Honeypot network simulation method and system based on an attack trapping system

By building a multi-level honeypot network and generating structured attack instructions, using threat assessment and deception factor adjustment, the honeypot network is solved by insufficient accuracy in analyzing attacker behavior, and achieving more efficient attacker trapping and identification.

CN119696932BActive Publication Date: 2025-06-20BEIJING YUAN FULCRUM INFORMATION SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510199363.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-06-20
Estimated Expiration
2045-02-24

AI Technical Summary

Technical Problem

When analyzing attacker behavior, the existing honeypot network has a large number of trial and error attack instructions, which makes it difficult for security personnel to understand the attacker's purpose, reducing the accuracy of the honeypot network's trapping of attack behavior.

Method used

By building a multi-level honeypot network, we generate attack instructions that include attack order, target hierarchy and threat target types, use the number of threat files and threat ratings to calculate the defense impact requirements evaluation and attack link deployment integrity, adjust the file type deception factor, improve the anti-identification probability of attack instructions, and realize the trapping of attackers.

Benefits of technology

It improves the accuracy of the honeypot network to trap attackers, enhances the ability to identify and trace attackers, and improves the security policies and defense measures of the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696932B_ABST
    Figure CN119696932B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of network security implementation countermeasures, and specifically relates to a honeypot network simulation method and system based on an attack decoy system, including: constructing a honeypot network with a number of honeypots at each level and attack instructions, obtaining an evaluation of the defense impact requirements of the attack instructions and the integrity of the attack link deployment; comparing the stability of the current attack instructions to obtain the file type deception factor of the attack instructions; using the file type deception factor under the attack instructions of the next attack order to adjust the authorization status of the authorized decoy files corresponding to the threat target type, and combining the threat rating changes of the current attack instructions and the next attack instructions to obtain the anti-identification probability of the current attack instructions; obtaining a prior attack interaction link according to the anti-identification probability to achieve the decoy of the attacker. The purpose of the present invention is to dynamically decoy the attacker by the honeypot network according to the tactical purpose tendency of the attack instructions, and increase the decoy interaction times of the honeypot network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security implementation countermeasures, and particularly relates to a honeypot network simulation method and system based on an attack trapping system. Background Art

[0002] Honeypot network simulation is an attack trapping method for protecting server security. By constructing a honeypot network, some virtual resources with temptation and importance are actively exposed to attackers, so as to attract attackers to attack. Security personnel can understand the attack methods, tools used, attack targets and attack intentions of attackers by monitoring the logs of the interaction content between attackers and the honeypot network, and then improve the server's security policy, strengthen defense measures and trace the origin of attackers.

[0003] All behaviors generated by attackers when attacking a server are recorded in the threat intelligence of the honeypot network and the attack and defense logs of the server. However, when attackers attack the server, they are in a blind attack state, resulting in a large number of attack instructions belonging to trial-and-error behaviors when analyzing the attack and defense logs. As a result, there is not much available information in the attack and defense logs for security personnel to understand the attack purposes of attackers, which affects the targeted assessment of attackers and reduces the trapping accuracy of the honeypot network for attack behaviors. Summary of the Invention

[0004] The present invention provides a honeypot network simulation method and system based on an attack trapping system to solve the existing problems.

[0005] The honeypot network simulation method and system based on an attack trapping system of the present invention adopt the following technical solutions:

[0006] An embodiment of the present invention provides a honeypot network simulation method based on an attack trapping system, and the method includes the following steps:

[0007] Construct a honeypot network with several honeypots at each level, and each honeypot contains several authorized trapping files;

[0008] Construct attack instructions including the attack order, the targeted level and the threat target type;

[0009] Obtain the threat rating and the number of threat files of the attack instructions;

[0010] Use the number of threat files and the threat rating to reflect the threat situation of the attack instructions, and obtain the defense impact requirement evaluation of the attack instructions;

[0011] Analyze the attack order of the attack instructions and the degree of intrusion into the honeypot network level, and obtain the integrity of the attack link deployment of the attack instructions;

[0012] Compare the stability of the defense impact requirement evaluation of the current attack instruction relative to the attack instructions in the previous attack order, and combine the integrity of the attack link deployment of the current attack instruction to obtain the file type deception factor of the honeypot network for the current attack instruction;

[0013] Under the attack instruction of the next attack order, use the file type deception factor to adjust the authorization status of the authorized trapped files corresponding to the threat target type, and combine the change in the threat rating of the current attack instruction and the next attack instruction to obtain the anti-identification probability of the current attack instruction;

[0014] Implement and judge the attack instructions in sequence according to the anti-identification probability to obtain the prior attack interaction link;

[0015] Use the prior attack interaction link to induce the attacker to achieve the trapping of the attacker.

[0016] Preferably, the specific steps for obtaining the defense impact requirement evaluation include:

[0017] Record the targeting level of the th attack instruction as the th level;

[0018] Record the threat target type of the th attack instruction as the th type;

[0019] Record the number of authorized trapped files of the th type in the th level as ;

[0020] Record the number of threat files of the th attack instruction as ;

[0021] Record the total number of trapped files accessed by the th attack instruction in the th level as ;

[0022] The calculation method of the defense impact requirement evaluation of the th attack instruction is:

[0023]

[0024] where is a preset hyperparameter, , used to avoid the denominator being 0;

[0025] is the threat rating of the th attack instruction, The maximum threat rating of all attack instructions before the attack order of the attack instruction of the

[0026] Preferably, the specific steps for obtaining the integrity of the attack link deployment include:

[0027] Record the current attack instruction as the attack instruction of the

[0028] Record the number of first occurrences of the targeted levels of all attack instructions before the attack order of the attack instruction of the as the intrusion level number of the attack instruction of the

[0029] wherein, the number of first occurrences of the targeted levels of all attack instructions refers to the number of levels in all levels of the honeypot network that have been attacked by the attack instructions; The calculation method of the integrity of the attack link deployment of the attack instruction of the

[0030]

[0031] is: where is the attack order of the

[0032] attack instruction of the

[0033] Preferably, the specific steps for obtaining the file type decoy factor of the honeypot network for the current attack instruction by comparing the stability of the evaluation of the defense impact requirement of the current attack instruction with respect to the attack instructions of the previous attack order and combining the integrity of the attack link deployment of the current attack instruction include:

[0034] Compare the evaluation of the defense impact requirement of the current attack instruction with respect to the attack instructions of the previous attack order to obtain the deviation degree of the tactical purpose of the current attack instruction;

[0035] According to the deviation degree of the tactical purpose of the current attack instruction and the integrity of the attack link deployment of the current attack instruction, obtain the file type decoy factor of the honeypot network for the current attack instruction.

[0036] Preferably, the specific steps for obtaining the deviation degree of the tactical purpose include:

[0037] Obtain the evaluation of the defense impact requirement of all attack instructions before the attack order of the current attack instruction, denoted as the evaluation of the defense impact requirement of historical attack instructions, and calculate the skewness of the evaluation of the defense impact requirement of all historical attack instructions with respect to the evaluation of the defense impact requirement of the current attack instruction, denoted as the deviation degree of the tactical purpose of the current attack instruction.Preferably, the specific steps for obtaining the file type decoy factor include:

[0038] Multiply the reciprocal of the absolute value of the deviation degree of the tactical purpose of the current attack instruction by the integrity of the attack link deployment of the current attack instruction, and denote it as the file type decoy factor of the current attack instruction;

[0039] The inverse proportional result of the deviation degree of the tactical purpose of the current attack instruction is used to reflect the stability of the evaluation of the defense impact requirement of the current attack instruction relative to the attack instructions in the previous attack order.

[0040] Preferably, the specific steps for obtaining the anti-identification probability of the current attack instruction by using the file type decoy factor under the attack instruction in the next attack order, adjusting the authorization status of the authorized trap files corresponding to the threat target type, and combining the changes in the threat ratings of the current attack instruction and the next attack instruction include:

[0041] Preset the initial reward amount;

[0042] When the first attack instruction is executed, record the initial reward amount as the reward amount of the first attack instruction;

[0043] Adjust the reward amount of the first attack instruction according to the file type decoy factor of the first attack instruction in the honeypot network to obtain the reward amount of the second attack instruction;

[0044] And so on, obtain the reward amount of the attack instruction in the next attack order;

[0045] Adjust the authorization status of the authorized trap files corresponding to the threat target type of the attack instruction in the next attack order according to the reward amount of the attack instruction in the next attack order;

[0046] Obtain the anti-identification probability of the current attack instruction according to the reward amount and threat rating of the attack instruction in the next attack order.

[0047] Preferably, the specific steps for obtaining the reward amount of the attack instruction in the next attack order include:

[0048] Denote the attack instruction in the next attack order as the th attack instruction;

[0049] The way to obtain the reward amount of the th attack instruction is:

[0050] Denote the reward amount of the attack by the th attack instruction as ;

[0051] The reward amount of the th attack instruction The calculation method is as follows:

[0052]

[0053] is the file type deception factor of the honeypot network for the th attack instruction, and is the premnmx function.

[0054] Preferably, the specific steps for obtaining the prior attack interaction link include:

[0055] Preset a recognition threshold. If the anti-recognition probability of the current attack instruction is greater than or equal to the recognition threshold, stop adjusting the reward amount of the attack instruction corresponding to the next attack order by the reward amount of the next attack instruction. If the anti-recognition probability of the current attack instruction is less than the recognition threshold, adjust the reward amount of the attack instruction corresponding to the next attack order by the reward amount of the next attack instruction;

[0056] After obtaining the anti-recognition probability of each attack instruction and sequentially executing all attack instructions, use the number of authorized trapped files of each type of file at each level in the honeypot network as a prior attack interaction link.

[0057] The present invention also proposes a honeypot network simulation system based on the attack trapping system. The system includes a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of the above method are implemented.

[0058] The beneficial effects of the technical solution of the present invention are as follows: constructing a honeypot network with several honeypots at each level; constructing attack instructions including the attack order, the targeted level, and the type of threat target; obtaining the threat rating and the number of threat files of the attack instructions; using the number of threat files and the threat rating to reflect the threat situation of the attack instructions, and obtaining the evaluation of the defense impact requirement of the attack instructions; the evaluation of the defense impact requirement can reflect the clarity of the tactical purpose of the attack instructions, and distinguish between interference attack instructions and attack instructions with clear tactical purposes; analyzing the attack order of the attack instructions and the degree of intrusion into the levels of the honeypot network, and obtaining the integrity of the attack link deployment of the attack instructions; the integrity of the attack link deployment reflects the degree of deception of the virtual attacker by the honeypot network, and the greater the degree of deception, the easier it is for the honeypot network to be recognized by the virtual attacker, and the greater the degree of deception of the attacker is required; comparing the stability of the evaluation of the defense impact requirement of the current attack instruction with that of the attack instructions in the previous attack order, and combining the integrity of the attack link deployment of the current attack instruction, obtaining the file type deception factor of the honeypot network for the current attack instruction; reflecting the degree of adjustment of the authorization situation of the authorized trap files corresponding to the type of threat target, and being used to continue the interaction between the honeypot network and the virtual attacker; under the attack instructions of the next attack order, using the file type deception factor to adjust the authorization situation of the authorized trap files corresponding to the type of threat target, and combining the change in the threat rating between the current attack instruction and the next attack instruction, obtaining the anti-identification probability of the current attack instruction; reflecting the recognition situation of the virtual attacker for the honeypot network; implementing and judging the attack instructions in sequence according to the anti-identification probability, and obtaining the prior attack interaction link; using the prior attack interaction link to induce the attacker and realizing the trapping of the attacker. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0060] Figure 1 It is a flowchart of the steps of the honeypot network simulation method based on the attack trapping system of the present invention;

[0061] Figure 2 It is a schematic diagram of the honeypot network proposed in an embodiment of the present invention;

[0062] Figure 3 It is a flowchart of sequentially executing attack instructions proposed in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0063] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of the honeypot network simulation method and system based on the attack trapping system proposed by the present invention, its specific implementation method, structure, features and effects, in conjunction with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.

[0064] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0065] The specific scheme of the honeypot network simulation method and system based on the attack trapping system provided by the present invention is described in detail below with reference to the accompanying drawings.

[0066] See also Figure 1 , which shows a flow chart of the steps of a honeypot network simulation method based on an attack trapping system provided by an embodiment of the present invention, the method comprising the following steps:

[0067] Traditional honeypot networks analyze the attacker's intentions based on the attack and defense logs recorded by the server, and randomly release virtual important information through honeypots to guide the attacker to attack virtual resources, and then adjust the server's protection strategy after inducing the attacker; however, the attacker behavior analyzed by the traditional honeypot network mainly depends on the interaction between the honeypot and the attacker. When the type of important information released by the honeypot is different from the attacker's attack type, invalid records will exist in the attack and defense logs, and the different types will also reduce the number of interactions between the attacker and the honeypot, causing the attacker to see through the honeypot too early, causing the server's deception defense to fail.

[0068] In order to solve the above problems, this embodiment proposes a honeypot network simulation method based on an attack trapping system. The method constructs an attack instruction of a virtual attacker, and the attack instruction has an attack order. The virtual attacker attacks the honeypot network according to the attack order. The honeypot network analyzes the attack situation of each attack instruction on the decoy file under the honey point in the honeypot network, analyzes the type of the attacked decoy file, and adjusts the proportion of the corresponding type of decoy file in the honey point, so that the next attack instruction is more inclined to the file type expected by the current attack instruction, thereby preventing the attacker from seeing through the honeypot network too early, increasing the number of interactions between the attacker and the honeypot, and generating a priori attack interaction links according to the attack order based on the virtual attacker's attack instructions on the honeypot network. When the attack of the actual attacker's attack instruction is the same as the priori attack interaction link, the priori attack interaction link is used to induce the attacker to reduce the difficulty of analysis.

[0069] In this embodiment, the specific steps of the honeypot network simulation method based on the attack trapping system are as follows:

[0070] Step S001: Construct a honeypot network with several honeypots at each level; construct attack instructions including the attack order, the targeted level, and the threat target type, and obtain the threat rating and the number of threat files of the attack instructions.

[0071] It should be noted that in this embodiment, by increasing the interaction times between the attacker and the honeypot, and then analyzing the attack instructions to increase the interaction times and generate the prior attack interaction link, so first construct the honeypot network of the attack trapping system and the attack instructions of the virtual attacker.

[0072] Preferably, the constructed honeypot network in this embodiment is as follows:

[0073] Construct an initialization network, the initialization network is a tree - type network topology, the initialization network contains several levels, and each level contains several network nodes; it should be noted that constructing the initialization network is a prior art, and this embodiment does not specifically limit the construction of the initialization network. The initialization configuration of each node in the initialization network, such as port information and other well - known operations, will not be elaborated in this embodiment.

[0074] Deposit several prior trap files of the same file type into each node, and the file types include images, data, structured data, unstructured data, etc.;

[0075] Divide all the trap files in each node equally, mark half of them as authorized trap files and the other half as unauthorized trap files;

[0076] Randomly mark several nodes as honeypots to form a honeypot network;

[0077] It should be noted that the authorized trap files are files that can be accessed by the attacker, and the unauthorized trap files are files that cannot be accessed by the attacker. This embodiment does not limit the division of the authorization situation of the trap files, and other embodiments can adjust the proportion of the authorized files. As Figure 2 shown, it is a schematic diagram of the honeypot network with a tree - type network topology in this embodiment, which contains three levels, each level contains several nodes, and the nodes marked with "star" are honeypots.

[0078] Preferably, the steps for constructing the attack instructions in this embodiment are:

[0079] It should be noted that the attack instructions in this embodiment are threat intelligence in the format of Structured Threat Information Expression (STIX). Structured Threat Information Expression is a language and serialization format for exchanging Cyber Threat Intelligence (CTI), usually in the json data format, and is used to store the information of attack instructions and the targeted objects.

[0080] Construct a number of attack instructions. Each attack instruction includes the attack order, the targeted level, the expected number of attacked files, the set of threat keywords, and the threat target type. It should be noted that the attack order and the targeted level of the attack instructions do not correspond, and the levels are random in the sequential attack order. In this embodiment, a total of 50 attack instructions are constructed for description. Among them, the threat keywords are the keywords of the attack instructions under the threat target type, and are used to match the trap files in the honeypots that need to be attacked.

[0081] It should be especially noted that since the attacker has obvious targeting when attacking the server, in order to simulate the attacks of real attackers as much as possible, the threat target types and threat keywords of the attack instructions constructed in this embodiment have a high degree of similarity.

[0082] Therefore, by using the jieba word segmentation algorithm and the TF-TDF algorithm, obtain the keywords of all trap files corresponding to the file type of the threat target type of the attack instruction, which are recorded as the quasi-matching keywords of each attack instruction. Use the threat keywords and quasi-matching keywords of each attack instruction to construct word vectors, and obtain the similarity between each threat keyword in the threat keyword set of each attack instruction and all quasi-matching keywords through the cosine similarity algorithm. Denote the mean value of the similarities as the threat rating of the attack instruction. The value range of the threat rating of the attack instruction is .

[0083] It should be noted that the more similar each threat keyword in the threat keyword set is to the quasi-matching keyword in the trap file, the easier it is for the attack instruction to attack the node or honeypot containing the trap file, that is, the higher the threat of the attack instruction to the server. Among them, the jieba word segmentation algorithm and the TF-TDF algorithm are well-known existing technologies, and will not be elaborated in this embodiment.

[0084] Further, connect the attack instruction to the honeypot network, and obtain the number of trap files accessed by each attack instruction among all honeypots at the corresponding level through the honeypot network log, which is recorded as the threat file number of each attack instruction; the number of trap files accessed by the attacked instruction represents the number of authorized trap files of the file type corresponding to the threat target type of the attack instruction.

[0085] Step S002: Use the threat file number and threat rating to reflect the threat situation of the attack instruction, and obtain the evaluation of the defense impact requirement of the attack instruction.

[0086] It should be noted that the tactical purpose of the virtual attacker is unknown to the honeypot network. However, during the attack process, as the attack order of the attack instructions increases, the tactical purpose will gradually be exposed, which is reflected in the access situation of the threat file number of the attack instructions to all trap files in the honeypot network.

[0087] Furthermore, it should be noted that the attack instructions of the virtual attacker do not fully conform to its attack tactical purpose. Some attack instructions are used to interfere and avoid easily recognizable attack instructions by the server. Therefore, some attack instructions belong to interfering with the server to avoid exposing the attack purpose. If the current attack instruction is more in line with the tactical purpose of the virtual attacker, after the threat keywords in the attack instruction match the trap files in the honeypot, more trap files will be accessed by the attack instruction, and the threat rating of the attack instruction will be greater. Therefore, more trap files of the same file type as the threat target type in the honeypot are accessed, and this attack instruction requires a greater server defense impact requirement.

[0088] Preferably, the specific steps of using the threat file number and threat rating to reflect the threat situation of the attack instruction and obtaining the evaluation of the defense impact requirement of the attack instruction are as follows:

[0089] Record the corresponding level of the th attack instruction as the th level;

[0090] Record the threat target type of the th attack instruction as the th type;

[0091] Record the number of authorized trap files of the th type in the th level as ;

[0092] Record the threat file number of the th attack instruction as ;

[0093] Record the th attack instruction at the The total number of trap files accessed in a level is denoted as ;

[0094] The defense impact requirement evaluation of the attack instruction is calculated as follows: The calculation method is:

[0095]

[0096] wherein, is a preset hyperparameter, and in this embodiment, is taken to avoid the denominator being 0; is the threat rating of the attack instruction, is the maximum value of the threat ratings of all the attack instructions before the attack order of the attack instruction.

[0097] It should be noted that represents the number of trap files not accessed by the attack instruction under all the authorized trap files corresponding to the threat target type of the attack instruction. The smaller this value is, and the larger the total number of trap files accessed by the attack instruction in the level is, the greater the threat of the attack instruction to the authorized trap files of its threat target type; represents the threat rating of the attack instruction. The larger this value is, the more it can show the purposefulness of the attack among all the previous attack instructions.

[0098] So far, the defense impact requirement evaluations of each attack instruction have been obtained. The defense impact requirement evaluation can reflect the clarity of the tactical purpose of the attack instruction and distinguish between interference attack instructions and attack instructions with clear tactical purposes.

[0099] Step S003: Analyze the attack order of the attack instruction and the degree of intrusion into the honeypot network layer to obtain the integrity of the attack link deployment of the attack instruction.

[0100] It should be noted that when the attacker attacks the server, the more attack instructions are executed, the more resources of the server are stolen by the attacker. Similarly, the more attack instructions of the attacker are trapped by the honeypot network, the more it can show the effectiveness of the honeypot network and the more the analysis of the attack can reflect the tactical purpose of the attacker.

[0101] Further, it should be noted that the target level of the attack instructions set in this embodiment has no relation to the attack order. Therefore, the more levels of the honeypot network the executed attack instructions invade and the more attack instructions are executed, the more it can show that the honeypot network has not been detected by the attacker. Furthermore, the attacker can be continuously lured to execute attack instructions. The honeypot network can continuously lure the attacker by releasing more unauthorized decoy files that tend to tactical purposes to the honey points, and the greater the degree of release required as more attack instructions are executed.

[0102] Preferably, the specific steps for analyzing the attack order of the attack instructions and the degree of invading the levels of the honeypot network to obtain the integrity of the attack link deployment of the attack instructions are as follows:

[0103] Record the current attack instruction as the th attack instruction;

[0104] Record the number of the first occurrences of the target levels of all the attack instructions before the attack order of the th attack instruction as the number of invaded levels of the th attack instruction ; The number of the first occurrences of the target levels indicates: the levels in all levels of the honeypot network that have been attacked by the attack instructions when the th attack instruction is executed.

[0105] The integrity of the attack link deployment of the th attack instruction is calculated as follows:

[0106]

[0107] where is the attack order of the th attack instruction.

[0108] It should be noted that the larger the value of the attack order of the attack instructions, the more complete the attack link established by the virtual attacker through executing multiple attack instructions on the honeypot network. The larger the value of the number of invaded levels, the more levels in the network hierarchy the virtual attacker has penetrated up to the current attack instruction. Then, when the invaded attack link is more complete, the tactical purpose of the virtual attacker is more clear. At this time, more trapping information needs to be applied to the virtual attacker to maintain the attack desire of the virtual attacker.

[0109] So far, the integrity of the attack link deployment of the current attack instruction has been obtained. The integrity of the attack link deployment reflects the degree of being lured of the virtual attacker by the honeypot network. The greater the degree of being lured, the easier it is for the honeypot network to be detected by the virtual attacker, and the greater the degree of luring the attacker required.

[0110] Step S004, compare the stability of the defense impact demand evaluation of the current attack instruction with that of the previous attack order attack instruction, and combine the attack link deployment integrity of the current attack instruction to obtain the file type deception factor of the honeypot network for the current attack instruction; use the file type deception factor under the attack instruction of the next attack order to adjust the authorization status of the authorized trapping file corresponding to the threat target type, and combine the threat rating changes of the current attack instruction and the next attack instruction to obtain the anti-recognition probability of the current attack instruction.

[0111] It should be noted that the greater the attack link deployment integrity of the current attack instruction, the more sensitive the virtual attacker is to whether he is induced by the honeypot network, that is, whether the honeypot network is discovered by the virtual attacker. If the virtual attacker cannot obtain more entrapped files in the next attack instruction, he may lose the desire to attack and terminate the interaction with the honeypot network, causing the honeypot network to lack the basis for analyzing the tactical purpose of the virtual attacker.

[0112] It should be further explained that, in this embodiment, the tactical objectives of the virtual attacker are unknown, and therefore the ratio of authorized entrapped files to unauthorized entrapped files for different file types in each preset node and honey spot is the same. However, in the process of responding to the attacker's attack instructions, the entrapped files exposed by the honey spot may not arouse the attacker's intention. When the attacker finds entrapped files that meet his tactical objectives, his attack instructions access more file types corresponding to the threat target type at the targeted level, making the defense impact demand evaluation value of the attack instruction larger. Then the honeypot network needs to release more authorization permissions for unauthorized entrapped files according to the file types corresponding to the threat target type.

[0113] It should be further explained that the honeypot network adjusts the authorization permissions mainly based on the preset fixed reward amount for each attack instruction. The reward amount is used to open the permissions of a certain proportion of unauthorized entrapped files to authorized entrapped files, thereby inducing the virtual attacker. However, in this process, if an attack instruction with a smaller attack order releases too many entrapped files, it will make it easier for the virtual attacker to detect the honeypot network. If an attack instruction with a larger attack order releases too few entrapped files, it will lead to insufficient attack desire of the virtual attacker, that is, the virtual attacker will not be interested in attacking, thereby terminating the interaction prematurely. Therefore, this embodiment analyzes the changes in the defense impact demand evaluation of different attack instructions during the execution of the attack instructions, thereby adaptively changing the reward amount for the next attack instruction, thereby improving the probability of maintaining the interaction between the virtual attacker and the honeypot network.

[0114] Preferably, the specific steps for obtaining the file type deception factor of the honeypot network for the current attack instruction by comparing the stability of the defense impact requirement evaluation of the current attack instruction with that of the attack instruction in the previous attack order and combining the integrity of the attack link deployment of the current attack instruction are as follows:

[0115] The file type deception factor of the honeypot network for the th attack instruction is calculated as follows:

[0116]

[0117] Wherein, is the integrity of the attack link deployment of the th attack instruction, is the attack order of the th attack instruction, is the standard deviation of the defense impact requirement evaluations of all the attack instructions before the attack order of the th attack instruction, is the defense impact requirement evaluation of the th attack instruction before the attack order of the th attack instruction, is the defense impact requirement evaluation of the th attack instruction; is the absolute value function, is the reciprocal function, is a preset hyperparameter, which is taken as in this embodiment to avoid a zero denominator.

[0118] Wherein represents represents the defense impact requirement evaluation of the th attack instruction before the attack order of the th attack instruction, that is, the defense impact requirement evaluation of the th attack instruction is used as the defense impact requirement evaluation of the historical attack instruction, and the skewness of the defense impact requirement evaluations of all historical attack instructions relative to the defense impact requirement evaluation of the th attack instruction is obtained and denoted as the deviation degree of the tactical purpose of the current attack instruction. The closer the value of the deviation degree of the tactical purpose is to 0, the smaller the deviation is. The skewness is a well-known technology and will not be elaborated in this embodiment;

[0119] In this embodiment, the result of taking the reciprocal of the absolute value of the skewness reflects the stability of the defense impact requirement evaluation of the current attack instruction relative to the attack instructions in the previous attack order. The larger the value, the more stable the defense impact requirement evaluation, that is, the The more an attack instruction conforms to the tactical objectives of the virtual attacker, the more conducive the deception based on this attack instruction is to the continuation of the interaction and the prevention of the honeypot network from being detected. Conversely, it is easier for the virtual attacker to see through the inducement of the honeypot network;

[0120] For the attack link deployment integrity of the attack instruction, it reflects the completeness of the attack link construction. The more complete the construction, the greater the file type deception factor, that is, more information needs to be released to continue the interaction.

[0121] So far, after obtaining the file type deception factor of the honeypot network for the current attack instruction, it reflects the adjustment degree of the authorization situation of the authorized trap files corresponding to the threat target type, and is used to continue the interaction between the honeypot network and the virtual attacker.

[0122] Preferably, under the attack instruction of the next attack order, using the file type deception factor, adjusting the authorization situation of the authorized trap files corresponding to the threat target type, and combining the threat rating changes of the current attack instruction and the next attack instruction, the specific steps to obtain the anti-identification probability of the current attack instruction are as follows:

[0123] When constructing the honeypot network, a preset initial reward amount is set. In this embodiment, the initial reward amount is described by taking 10% as an example;

[0124] When the first attack instruction is executed, record the initial reward amount as the reward amount of the first attack instruction;

[0125] According to the file type deception factor of the honeypot network for the first attack instruction, adjust the reward amount of the first attack instruction to obtain the reward amount of the second attack instruction;

[0126] And so on, the acquisition method of the reward amount of the attack instruction is:

[0127] Record the reward amount of the attack of the attack instruction as ;

[0128] The reward amount of the attack instruction

[0129]

[0130] Among them, is the file type deception factor of the honeypot network for the attack instruction, is the premnmx function, which is used to normalize the file type deception factor, and the normalization range is .

[0131] It should be noted that, in this embodiment, The file type deception factor has a value range of the bonus effect on the reward amount. When it is less than 1, it weakens the gain, and when it is greater than 1, it strengthens the gain, reflecting the The degree to which an attack order tends toward a tactical goal.

[0132] Further, The attack instructions are adjusted according to the threat target type in the hierarchy as follows:

[0133] The first The number of unauthorized trap files corresponding to the threat target type in the level for the attack instruction is recorded as ;

[0134] No. The number of unauthorized trap files corresponding to the threat target type in the level for the attack instructions that require authorization for:

[0135]

[0136] in, For the The reward amount for attack commands;

[0137] The first In the unauthorized trap file corresponding to the threat target type in the target level, the attack instructions are randomly selected Change the permissions of an unauthorized trap file to an authorized trap file.

[0138] It should be noted that the virtual attacker may be able to detect the honeypot network during the execution of the attack command. The honeypot network accordingly uses the anti-identification probability to enhance its own concealment. The worse the response of the honeypot network to the attack command, the higher the probability of being detected by the virtual attacker. Conversely, the better the response of the honeypot network to the attack command, the lower the probability of being detected by the virtual attacker. That is, the response action and the detection probability are in positive feedback. In this embodiment, the response action is reflected by the reward value. The more reasonable the response action, the greater the reward value, and the stronger the anti-identification ability.

[0139] Therefore, the The anti-recognition probability of attack instructions The calculation method is:

[0140]

[0141] in, For the The threat rating of the attack instructions, For the The threat rating of the attack instruction is the reward amount of the th attack instruction, where is the maximum value of the reward amount;

[0142] It should be noted that the calculation process of the anti-identification probability is a well-known existing technology, and will not be elaborated in this embodiment.

[0143] So far, the anti-identification probability of the current attack instruction is obtained, which reflects the detection situation of the virtual attacker for the honeypot network. The larger the value, the greater the probability that the virtual attacker can identify it.

[0144] Step S005: Sequentially execute and judge the attack instructions according to the anti-identification probability to obtain a prior attack interaction link; use the prior attack interaction link to induce the attacker to achieve the entrapment of the attacker.

[0145] After obtaining the anti-identification probability of the current attack instruction, a detection threshold of 0.7 is preset. If the anti-identification probability of the current attack instruction is greater than or equal to the detection threshold, it means that after the execution of the current attack instruction, the honeypot network is detected by the virtual attacker, and stop adjusting the reward amount of the next attack instruction to the reward amount of the attack instruction corresponding to the next attack order by the reward amount of the next attack instruction, and use the reward amount of the next attack instruction as the reward amount of the attack instruction corresponding to the next attack order; if the anti-identification probability of the current attack instruction is less than the detection threshold, it means that the honeypot network is not detected by the virtual attacker after the execution of the current attack instruction, and adjust the reward amount of the next attack instruction to the reward amount of the attack instruction corresponding to the next attack order by the reward amount of the next attack instruction.

[0146] Furthermore, based on the above steps, the anti-identification probability of each attack instruction is obtained and judged until all attack instructions are sequentially executed. After all attack instructions are adjusted, the number of authorized entrapment files of each type of file at each level in the honeypot network is used as a prior attack interaction link. When the real attacker exists and is similar to the attack instructions in the prior attack interaction link, the prior attack interaction link can be used to entrap the real attacker.

[0147] Such as Figure 3 shown, which shows the flow chart of sequentially executing attack instructions described in this embodiment. The specific implementation is based on well-known existing technologies, and this embodiment does not specifically limit the implementation method.

[0148] Another embodiment of the present invention provides a honeypot network simulation system based on an attack deception system. The system includes a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the above method steps S001 to S005 are implemented.

[0149] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A honeypot network simulation method based on an attack trapping system, characterized in that: The method comprises the following steps: Constructing a honeypot network including a plurality of honey points at each level, wherein the honey points include a plurality of authorized trapping files; Construct attack instructions that include attack sequence, targeting level, and threat target type; Get the threat rating of the attack instructions and the number of threat files; The number of threat files and threat ratings are used to reflect the threat situation of attack instructions, and the defense impact demand evaluation of attack instructions is obtained; Analyze the attack sequence of attack instructions and the degree of intrusion into the honeypot network layer to obtain the attack link deployment integrity of the attack instructions; Obtain the defense impact demand evaluation of all attack instructions before the attack sequence of the current attack instruction and record it as the defense impact demand evaluation of the historical attack instruction; obtain the skewness of the defense impact demand evaluation of all historical attack instructions relative to the defense impact demand evaluation of the current attack instruction and record it as the tactical purpose deviation degree of the current attack instruction; multiply the inverse of the absolute value of the tactical purpose deviation degree of the current attack instruction by the attack link deployment integrity of the current attack instruction and record it as the file type deception factor of the current attack instruction; Using the file type deception factor under the attack instruction of the next attack order, adjusting the authorization status of the authorized trapping file corresponding to the threat target type, combining the threat rating changes of the current attack instruction and the next attack instruction, to obtain the anti-recognition probability of the current attack instruction; The attack instructions are sequentially implemented and judged according to the anti-identification probability to obtain a priori attack interaction links; The attacker is lured and trapped by using the prior attack interaction link.

2. According to claim 1, the honeypot network simulation method based on the attack trapping system is characterized in that: The specific steps of obtaining the defense impact demand evaluation include: The first The attack instruction's target level is recorded as Level; The first The threat target type of the attack instruction is recorded as type; The first Level The number of authorized trap files of the type is recorded as ; The first The number of threat files of attack instructions is recorded as ; The first The attack instruction is in The total number of trap files accessed in the hierarchy is recorded as ; No. Evaluation of defense impact requirements for attack instructions The calculation method is: in, To preset hyperparameters, , used to avoid the denominator being 0; For the The threat rating of the attack instructions, For the The maximum threat rating of all attack instructions before the attack order of the attack instruction.

3. According to claim 1, the honeypot network simulation method based on the attack trapping system is characterized in that: The specific steps of obtaining the deployment integrity of the attack link include: Record the current attack command as Attack instructions; The first The number of first appearances of all attack instructions in the attack order before the attack instruction is recorded as Number of intrusion levels of attack instructions ; Among them, the number of first appearances of all attack instructions on the level refers to the number of levels that have been attacked by the attack instructions in all levels of the honeypot network; No. The attack chain deployment integrity of the attack instructions The calculation method is: in, For the The attack order of the attack instructions.

4. According to claim 1, the honeypot network simulation method based on the attack trapping system is characterized in that: The specific steps of using the file type deception factor under the attack instruction of the next attack order to adjust the authorization status of the authorized trapping file corresponding to the threat target type, and combining the threat rating change of the current attack instruction and the next attack instruction to obtain the anti-recognition probability of the current attack instruction include: Preset initial reward amount; When the first attack instruction is executed, the initial reward amount is recorded as the reward amount of the first attack instruction; According to the file type deception factor of the honeypot network for the first attack instruction, the reward amount of the first attack instruction is adjusted to obtain the reward amount of the second attack instruction; And so on, the reward amount of the attack command of the next attack sequence is obtained; According to the reward amount of the attack instruction of the next attack sequence, adjusting the authorization status of the authorized trapping file corresponding to the threat target type of the attack instruction of the next attack sequence; According to the reward amount and threat rating of the attack instruction of the next attack sequence, the anti-recognition probability of the current attack instruction is obtained.

5. According to claim 4, the honeypot network simulation method based on the attack trapping system is characterized in that: The specific steps of obtaining the reward amount of the attack instruction of the next attack order include: The attack instruction of the next attack sequence is recorded as Attack instructions; No. The reward amount for attack commands is obtained as follows: The first The reward amount for attacking an attack instruction is recorded as ; No. The reward amount for attack commands The calculation method is: For the honeypot network File type deception factors of attack instructions, It is the premnmx function.

6. The honeypot network simulation method based on the attack trapping system according to claim 1 is characterized in that: The specific steps of obtaining the prior attack interaction link include: A detection threshold is preset. If the anti-recognition probability of the current attack instruction is greater than or equal to the detection threshold, the reward amount of the next attack instruction is stopped from adjusting the reward amount of the attack instruction corresponding to the next attack instruction in the next attack order. If the anti-recognition probability of the current attack instruction is less than the detection threshold, the reward amount of the next attack instruction is adjusted by the reward amount of the next attack instruction. After obtaining the anti-recognition probability of each attack instruction, all attack instructions are executed sequentially, and the number of authorized trapping files of each type of file at each level in the honeypot network is used as a priori attack interaction link.

7. A honeypot network simulation system based on an attack trapping system, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the honeypot network simulation method based on the attack trapping system are implemented as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Bait file deployment method and device based on incomplete information game and medium

    CN117061191A

  • Safety exploration reinforcement learning method based on honeypot and pseudo honeypot deployment

    CN117459289A