-described active trapping method based on network feature analysis.

[0169] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0170] This invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to perform... Figure 1 The method shown.

[0171] In some alternative embodiments, the functions / operations mentioned in the block diagrams may not occur in the order shown in the operation diagrams. For example, depending on the functions / operations involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the aforementioned blocks may sometimes be executed in reverse order. Furthermore, the embodiments presented and described in the flowcharts of this invention are provided by way of example to provide a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logic flows presented herein. Alternative embodiments are contemplated in which the order of various operations is changed and sub-operations described as part of a larger operation are executed independently.

[0172] Furthermore, although the invention has been described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the aforementioned functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the invention. Rather, given the properties, functions, and internal relationships of the various functional modules in the apparatus disclosed herein, the actual implementation of the module will be understood within the scope of conventional skill of an engineer. Therefore, those skilled in the art can implement the invention as set forth in the claims using ordinary techniques without excessive experimentation. It is also understood that the specific concepts disclosed are merely illustrative and not intended to limit the scope of the invention, which is determined by the full scope of the appended claims and their equivalents.

[0173] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0174] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0175] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the aforementioned program can be printed, because the aforementioned program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0176] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0177] In the foregoing description of this specification, references to terms such as "one embodiment," "another embodiment," or "some embodiments" indicate that a specific feature, structure, material, or characteristic described in connection with an embodiment or example is included in at least one embodiment or example of the present invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0178] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.

[0179] The above is a detailed description of the preferred embodiments of the present invention. However, the present invention is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of the present invention. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.

Claims

1. A method of active trapping based on network feature analysis, characterized in that, The method comprises the following steps: The access traffic data is mirrored by the traffic mirroring module to obtain traffic mirror data, and the traffic mirror data is sent to the network feature analysis module; The traffic mirror data is detected by the network feature analysis module according to the malicious IP intelligence library and the attack feature intelligence library, and the traffic detection result is returned to the traffic arrangement module; The traffic mirror data is arranged by the traffic arrangement module according to the traffic detection result, so that the suspected malicious traffic is forwarded to the attack trapping module; The suspected malicious traffic is redirected to the dynamic simulation module by the attack trapping module; The suspected malicious traffic is trapped by the dynamic simulation module, and the trapping result is output to the honeynet management module; The local intelligence data is obtained by the honeynet management module by analyzing the trapping result, and the local intelligence data is sent to the threat intelligence module; The threat intelligence module generates intelligence empowerment data according to the cloud intelligence data and the local intelligence data, and updates the malicious IP intelligence library and the attack feature intelligence library according to the intelligence empowerment data; The traffic mirror data is detected according to the malicious IP intelligence library and the attack feature intelligence library, which specifically comprises: Determine the source IP of the traffic mirror data, and match the source IP according to the malicious IP intelligence library to determine whether the source IP is a malicious IP; When the source IP is a malicious IP, the attack feature intelligence library is used to detect the attack features of the traffic mirror data. If the traffic mirror data has attack features, it is determined that the traffic mirror data is malicious traffic. If the traffic mirror data does not have attack features, it is determined that the traffic mirror data is suspected malicious traffic. When the source IP is not a malicious IP, the attack feature intelligence library is used to detect the attack features of the traffic mirror data. If the traffic mirror data has attack features, it is determined that the traffic mirror data is suspected malicious traffic. If the traffic mirror data does not have attack features, it is determined that the traffic mirror data is real access traffic.

2. The method of claim 1, wherein, The traffic mirror data is arranged according to the traffic detection result, which specifically comprises: The real access traffic is forwarded to the real business system; The suspected malicious traffic is forwarded to the attack trapping module; The malicious traffic is blocked, and the malicious IP corresponding to the malicious traffic is banned.

3. The method of claim 1, wherein the method further comprises: The dynamic simulation module comprises a plurality of high-fidelity honeypots, the high-fidelity honeypot is simulated based on a real business system, the high-fidelity honeypot is built-in with a plurality of exploitable vulnerabilities, a plurality of high-fidelity honeypots simulate a real business topology to form a honeynet, and the attack trapping module is bound with a service port of the high-fidelity honeypot for redirecting the suspected malicious traffic to the high-fidelity honeypot.

4. The active trapping method based on network feature analysis according to claim 3, characterized in that, The suspected malicious traffic is trapped, which specifically comprises: The suspected malicious traffic is trapped by the exploitable vulnerabilities built-in in the high-fidelity honeypot, and whether the suspected malicious traffic has attack behavior is monitored; When the suspected malicious traffic exists an attack behavior, an alarm log is recorded, sample analysis and attack traffic tracing are performed on the suspected malicious traffic, and analysis log and original traffic log are obtained.

5. The method of claim 4, wherein, The local intelligence data is obtained by performing summary analysis on the trapping results, and specifically includes: The alarm logs output by the multiple high-simulation honeypots are merged to obtain attack start time, attack end time, attack target IP, and attack type; The analysis logs output by the multiple high-simulation honeypots are correlated to obtain attack source IP and attack tools used by the attacker; The original traffic logs output by the multiple high-simulation honeypots are traced to obtain personal ID, device fingerprint, and device MAC of the attacker; The attacker portrait is generated according to the personal ID, the device fingerprint, the device MAC, the attack source IP, the attack tools, the attack start time, the attack end time, the attack target IP, and the attack type, and the attacker portrait is taken as the local intelligence data.

6. The method of active trapping based on network feature analysis according to any one of claims 1 to 5, characterized in that, The intelligence empowerment data is generated according to the cloud intelligence data and the local intelligence data, and the malicious IP intelligence database and the attack feature intelligence database are updated according to the intelligence empowerment data, and specifically includes: Real-time acquisition of cloud intelligence data; Determination of attack source IP and attack feature data according to the cloud intelligence data and the local intelligence data; The attack source IP and the attack feature data are taken as the intelligence empowerment data and sent to the network feature analysis module, so that the network feature analysis module updates the malicious IP intelligence database according to the attack source IP, and updates the attack feature intelligence database according to the attack feature data.

7. An active trapping device based on network feature analysis, characterized in that, The system includes a traffic arrangement module, a network feature analysis module, an attack trapping module, a dynamic simulation module, a honeynet management module, and a threat intelligence module, wherein: The traffic arrangement module is configured to perform traffic mirroring on access traffic data to obtain traffic mirror data, and send the traffic mirror data to the network feature analysis module, and is further configured to perform traffic arrangement on the traffic mirror data according to the traffic detection result returned by the network feature analysis module, so that suspected malicious traffic is forwarded to the attack trapping module; The network feature analysis module is configured to perform traffic detection on the traffic mirror data according to the malicious IP intelligence database and the attack feature intelligence database, and return the traffic detection result to the traffic arrangement module; The attack trapping module is configured to redirect the suspected malicious traffic to the dynamic simulation module; The dynamic simulation module is configured to trap the suspected malicious traffic, and output trapping results to the honeynet management module; The honeynet management module is configured to perform summary analysis on the trapping results to obtain local intelligence data, and send the local intelligence data to the threat intelligence module; The threat intelligence module is configured to generate intelligence empowerment data according to cloud intelligence data and the local intelligence data, and update the malicious IP intelligence database and the attack feature intelligence database according to the intelligence empowerment data; The threat intelligence module is configured to generate intelligence empowerment data according to cloud intelligence data and the local intelligence data, and update the malicious IP intelligence database and the attack feature intelligence database according to the intelligence empowerment data; The traffic detection on the traffic mirror data according to the malicious IP intelligence base and the attack feature intelligence base specifically includes: Determining a source IP of the traffic mirror data, performing matching search on the source IP according to the malicious IP intelligence base, and judging whether the source IP is a malicious IP; When the source IP is a malicious IP, performing attack feature detection on the traffic mirror data according to the attack feature intelligence base, if the traffic mirror data has attack features, determining that the traffic mirror data is malicious traffic, and if the traffic mirror data does not have attack features, determining that the traffic mirror data is suspected malicious traffic; When the source IP is not a malicious IP, performing attack feature detection on the traffic mirror data according to the attack feature intelligence base, if the traffic mirror data has attack features, determining that the traffic mirror data is suspected malicious traffic, and if the traffic mirror data does not have attack features, determining that the traffic mirror data is real access traffic.

8. An electronic device, comprising: The electronic device includes a memory, a processor, a program stored on the memory and executable on the processor, and a data bus for realizing connection communication between the processor and the memory, and the program, when executed by the processor, realizes the steps of the active trapping method based on network feature analysis according to any one of claims 1 to 6.

9. A storage medium, the storage medium being a computer-readable storage medium for computer-readable storage, characterized in that, The storage medium stores one or more programs, and the one or more programs are executable by one or more processors to realize the steps of the active trapping method based on network feature analysis according to any one of claims 1 to 6.