A method for constructing and deploying command honeypots based on large models

By building a directed graph of users and attack paths based on a large model and generating and deploying command honey spots, the problem of attackers collecting information through command history records is solved, the defense effect is improved, and real-time alerts and tracing support are provided.

CN119728206BActive Publication Date: 2025-09-23GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411837387.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-09-23
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

Existing technologies are difficult to effectively prevent attackers from collecting information through command history records, and lack a trapping mechanism to induce attackers to reveal their true intentions, making traditional defense measures ineffective.

Method used

Based on the large model, a directed graph of user operation chains and attack paths is constructed, command honeypot templates are generated, honeypot locations and trigger paths are dynamically deployed and adjusted, trigger events are recorded in real time, and structured feedback data is generated.

Benefits of technology

It improves the confusing and trapping effects on attackers, guides attackers' behavior paths and issues real-time alerts, supports tracing and security response, and optimizes the generation and deployment of honey spots.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728206B_ABST
    Figure CN119728206B_ABST
Patent Text Reader

Abstract

The present invention provides a method for constructing and deploying command honey spots based on a large model, and relates to the field of cyberspace security technology. The method for constructing and deploying command honey spots includes the following steps: constructing a user behavior model based on the command history record of the user terminal, and constructing an attack behavior model based on the attack log; generating a command honey spot template based on the user behavior model and the attack behavior model, and dynamically generating multiple command honey spots by matching the command honey spot template with the user's current operating environment based on the large model; selecting the deployment location of the command honey spot based on the user behavior model, the attack behavior model, and the user's current operating environment; issuing an alarm when the command honey spot is triggered and recording the triggering event of the command honey spot, generating structured feedback data based on the triggering event, and optimizing the command honey spot based on the structured feedback data. The method for constructing and deploying command honey spots provided by the present invention improves the problems of low defense effect and insufficient security of command history records in traditional methods.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cyberspace security technology, and in particular to a method for constructing and deploying command honeypots based on a large model. Background Art

[0002] In modern cybersecurity environments, attacks such as advanced persistent threats (APTs) are becoming increasingly sophisticated. Attackers possess not only extensive technical expertise but also exploit legitimate system interfaces or normal operational paths to gather information and conceal their activities. After infiltrating a system, attackers typically review the system's command history to gather key information, determine the presence of sensitive resources in the target system, understand system usage patterns, and even uncover traces of high-privilege operations.

[0003] The command history log is a log file that records user command operations, typically used to help users retrace past actions. However, attackers use the command history log as a tool for indirectly obtaining system information. For example, by searching for common commands such as file access and network status checks, attackers can quickly understand system status and the location of potentially sensitive resources. This passive information collection method provides attackers with a low-risk exploration method that often does not trigger alerts from traditional detection systems.

[0004] Current defenses, however, primarily focus on system logs, network traffic monitoring, and behavioral anomaly detection. These traditional methods are ineffective in preventing attackers from collecting information through command history, and they also lack corresponding decoy mechanisms to trick attackers into revealing their true intentions. Therefore, a solution is urgently needed to address these issues. Summary of the Invention

[0005] The purpose of the present invention is to provide a command honeypot construction and deployment method based on a large model, which improves the problems of low defense effect and insufficient security of command history records in traditional methods.

[0006] The present invention provides a method for constructing and deploying command honeypots based on a large model, which adopts the following technical solutions:

[0007] Build a user operation chain directed graph based on the user terminal command history, analyze the user operation chain directed graph based on the large model to build a user behavior model, build an attack path directed graph based on the attack log, and analyze the attack path directed graph based on the large model to build an attack behavior model;

[0008] Generate command honeypot templates based on user behavior models and attack behavior models, and dynamically generate multiple command honeypots by matching the command honeypot templates with the user's current operating environment based on the large model;

[0009] Selecting deployment locations of command sweet spots based on a user behavior model, an attack behavior model, and the user's current operating environment, constructing trigger paths between the command sweet spots, and dynamically adjusting the deployment locations and trigger paths based on real-time trigger data from the command sweet spots;

[0010] When a command sweet spot is triggered, an alarm is issued and the triggering event of the command sweet spot is recorded, structured feedback data is generated based on the triggering event, and the command sweet spot is optimized based on the structured feedback data.

[0011] Optionally, the process of constructing a user behavior model by analyzing the user operation chain directed graph based on the big model includes: generating command context embedding for the user operation chain directed graph based on the big model; constructing a user operation chain model based on the Markov chain and the user operation chain directed graph; calculating the command frequency distribution based on the user operation chain directed graph; composing a user behavior model based on the command context embedding, the user operation chain model and the command frequency distribution; and updating the user behavior model in real time using incremental learning technology based on dynamic changes in user behavior.

[0012] Optionally, the process of constructing an attack behavior model by analyzing the attack path directed graph based on the large model includes: generating an attack context embedding for the attack path directed graph based on the large model; constructing an attack path probability model based on the attack behavior data in the attack path directed graph; generating an attack preference description by analyzing the attack path directed graph based on the large model; and composing an attack behavior model based on the attack context embedding, the attack path probability model, and the attack preference description.

[0013] Optionally, the process of generating a command honey spot template based on the user behavior model and the attack behavior model includes: obtaining a command template that imitates the user's common operations based on the user behavior model, obtaining a target path that the attacker is interested in based on the attack preference description of the attack behavior model, and generating a command honey spot template for forged commands based on the command template and the target path that the attacker is interested in.

[0014] Optionally, the process of dynamically generating multiple command honey spots by analyzing the user's current operating environment based on the large model and matching the command honey spot template includes:

[0015] Based on the large model, a semantic analysis is performed on the context of the user's current operating environment, and a plurality of command honey spots are dynamically generated by matching the command honey spot template; a first semantic vector of the command honey spot and a second semantic vector of the context of the user's current operating environment are generated based on the large model, and the semantic relevance of the first semantic vector and the second semantic vector is calculated; a first matching probability between the command honey spot and the user's current operating environment is obtained based on the large model; a second matching probability between the command honey spot and the target path of interest to the attacker is obtained based on the large model; and the plurality of command honey spots are optimized based on the semantic relevance, the first matching probability, and the second matching probability.

[0016] Optionally, the parameters of the command honeypot include a path and a file name, the path is generated based on the user's access history, and the file name is generated based on the attacker's target.

[0017] Optionally, the process of selecting a deployment location of a command honeypot based on the user behavior model, the attack behavior model, and the user's current operating environment includes:

[0018] Based on the user behavior model, command high-frequency nodes are obtained, based on the attack behavior model, attack preference nodes are obtained, and a time window is created based on the user's current operating environment to obtain the time distribution of user operations. Based on the time distribution, a time period in which the user operation frequency is lower than the threshold is obtained. When in the said time period, command honey spots are deployed at logical breakpoints based on command high-frequency nodes and attack preference nodes.

[0019] Optionally, the process of constructing the trigger path between the multiple command sweet spots includes: calculating the transition probabilities between the multiple sweet spots, and constructing logical associations between the multiple command sweet spots based on the transition probabilities to obtain the trigger path between the sweet spots.

[0020] Optionally, the process of dynamically adjusting the deployment position and trigger path based on the command honeypot real-time trigger data includes:

[0021] Design forged results based on command sweet spots, guide the attacker to execute subsequent commands based on the output of the forged results, record the real-time trigger data of the command sweet spots, increase the density of command sweet spots at high trigger rate locations based on the real-time trigger data, and redesign the trigger paths between the sweet spots, giving priority to enhancing high-probability paths. The real-time trigger data includes the triggered command sweet spot, whether the sweet spot is triggered, the trigger time, and the attacker's subsequent commands.

[0022] Optionally, the process of generating structured feedback data based on the trigger event and optimizing the command honey spot based on the structured feedback data includes:

[0023] Based on the triggering event, the triggered command sweet spot, the triggering frequency of the command sweet spot and the attacker's operation path map are obtained; based on the triggered command sweet spot, the triggering frequency of the command sweet spot and the attacker's operation path map, structured feedback data is generated; based on the triggering frequency of the structured feedback data, the command sweet spot generation content is optimized; based on the attacker's operation path map of the structured feedback data, the deployment position and triggering path of the command sweet spot are adjusted.

[0024] The present invention provides a method for constructing and deploying command honeypots based on a large model, which has the following beneficial effects:

[0025] 1. The command honeypots of the present invention are generated by forging historical commands and the target paths that the attacker is interested in. The honeypots are more sweet, which increases the confusing and trapping effect on the attacker.

[0026] 2. The present invention guides the attacker's behavior path by designing trigger paths between honey spots;

[0027] 3. When a command honeypot is triggered, the system can immediately record the triggering behavior and generate real-time alerts, providing technical support for attack tracing and security response;

[0028] 4. The present invention can update the generated content of the command sweet spot and the deployment location and trigger path of the command sweet spot in real time by generating structured feedback data. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 This is a flow chart of a method for constructing and deploying command honeypots based on a large model provided by the present invention. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the invention belongs. The words "including" and similar words used in this article mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects.

[0031] The embodiment of the present invention provides a method for constructing and deploying command honeypots based on a large model. Figure 1 ,include:

[0032] S1. Build a user operation chain directed graph based on the user terminal command history, analyze the user operation chain directed graph based on the large model to build a user behavior model, build an attack path directed graph based on the attack log, and build an attack behavior model based on the large model analysis of the attack path directed graph;

[0033] S2. Generate a command honeypot template based on the user behavior model and the attack behavior model. Analyze the user's current operating environment based on the large model and match the command honeypot template to dynamically generate multiple command honeypots.

[0034] S3. Selecting deployment locations of command sweet spots based on the user behavior model, the attack behavior model, and the user's current operating environment, constructing trigger paths between the multiple command sweet spots, and dynamically adjusting the deployment locations and trigger paths based on real-time trigger data of the command sweet spots;

[0035] S4. When a command sweet spot is triggered, an alarm is issued and the triggering event of the command sweet spot is recorded, structured feedback data is generated based on the triggering event, and the command sweet spot is optimized based on the structured feedback data.

[0036] In some embodiments, the process of executing step S1 includes:

[0037] S1.1. Construct a user operation chain directed graph based on the user terminal command history;

[0038] S1.2. Construct an attack path directed graph based on the attack log;

[0039] S1.3. Analyze the user operation chain directed graph based on the large model to build a user behavior model;

[0040] S1.4. Analyze the attack path directed graph based on the large model to build an attack behavior model.

[0041] Specifically, when executing step S1.1, constructing a user operation chain directed graph based on the user terminal command history record includes:

[0042] Get the user terminal command history:

[0043] U={(c1,t1),(c2,t2),…,(c n ,t n )};

[0044] Among them, U is the user terminal command history, c n The nth command executed by the user, t n The timestamp of executing the nth command.

[0045] Furthermore, a user operation chain directed graph G is constructed based on the user terminal command history. u =(V u ,E u ), V u is a set of commands, E u Dependencies between commands.

[0046] Specifically, when executing step S1.2, constructing the attack path directed graph based on the attack log includes:

[0047] Collect attack logs or simulate attack data:

[0048] A={(a1,t1),(a2,t2),…,(a m ,t m )};

[0049] Among them, A is the attack behavior data, a mThe mth command operated by the attacker, t m The operation time for executing the mth command.

[0050] Furthermore, based on the attack behavior data, the attack path directed graph G is constructed a =(V a ,E a ), V a is the set of command nodes executed by the attacker, E a The logical or causal relationship between commands.

[0051] In fact, after obtaining the user operation chain directed graph and the attack path directed graph, the directed graph is first filtered to remove invalid commands, and then the commands in the directed graph are segmented and parsed to extract the command name, parameters and target path, and finally a contextual semantic representation is generated for each command.

[0052] Specifically, when executing step S1.3, building a user behavior model based on the large model analysis of the user operation chain directed graph includes:

[0053] Generate command context embedding for the user operation chain directed graph based on the large model:

[0054] v(c i )=Enc(c i |c i-1 ,c i-2 ,…,c1);

[0055] Where v(c i ) is the command context embedding, Enc is the large model encoder, c i-1 ,c i-2 ,…,c1 is the context of the current command;

[0056] Construct a user operation chain model based on Markov chain and user operation chain directed graph:

[0057]

[0058] Among them, P(c i+1 |c i ) is the user operation chain model, Count(c i →c i+1 ) is the command c i Jump to command c i+1 The number of times, ∑ j Count(c i →c j ) is from command c i Jump to all commands c j The sum of the number of times, j is to traverse all possible commands;

[0059] Calculate the command frequency distribution based on the user operation chain directed graph:

[0060]

[0061] Among them, F(c i ) is the command frequency, Count(c i ) is the command c i The number of occurrences of , N is the total number of commands;

[0062] The user behavior model is constructed based on command context embedding, user operation chain model and command frequency distribution;

[0063] M u ={v(c i ),P(c i+1 |c i ),F(c i )};

[0064] Among them, M u is the user behavior model, v(c i ) is the command context embedding, P(c i+1 |c i ) is the user operation chain model, F(c i ) is the command frequency;

[0065] Furthermore, incremental learning technology is used to update the user behavior model in real time based on the dynamic changes in user behavior.

[0066] Specifically, when executing step S1.4, analyzing the attack path directed graph based on the large model to construct the attack behavior model, the following steps are included:

[0067] Generate attack context embedding for the attack path directed graph based on the large model:

[0068] v(a i )=Enc(a i |a i-1 ,a i-2 ,…,a1);

[0069] where v(a i ) is the attack context embedding, Enc is the large model encoder, a i-1 ,a i-2 ,…,a1 is the context of the current attack behavior;

[0070] Based on the attack behavior data in the attack path directed graph, an attack path probability model is constructed:

[0071]

[0072] Among them, P(ai+1 |a i ) is the attack path probability model, Count(a i →a i+1 ) is an aggressive behavior a i Jump to attack behaviora i+1 The number of times, ∑ k Count(a i →a k ) is an aggressive behavior a i Jump to all attacks k The sum of the number of times, k is to traverse all possible attack behaviors;

[0073] Analyze the attack path directed graph based on the large model to generate attack preference description;

[0074] The attack behavior model is composed of attack context embedding, attack path probability model and attack preference description:

[0075] M a ={v(a i ),P(a i+1 |a i ),F(A)};

[0076] Among them, M a is the attack behavior model, v(a i ) is the attack context embedding, P(a i+1 |a i ) is the attack path probability model, and F(A) is the attack preference description.

[0077] In some embodiments, the process of executing step S2 includes:

[0078] S2.1. Generate command honeypot template based on user behavior model and attack behavior model;

[0079] S2.2. Analyze the user's current operating environment based on the large model and match the command honey spot template to dynamically generate multiple command honey spots.

[0080] Specifically, when executing step S2.1, generating a command honey spot template based on the user behavior model and the attack behavior model, it includes: obtaining a command template that imitates the user's common operations based on the user behavior model, obtaining the target path of the attacker's attention based on the attack preference description of the attack behavior model, and generating a command honey spot template for forged commands based on the command template and the target path of the attacker's attention.

[0081] Specifically, the process of executing step S2.2 includes:

[0082] S2.2.1. Generate command honeypots;

[0083] S2.2.2. Optimize command sweet spots.

[0084] Specifically, when executing step S2.2.1 and generating command honey spots, a semantic analysis is performed on the context of the user's current operating environment based on the large model, and a plurality of command honey spots are dynamically generated by matching the command honey spot template.

[0085] In fact, by performing semantic analysis on the context of the user's current operating environment through a large model, it is possible to dynamically generate forged paths based on the user's access history, and generate forged file names based on the attacker's goals, thereby improving the authenticity of command honey spots.

[0086] Furthermore, when executing step S2.2.2, optimizing the command honey spot, the following steps are included:

[0087] Based on the large model, a first semantic vector of the command honey spot and a second semantic vector of the context of the user's current operating environment are generated, and the semantic correlation between the first semantic vector and the second semantic vector is calculated; based on the large model, a first matching probability of the command honey spot and the user's current operating environment is obtained; based on the large model, a second matching probability of the command honey spot and the target path of the attacker's concern is obtained; and the multiple command honey spots are optimized based on the semantic correlation, the first matching probability and the second matching probability.

[0088] Furthermore, when optimizing the plurality of command honey spots based on semantic relevance, the first matching probability, and the second matching probability, the following formula is used:

[0089] P(H|M u ,M a )=w1·Rel(H,Context)+w2·P u (H)+w3·P a (H);

[0090] Among them, P(H|M u ,M a ) is the optimized command honey point, Rel(H,Context) is the semantic relevance, P u (H) is the first matching probability, P a (H) is the second matching probability, w1, w2, and w3 are weight factors.

[0091] In some embodiments, the process of executing step S3 includes:

[0092] S3.1. Select the deployment location of the command honeypot based on the user behavior model, attack behavior model, and the user's current operating environment;

[0093] S3.2, construct trigger paths between multiple command honey spots;

[0094] S3.3. Dynamically adjust the deployment position and trigger path based on the real-time trigger data of the command honeypot.

[0095] Specifically, when executing step S3.1, the command high-frequency node is obtained based on the user behavior model, the attack preference node is obtained based on the attack behavior model, a time window is created based on the user's current operating environment, the time distribution of the user operation is obtained, and the time period in which the user operation frequency is lower than the threshold is obtained based on the time distribution. When in the said time period, the command honey spot is deployed at the logical breakpoint based on the command high-frequency node and the attack preference node.

[0096] Specifically, when executing step S3.2 and constructing the trigger path between multiple command sweet spots, the transition probabilities between the multiple sweet spots are calculated, and logical associations between the multiple command sweet spots are constructed based on the transition probabilities to obtain the trigger path between the sweet spots.

[0097] Furthermore, the calculation formula for the transition probability between honey spots is:

[0098]

[0099] Among them, P(H i+1 |H i ) is the honey point H i Transfer to honey spot H i+1 The probability of Count(H i →H i+1 ) is the honey point H i Jump to honey spot H i+1 The number of times, ∑ j Count(H i →H l ) is the honey point H i Jump to all honey spots H l The sum of the number of times, l is to traverse all possible commands.

[0100] Furthermore, the trigger path L between the honey spots is constructed based on the transition probability between the honey spots:

[0101] L={H1→H2→…→H z};

[0102] Where L is the trigger path between honey spots, H z is the honey point z, → is the logical association between command honey points.

[0103] Specifically, when executing step S3.3, dynamically adjusting the deployment position and trigger path based on the command honeypot real-time trigger data includes:

[0104] Design forged results based on command sweet spots, guide the attacker to execute subsequent commands based on the output of the forged results, record the real-time trigger data of the command sweet spots, increase the density of command sweet spots at high trigger rate locations based on the real-time trigger data, and redesign the trigger paths between the sweet spots, giving priority to enhancing high-probability paths. The real-time trigger data includes the triggered command sweet spot, whether the sweet spot is triggered, the trigger time, and the attacker's subsequent commands.

[0105] In fact, when an attacker triggers a command honeypot, the command honeypot will design a forged result based on the content of the honeypot, and guide the attacker to execute subsequent commands based on the output of the forged result.

[0106] Furthermore, the honey spot trigger data is captured in real time, and the trigger data is:

[0107] T H ={(H,Triggered_Flag,Time,Action)};

[0108] Among them, T H is the trigger data, Triggered_Flag is whether the honey spot is triggered, Time is the trigger time, and Action is the attacker's subsequent operation.

[0109] In some embodiments, the process of executing step S4 includes:

[0110] S4.1. When a command sweet spot is triggered, an alarm is issued and the triggering event of the command sweet spot is recorded;

[0111] S4.2. generating structured feedback data based on the triggering event;

[0112] S4.3. Optimize command honey spots based on structured feedback data.

[0113] In fact, when executing step S4.1, after the attacker triggers the command honey spot, it will detect whether the command honey spot is called, record the parameters and results when the command is triggered, collect the environmental information and targets when the command honey spot triggering event occurs, generate the trigger frequency distribution, and issue an alarm to notify the administrator and generate the corresponding alarm log.

[0114] Furthermore, the command honey spot trigger event record format is:

[0115] E H ={ID H ,T H ,A H ,P H ,C H};

[0116] E H Honey spot trigger event, ID His the unique identifier of the triggering honeypoint, T H is the honey point trigger time, A H is the attacker's identity feature (such as IP address, device fingerprint, etc.), P H is the parameter value when the honey point is triggered, C H To trigger context information.

[0117] Furthermore, when generating the trigger frequency distribution:

[0118]

[0119] F(H) is the trigger frequency, Count(H) is the number of times the command sweet spot H is triggered, and Δt is the time interval.

[0120] Specifically, when executing step S4.2 and generating structured feedback data based on the triggering event, the triggered command sweet spot, the triggering frequency of the command sweet spot, and the attacker's operation path map are obtained based on the triggering event, and the structured feedback data is generated based on the triggered command sweet spot, the triggering frequency of the command sweet spot, and the attacker's operation path map.

[0121] In fact, by analyzing the attacker's operation path graph, we can extract the attacker's behavioral characteristics, record the parameters used by the attacker, such as the target path or file name, count the time intervals between operations, and judge the attacker's degree of automation; and identify high-frequency nodes in the path graph, and prioritize generating feedback related to these nodes.

[0122] Further, execute S4.3 to optimize the command honey spots based on the structured feedback data, optimize the command honey spot generation content based on the trigger frequency of the structured feedback data, and adjust the deployment location and trigger path of the command honey spots based on the attacker operation path diagram of the structured feedback data.

[0123] While the embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations of these embodiments are possible. However, it should be understood that such modifications and variations are within the scope and spirit of the present invention as set forth in the claims. Furthermore, the invention described herein is susceptible to other embodiments and may be practiced or implemented in a variety of ways.

Claims

1. A method for constructing and deploying command honeypots based on a large model, characterized in that: The following steps are involved: Build a user operation chain directed graph based on the user terminal command history, analyze the user operation chain directed graph based on the large model to build a user behavior model, build an attack path directed graph based on the attack log, and analyze the attack path directed graph based on the large model to build an attack behavior model; Generate command honeypot templates based on user behavior models and attack behavior models, and dynamically generate multiple command honeypots by matching the command honeypot templates with the user's current operating environment based on the large model; Selecting deployment locations of command sweet spots based on a user behavior model, an attack behavior model, and the user's current operating environment, constructing trigger paths between the command sweet spots, and dynamically adjusting the deployment locations and trigger paths based on real-time trigger data from the command sweet spots; When a command sweet spot is triggered, an alarm is issued and the triggering event of the command sweet spot is recorded, structured feedback data is generated based on the triggering event, and the command sweet spot is optimized based on the structured feedback data.

2. A method for constructing and deploying command honeypots based on a large model according to claim 1, characterized in that: The process of building a user behavior model based on a large model analysis of the user operation chain directed graph includes: Generate command context embedding for the user operation chain directed graph based on the big model; Construct a user operation chain model based on Markov chain and user operation chain directed graph; Calculate command frequency distribution based on the user operation chain directed graph; The user behavior model is constructed based on command context embedding, user operation chain model and command frequency distribution; The user behavior model is updated in real time using incremental learning technology based on the dynamic changes in user behavior.

3. The method for constructing and deploying command honeypots based on a large model according to claim 1, characterized in that: The process of constructing an attack behavior model based on a large model-based attack path directed graph analysis includes: Generate attack context embedding for the directed graph of attack paths based on the large model; Based on the attack behavior data in the attack path directed graph, an attack path probability model is constructed; Analyze the attack path directed graph based on the large model to generate attack preference description; The attack behavior model is composed based on attack context embedding, attack path probability model and attack preference description.

4. A method for constructing and deploying command honeypots based on a large model according to claim 3, characterized in that: The process of generating command honeypot templates based on user behavior models and attack behavior models includes: Based on the user behavior model, a command template that imitates the user's common operations is obtained. Based on the attack preference description of the attack behavior model, the target path of the attacker's attention is obtained. Based on the command template and the target path of the attacker's attention, a command honeypot template of forged commands is generated.

5. A method for constructing and deploying command honeypots based on a large model according to claim 4, characterized in that: The process of dynamically generating multiple command honey spots by analyzing the user's current operating environment based on a large model and matching the command honey spot template includes: Perform semantic analysis on the context of the user's current operating environment based on the large model, and dynamically generate multiple command honey spots by matching command honey spot templates; Generate a first semantic vector of the command honey point and a second semantic vector of the context of the user's current operating environment based on the large model, and calculate the semantic relevance between the first semantic vector and the second semantic vector; Obtaining a first matching probability between a command sweet spot and the user's current operating environment based on the large model; Obtaining a second matching probability between the command honey point and the target path of interest to the attacker based on the large model; The plurality of command sweet spots are optimized based on the semantic relevance, the first matching probability, and the second matching probability.

6. A method for constructing and deploying command honeypots based on a large model according to claim 5, characterized in that: The parameters of the command honeypot include a path and a file name, wherein the path is generated based on the user's access history, and the file name is generated based on the attacker's target.

7. The method for constructing and deploying command honeypots based on a large model according to claim 1, characterized in that: The process of selecting the deployment location of the command honeypot based on the user behavior model, attack behavior model, and the user's current operating environment includes: Based on the user behavior model, command high-frequency nodes are obtained, based on the attack behavior model, attack preference nodes are obtained, and a time window is created based on the user's current operating environment to obtain the time distribution of user operations. Based on the time distribution, a time period in which the user operation frequency is lower than the threshold is obtained. When in the said time period, command honey spots are deployed at logical breakpoints based on command high-frequency nodes and attack preference nodes.

8. The method for constructing and deploying command honeypots based on a large model according to claim 1, characterized in that: The process of constructing the trigger path between the plurality of command honey spots includes: The transition probabilities between the plurality of honey points are calculated, and logical associations between the plurality of command honey points are constructed based on the transition probabilities to obtain trigger paths between the honey points.

9. The method for constructing and deploying command honeypots based on a large model according to claim 1, characterized in that: The process of dynamically adjusting the deployment position and trigger path based on the command honeypot real-time trigger data includes: Design forged results based on command sweet spots, guide the attacker to execute subsequent commands based on the output of the forged results, record the real-time trigger data of the command sweet spots, increase the density of command sweet spots at high trigger rate locations based on the real-time trigger data, and redesign the trigger paths between the sweet spots, giving priority to enhancing high-probability paths. The real-time trigger data includes the triggered command sweet spot, whether the sweet spot is triggered, the trigger time, and the attacker's subsequent commands.

10. The method for constructing and deploying command honeypots based on a large model according to claim 1, characterized in that: The process of generating structured feedback data based on the trigger event and optimizing command honey spots based on the structured feedback data includes: Based on the triggering event, the triggered command sweet spot, the triggering frequency of the command sweet spot and the attacker's operation path map are obtained; based on the triggered command sweet spot, the triggering frequency of the command sweet spot and the attacker's operation path map, structured feedback data is generated; based on the triggering frequency of the structured feedback data, the command sweet spot generation content is optimized; based on the attacker's operation path map of the structured feedback data, the deployment position and triggering path of the command sweet spot are adjusted.

Citation Information

Patent Citations

  • Honey array defense strategy dynamic generation method and system based on large model

    CN118842645A

  • Network security protection method and apparatus

    WO2022127482A1