A combined portable high-interaction honeypot system and honeypot protection method

By integrating honeypot management and service modules into a combined portable, highly interactive honeypot system, the problem of long deployment cycles for honeypot systems is solved, achieving rapid deployment and cost reduction.

CN119583139BActive Publication Date: 2026-03-27AGRICULTURAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing honeypot systems have long deployment cycles and complex debugging processes, making them unsuitable for temporary or rapid deployment scenarios.

Method used

By integrating the honeypot management module and honeypot service module into portable and enhanced hosts, the management and probe functions can operate independently, providing a combined portable, highly interactive honeypot system that supports rapid deployment and reduces deployment costs.

Benefits of technology

It enables rapid deployment of honeypots, suitable for scenarios with temporary and rapid deployment needs, and reduces deployment costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583139B_ABST
    Figure CN119583139B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a combined portable high-interaction honeypot system and a honeypot protection method, the system comprising: a portable host and a reinforced host in communication connection, the portable host comprising an input and output module, a first honeypot management module and at least one first honeypot service module, and the reinforced host comprising a second honeypot management module and at least one second honeypot service module; the first honeypot management module and / or the second honeypot management module are used for receiving a honeypot configuration operation performed through the input and output module, so as to configure the first honeypot service module and / or the second honeypot service module; the first honeypot service module and / or the second honeypot service module are used for providing a honeypot service based on honeypot configuration information formed by the honeypot configuration operation. By using the system, the combined honeypot integrates a management end and a probe, the management and the probe function independently run through a plurality of honeypot service modules, and the fast deployment and the reduced deployment cost can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of honeypot, and particularly relates to a combined portable high-interaction honeypot system and a honeypot protection method. BACKGROUND

[0002] The honeypot is a computer system used in the field of information security, which is used to deceive hackers and trap their attack behaviors, and can be in the form of software or hardware. The honeypot simulates a computer system, a website or a device vulnerable to attack internally by software to deceive intrusion attackers to attack the honeypot, so as to collect the behavior characteristics of the attackers and locate the attackers.

[0003] The existing honeypot system mainly comprises a management end and a probe part, wherein the management end is usually a set of servers, and the probe is a honeypot distributed in different subnets to simulate different hosts or services. The management end and the probe need to be deployed separately, and each probe needs to be configured separately. The whole deployment cycle is long and the debugging is relatively complex, which is not suitable for some temporary deployment and rapid deployment scenarios. SUMMARY

[0004] The present application provides a combined portable high-interaction honeypot system and a honeypot protection method. The management and probe functions are independently operated by a honeypot management module and a plurality of honeypot service modules, which can realize rapid deployment of the honeypot and reduce the deployment cost.

[0005] In a first aspect, the present application provides a combined portable high-interaction honeypot system, comprising: a portable host and a reinforced host, the portable host being in communication connection with the reinforced host, the portable host comprising an input and output module, a first honeypot management module and at least one first honeypot service module, and the reinforced host comprising a second honeypot management module and at least one second honeypot service module.

[0006] The first honeypot management module and / or the second honeypot management module are configured to receive a honeypot configuration operation performed through the input and output module, so as to configure the first honeypot service module and / or the second honeypot service module.

[0007] The first honeypot service module and / or the second honeypot service module are configured to provide a honeypot service based on honeypot configuration information formed by the honeypot configuration operation.

[0008] In a second aspect, the present application provides a honeypot protection method, which is executed by the combined portable high-interaction honeypot system of the first aspect, and the combined portable high-interaction honeypot system comprises a portable host and a reinforced host. The method comprises the following steps.

[0009] According to the working mode of the combined portable high-interactive honeypot system, the portable host and / or the enhanced host are controlled to network, so as to provide a honeypot service through the portable host and / or the enhanced host.

[0010] The embodiment of the present application provides a combined portable high-interactive honeypot system and a honeypot protection method, the system comprises: a portable host and an enhanced host, the portable host is in communication connection with the enhanced host, the portable host comprises an input and output module, a first honeypot management module and at least one first honeypot service module, the enhanced host comprises a second honeypot management module and at least one second honeypot service module; the first honeypot management module and / or the second honeypot management module are used for receiving a honeypot configuration operation performed through the input and output module, so as to configure the first honeypot service module and / or the second honeypot service module; the first honeypot service module and / or the second honeypot service module are used for providing a honeypot service based on honeypot configuration information formed by the honeypot configuration operation. In the above technical solution, the portable host and the enhanced host of the combined honeypot integrate the management end and the probe into one body respectively, the management and the probe function independently run through the honeypot management module and the plurality of honeypot service modules, the honeypot can be quickly deployed and the deployment cost is reduced.

[0011] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0013] Figure 1 A structural schematic diagram of a combined portable high-interactive honeypot system provided for the first embodiment of the present application;

[0014] Figure 2 A structural schematic diagram of another combined portable high-interactive honeypot system provided for the first embodiment of the present application;

[0015] Figure 3 A flowchart of a honeypot protection method provided for the second embodiment of the present application. DETAILED DESCRIPTION

[0016] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative effort should belong to the scope of the present application.

[0017] It should be noted that the terms "first", "second" and the like in the description and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in other than the order illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a list of steps or units need not be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to such processes, methods, products or devices.

[0018] Embodiment one

[0019] Figure 1 A structural schematic diagram of a combined portable high-interactive honeypot system provided by the embodiment one of the present application is shown in the figure. The system can be suitable for the case of quickly deploying the honeypot to locate the attacker. The system can be realized in the form of hardware and / or software, and can be configured in an electronic device. Figure 1 As shown in the figure, the combined portable high-interactive honeypot system provided by the embodiment one can specifically include:

[0020] The portable host 10 and the enhanced host 20 are in communication connection. The portable host 10 includes an input / output module 11, a first honeypot management module 12 and at least one first honeypot service module 13. The enhanced host 20 includes a second honeypot management module 21 and at least one second honeypot service module 22.

[0021] The first honeypot management module 12 and / or the second honeypot management module 21 are used to receive a honeypot configuration operation performed through the input / output module 11, so as to configure the first honeypot service module 13 and / or the second honeypot service module 22.

[0022] The first honeypot service module 13 and / or the second honeypot service module 22 are used to provide a honeypot service based on honeypot configuration information formed by the honeypot configuration operation.

[0023] It should be noted that the honeypot is a computer system used in the field of information security, which is used to deceive hackers and trap their attack behavior, and can be in the form of software or hardware. It simulates a computer system, website or device vulnerable to attack from the inside through software, to deceive intruders to attack the honeypot, to collect the behavior characteristics of the attacker and locate the attacker. Unlike the traditional honeypot, the management control front end and the honeypot function back end are deployed separately, which has the problems of long deployment period and relatively complex debugging. The combined honeypot integrates the honeypot management function and the honeypot function together.

[0024] In the embodiment, the combined portable high-interaction honeypot is composed of a portable host 10 and a reinforced host 20, and the portable host 10 and the reinforced host 20 can be used in combination or independently. The portable host 10 and the reinforced host 20 can be connected by a network cable or through a switch. The portable host 10 can be in the form of a notebook computer. The reinforced host 20 is in the form of a server. The portable host 10 includes an input / output module 11, a first honeypot management module 12 and at least one first honeypot service module 13. The input / output module 11 includes a display screen, a keyboard, a touchpad and the like, which are used for user honeypot configuration operation and honeypot configuration content display. The module for realizing the management function of the honeypot in the portable host 10 is referred to as the first honeypot management module 12, which is used to support the front-end operation face management end, such as managing the honeypot service, calling other modules and the like. The honeypot service module included in the portable host 10 is referred to as the first honeypot service module 13. The module for realizing the management function of the honeypot in the reinforced host 20 is referred to as the second honeypot management module 21, which is used to support the front-end operation face management end, such as managing the honeypot service, calling other modules and the like. The honeypot service module included in the reinforced host 20 is referred to as the second honeypot service module 22. The second honeypot management module 21 and the second honeypot service module 22 both include a computing unit, a storage unit and an editable network card. The first honeypot service module 13 is used alone according to the demand of the honeypot simulation function, and the second honeypot service module 22 is also used alone according to the demand of the honeypot simulation function.

[0025] It can be understood that the portable host and the enhanced host of the combined honeypot provided by the embodiment are integrated with the management terminal and the probe respectively, and the management and the probe function independently run through the combination of the plurality of computing units and the storage units. The first honeypot management module 12 and / or the second honeypot management module 21 are used to receive a honeypot configuration operation to configure the first honeypot service module 13 and / or the second honeypot service module 22. The first honeypot management module 12 is used to manage the first honeypot service module 13, and the second honeypot management module 21 is used to manage the second honeypot service module 22. The first honeypot management module 12 and the second honeypot management module 21 are equivalent to the modules for managing the respective honeypots, and do not depend on other operation and maintenance terminals to configure the honeypot. If the portable host is used to provide the honeypot service, the first honeypot management module 12 and the first honeypot service module 13 work. If the enhanced host is used to provide the honeypot service, the second honeypot management module 21 and the second honeypot service module 22 work. If the portable host provides the honeypot service and the enhanced host also provides the honeypot service, the first honeypot management module 12, the first honeypot service module 13, the second honeypot management module 21 and the second honeypot service module 22 work. The honeypot configuration operation can include opening several honeypots, setting what kind of interface to open, what kind of test vulnerability to deploy, and what kind of warning to generate, etc. For example, simulate a printer with penetration, or an older Windows office device, or a server with a sensitive port, etc. Here, what kind of information can be configured can be designed according to the actual situation, and is not specifically limited here.

[0026] In the embodiment, after the first honeypot management module 12 and / or the second honeypot management module 21 receives the honeypot configuration operation, the honeypot configuration information is generated according to the specific configuration of the honeypot configuration operation, and the first honeypot service module 13 and / or the second honeypot service module 22 provides the honeypot service based on the honeypot configuration information. For example, the working mode of the combined portable high-interaction honeypot system includes a rapid deployment mode, an enhanced mode and a combined deployment mode. If the working mode is the rapid deployment mode, the portable host is networked to enable the portable host to provide the honeypot service, i.e., the first honeypot service module 12 provides the honeypot service based on the honeypot configuration information formed by the honeypot configuration operation. If the working mode is the enhanced mode, the portable host and the enhanced host are connected through the control port, and the input and output module of the portable host is used to control the networking of the enhanced host to enable the enhanced host to provide the honeypot service, i.e., the second honeypot service module 22 provides the honeypot service based on the honeypot configuration information formed by the honeypot configuration operation. If the working mode is the combined deployment mode, the portable host and the enhanced host are both networked to enable the portable host and the enhanced host to both provide the honeypot service, i.e., the first honeypot service module 13 and the second honeypot service module 22 both provide the honeypot service based on the honeypot configuration information formed by the honeypot configuration operation.

[0027] For example, the portable host form such as a notebook computer is composed of a screen, a keyboard, a touchpad, a computing unit, a storage unit, a network card, a power module (including a battery), etc., wherein according to needs, the computing unit, the storage unit and the network card and the like can have multiple parts, which can realize the collection of the hacker attack log and record the behavior record of the hacker. The enhanced host form such as a server is composed of a computing unit, a storage unit, a network card, a power module, etc., wherein according to needs, the computing unit, the storage unit and the network card and the like can have multiple parts, which can realize the collection of the hacker attack log and record the full flow of the hacker intrusion behavior, facilitating the complete restoration of the behavior of the attacker in the later period.

[0028] The combination portable high-interactive honeypot system provided by the embodiment can realize rapid deployment because the system can realize subsequent configuration after being plugged into a network cable, and can perform related deployment after being assigned with a plurality of addresses after networking. The early work is relatively simple, and the deployment can be realized relatively fast, and the combination portable high-interactive honeypot system is more suitable for scenarios requiring rapid deployment and non-persistent use. The portable host can independently realize deployment and configuration work, and is suitable for scenarios requiring rapid deployment of honeypot technology, including but not limited to enterprise network reinforcement in large network security red-blue confrontation activities, target environment setting of network attack and defense competition, etc.

[0029] The embodiment of the present application provides a combination portable high-interactive honeypot system, which comprises a portable host and an enhanced host, the portable host and the enhanced host are in communication connection, the portable host comprises an input and output module, a first honeypot management module and at least one first honeypot service module, the enhanced host comprises a second honeypot management module and at least one second honeypot service module; the first honeypot management module and / or the second honeypot management module are used for receiving a honeypot configuration operation to configure the first honeypot service module and / or the second honeypot service module; the first honeypot service module and / or the second honeypot service module are used for providing a honeypot service based on honeypot configuration information formed by the honeypot configuration operation. In the above technical solution, the portable host and the enhanced host of the combination honeypot integrate the management end and the probe into one body, the management and the probe function independently run through the honeypot management module and the plurality of honeypot service modules, rapid deployment can be realized and the deployment cost can be reduced.

[0030] Figure 2 Another structure schematic diagram of the combination portable high-interactive honeypot system provided by the embodiment of the present application is shown in Figure 2 As an optional embodiment of the present application, the input and output module 11 of the above embodiment can be optimized to comprise a display screen 111 and an input device 112, wherein the display screen 111 is used for displaying a honeypot management interface to receive a honeypot configuration operation performed on the honeypot management interface through the input device 112.

[0031] In the embodiment, the honeypot management module 11 is provided with a display screen 111 and an input device 112, such as a keyboard, a mouse, or a touchpad. Specifically, the display screen 111 can display a honeypot management interface, and a user can perform honeypot configuration operations on the honeypot management interface through the input device 112, such as simulating a printer with penetration or a server with a sensitive port.

[0032] With reference to Figure 2 Further, the first honeypot management module 12 and the first honeypot service module 13 can be optimized to each include a computing unit, a storage unit, and an editable network card, the first honeypot management module being configured to support management of honeypot services, and the first honeypot service module being configured to provide honeypot services according to honeypot simulation function requirements.

[0033] Unlike conventional honeypot products, which are mostly combined with a management end and a probe part, the probe, whether implemented in hardware or software, needs to be distributed in different areas of the network for deployment, and the deployment cost in the early stage will be relatively high. For example, the hardware needs to be wired in advance, and the software needs to be applied for virtualization resources in advance. In the embodiment, the computing unit, the storage unit, and the editable network card can form a separate computing node to simulate a honeypot that needs to be deployed separately. The reason for using a computing unit instead of a virtual machine is that the virtual machine simulation is easy to be recognized by hackers, so the embodiment adopts a computing unit with independence, which is more like a real device in a physical sense.

[0034] As described above, the computing unit and the storage unit are configured to the honeypot to be simulated, and the editable network card has an editable MAC address, such as a printer address if a printer is to be simulated, or an office computer address if an office computer is to be simulated. The portable host has two or more sets of computing units, storage units, and network cards, and a front-end operation face management end, and one set is used independently, that is, the first honeypot management module 12 is configured to manage honeypot services. The honeypot simulation function is used independently according to requirements, and the simulation is realized at the hardware level, that is, the first honeypot service module 13 is configured to provide honeypot services according to honeypot simulation function requirements. The honeypot is composed of a computing unit, a storage unit, and a network card, and each honeypot is deployed physically based on this, so it is not easy to be considered as a simulated device.

[0035] With reference to Figure 2 Further, the portable host 10 can be optimized to further include a first attack detection module 14 configured to detect traffic attack behaviors to and from the simulated honeypot of the portable host.

[0036] In the embodiment, the portable host 10 is provided with a separate attack detection module, referred to as a first attack detection module 14, which is configured to detect the attack behavior of the traffic to and from the simulated honeypot of the portable host.

[0037] With reference to the foregoing Figure 2 Further, the portable host further comprises a power module 15 configured to supply power to the portable host.

[0038] In the embodiment, the portable host further comprises a separate power module 15, which is exemplarily configured as a battery, and can be independently operated for 3-5 hours without external power supply.

[0039] With reference to the foregoing Figure 2 As an optional embodiment of the present application, on the basis of the foregoing embodiment, the optional embodiment can optimize the second honeypot management module 21 and the second honeypot service module 22, both of which comprise a computing unit, a storage unit and an editable network card, the second honeypot management module 21 is configured to support the management of the honeypot service, and the second honeypot service module 22 is configured to provide the honeypot service according to the functional requirements of the simulated honeypot.

[0040] It should be noted that the portable host 10 is already provided with a screen and an input device, so that the enhanced host 20 can be connected to the portable host 10, and the portable host 10 can control and configure the enhanced host 20, and the enhanced host 20 does not need a separate input / output device, but provides computing, storage and network-related functions.

[0041] In the embodiment, the same as the portable host, in the enhanced host 20, based on the computing unit, the storage unit and the editable network card, a separate computing node can be formed to simulate a honeypot that needs to be separately deployed originally. The reason why the computing unit is used instead of a virtual machine is that the virtual machine is easy to be recognized by hackers, so the embodiment adopts a separate computing unit, which is more like a real device in a physical sense.

[0042] According to the above description, the computing unit and the storage unit are configured as the honeypot to be simulated, and the editable network card has an editable MAC address, such as a printer to be simulated, the MAC address is edited into the address in the form of a printer, and such as an office computer to be simulated, the MAC address is edited into the address in the form of an office computer. The enhanced host has two or more sets of computing units, storage units, and network cards, and a management end, and one set is independently used, that is, the second honeypot management module 21 is used to support the management of the honeypot. The honeypot simulation function is independently used according to the demand, and the simulation at the hardware level is realized, that is, the second honeypot service module 22 is used to provide the honeypot service according to the demand of the honeypot simulation function. The constitution of the honeypot is constituted by the computing unit, the storage unit, and the network card, and based on this, the independent deployment of each honeypot from the physical aspect is realized, so that it is not easy to be considered as a simulated device. For the enhanced host 20, the computing unit and the storage unit at the server level can be used.

[0043] With reference to Figure 2 Further, the enhanced host 20 can further include a second attack detection module 23 configured to detect the traffic attack behavior of the simulated honeypot of the enhanced host.

[0044] In the embodiment, the enhanced host 20 has an independent attack detection module, which is referred to as the second attack detection module 23, and the second attack detection module 23 is configured to detect the traffic attack behavior of the simulated honeypot of the enhanced host.

[0045] With reference to Figure 2 Further, the enhanced host 20 can further include a full-traffic collection module 24 configured to collect and record the traffic attack behavior of the simulated honeypot of the portable host and the enhanced host.

[0046] In the embodiment, the portable host has limited performance, and therefore the full-traffic collection module is not integrated on the portable host 10. The enhanced host has larger volume and better performance, and can carry more hard disks and computing resources, and therefore the enhanced host 20 integrates the full-traffic collection module 24, which is configured to collect and record the traffic attack behavior of the simulated honeypot of the portable host and the enhanced host. In this way, when the attack behavior is detected, the complete attack traffic can be recorded, which is convenient for subsequent backtracking to find the attack behavior, portrait the attack behavior to locate the attack behavior, and improve the function of the honeypot to better capture the entire evidence chain through the honeypot.

[0047] Embodiment two

[0048] Figure 3A flowchart of a honeypot protection method provided by the second embodiment of the present application is shown in the figure. The method can be applied to the rapid deployment of a honeypot to locate an attacker. The method can be executed by a combined portable high-interactive honeypot system, which includes a portable host and a strengthened host. The system can be implemented in the form of hardware and / or software and can be configured in an electronic device, such as a notebook computer, as shown in the figure. The honeypot protection method provided by the second embodiment of the present application can specifically include the following steps: Figure 3

[0049] S301. According to the working mode of the combined portable high-interactive honeypot system, the portable host and / or the strengthened host are networked to provide a honeypot service through the portable host and / or the strengthened host.

[0050] In this embodiment, the combined portable high-interactive honeypot is composed of a portable host and a strengthened host, which can be used in combination or independently. The portable host and the strengthened host can be connected using a network cable or through a switch. The portable host can be in the form of a notebook computer. The strengthened host can be in the form of a server. The portable host includes an input / output module, a honeypot management module, and at least one first honeypot service module. The input / output module includes a display screen, a keyboard, a touchpad, etc., for user honeypot configuration operations and honeypot configuration content display. The module for implementing the management function of the honeypot is referred to as the first honeypot management module, which supports the front-end operation face management end, such as management of the honeypot service, calling of other modules, etc. The honeypot service module included in the portable host is referred to as the first honeypot service module. The module for implementing the management function of the honeypot is referred to as the second honeypot management module, which supports the front-end operation face management end, such as management of the honeypot service, calling of other modules, etc. The honeypot service module included in the strengthened host is referred to as the second honeypot service module. The second honeypot management module and the second honeypot service module both include a computing unit, a storage unit, and an editable network card, etc. The first honeypot service module is used independently according to demand for honeypot simulation functions, and the second honeypot service module is also used independently according to demand for honeypot simulation functions.

[0051] ​The combined portable high-interactive honeypot system has three working modes, including a rapid deployment mode, a strengthened mode and a combined deployment mode. If the working mode of the combined portable high-interactive honeypot system is the rapid deployment mode, the portable host is connected to a network so that the portable host provides a honeypot service. If the working mode of the combined portable high-interactive honeypot system is the strengthened mode, the portable host is connected to the strengthened host through a control port, and the strengthened host is controlled to be connected to the network so that the strengthened host provides the honeypot service. If the working mode of the combined portable high-interactive honeypot system is the combined deployment mode, the portable host and the strengthened host are both controlled to be connected to the network so that the portable host and the strengthened host both provide the honeypot service.

[0052] In the above technical solution, the portable host and the strengthened host of the combined honeypot are integrated with the management end and the probe, respectively, the management and the probe function are independently operated through the plurality of honeypot service modules, the portable host and the strengthened host can be used in combination or independently, and the rapid deployment and the reduced deployment cost can be achieved.

[0053] As a specific implementation, the portable host and / or the strengthened host can be controlled to be connected to the network according to the working mode of the combined portable high-interactive honeypot system, so that the honeypot service is provided through the portable host and / or the strengthened host, including:

[0054] 1) If the working mode of the combined portable high-interactive honeypot system is the rapid deployment mode, the portable host is controlled to be connected to the network, so that the portable host simulates the honeypot to provide the honeypot service.

[0055] In this embodiment, if the working mode of the combined portable high-interactive honeypot system is the rapid deployment mode, the portable host is connected to the network alone, a printer with weak password, a pos machine with vulnerability, an office terminal with remote login enabled, a file server and the like can be simulated, and the portable host is provided with a battery, so that the portable host can continuously work for 3-5 hours in some non-powered environment, and the needs of temporarily building a target field environment of attack and defense competition can be met.

[0056] 2) If the working mode of the combined portable high-interactive honeypot system is the strengthened mode, the portable host is connected to the strengthened host through the control port, the portable host is used to control the strengthened host to be connected to the network, and the strengthened host simulates the honeypot to provide the honeypot service.

[0057] In this embodiment, if the working mode of the combined portable high-interactive honeypot system is the strengthened mode, the portable host is connected to the network, the portable host is connected to the strengthened host through the control port, and the strengthened host simulates a medium-interactive website background, a subnet composed of a firewall and multiple servers, and a relatively complex multiple office terminal scene. It can be understood that the portable host is used to control the strengthened host, and the strengthened host is provided with an input and output device.

[0058] 3) If the working mode of the combined portable high-interactive honeypot system is the combined deployment mode, the portable host and the enhanced host are both networked, the portable host simulates the operation and maintenance terminal, and the enhanced host simulates the server cluster, so as to simulate the scenario that the hacker attacks the server cluster after obtaining the operation and maintenance terminal permission.

[0059] In the embodiment, if the working mode of the combined portable high-interactive honeypot system is the combined deployment mode, the portable host and the enhanced host are both networked, the portable host simulates the operation and maintenance terminal, and the enhanced host simulates the server cluster, so as to simulate the scenario that the hacker attacks the server cluster after obtaining the operation and maintenance terminal permission.

[0060] The above technical solution specifically realizes three working modes of the combined portable interactive honeypot system in honeypot protection, and the portable host and / or the enhanced host are used for working in different working modes. Different from the traditional honeypot management control front end and the honeypot function back end, which are deployed separately, there is a long deployment cycle and relatively complex debugging. The combined portable interactive honeypot system provided by the present application integrates the honeypot management function and the honeypot function together. The present application is more convenient to deploy and is more suitable for scenarios that require rapid deployment and non-persistent use. The portable host can be used to independently realize deployment and configuration work, and is suitable for scenarios that require rapid deployment of honeypot technology.

[0061] The honeypot protection method provided by the embodiment of the present application can be executed by the combined portable interactive honeypot system provided by any embodiment of the present application, and has the corresponding functions and beneficial effects of the execution system.

[0062] It should be understood that various forms of processes shown above can be used to reorder, add or delete steps. For example, each step described in the present application can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, and the present application does not limit this.

[0063] The above specific embodiments do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent replacement and improvement within the spirit and principles of the present application should be included in the protection scope of the present application.

Claims

1. A combined portable high-interaction honeypot system, characterized in that, include: A portable host and an enhanced host are provided, wherein the portable host is communicatively connected to the enhanced host, the portable host includes an input / output module, a first honeypot management module and at least one first honeypot service module, and the enhanced host includes a second honeypot management module and at least one second honeypot service module; The first honeypot management module is used to receive honeypot configuration operations performed through the input / output module in order to configure the first honeypot service module; and / or The second honeypot management module is used to receive honeypot configuration operations performed through the input / output module in order to configure the second honeypot service module; The first honeypot service module and / or the second honeypot service module are used to provide honeypot services based on the honeypot configuration information formed by the honeypot configuration operation; Wherein, the first honeypot service module and / or the second honeypot service module are used to provide honeypot services based on the honeypot configuration information formed by the honeypot configuration operation, including: The working modes of the combined portable high-interaction honeypot system include rapid deployment mode, enhanced mode, and combined deployment mode. If the working mode is the rapid deployment mode, the portable host connects to the network, and the first honeypot service module provides honeypot services based on the honeypot configuration information formed by the honeypot configuration operation; If the working mode is the enhanced mode, the portable host and the enhanced host are connected through the control port, and the input / output module of the portable host is used to control the enhanced host to connect to the network. The second honeypot service module provides honeypot services based on the honeypot configuration information formed by the honeypot configuration operation. If the working mode is a combined deployment mode, then both the portable host and the enhanced host are connected to the network, and both the first honeypot service module and the second honeypot service module provide honeypot services based on the honeypot configuration information formed by the honeypot configuration operation.

2. The combined portable high-interaction honeypot system according to claim 1, characterized in that, The input / output module includes: a display screen and an input device, wherein... The display screen is used to display the honeypot management interface to receive honeypot configuration operations performed on the honeypot management interface through the input device.

3. The combined portable high-interaction honeypot system according to claim 1, characterized in that, Both the first honeypot management module and the first honeypot service module include: a computing unit, a storage unit, and an editable network interface card. The first honeypot management module is used to manage the honeypot service, and the first honeypot service module is used to provide honeypot services according to the honeypot simulation function requirements.

4. The combined portable high-interaction honeypot system according to claim 1, characterized in that, The portable host also includes a first attack detection module, used for: Traffic attack behaviors entering and leaving the honeypot simulated by the portable host are detected.

5. The combined portable high-interaction honeypot system according to claim 1, characterized in that, The portable host also includes a power module for: Power the portable host unit.

6. The combined portable high-interaction honeypot system according to claim 1, characterized in that, Both the second honeypot management module and the second honeypot service module include: a computing unit, a storage unit, and an editable network interface card. The second honeypot management module is used to manage the honeypot service, and the second honeypot service module is used to provide honeypot services according to the honeypot simulation function requirements.

7. The combined portable high-interaction honeypot system according to claim 1, characterized in that, The enhanced host also includes a second attack detection module, used for: Traffic attack behaviors entering and leaving the honeypot simulated by the enhanced host are detected.

8. The combined portable high-interaction honeypot system according to claim 7, characterized in that, The enhanced host also includes a full-traffic acquisition module, used for: Collect and record the traffic attack behavior entering and leaving the simulated honeypot of the portable host and the enhanced host.

9. A honeypot protection method, characterized in that, Performed by the combined portable high-interaction honeypot system according to any one of claims 1-8, the combined portable high-interaction honeypot system comprising a portable host and an enhanced host, the method comprising: According to the working mode of the combined portable high-interaction honeypot system, the portable host is controlled to connect to the network so as to provide honeypot services through the portable host; and / or According to the working mode of the combined portable high-interaction honeypot system, the enhanced host is controlled to connect to the network so as to provide honeypot services through the enhanced host.

10. The method according to claim 9, characterized in that, According to the working mode of the combined portable high-interaction honeypot system, the portable host is controlled to connect to the network so as to provide honeypot services through the portable host; And / or, according to the operating mode of the combined portable high-interaction honeypot system, control the enhanced host to connect to the network to provide honeypot services through the enhanced host, including: If the working mode of the combined portable high-interaction honeypot system is the rapid deployment mode, then the portable host is controlled to connect to the network to simulate a honeypot and provide honeypot services through the portable host; If the working mode of the combined portable high-interaction honeypot system is the enhanced mode, then the portable host and the enhanced host are connected through the control port, the input / output module of the portable host is used to control the enhanced host to connect to the network, and the enhanced host is used to simulate a honeypot to provide honeypot services. If the working mode of the combined portable high-interaction honeypot system is the combined deployment mode, then both the control portable host and the enhanced host are connected to the network. The portable host simulates the operation and maintenance terminal, and the enhanced host simulates the server cluster, so as to simulate the scenario where a hacker attacks the server cluster after obtaining the operation and maintenance terminal privileges.

Citation Information

Patent Citations

  • Honeypot-based defense method, device, honeypot system and honeypot management server

    CN110493238A