A method for designing a mimicry bastion machine
By using big data analysis and mimicry wall construction, the problem of incomplete bastion host defense was solved, enabling precise defense of vulnerable modules and improving the overall comprehensiveness of network security.
Patent Information
- Application Number
- CN202411856744.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-12-17
AI Technical Summary
Existing bastion hosts have the problem of being attacked in conjunction with non-target targets when defending against external attacks, resulting in incomplete defense.
By acquiring network attack and defense data through big data, analyzing vulnerable modules and their associated modules and their associated strength, establishing a mimicry wall, constructing a mimicry bastion host, and using the mimicry wall to protect vulnerable modules.
It achieves precise defense against vulnerable modules, prevents non-targeted attacks from being carried out by collateral damage, and improves the comprehensiveness of network security defense.
Smart Images

Figure CN119728220B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network security, and particularly relates to a design method of a mimic fortress. BACKGROUND
[0002] The mimic fortress is a network security device, which generates a plurality of virtual entities through mimic technology, the virtual entities are similar to real devices in appearance and behavior, but are independent of each other, so as to confuse attackers and increase the difficulty of attack.
[0003] When the existing fortress carries out network defense, a plurality of virtual entities are usually generated to confuse attackers and increase the difficulty of attack. For example, the patent application with the publication number CN113364758A discloses a network security operation and maintenance management system based on a fortress. The system stores, analyzes and processes data generated in the operation and maintenance process, optimizes the operation and maintenance scene, monitors and warns abnormal behaviors in the operation and maintenance process. The method does not monitor and defend against network attack. The existing network security technology has the problem that non-target attack objects are attacked in a network attack, resulting in incomplete defense of the fortress. SUMMARY
[0004] The application aims to at least solve one of the technical problems in the prior art. A plurality of vulnerable modules are obtained through big data, each vulnerable module is analyzed to obtain the attack modules and attack strength of each vulnerable module, and then the mimic wall corresponding to each vulnerable module is established based on each vulnerable module and the corresponding attack module. When any vulnerable module is attacked, the corresponding mimic wall is called based on the mimic fortress to carry out protection. The problem that non-target attack objects are attacked in a network attack, resulting in incomplete defense of the fortress, is solved.
[0005] To achieve the above-mentioned purpose, the application provides a design method of a mimic fortress, which comprises the following steps:
[0006] Step S1: network attack and defense data are obtained based on big data, and a plurality of vulnerable modules are obtained based on the network attack and defense data;
[0007] Step S2: each vulnerable module is analyzed based on the network attack and defense data, and the attack modules and attack strength of each vulnerable module are obtained based on the analysis result; a basic fortress is built, and the mimic wall corresponding to each vulnerable module is established based on each vulnerable module and the corresponding attack module; and the basic fortress in which the mimic walls of all vulnerable modules are stored is recorded as a mimic fortress;
[0008] Step S3: network security protection is performed using the mimic fortress machine, and when any vulnerable module is attacked, the corresponding mimic wall is called based on the mimic fortress machine to perform protection.
[0009] Further, the step S1 comprises:
[0010] Based on big data, network attack and defense data are obtained, wherein the network attack and defense data are data of network under attack and defense data based on network attack; for any network attack and defense data, a module attacked in the network attack and defense data is obtained and recorded as a vulnerable module of the network attack and defense data;
[0011] All vulnerable modules corresponding to all network attack and defense data are obtained.
[0012] Further, the step S2 comprises:
[0013] For any vulnerable module a in any network attack and defense data, the vulnerable modules other than the vulnerable module a in the network attack and defense data are recorded as the cooperative modules of the vulnerable module a;
[0014] The time period when the vulnerable module a is attacked in the network attack and defense data is recorded as a vulnerable attack period; for any cooperative module of the vulnerable module a, the time period when the cooperative module is attacked in the network attack and defense data is recorded as a cooperative attack period; when the cooperative attack period and the vulnerable attack period do not overlap, the cooperative module is removed from all cooperative modules.
[0015] Further, the step S2 further comprises:
[0016] When the cooperative attack period and the vulnerable attack period overlap, the overlapping region of the cooperative attack period and the vulnerable attack period is recorded as a vulnerable overlap period; the length of the vulnerable overlap period is divided by the length of the vulnerable attack period to obtain a cooperative proportion of the cooperative module;
[0017] The cooperative proportions of all cooperative modules corresponding to all vulnerable modules of all network attack and defense data are obtained.
[0018] Further, the step S2 further comprises:
[0019] For any cooperative module, the sum of the cooperative proportions of the cooperative module in all network attack and defense data is recorded as a cooperative intensity of the cooperative module; a basic fortress machine is built, wherein the basic fortress machine is used to monitor and record the operation and maintenance equipment;
[0020] For any vulnerable module a monitored by the basic bastion machine, record all network attack and defense data in which the vulnerable module a is located as training data; for any training data, sequentially number the cooperation modules of the vulnerable module a in the training data from high to low based on the cooperation strength of the cooperation modules, and the number is 1 to n, wherein n is the number of cooperation modules of the vulnerable module a in the training data.
[0021] Further, the step S2 further comprises:
[0022] Sort the cooperation modules in all training data, and use the cooperation strength algorithm to obtain the corresponding wall strength of each cooperation module, and the cooperation strength algorithm is: Wherein, G is the wall strength, g1 is the cooperation strength of the cooperation module, c is the number of training data, h i is the number of cooperation modules in the i-th training data, f i is the number of cooperation modules in the j-th training data.
[0023] Further, the step S2 further comprises:
[0024] The quasi-state wall of the vulnerable module a is set as: all cooperation modules corresponding to the vulnerable module a are recorded as network defense nodes to establish a network defense, which is recorded as the quasi-state wall of the vulnerable module a.
[0025] Further, the step S2 further comprises:
[0026] Obtain the quasi-state wall corresponding to all vulnerable modules, and record the basic bastion machine recording all quasi-state walls of vulnerable modules as a quasi-state bastion machine.
[0027] Further, the step S3 comprises:
[0028] Use the basic bastion machine to monitor and record the operation and maintenance equipment in real time, and when any vulnerable module monitored or recorded by the basic bastion machine has a network attack behavior, switch the basic bastion machine to the quasi-state bastion machine, and record the vulnerable module with the network attack behavior as a real-time protection module.
[0029] Further, the step S3 further comprises:
[0030] Obtain the quasi-state wall corresponding to the real-time protection module, and establish a network defense based on the network defense nodes in the quasi-state wall, allocate defense modules to each network defense node from large to small based on the wall strength of the network defense node, and preferentially allocate resources to the network defense nodes with larger wall strength.
[0031] The present application has the following beneficial effects: the present application obtains network attack and defense data based on big data, and obtains a plurality of vulnerable modules based on the network attack and defense data, the network attack and defense data contain a large variety and large difference, and the plurality of network attack and defense data are collected and obtained, so that the accuracy and comprehensiveness of subsequent analysis are ensured;
[0032] The present application also establishes a corresponding quasi-state wall for each vulnerable module based on each vulnerable module and its corresponding cooperative module; a base bastion machine storing the quasi-state walls of all vulnerable modules is recorded as a quasi-state bastion machine; when any vulnerable module is attacked, the corresponding quasi-state wall is called based on the quasi-state bastion machine for protection, the cooperative modules of different vulnerable modules are different, and the vulnerable modules and the cooperative modules are simultaneously and accurately defended, so that the cooperative modules can be prevented from being attacked due to incomplete protection. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 The method flowchart of the present application is shown in the following;
[0034] Figure 2 The relationship network diagram of the vulnerable module of the present application is shown in the following;
[0035] Figure 3 The structural schematic diagram of the electronic device of the present application is shown in the following. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.
[0037] Embodiment 1, please refer to Figure 1 A quasi-state bastion machine design method, including the following steps:
[0038] Step S1: obtaining network attack and defense data based on big data, and obtaining a plurality of vulnerable modules based on the network attack and defense data;
[0039] Step S1 includes obtaining network attack and defense data based on big data, wherein the network attack and defense data are data of network under attack and defense data based on network attack; for any network attack and defense data, the module attacked in the network attack and defense data is obtained and recorded as the vulnerable module of the network attack and defense data;
[0040] Obtain the vulnerable module corresponding to all network attack and defense data;
[0041] Please refer to Figure 2As shown, step S2: analyzing each vulnerable module based on network attack and defense data, and obtaining the cooperative module and the cooperative strength of each vulnerable module based on the analysis result; building a basic bastion host, and establishing a quasi-state wall corresponding to each vulnerable module based on each vulnerable module and its corresponding cooperative module; the basic bastion host storing all quasi-state walls of the vulnerable modules is recorded as a quasi-state bastion host; step S2 includes the following sub-steps:
[0042] Step S201: for any one vulnerable module a in any one network attack and defense data, the vulnerable modules other than the vulnerable module a are recorded as the cooperative modules of the vulnerable module a; in the specific implementation process, for example, the vulnerable module a is a monitoring log module, and the other vulnerable modules are boundary security modules and data security modules, then the boundary security modules and the data security modules are the cooperative modules of the monitoring log module;
[0043] Step S202: the time period when the vulnerable module a is attacked in the network attack and defense data is recorded as the vulnerable hit period; for any one cooperative module of the vulnerable module a, the time period when the cooperative module is attacked in the network attack and defense data is recorded as the cooperative hit period; when the cooperative hit period and the vulnerable hit period do not overlap, the cooperative module is excluded from all cooperative modules; in the specific implementation process, for example, the vulnerable module a is a monitoring log module, the monitoring log module is attacked from 20:35:20 to 20:55:40 on a certain day, and the time period from 20:35:20 to 20:55:40 on that day is recorded as the vulnerable hit period; at the same time, the cooperative module of the monitoring log module is the boundary security module, and is attacked from 20:45:20 to 20:55:40 on that day, and the time period from 20:45:20 to 20:55:40 is recorded as the cooperative hit period;
[0044] Through analysis, it can be obtained that the vulnerable hit period and the cooperative hit period overlap, and the time period corresponding to the overlapping region: 20:45:20 to 20:55:40 is recorded as the hit overlap period, and the length of the hit overlap period is 620 seconds, and the length of the vulnerable hit period is 1220 seconds, and the cooperative proportion is 0.508; by obtaining the cooperative proportion, the relevance value corresponding to each cooperative module and the vulnerable module when the vulnerable module is attacked can be obtained, and the modules irrelevant to the vulnerable module can be excluded from the cooperative modules, unnecessary analysis items are avoided, and the cooperative proportion of the excluded cooperative module is set to 0;
[0045] Step S203: when the cooperative hit period and the vulnerable hit period overlap, the time period corresponding to the overlapping region of the cooperative hit period and the vulnerable hit period is recorded as the hit overlap period; the length of the hit overlap period is divided by the length of the vulnerable hit period to obtain the cooperative proportion of the cooperative module;
[0046] obtaining a cooperation ratio of all the cooperation modules corresponding to all the vulnerable modules of all the network attack and defense data;
[0047] Step S204: For any one cooperation module, summing up the cooperation ratios of the cooperation module in all the network attack and defense data as the cooperation strength of the cooperation module; and building a basic bastion host, wherein the basic bastion host is used for monitoring the operation and maintenance equipment and recording;
[0048] In the specific implementation process, for example, the boundary security module is the cooperation module, and the cooperation ratios of the boundary security module in all the network attack and defense data are 0.1, 0.5, 0.2 and 0 respectively; then through analysis, it can be obtained that the cooperation strength of the boundary security module is 0.8; by obtaining the cooperation strength, the strength of each cooperation module in all the data can be obtained in combination with a large amount of network attack and defense data;
[0049] For any one vulnerable module a monitored by the basic bastion host, all the network attack and defense data in which the vulnerable module a is located are recorded as training data; for any one training data, the cooperation modules of the vulnerable module a in the training data are numbered from high to low based on the cooperation strength of the cooperation modules as 1 to n, wherein n is the number of the cooperation modules of the vulnerable module a in the training data;
[0050] The cooperation modules in all the training data are sorted, and the wall strength corresponding to each cooperation module is obtained by using a cooperation strength algorithm, and the cooperation strength algorithm is: wherein G is the wall strength, g1 is the cooperation strength of the cooperation module, c is the number of the training data, h i is the number of the cooperation modules in the i-th training data, and f i is the number of the cooperation modules in the j-th training data.
[0051] In the specific implementation process, for example, in one data processing, it is obtained that the cooperation module is the boundary security module, the cooperation strength of the boundary security module is 0.8, the number of the training data is 4, the numbers of the cooperation modules in all the training data are 2, 3, 1 and 2 respectively, and the numbers of the cooperation modules in all the training data are 2, 3, 2 and 3 respectively; then through calculation, it can be obtained that the wall strength of the boundary security module is 5.467;
[0052] The quasi-state wall of the vulnerable module a is set as: the network defense established by taking all the cooperation modules corresponding to the vulnerable module a as the network defense nodes is recorded as the quasi-state wall of the vulnerable module a.
[0053] In the specific implementation process, the network defense can be established by the modules such as the firewall, the UTM, the WAF and the traffic cleaning system for defense in the network attack and defense;
[0054] Obtain the corresponding wall of the quasi-state of all vulnerable modules, and record the base fortress machine recording all the walls of the quasi-state of the vulnerable modules as the quasi-state fortress machine.
[0055] Step S3: using the quasi-state fortress machine for network security protection, when any one vulnerable module is attacked, the corresponding wall of the quasi-state fortress machine is called for protection.
[0056] The base fortress machine is used for real-time monitoring and real-time recording of the operation and maintenance equipment, and when any one vulnerable module exists network attack behavior monitored or recorded by the base fortress machine, the base fortress machine is switched to the quasi-state fortress machine, and the vulnerable module existing network attack behavior is recorded as a real-time protection module.
[0057] In the specific implementation process, for example, the vulnerable module is a monitoring log module, and the wall of the quasi-state of the monitoring log module is a network defense established by a firewall and a flow cleaning system, and when the base fortress machine monitors that the monitoring log module exists network attack behavior, the base fortress machine should be switched to the quasi-state fortress machine, and the network defense is established by the firewall and the flow cleaning system.
[0058] Obtain the corresponding wall of the quasi-state of all vulnerable modules, and record the base fortress machine recording all the walls of the quasi-state of the vulnerable modules as the quasi-state fortress machine.
[0059] Embodiment 2, please refer to Figure 3 As shown in the figure, Figure 3 An electronic device structure diagram is shown, which can include: a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface, the memory complete mutual communication through the communication bus. The memory stores computer readable instructions, and the processor can call the instructions in the memory, when the computer readable instructions are executed by the processor, run as a step in a quasi-state fortress machine design method, to realize the following functions: based on big data, obtain network attack and defense data, and based on the network attack and defense data, obtain a plurality of vulnerable modules; based on the network attack and defense data, analyze each vulnerable module, and based on the analysis result, obtain the cooperation module and the cooperation strength of each vulnerable module; build a base fortress machine, and based on each vulnerable module and its corresponding cooperation module, establish the corresponding wall of the quasi-state of each vulnerable module; record the base fortress machine storing all the walls of the quasi-state of the vulnerable modules as the quasi-state fortress machine; using the quasi-state fortress machine for network security protection, when any one vulnerable module is attacked, the corresponding wall of the quasi-state fortress machine is called for protection.
[0060] Further, the logic instructions in the above-mentioned memory can be realized in the form of a software function unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts of the prior art that make contributions or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0061] Embodiment 3, the present application also provides a computer program product, the computer program product includes a computer program stored on a computer readable storage medium, the computer program includes program instructions, when the program instructions are executed by a computer, the computer can execute the above-mentioned method to provide a kind of quasi-state bastion machine design method, which includes: obtaining network attack and defense data based on big data, and obtaining a plurality of vulnerable modules based on network attack and defense data;Each vulnerable module is analyzed based on network attack and defense data, and the cooperation module and cooperation strength of each vulnerable module are obtained based on analysis result;Build basic bastion machine, and establish the corresponding quasi-state wall of each vulnerable module based on each vulnerable module and its corresponding cooperation module;The basic bastion machine that stores the quasi-state wall of all vulnerable modules is recorded as quasi-state bastion machine;Network security protection is carried out using quasi-state bastion machine, when any one vulnerable module is attacked, corresponding quasi-state wall is called based on quasi-state bastion machine to carry out protection.
[0062] Embodiment 4, the present application also provides a computer readable storage medium, the present application provides a storage medium, which stores a computer program, when the computer program is executed by a processor, the steps in the above quasi-state bastion machine design method are run to realize the following functions: obtaining network attack and defense data based on big data, and obtaining a plurality of vulnerable modules based on network attack and defense data;Each vulnerable module is analyzed based on network attack and defense data, and the cooperation module and cooperation strength of each vulnerable module are obtained based on analysis result;Build basic bastion machine, and establish the corresponding quasi-state wall of each vulnerable module based on each vulnerable module and its corresponding cooperation module;The basic bastion machine that stores the quasi-state wall of all vulnerable modules is recorded as quasi-state bastion machine;Network security protection is carried out using quasi-state bastion machine, when any one vulnerable module is attacked, corresponding quasi-state wall is called based on quasi-state bastion machine to carry out protection.
[0063] Through the description of the above embodiments, the embodiments of the present application can be provided as a method, a system or a computer program product. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in various embodiments or some parts of the embodiments.
[0064] In the embodiments provided by the present application, it should be understood that the disclosed system or method can be implemented in other manners. The embodiments described above are merely schematic, and should not be construed as limiting the present application. For example, the division of the modules or the units is merely logical function division, and there can be other division manners in actual implementation. For example, a plurality of modules or units can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different modules can be indirect couplings or communication connections through some interfaces, and there can be electric, mechanical or other forms.
[0065] Finally, it should be noted that the above-mentioned embodiments are merely used to illustrate the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still make modifications to the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for designing a mimicry bastion machine, characterized by, The method comprises the following steps: Step S1: obtaining network attack and defense data based on big data, and obtaining a plurality of vulnerable modules based on the network attack and defense data; Step S2: analyzing each vulnerable module based on the network attack and defense data, and obtaining the cooperation module and the cooperation strength of each vulnerable module based on the analysis result; building a basic bastion host, and establishing a quasi-state wall corresponding to each vulnerable module based on each vulnerable module and its corresponding cooperation module; and recording the basic bastion host storing all quasi-state walls of the vulnerable modules as a quasi-state bastion host; Step S3: using the quasi-state bastion host for network security protection, and when any vulnerable module is attacked, calling the corresponding quasi-state wall based on the quasi-state bastion host for protection; Wherein, for any network attack and defense data, the module attacked in the network attack and defense data is obtained and recorded as the vulnerable module of the network attack and defense data; For any vulnerable module a in any network attack and defense data, the vulnerable modules other than the vulnerable module a in the network attack and defense data are recorded as the cooperation modules of the vulnerable module a; the time period when the vulnerable module a is attacked in the network attack and defense data is recorded as the vulnerable attack period; for any cooperation module of the vulnerable module a, the time period when the cooperation module is attacked in the network attack and defense data is recorded as the cooperation attack period; when the cooperation attack period and the vulnerable attack period do not overlap, the cooperation module is excluded from all cooperation modules; When the cooperation attack period and the vulnerable attack period overlap, the overlapping region of the cooperation attack period and the vulnerable attack period is recorded as the attack overlap period; the length of the attack overlap period is divided by the length of the vulnerable attack period to obtain the cooperation proportion of the cooperation module; and the cooperation proportions of all cooperation modules corresponding to all vulnerable modules of all network attack and defense data are obtained; For any cooperation module, the sum of the cooperation proportions of the cooperation module in all network attack and defense data is recorded as the cooperation strength of the cooperation module; The quasi-state wall of the vulnerable module a is set as follows: all cooperation modules corresponding to the vulnerable module a are established as network defense nodes to establish the quasi-state wall of the vulnerable module a.
2. The method of designing a mimicry bastion machine according to claim 1, wherein, The step S1 comprises: obtaining network attack and defense data based on big data, wherein the network attack and defense data is data of network under attack and defense data based on network attack; obtaining vulnerable modules corresponding to all network attack and defense data.
3. The method of claim 2, wherein, The step S2 further comprises: building a basic bastion host, wherein the basic bastion host is used for monitoring and recording operation and maintenance equipment; For any vulnerable module a monitored by the basic bastion host, all network attack and defense data in which the vulnerable module a is located are recorded as training data; and for any training data, the cooperation modules of the vulnerable module a in the training data are numbered from 1 to n in descending order of the cooperation strength of the cooperation modules, wherein n is the number of the cooperation modules of the vulnerable module a in the training data.
4. The method of designing a mimicry bastion machine according to claim 3, wherein, The step S2 further comprises: Sort the collaboration modules in all the to-be-trained data, and obtain the wall strength corresponding to each collaboration module using a collaboration strength algorithm, which is: wherein G is the wall strength, g1 is the collaboration strength of the collaboration module, c is the number of to-be-trained data, h i is the number of collaboration modules in the i-th to-be-trained data. i is the number of collaboration modules in the i-th to-be-trained data.
5. The method of designing a Schelling’s Bazaar according to claim 4, wherein, The step S2 further comprises: obtaining quasi-state walls corresponding to all vulnerable modules, and recording the basic bastion host recording all quasi-state walls of the vulnerable modules as a quasi-state bastion host.
6. The method of designing a Schelling’s Bazaar according to claim 5, wherein, The step S3 comprises: The base bastion machine is used for real-time monitoring and real-time recording of the operation and maintenance equipment, and when any vulnerable module of the base bastion machine monitoring or recording has a network attack behavior, the base bastion machine is switched to the quasi-state bastion machine, and the vulnerable module having the network attack behavior is recorded as a real-time protection module.
7. The method of designing a Schelling’s Bittorrent according to claim 6, wherein, The step S3 further comprises: A quasi-state wall corresponding to the real-time protection module is acquired, network defense is established based on the network defense nodes in the quasi-state wall, the defense modules are sequentially assigned based on the wall strength of each network defense node from large to small, and resources are preferentially assigned to the network defense nodes with larger wall strength.
Citation Information
Patent Citations
Network security operation and maintenance management system based on bastion host
CN113364758A
Attack and defense behavior quantitative evaluation method and system based on game theory
CN110035066A
Multi-step attack dynamic defense decision selection method and system for network attack and defense
CN110602047A