A dynamic attack surface transformation active defense system for a production system

By combining mobile target defense and network deception technologies, the dynamic attack surface transformation proactive defense system solves the problem that traditional defense technologies cannot cope with complex network attacks, and improves security and stability in production systems without affecting business operations.

CN119728240BActive Publication Date: 2025-11-11NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411892510.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-20
Publication Date
2025-11-11
Estimated Expiration
2044-12-20

AI Technical Summary

Technical Problem

Existing network security defense technologies are unable to effectively cope with complex and ever-changing network attacks. Traditional defense methods rely on static signature and rule bases, which cannot identify new attack methods in a timely manner, especially zero-day attacks and variant attacks. Furthermore, existing defense technologies are complex to deploy in production systems and affect normal business operations.

Method used

Combining mobile target defense and network deception technologies, a dynamic attack surface transformation proactive defense system is provided. Through system support modules, interface interpreter modules, mobile target construction modules, dynamic orchestration modules, management modules, and threat monitoring modules, the system dynamically adjusts attack surface characteristics to confuse attackers and enhance system security.

Benefits of technology

Without affecting the normal operation of the production system, it effectively confuses attackers, increases the difficulty of attacks, avoids resource waste, improves system security and stability, and provides lightweight deployment and real-time response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728240B_ABST
    Figure CN119728240B_ABST
Patent Text Reader

Abstract

The application discloses a kind of dynamic attack surface transformation active defense system for production system, it is related to network security field, the active defense system includes: system support module, interface interpreter module, mobile target construction module, dynamic arrangement module, management module, information processing module, threat monitoring module;System support module provides the camouflage function of network service, file system and user account, and is converted into standard interface by interface interpreter module for upper module call, mobile target construction module interacts with system support module by interface interpreter, supports dynamic arrangement camouflage resource, dynamic arrangement module adjusts the attack surface characteristics of system resource according to the real-time threat information provided by threat monitoring module, when potential attack is found by threat monitoring module, threat information is passed to management module, and dynamic arrangement module is triggered to adjust, information processing module records log and shows system state and threat alarm, assist administrator decision-making.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of network security, and more specifically, to a dynamic attack surface transformation proactive defense system for production systems. Background Technology

[0002] With the rapid development of information technology, cybersecurity issues are becoming increasingly serious, especially in critical areas such as industrial control systems and production systems, where ensuring cybersecurity has become an urgent problem to solve. Existing cybersecurity defense technologies mainly rely on traditional passive defense methods such as firewalls, intrusion detection systems, and virus scanning. However, these traditional defense technologies often have many limitations and cannot effectively cope with increasingly complex and ever-changing cyberattacks.

[0003] Traditional network defense technologies rely on static signature and rule bases for attack identification. Defense measures are usually activated only after an attack occurs, allowing attackers to penetrate the system beforehand for reconnaissance and vulnerability exploitation. Defense systems often cannot effectively prevent attacks before they occur. Signature-based defenses rely on regularly updating signature bases, which makes it difficult for the system to identify new attack methods in a timely manner, especially zero-day attacks and variant attacks.

[0004] Mobile Target Defense (MTD), as a proactive network defense technique, aims to provide defenders with an asymmetric advantage by randomizing, diversifying, and redundant the characteristics of the protected network and system across different dimensions. This creates a dynamic attack surface that is difficult for attackers to identify and exploit, achieving unpredictability in system configuration changes and thus hindering attack reconnaissance and exploitation attempts. Deceptive defense techniques focus on camouflage and obfuscation, misleading false responses, and other techniques to distract attackers from legitimate targets and lure them into decoys and other decoy systems, thereby increasing the complexity and cost of attacks; however, they have the following drawbacks:

[0005] 1) Network address change technology is one of the mainstream implementation techniques in mobile target defense. Using network address as a mobility parameter, changing the address can make the address carried by packets in the network change randomly over time, thus confusing attackers. Even if the packet is intercepted, its address information is only valid for a short period of time. Deploying address randomization mobile target defense methods in production systems may impose significant overhead on real systems, be complex to implement, and potentially affect normal business services in production systems.

[0006] 2) Existing deception defense technologies, such as honeypots, honeynets, and honey baits, are usually deployed independently in production systems. They construct separate, fake nodes that are independent of the production system and virtualize real system functions and business services on them. They are not effectively integrated with the production system, and their independent deployment makes them easy for attackers to identify and bypass. Summary of the Invention

[0007] The purpose of this invention is to provide a dynamic attack surface change proactive defense system that combines mobile target defense and network deception technology. This system can dynamically adjust the attack surface to confuse attackers and improve system security without affecting the normal operation of the production system.

[0008] The technical solution of the present invention is: to provide a dynamic attack surface change active defense system for production systems, the active defense system comprising: a system support module, an interface interpreter module, a moving target construction module, a dynamic orchestration module, a management module, an information processing module, and a threat monitoring module;

[0009] The system support module provides spoofing and disguise functions for network services, file systems, and user account resources. The system support module encapsulates the underlying spoofing resources into standard interfaces that can be called by upper-layer modules through the interface interpreter module. The system support module and the mobile target construction module use different programming languages. The interface interpreter module establishes the interface standard between the programming languages ​​of the system support module and the mobile target construction module. The mobile target construction module interacts with the system support module through the interface interpreter, supporting the upper-layer dynamic orchestration module to adjust attack surface characteristics, perform network service spoofing, file system spoofing, and user account spoofing, increasing the difficulty for attackers to identify and exploit vulnerabilities.

[0010] When the threat monitoring module detects a potential attack, it transmits the relevant threat information to the dynamic orchestration module through the management module. The dynamic orchestration module then triggers dynamic orchestration and changes to the underlying masquerading resources of network services, file systems, and user accounts based on the threat information, thereby adjusting the attack surface characteristics.

[0011] At the same time, the information processing module records the system's operation logs and displays the system status and threat alerts in real time, providing information for administrators to make decisions.

[0012] In any of the above technical solutions, the system support module further includes a network component, a file system component, a user environment component, and a log component, which respectively provide network masquerading services, file system masquerading, user environment masquerading, and operation log recording functions.

[0013] In any of the above technical solutions, the interfaces provided by the interface interpreter module further include: a network service interface for dynamically configuring the masquerading service and listening port; a file system interface for configuring masquerading files and access monitoring; and a user environment interface for configuring masquerading user accounts and dynamic user environments.

[0014] In any of the above technical solutions, the dynamic orchestration module, based on finite state machine theory, abstracts the states of resources such as network services, file systems, and user accounts in the system into attack surface feature vectors, and adjusts the states of various resources through an event-driven mechanism.

[0015] In any of the above technical solutions, the dynamic orchestration module further adjusts the configuration of system resources based on the threat information fed back by the threat monitoring module. The adjustments include: dynamically changing the configuration of the masquerading service; randomizing the file names, permissions, and access paths of the file system; and dynamically adjusting the root directory and environment configuration of the masquerading user account.

[0016] In any of the above technical solutions, the proactive defense system further includes: a security deployment module; the security deployment module achieves isolation between the defense system and the production system through a multi-layered sandbox isolation architecture, specifically including:

[0017] The first layer of isolation: container technology is used to isolate the processes of the proactive defense system from the processes of the normal production system. The permissions of the containers are configured in a fine-grained manner, limited to the permissions actually needed by the system, and avoiding direct interaction between the defense system and the production system.

[0018] The second layer of isolation: controls access to the production system kernel through whitelisting technology, ensuring that only authorized processes can access production system resources;

[0019] The third layer of isolation: By enforcing access control policies, the interaction between the proactive defense system and the production system is restricted, preventing the defense system from accessing unnecessary objects.

[0020] In any of the above technical solutions, the dynamic orchestration module further adjusts the attack surface characteristics dynamically at different points in time through an event-driven approach, including:

[0021] At time t1, the production node confuses the attacker by configuring a fake Bind DNS, HTTP server, Samba, FTP, and Apache Tomcat network service, and logs all IPs accessing the service.

[0022] At time t2, the production node is configured with SSH, Bind DNS, Rpcbind, and MySQL network services to redirect all access requests to a specific port. At the same time, the production node is configured with a fake file named Fakefile0 and external access records to this fake file are monitored.

[0023] At time t3, the production node reconfigures Bind DNS, HTTP server, and Samba, and constructs a fake file Fakefile1. The system denies all access to the fake file Fakefile1 and locks users who attempt to access it. The production node also reconfigures FTP, Bind DNS, Samba, and Apache Tomcat, and constructs a fake file Fakefile2. The system records all IPs that access Fakefile2 and transparently filters access requests from these recorded IPs globally.

[0024] A dynamic attack surface transformation active defense method for production systems is also provided, which is applied to any of the above-mentioned dynamic attack surface transformation active defense systems for production systems.

[0025] The beneficial effects of this invention are:

[0026] The technical solution in this invention combines mobile target defense technology with network deception technology to dynamically adjust the attack surface of the production system. This not only effectively confuses attackers and increases the difficulty of their attacks, but also avoids interference with the production environment and waste of resources. Thus, while improving system security, it ensures the stability and efficiency of the production system.

[0027] Furthermore, the defense system of this invention adopts a lightweight deployment method, which avoids the excessive burden that traditional defense technologies place on the production system, and can respond to potential threats in real time, providing stronger proactive defense capabilities. Attached Figure Description

[0028] The advantages of the above and additional aspects of the present invention will become apparent and readily understood in the description of the embodiments in conjunction with the following drawings, wherein:

[0029] Figure 1 This is a schematic diagram of a dynamic attack surface transformation active defense system for a production system according to an embodiment of the present invention;

[0030] Figure 2 This is a schematic diagram of dynamic attack surface transformation of an active defense system for a production system, according to an embodiment of the present invention. Detailed Implementation

[0031] To better understand the above-mentioned objectives, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other.

[0032] In the following description, many specific details are set forth in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and therefore the scope of protection of the invention is not limited to the specific embodiments disclosed below.

[0033] like Figure 1 and Figure 2 As shown, this embodiment provides a dynamic attack surface transformation proactive defense system for production systems. By combining moving target defense technology and network deception technology, it provides an integrated proactive defense solution. This system can disguise and dynamically change network services, file systems, user accounts, and other resources on real nodes of the production system, thereby dynamically changing the attack surface, confusing attackers, and improving system security.

[0034] The proactive defense system includes: a system support module, an interface interpreter module, a moving target construction module, a dynamic orchestration module, a management module, an information processing module, a threat monitoring module, and a security deployment module.

[0035] The various modules mentioned above work together in close collaboration to protect the security of the production system: the system support module provides basic resources and support to other modules, including providing fake and masquerading functions for network services, file systems, and user account resources. The system support module encapsulates the underlying masquerading resources into standard interfaces that can be called by upper-layer modules through the interface interpreter module. The programming languages ​​of the system support module and the mobile target construction module are different: the underlying masquerading resources provided by the system support module are closer to the underlying implementation of the operating system, so its programming language is generally C or C++, while the mobile target construction module is closer to the user operation application layer and is usually implemented in Python. The interface interpreter module establishes the interface standard between the programming languages ​​of the system support module and the mobile target construction module. The mobile target construction module interacts with the system support module through the interface interpreter, supporting the upper-layer dynamic orchestration module to adjust the attack surface characteristics, perform network service masquerading, file system masquerading, and user account masquerading, increasing the difficulty for attackers to identify and exploit vulnerabilities.

[0036] When the threat monitoring module detects a potential attack, it transmits the relevant threat information to the dynamic orchestration module through the management module. The dynamic orchestration module then triggers dynamic orchestration and changes to the underlying masquerading resources of network services, file systems, and user accounts based on the threat information, thereby adjusting the attack surface characteristics.

[0037] Meanwhile, the information processing module helps administrators understand the system's security posture and the activities of each module in a timely manner by displaying system status, storing logs, and handling alarms. The information processing module not only displays attack surface changes from the dynamic orchestration module, but also handles security alarms from the threat monitoring module, providing administrators with a comprehensive defense view.

[0038] Through this collaborative work, the various modules in the system form a multi-layered defense system, ensuring that the system can respond and adjust in a timely manner in the event of any potential attack, thereby effectively protecting the production system from external threats.

[0039] Specifically, the system support module is the basic support part of the defense system. It is responsible for providing basic functions in multiple aspects, including technical support for network, file system, user environment and logs, to ensure that the system can operate efficiently and securely, and to support upper-layer modules (such as the moving target construction module, dynamic orchestration module, etc.) to camouflage and dynamically change.

[0040] Network Components: By simulating real network services and enabling these services to exhibit different characteristics at different times, the network component confuses attackers and increases the difficulty of their attacks. The network component supports disguising specified network services. By disguising common network services (such as HTTP, DNS, FTP, etc.) on open ports, the system can make attackers believe that these services are real targets within the system, when in reality they are just decoys with no real service content. Building upon the disguised services, the network component can also dynamically generate signatures for the disguised services. These are seemingly valid false response messages obtained by attackers when probing service characteristics, thus increasing the difficulty of reconnaissance. The disguised services can change at any time, making it impossible for attackers to determine the true state of the disguised service through signatures and other information. The network component supports listening on a set of predefined ports, which may be ports for real business operations or ports for disguised services. When attackers attempt to access these ports, the network component dynamically monitors and responds to these requests, thus guiding the attackers to false targets. The network component can also dynamically adjust the listening ports according to the system's security requirements; it can adjust which ports are open at different times, further confusing attackers.

[0041] File system components: By simulating the structure of a real file system, attackers find it difficult to distinguish which files are actually present and which are decoys. These components can create fake files or directories in production systems that appear very similar to files in the real system, even sharing the same filenames, directory structures, and permission settings, thus misleading attackers into believing they have gained genuine file access. The components can attach listeners to both fake and real files, monitoring and recording attacker activity in real time whenever they access these files. Furthermore, the components perform integrity checks on real files to ensure they haven't been accessed or tampered with without authorization. This allows the system to promptly detect if attackers are attempting to penetrate the file system and obtain sensitive data. For real files and directories, the components can monitor for abnormal operations. For example, the system can record which users or processes accessed which files and check for unauthorized operations. If attackers are detected exploiting file vulnerabilities, the system can take measures such as terminating their operations or locking their access permissions.

[0042] User Environment Component: This component simulates user accounts and environments, preventing attackers from gaining true access to the core of the production system even if they acquire certain user privileges. It deceives attackers by providing fake user accounts and dynamically configured user environments. The component can create numerous fake user accounts, each possessing characteristics of a real user, such as username, password, UID (User ID), and user root directory. Attackers might gain access to these fake accounts through some means, believing they have successfully penetrated the system, but in reality, these accounts do not have actual access to the production system. The component also configures user root directories and initial environment settings for these fake user accounts, simulating a normal user environment, which may lead attackers to believe they have obtained valid user privileges. It can even edit files and run programs; however, these operations are merely for creating a fake environment and pose no threat to the production system. To further confuse attackers, the user environment component also provides a highly interactive fake shell service. When an attacker successfully logs in through an account, the system provides a fake shell environment that looks identical to a real user shell, but in reality, it is just simulating the attacker's actions. In this way, attackers cannot actually access sensitive data or critical applications in the production system. The user environment component can dynamically adjust the configuration of the fake user account. For example, the system can change the password or root directory path of the fake account at different times, further increasing the level of obfuscation for attackers. In this way, attackers cannot obtain continuous access through a fixed configuration.

[0043] Log Component: Records and processes various operation and event logs within the system. Through standardized processing and analysis of logs, the log component helps the system promptly detect abnormal behavior and issue alerts, while also providing a basis for subsequent security analysis. The log component records the operations of all system support modules, including access to spoofed services, spoofed files, and spoofed user accounts. Detailed log recording allows the system to track attacker behavior, helping administrators analyze attack methods. When attackers perform malicious operations, the log component can trigger alerts, promptly notifying system administrators. The log component standardizes all log information and stores it in a structured database, allowing administrators to query and analyze this log data as needed, extracting potential security threat information. The log component also possesses analytical capabilities, automatically identifying potential security events and abnormal behavior patterns. Through log data analysis, the system can discover attackers' attempts to bypass defenses and adjust defense strategies to address new threats.

[0044] The main task of the interface interpreter module is to standardize and unify the interfaces of the various functions provided by the system support modules. It transforms the management capabilities of various underlying resources (such as network, file system, and user environment) into a unified interface for upper-layer modules to call. This module provides a set of standardized API interfaces to ensure coordinated operation between different modules.

[0045] The interfaces provided by the interface interpreter module include:

[0046] The network service interface is used to dynamically configure masquerading services and listening ports.

[0047] The file system interface is used to configure masquerading files and access monitoring.

[0048] The user environment interface is used to configure fake user accounts and dynamic user environments.

[0049] The function of the mobile target building module is to interact with the system support module through the interface interpreter, build and support the dynamic orchestration of fake network services, fake file systems and fake user accounts, and enhance the system's defense capabilities; the mobile target building module includes network service components, file system components and user account components.

[0050] Network Service Component: This component supports the function of masquerading services, which can masquerade any service on a selected open port and respond to the probe of these services through dynamically generated signatures. The purpose of masquerading services is to make it impossible for attackers to identify which services are real, thereby prolonging the attack reconnaissance phase. In addition, the network service component also provides a listening service function, which listens to predefined ports in real time and can dynamically adjust the listening ports, supporting multiple port configurations including real business service ports and masquerading service ports.

[0051] File System Component: The main function of the file system component is to provide file system masquerading and dynamic orchestration support. It supports the creation of masquerading files and attaches listeners to all masquerading files to detect whether anyone is accessing these files. Once abnormal file access is detected, it can trigger alarms and take countermeasures. In addition, the file system component also supports monitoring access to real files and directories in the production system and logging all operations. In this way, potential security risks can be detected and responded to in a timely manner in the production system.

[0052] User Account Component: The User Account Component is responsible for building fake user accounts in the production system and providing a dynamic and interactive environment for these fake accounts. For example, it can simulate a highly interactive fake shell service, making attackers believe that they have obtained the privileges of a real user and begin to operate on the real file system. However, in reality, the attacker is still in a fake environment and cannot actually harm the production system.

[0053] The dynamic orchestration module is responsible for dynamically changing attack surface features in an event-driven manner. Based on finite state machine theory, this module constructs an attack surface state transformation model based on resources such as network services, file systems, and user accounts in the system. In this model, the attack surface feature vector is composed of the states of multiple system resources, and the characteristics of each resource determine the current security state faced by the system. Through rule configuration and threat event feedback, the dynamic orchestration module can adjust the configuration of various resources, thereby changing the attack surface seen by the attacker.

[0054] The dynamic orchestration module is designed based on the finite state machine theory. It abstracts the state of the system at each moment into an attack surface feature vector. This vector is composed of the features of multiple system resources (such as network services, file systems, user accounts, etc.) at that moment. The features of each resource (such as port, protocol, file name, user account information, etc.) determine the security state of the resource.

[0055] In the attack surface feature vector model, the system's attack surface is presented as a set of states; each state represents the system's feature configuration at a certain moment, and the state of each resource is affected by external threat events; through linkage with the threat monitoring module, the system can update the attack surface state and change the system's security layout based on real-time threat events.

[0056] The attack surface state transition is triggered by the threat monitoring module. When the threat monitoring module detects a potential security threat, it transmits the threat information to the dynamic orchestration module. The dynamic orchestration module then adjusts the state of various resources in the system based on this information. For example, it might close certain ports or switch masquerading services, thereby altering the attack surface so that attackers see different attack surface characteristics at different times.

[0057] This dynamic process is achieved through "rule configuration." Administrators can configure different rules based on different threat events, instructing the system on how to adjust the characteristics of network services, file systems, and user accounts, thereby changing the attack surface state.

[0058] Each attack surface feature vector consists of the states of multiple resources. The following are some common resource types in the system and their feature composition:

[0059] Network service characteristics include service name, protocol type, and open ports.

[0060] File system characteristics include filename, file permissions, file path, and file owner.

[0061] User account characteristics include username, password, UID (user ID), and user root directory.

[0062] These resource characteristics together constitute a constant attack surface state. The task of the dynamic orchestration module is to adjust these characteristics according to different threat events, so that the "attack surface" seen by attackers is constantly changing, thereby increasing the difficulty of their attacks.

[0063] To better demonstrate how the dynamic orchestration module works, the following example illustrates the changes in the attack surface state at different points in time.

[0064] Table 1. Attack surface characteristics at times t1, t2, and t3

[0065]

[0066]

[0067] At time t1, production node 1 exposes DNS, HTTP, and Samba services, and all IPs accessing these services will be logged; production node 2 exposes FTP, DNS, Samba, and Apache Tomcat services, and provides fake interactions for these services, making it impossible for attackers to confirm which services are genuine.

[0068] At time t2, production node 1 exposed SSH, DNS, Rpcbind, and MySQL services, and all requests to these services were redirected to a specific port; production node 2 exposed the DNS service and introduced a fake file named "Fakefile0", and all access to Fakefile0 was logged and triggered an alarm.

[0069] At time t3, production node 1 exposed DNS, HTTP, and Samba services and introduced the fake file Fakefile1. All access to Fakefile1 was denied, and users who operated on the file were locked out. Production node 2 exposed FTP, DNS, Samba, and Apache Tomcat services and introduced the fake file Fakefile2. All IPs that had accessed Fakefile2 were transparently filtered when accessing the real services, thus preventing attackers from continuing to penetrate the network.

[0070] In practical applications, the workflow of the dynamic orchestration module is as follows:

[0071] Threat monitoring: The threat monitoring module monitors potential threat events inside and outside the system in real time, such as abnormal logins, network scans, and vulnerability exploits.

[0072] Adjusting rule configurations: When the threat monitoring module detects a potential threat, the dynamic orchestration module adjusts the characteristics of network services, file systems, and user accounts according to preset rule configurations. For example, it can close certain ports, hide real services, or start new masquerading services.

[0073] Updated attack surface features: Based on the new rule configuration, the attack surface feature vector changes, making the attack surface unpredictable. Attackers cannot predict the attack surface they will face in the next moment, increasing the difficulty of their attacks.

[0074] Feedback and learning: The system continuously learns and accumulates attacker behavior patterns, and adjusts the attack surface configuration based on attacker actions to maximize defense effectiveness.

[0075] The management module is the centralized management and configuration module of the system, providing functions for the use, deployment, maintenance, and management of the entire defense system. Through collaboration with other modules, it achieves the following key functions:

[0076] Remote deployment: The management module is responsible for remotely deploying components such as the system support module, interface interpreter module, moving target construction module, and dynamic orchestration module to the production system nodes.

[0077] Threat Alerts: When the threat monitoring module triggers a threat alert, the management module can receive the alert information in real time and adjust the system configuration or activate emergency response measures according to the security administrator's operational requirements.

[0078] Dynamic orchestration with manual intervention: The management module provides manual intervention capabilities, allowing security managers to directly modify orchestration rules or reset system configurations after a threat event occurs in real time.

[0079] The information processing module is primarily responsible for processing and displaying various status information, operation logs, and threat alerts within the system. This module stores logs from system support modules in a structured manner, generates external reports, and supports the threat monitoring module's automated decision-making regarding security incidents. Simultaneously, it also provides security operations personnel with support for analyzing, assessing, and making decisions regarding security incidents.

[0080] The threat monitoring module periodically processes data from the information processing module, generating alerts about potential threats detected. It also alerts the management module to real-time threat events, allowing security administrators to modify and reset configurations based on event-driven attack surface shift strategies. Furthermore, the threat monitoring module can integrate with existing security devices in the production system to promptly eliminate potential risks.

[0081] To ensure the security of the defense system itself, the security deployment module adopts a multi-layered sandbox isolation architecture to restrict access to the production system. Specific deployment measures include:

[0082] The first layer of isolation: Container technology is used to isolate the processes of the proactive defense system from those of the normal production system. Container permissions are configured with fine granularity, limiting access to only what the system actually needs, thus preventing direct interaction between the defense system and the production system.

[0083] The second layer of isolation: whitelisting technology is used to control access to the production system kernel, ensuring that only authorized processes can access system resources.

[0084] The third layer of isolation: By enforcing access control policies, the interaction between the defense system and the production system is restricted, preventing the proactive defense system from accessing unnecessary objects.

[0085] This multi-layered isolation architecture makes it difficult for attackers to breach the production system even if they manage to break through the defense system, thus further improving the overall system security.

[0086] In another embodiment of the present invention, the active defense system proposed in this invention is configured on a test server to simulate external attacks and verify the reliability of the active defense system.

[0087] The test server is equipped with a Production Control System (PCS) and a Manufacturing Execution System (MES). During the production process, it is necessary to ensure the security of the network and data to prevent attackers from penetrating the network and affecting the operation of the production line.

[0088] The system support module provides underlying camouflage resources to the moving target construction module, which then deploys the following camouflage resources in the nodes of the production control system and manufacturing execution system:

[0089] Disguised network services: including HTTP, FTP, DNS, and database (MySQL) services.

[0090] Fake file system: Multiple fake file directories and files were created, such as "Production Plan Table.xlsx" and "Confidential Data.csv".

[0091] Fake user accounts: Multiple seemingly real but invalid user accounts were added, such as user_admin and guest_operator.

[0092] The dynamic orchestration module dynamically adjusts the attack surface of the production system to reflect different states at different times. The state at each moment is determined by the configuration of network services, file systems, and user accounts. The orchestration rules set in this case are as follows:

[0093] Time t1: The core node exposes a fake network service, and the system records the visitor's behavior.

[0094] At time t2: Provide a disguised file to lure attackers to access it and record their access path.

[0095] Time t3: Disable access to sensitive files and directly lock down users who attempt to access them illegally.

[0096] The system exposed spoofing services: Bind DNS-53 for DNS queries, HTTP server-80 providing a fake production status monitoring page, and Samba-139,445 for sharing spoofed content files. After starting the simulated external attack, the attacker discovered the above services through network scanning tools and attempted to use brute-force tools to log in to the HTTP service and access certain shared files in the spoofed file system.

[0097] The dynamic orchestration module continuously monitors the access behavior of the above services and records the access IP in the log. For example, the dynamic orchestration module detects an abnormal request from the attacker's IP 192.168.1.101. The main characteristics of this request include: multiple attempts to log in to the fake HTTP service (triggering a large number of failed POST requests in a short period of time) and attempts to read the fake file "Production Plan Table.xlsx". The dynamic orchestration module records the IP 192.168.1.101 in the log.

[0098] The threat monitoring module determines that the abnormal requests detected by the dynamic orchestration module have malicious characteristics, generates a threat event alarm and pushes it to the management module. The threat event alarm includes the attacker's behavioral characteristics and IP address.

[0099] After receiving a threat event alert, the management module sends a control command to the dynamic orchestration module to shut down the originally exposed HTTP server-80 service, open SSH-22 and Rpcbind-111, and redirect all access to the fake service. The new fake service simulates the real login page and records all login attempts.

[0100] The dynamic orchestration module exposes a new fake file, Fakefile0 (named "financial data.csv"), to the attacker. When the attacker attempts to access this file, the system will capture their access path, access tools, and related behavioral data.

[0101] The simulated attacker continued the attack, and the dynamic orchestration module activated a new fake file, Fakefile1 (filenamed "production line equipment parameters.cfg"). The system directly locked the attacker's account that attempted to access Fakefile1, added the attacker's IP (192.168.1.101) to the blacklist, and the dynamic orchestration module triggered a system alarm through the management module. The information processing module displayed the system alarm to the administrator.

[0102] Finally, the information processing module collects and integrates all data from the threat monitoring module, dynamic orchestration module, and log component to generate a detailed attack event report. The attack event report includes: the attacker's IP address and timeline of behavior, the spoofed services and files accessed, the defense rules triggered by the system, and the adjustment measures. The administrator checks the event report and manually confirms whether further adjustments to the defense rules are needed. If new defense rules are developed, the dynamic orchestration module is updated and the new rules are enabled in the next attack.

[0103] In summary, this invention proposes a dynamic attack surface transformation proactive defense system for production systems, comprising: a system support module, an interface interpreter module, a moving target construction module, a dynamic orchestration module, a management module, an information processing module, and a threat monitoring module.

[0104] The system support module provides fake and disguise functions for network services, file systems, and user account resources. The system support module encapsulates the underlying resource functions into standard interfaces that can be called by upper-layer modules through the interface interpreter module. The interface interpreter module coordinates the interaction between different modules to ensure smooth information flow between them. The mobile target construction module interacts with the system support module through the interface interpreter to build and support the dynamic orchestration of fake network services, fake file systems, and fake user accounts, thereby enhancing the system's defense capabilities.

[0105] The dynamic orchestration module adjusts the attack surface characteristics by dynamically orchestrating and changing resources such as network services, file systems, and user accounts. These changes are triggered based on real-time security events detected by the threat monitoring module. When the threat monitoring module detects a potential attack, it transmits the relevant threat information to the dynamic orchestration module through the management module. The dynamic orchestration module immediately adjusts the attack surface according to the severity of the threat to increase the difficulty for attackers to identify and exploit vulnerabilities.

[0106] At the same time, the information processing module records the system's operation logs and displays the system status and threat alerts in real time, providing information for administrators to make decisions.

[0107] The steps in this invention can be adjusted, combined, or deleted according to actual needs.

[0108] The units in the device of the present invention can be merged, divided, or reduced according to actual needs.

[0109] Although the invention has been disclosed in detail with reference to the accompanying drawings, it should be understood that these descriptions are merely exemplary and not intended to limit the application of the invention. The scope of protection of the invention is defined by the appended claims and may include various modifications, alterations, and equivalents made to the invention without departing from the scope and spirit of the invention.

Claims

1. A dynamic attack surface changing active defense system for production systems, characterized in that, The active defense system includes: a system support module, an interface interpreter module, a moving target construction module, a dynamic orchestration module, a management module, an information processing module, and a threat monitoring module; The system support module provides spoofing and disguise functions for network services, file systems, and user account resources. The system support module encapsulates the underlying spoofing resources into standard interfaces that can be called by upper-layer modules through the interface interpreter module. The system support module and the mobile target construction module use different programming languages. The interface interpreter module establishes the interface standard between the programming languages ​​of the system support module and the mobile target construction module. The mobile target construction module interacts with the system support module through the interface interpreter, supporting the upper-layer dynamic orchestration module to adjust attack surface characteristics, perform network service spoofing, file system spoofing, and user account spoofing, increasing the difficulty for attackers to identify and exploit vulnerabilities. When the threat monitoring module detects a potential attack, it transmits the relevant threat information to the dynamic orchestration module through the management module. The dynamic orchestration module then triggers dynamic orchestration and changes to the underlying masquerading resources of network services, file systems, and user accounts based on the threat information, thereby adjusting the attack surface characteristics. At the same time, the information processing module records the system's operation logs and displays the system status and threat alerts in real time, providing information for administrators to make decisions.

2. The dynamic attack surface changing active defense system for production systems as described in claim 1, characterized in that, The system support modules include a network component, a file system component, a user environment component, and a log component, which respectively provide network masquerading services, file system masquerading, user environment masquerading, and operation log recording functions.

3. The dynamic attack surface changing active defense system for production systems as described in claim 2, characterized in that, The interfaces provided by the interface interpreter module include: a network service interface for dynamically configuring the masquerade service and listening port; a file system interface for configuring masquerade files and access monitoring; and a user environment interface for configuring masquerade user accounts and dynamic user environments.

4. The dynamic attack surface changing active defense system for production systems as described in claim 1, characterized in that, The dynamic orchestration module is based on finite state machine theory. It abstracts the states of resources such as network services, file systems and user accounts in the system into attack surface feature vectors, and adjusts the states of various resources through an event-driven mechanism.

5. The dynamic attack surface changing active defense system for a production system as described in claim 4, characterized in that, The dynamic orchestration module adjusts the configuration of system resources based on the threat information fed back by the threat monitoring module. The adjustments include: dynamically changing the configuration of the masquerading service; randomizing the file names, permissions, and access paths of the file system; and dynamically adjusting the root directory and environment configuration of the masquerading user account.

6. The dynamic attack surface changing active defense system for production systems as described in claim 1, characterized in that, The proactive defense system also includes: a security deployment module; the security deployment module achieves isolation between the defense system and the production system through a multi-layered sandbox isolation architecture, specifically including: The first layer of isolation: container technology is used to isolate the processes of the proactive defense system from the processes of the normal production system. The permissions of the containers are configured in a fine-grained manner, limited to the permissions actually needed by the system, and avoiding direct interaction between the defense system and the production system. The second layer of isolation: controls access to the production system kernel through whitelisting technology, ensuring that only authorized processes can access production system resources; The third layer of isolation: By enforcing access control policies, the interaction between the proactive defense system and the production system is restricted, preventing the defense system from accessing unnecessary objects.

7. The dynamic attack surface changing active defense system for a production system as described in claim 5, characterized in that, The dynamic orchestration module dynamically adjusts the attack surface characteristics at different points in time through an event-driven approach, including: At time t1, the production node confuses the attacker by configuring a fake Bind DNS, HTTP server, Samba, FTP, and Apache Tomcat network service, and logs all IPs accessing the service. At time t2, the production node is configured with SSH, Bind DNS, Rpcbind, and MySQL network services to redirect all access requests to a specific port. At the same time, the production node is configured with a fake file named Fakefile0 and external access records to this fake file are monitored. At time t3, the production node reconfigures Bind DNS, HTTP server, and Samba, and constructs a fake file Fakefile1. The system denies all access to the fake file Fakefile1 and locks users who attempt to access it. The production node also reconfigures FTP, Bind DNS, Samba, and Apache Tomcat, and constructs a fake file Fakefile2. The system records all IPs that access Fakefile2 and transparently filters access requests from these recorded IPs globally.

8. A method for proactive defense against dynamic attack surface changes in production systems, characterized in that, The active defense method is applied to the dynamic attack surface transformation active defense system for production systems as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Network security vulnerability defense system based on dynamic camouflage

    CN111835694A

  • Network security dynamic defense decision-making method based on space-time game

    CN112003854A