Network security active security defense method and system based on vulnerability utilization

Through global network situation chart and trapping chain technology, resources are dynamically allocated and trapping node deployment is adjusted, which solves the problems of static and unreasonable resource allocation in the existing technology, and effectively protects and resource optimization for high-risk areas.

CN119995960AActive Publication Date: 2025-05-13HANGZHOU YUHANG DISTRICT DATA RESOURCES MANAGEMENT BUREAU +1

Patent Information

Application Number
CN202510090333.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

When facing advanced persistent threats (APTs), the prior art is difficult to dynamically adjust defense strategies, unable to effectively guide attackers' behavior, and the resource allocation model is single, resulting in insufficient resources in high-risk areas or wasted resources in low-risk areas.

Method used

Through global network situation chart, path prediction and risk area division technology, resources are allocated dynamically, and a trap chain is formed by adjusting the deployment density of trapping nodes and feedback chain logic, guiding attackers' behavior, delaying the attack process, and capturing more attack feature data.

Benefits of technology

It significantly improves the protection capabilities of high-risk areas, optimizes resource utilization efficiency, reduces the attack risk of real nodes, and realizes dynamic defense of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995960A_ABST
    Figure CN119995960A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a network security active security defense method and system based on vulnerability utilization, and the method comprises the steps: collecting multi-modal data through a sensing module deployed in a network, and constructing a prediction model of a high-risk region and an attack path in combination with a global network situation map; according to the path prediction data and the risk region division result, dynamically allocating defense resources; by adjusting the deployment density of trapping nodes and feedback chain logic, a trapping chain is formed to guide an attack behavior, the operation characteristic data of an attacker is captured in real time, and a defense strategy is dynamically adjusted. Through the above process, the method achieves the precision of resource distribution, the optimization of the synergistic effect of trapping nodes, and the real-time guidance and interference of attack behaviors, greatly improves the defense efficiency and flexibility of a network, reduces the security threats of high-risk nodes, and effectively protects the core assets of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security active security defense method and system based on vulnerability exploitation. Background Art

[0002] As the complexity and diversity of cyber attacks continue to increase, traditional passive defense methods have become difficult to cope with emerging advanced persistent threats (APTs). Active defense can achieve more accurate and efficient network security protection by exploiting vulnerabilities to predict attack paths, guide attack behaviors, and dynamically adjust defense resources. This defense mode can not only identify potential threats in advance, but also weaken the attacker's threat capabilities to core nodes through entrapment mechanisms, providing a new technical solution for network security.

[0003] The existing technology (Chinese invention patent, publication number: CN118555134B) mainly predicts attack behaviors by analyzing the vulnerabilities of target nodes and their attack indicators, and optimizes defense strategies based on the attack probability of target nodes. However, the defense deployment of the existing technology is mainly based on static vulnerability analysis and probability prediction. Although it can simulate the attack path, it cannot adjust the trapping strategy according to the real-time behavior of the attacker, nor can it guide the attacker into the forged path; the existing technology does not fully consider the risk differences of different nodes in the network, and the resource allocation mode is relatively single, which may lead to insufficient resources in high-risk areas or waste of resources in low-risk areas; the existing technology only simulates attack behaviors, does not fully utilize the collaborative effect of trapping nodes, and cannot form an efficient trapping chain to guide the attacker's behavior. The existing technology performs complex quantitative analysis in high-dimensional space, resulting in low computational efficiency and response speed that is difficult to meet real-time defense requirements. Summary of the invention

[0004] In view of the many problems existing in the above-mentioned prior art, the present invention provides a network security active security defense method and system based on vulnerability exploitation. Based on vulnerability exploitation, the present invention dynamically allocates resources to high-risk areas in the network through a global network situation diagram, path prediction and risk area division technology, and forms a trapping chain by adjusting the deployment density of the trapping nodes and the feedback chain logic. By optimizing the synergy and feedback strategy of the trapping nodes, the present invention can guide the attacker's behavior, delay the attack process, and capture more attack feature data, and finally realize the dynamic defense of the network. The present invention significantly improves the protection capability of high-risk areas, optimizes resource utilization efficiency, and reduces the attack risk of real nodes.

[0005] A network security active security defense method based on vulnerability exploitation includes the following steps:

[0006] Collect multimodal data through the perception module deployed in the network, preprocess and extract features of the collected multimodal data, and generate vulnerability feature data; calculate the risk propagation factor and propagation probability of the node based on the vulnerability feature data to generate risk propagation data;

[0007] Generate a trap node based on the risk propagation data, the trap node simulates the vulnerability characteristics and high-value targets of the real node, and embeds a feedback model to capture the attacker's operation behavior and generate feedback behavior data and attack path data; adjust the deployment strategy of the trap node based on the feedback behavior data and attack path data;

[0008] Constructing a global network situation map according to the attack path data and the trapping node deployment strategy, predicting the attack path based on the situation map, generating path prediction data, and dividing the network into high-risk areas, medium-risk areas, and low-risk areas;

[0009] Based on the path prediction data and the risk area division results, defense resources are dynamically allocated, the deployment density of the trapping nodes and the feedback chain logic are adjusted, and resource dynamic allocation data is generated to optimize the defense effect of high-risk areas.

[0010] Preferably, the risk propagation factor of the node is calculated by the following formula:

[0011] R i =α·L i +β·T i +γ·A i

[0012] Among them, R i represents the risk propagation factor of node i, which is used to characterize the potential risk level of the node as the starting point of attack propagation in the network; L i represents the vulnerability score of node i, which is obtained by quantifying the severity and difficulty of exploitation of the vulnerability; T i A represents the attack complexity score of node i, which is quantified by evaluating the resource investment and permission requirements required to attack the node; i represents the abnormal behavior score of node i, which is obtained by analyzing the abnormal communication behavior of the node in the network log; α, β, and γ are the weight factors of the vulnerability score, attack complexity score, and abnormal behavior score, respectively. The weight factors are tuned according to the historical attack behavior data to balance the contribution of different scores to the risk propagation factor.

[0013] Preferably, the propagation probability between the nodes is calculated by the following formula:

[0014]

[0015] Among them, P(i→j) represents the probability of spreading the attack from node i to node j, which is used to quantify the propagation direction of the attack behavior; R i represents the risk propagation factor of node i, reflecting the risk level of the node as the starting point of attack propagation; W ij represents the communication weight between node i and node j, which is calculated by weighting the communication flow, access frequency and connection stability between the two nodes; ∑ k R k It represents the sum of risk propagation factors of all nodes in the network, and is used to normalize the propagation probability so that the probability of each propagation path is consistent with the distribution of the overall network propagation behavior; the propagation probability is used to determine the attacker's potential next target node.

[0016] Preferably, the trapping node dynamically responds to the attacker's operation behavior by embedding a feedback model, and the feedback model generates a feedback response according to the following formula:

[0017] F(x)=sin(k·x)+log(1+|x-μ|)

[0018] Among them, F(x) represents the feedback response value of the trapping node, which is used to interfere with and guide the attacker's behavior. The trapping node adjusts its behavior guidance strategy according to the feedback response value; x represents the characteristic value of the attacker's operation behavior, including the complexity of uploading malicious payloads and the behavior parameters of attempting to obtain resources; k represents the feedback frequency parameter of the trapping node, which is dynamically adjusted according to the current deployment strategy of the trapping node; μ represents the feedback center point, which is used to set the feedback trigger threshold of the trapping node.

[0019] Preferably, the construction of the global network situation map includes:

[0020] The real nodes and decoy nodes in the network are used as nodes of the graph;

[0021] Treat the communication relationships between nodes as edges of the graph;

[0022] The weight of the edge is calculated by the risk propagation factor and propagation probability of the node, and the weight is used to characterize the strength of the propagation relationship between the nodes.

[0023] Preferably, risk area division is performed through a global network situation map, and the division step includes:

[0024] Calculate the priority score of each node based on the path prediction data;

[0025] Nodes with priority scores greater than the set threshold and their associated nodes are classified as high-risk areas;

[0026] Nodes with priority scores within the set threshold range are classified as medium-risk areas;

[0027] Nodes with priority scores below a set threshold are classified as low-risk areas.

[0028] Preferably, the trapping nodes form a trapping chain by adjusting the deployment density and the logic of the feedback response chain. The trapping chain enhances the guidance of the attack behavior through the synergy between the nodes. The synergy is calculated according to the following formula:

[0029]

[0030] Where S(i→j) represents the collaborative optimization value between the trapping node i and the trapping node j; F i (x) and f j (x) represents the feedback function of the trapped node i and the trapped node j respectively;

[0031] The synergy effect is used to optimize the feedback chain strength between the decoy nodes to enhance the inducement of the attacker in the path.

[0032] Preferably, the step of dynamically allocating defense resources includes:

[0033] Deploy more decoy nodes in high-risk areas and enhance the feedback strength of decoy nodes to guide attacker behavior;

[0034] Keep the existing decoy node deployment in medium-risk areas and adjust the feedback frequency of decoy nodes to reduce resource usage;

[0035] Reduce the deployment of decoy nodes in low-risk areas and prioritize the released resources to high-risk areas.

[0036] Preferably, the resource allocation ratio of high-risk areas is calculated by the following formula:

[0037]

[0038] Among them, R alloc (i) represents the ratio of resources allocated to node i, which is used to dynamically allocate defense resources of decoy nodes or real nodes; R i represents the risk propagation factor of node i, which is calculated by comprehensively calculating the node vulnerability score, attack complexity score and abnormal behavior score; H represents the set of nodes in the high-risk area, which is determined according to the path prediction data and the network situation diagram; ∑ j∈H R j It represents the sum of risk propagation factors of all nodes in the high-risk area and is used to normalize the resource allocation ratio;

[0039] The resource allocation ratio is used to guide the deployment density adjustment of the decoy nodes and the defense strategy optimization of the real nodes, so as to give priority to improving the defense capabilities of high-risk areas.

[0040] A system for implementing the network security active security defense method based on vulnerability exploitation, comprising:

[0041] A perception module is used to be deployed in the network to collect multimodal data, wherein the multimodal data includes structured data, unstructured data and semi-structured data; the perception module is further used to format, clean and standardize the collected data, and generate vulnerability feature data;

[0042] A risk calculation module, used to calculate the risk propagation factor and propagation probability of the network node based on the vulnerability feature data, and generate risk propagation data, wherein the risk propagation factor is calculated according to the vulnerability score, attack complexity score and abnormal behavior score of the node, and the propagation probability is calculated based on the communication weight between nodes and the risk propagation factor;

[0043] A trapping node generation module, used to generate a trapping node based on the risk propagation data, wherein the trapping node simulates the vulnerability characteristics and high-value targets of the real node, and captures the attacker's operation behavior through an embedded feedback model to generate feedback behavior data and attack path data;

[0044] A deployment optimization module, used to adjust the deployment strategy of the trapping node based on the feedback behavior data and the attack path data, wherein the deployment strategy includes the optimization of the deployment position of the trapping node and the feedback response logic;

[0045] A situation awareness module is used to construct a global network situation map based on the attack path data and the trapping node deployment strategy, and the situation awareness module is further used to predict the attack path based on the global network situation map, generate path prediction data, and divide the network into high-risk areas, medium-risk areas, and low-risk areas according to the path prediction data;

[0046] A resource allocation module, for dynamically allocating defense resources based on the path prediction data and the risk area division results, wherein the resource allocation includes adjusting the deployment density and feedback chain logic of the trapping nodes, and generating resource dynamic allocation data to optimize the defense effect of the high-risk area;

[0047] A data storage module is used to store the multimodal data, vulnerability feature data, risk propagation data, feedback behavior data, attack path data, path prediction data and resource dynamic allocation data.

[0048] Compared with the prior art, the advantages and beneficial effects of the present invention are:

[0049] The present invention builds a dynamic trapping chain by adjusting the deployment density of the trapping nodes and the feedback response chain logic, guiding the attacker to operate cyclically in the forged path, thus greatly weakening the threat to the real nodes.

[0050] The resource allocation ratio is dynamically adjusted in combination with the risk propagation factor of the node. The present invention concentrates limited defense resources on key nodes and high-risk areas of the attack path, significantly improving resource utilization efficiency.

[0051] Combined with path prediction and risk area division, the present invention can update network defense strategies in real time and quickly adapt to changes in network environment and attack behavior;

[0052] Compared with the prior art, the present invention reduces complex high-dimensional operations and dynamically adjusts resource allocation strategies, so that the system can efficiently respond to network security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a schematic diagram of the process of the present invention;

[0054] Figure 2 It is a logical schematic diagram of the synergistic effect of the trapping chain in the present invention;

[0055] Figure 3 A logical schematic diagram of the risk area division in the present invention;

[0056] Figure 4 It is a structural block diagram of the system of the present invention. DETAILED DESCRIPTION

[0057] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure.

[0058] like Figure 1 As shown, a network security active security defense method based on vulnerability exploitation includes the following steps:

[0059] Collect multimodal data through the perception module deployed in the network, preprocess and extract features of the collected multimodal data, and generate vulnerability feature data; calculate the risk propagation factor and propagation probability of the node based on the vulnerability feature data to generate risk propagation data;

[0060] As a frontier component in the network environment, the perception module is deployed in multiple key locations to collect multimodal data in real time during network operation, including structured data (such as vulnerability information generated by vulnerability scanning tools), unstructured data (such as abnormal behavior records in network logs), and semi-structured data (such as communication protocol data extracted by protocol analyzers). The diversity of these multimodal data ensures that the perception module can fully capture potential threat information and abnormal behavior in the network operation status.

[0061] The collected multimodal data are first standardized and cleaned through the data preprocessing module to ensure the integrity and consistency of the data. Specifically, preprocessing includes the following steps: formatting, converting data from different sources into a unified format; noise filtering, removing irrelevant redundant data by setting thresholds or models; and standardization, normalizing data values ​​to eliminate deviations caused by different data sources. This process ensures high-quality input data required for subsequent analysis.

[0062] After completing the preprocessing, the present invention further performs an in-depth analysis of the multimodal data through a feature extraction module to generate vulnerability feature data. The feature extraction module uses targeted technical means according to different data types. For example, for the structured data generated by vulnerability scanning, relevant features are extracted by parsing vulnerability scores, utilization complexity, node exposure and other information; for unstructured network logs, abnormal access sequences and attackers' behavior time intervals are extracted through log mining and behavior pattern analysis; and for semi-structured data, abnormal communication features are extracted through field analysis and pattern matching of communication protocols. Through feature extraction, the original multimodal data is converted into structured vulnerability feature data. These data not only reflect the vulnerabilities existing in the network, but also include potential paths for vulnerability exploitation and possible actions of attackers, providing key support for subsequent analysis.

[0063] Based on the above vulnerability feature data, the risk calculation module further calculates the risk propagation factor and propagation probability of the node to generate risk propagation data. The risk propagation factor reflects the risk level of the node being exploited by attacks. Its calculation comprehensively considers the core indicators such as the node's vulnerability score, attack complexity score and abnormal behavior score. The attack complexity score is mainly quantified based on the resources and permissions required for the attacker to successfully exploit the node vulnerability; the abnormal behavior score is weighted based on the abnormal communication behavior characteristics of the node in the network log. The propagation probability is used to characterize the priority of the attacker's propagation path between nodes. Its calculation process combines the communication weights, traffic characteristics and risk propagation factors between nodes to ensure that the propagation probability can truly reflect the potential threat transmission relationship between nodes.

[0064] Example: Assume that in a certain enterprise network, the perception module is deployed on the network interface of the core switch and the server cluster. In a simulated attack experiment, the perception module captures the vulnerability information (structured data) generated by the attacker through the vulnerability scanning tool, as well as the failed records of attempts to log in through the SSH service (unstructured data). Through data preprocessing and feature extraction, the system identifies that a certain server node has a high-risk vulnerability (CVE-XXXX), and its vulnerability score is 9.0. Combined with network log analysis, it is found that the attacker attempted to brute force login multiple times, and the abnormal behavior score is 8.5. Subsequently, the risk calculation module combines these features to calculate the risk propagation factor of the server node as 7.8, and combines its communication weight with other nodes to determine the target node and path that the attacker may try to spread next.

[0065] Preferably, the risk propagation factor of the node is calculated by the following formula:

[0066] R i =α·L i +β·T i +γ·A i

[0067] Among them, R i represents the risk propagation factor of node i, which is used to characterize the potential risk level of the node as the starting point of attack propagation in the network; L i represents the vulnerability score of node i, which is obtained by quantifying the severity and difficulty of exploitation of the vulnerability; T i A represents the attack complexity score of node i, which is quantified by evaluating the resource investment and permission requirements required to attack the node; i represents the abnormal behavior score of node i, which is obtained by analyzing the abnormal communication behavior of the node in the network log; α, β, and γ are the weight factors of the vulnerability score, attack complexity score, and abnormal behavior score, respectively. The weight factors are tuned according to the historical attack behavior data to balance the contribution of different scores to the risk propagation factor.

[0068] The present invention calculates the risk propagation factor R of the node i , to quantitatively analyze the security risks of each node in the network, thus providing an important basis for subsequent active security defense operations. The calculation of the risk propagation factor integrates three key indicators: vulnerability score, attack complexity score, and abnormal behavior score, and flexibly adapts to different network environments and attack behavior patterns through the tuning of weight factors α, β, and γ.

[0069] Vulnerability Score (L i), vulnerability scores are obtained by extracting data from existing vulnerability databases (such as the CVE database) and quantified by combining the severity of the vulnerability and the difficulty of exploitation. The severity of the vulnerability is quantified based on the degree of damage that the vulnerability may cause, such as data leakage, system crash, etc.; the difficulty of exploitation is based on the operability of the vulnerability, such as whether specific conditions or complex steps are required for exploitation. The score is usually expressed in a range of 0 to 10, where a higher value indicates that the node has a high-risk vulnerability and is easily exploited by attackers.

[0070] Attack complexity score (T i ), the attack complexity score is quantified by analyzing the resources and permissions required by an attacker to exploit a node vulnerability. For example, whether an attacker needs administrator privileges, a specific time window, or a large amount of computing resources to implement an attack. The higher the complexity score, the less likely the node is to be attacked.

[0071] Abnormal behavior score (A i ), the abnormal behavior score is based on the analysis of abnormal communication behaviors captured in the network log, such as high-frequency access requests during abnormal periods, a large number of abnormal port connections or packet loss, etc. The logs are analyzed through pattern recognition and machine learning models (such as random forest or LSTM). The score of abnormal behavior reflects the degree of deviation of the node's current activity from normal behavior. The higher the score, the more likely the node is to be exploited.

[0072] Weight factors (α, β, γ) are tuned through statistical analysis of historical attack behavior data to adapt to different network scenarios. For example, in financial networks, abnormal behavior may be more important, so the weight of γ will be set higher, while the weight of vulnerability score α will be relatively low. The weight is tuned by minimizing the error between the historical attack path and the actual attack path.

[0073] By calculating the risk propagation factor of the node, potential high-risk nodes can be quickly identified in the network, and their possibility of being the starting point of the attack or the key node in the propagation path can be clarified. The calculation results of the risk propagation factor are not only used to directly evaluate the security status of the node, but also for the calculation of subsequent propagation probabilities and the dynamic allocation of global defense resources. Compared with traditional risk assessment methods that rely on a single indicator (such as vulnerability scores or abnormal behaviors), the present invention makes the risk assessment results more targeted and accurate through comprehensive calculations in multiple dimensions. In addition, the dynamic tuning of the weight factor enhances the adaptability of the solution to diverse network environments.

[0074] In the embodiment, it is assumed that there are three key nodes in a certain enterprise network: node A, node B and node C. The following features are extracted from the multimodal data collected by the perception module:

[0075] Node A, vulnerability score (LA ): 8.5 (there are multiple high-risk vulnerabilities, and they are easy to be exploited). Attack complexity score (T A ): 3.2 (low attack difficulty). Abnormal behavior score (A A ): 7.1 (abnormal access behaviors frequently occur). Weight factors: α=0.4, β=0.3, γ=0.3.

[0076] The risk propagation factor of node A is calculated according to the formula:

[0077] R A =0.4·8.5+0.3·3.2+0.3·7.1=6.46

[0078] Node B, vulnerability score (L B ): 5.0 (moderate vulnerability exists). Attack complexity score (T B ): 6.8 (high attack difficulty). Abnormal behavior score (A B ): 4.3 (a small amount of abnormal communication occurs). Weight factors: α=0.4, β=0.3, γ=0.3.

[0079] Calculate the risk propagation factor of node B:

[0080] R B =0.4·5.0+0.3·6.8+0.3·4.3=5.39

[0081] Node C, vulnerability score (L C ): 2.1 (no obvious vulnerability). Attack complexity score (T C ): 7.9 (very difficult to attack). Abnormal behavior score (A C ): 2.0 (normal behavior). Weighting factor:

[0082] α=0.4, β=0.3, γ=0.3.

[0083] Calculate the risk propagation factor of node C:

[0084] R C =0.4·2.1+0.3·7.9+0.3·2.0=3.77

[0085] From the above calculation, we can see that node A has the highest risk propagation factor, so it is identified as a high-risk node and prioritizes the allocation of defense resources or the deployment of trapping nodes. Node B has a medium propagation factor and can be monitored as a medium-risk node, while node C has a low risk and can be temporarily ignored.

[0086] Preferably, the propagation probability between the nodes is calculated by the following formula:

[0087]

[0088] Among them, P(i→j) represents the probability of spreading the attack from node i to node j, which is used to quantify the propagation direction of the attack behavior; R i represents the risk propagation factor of node i, reflecting the risk level of the node as the starting point of attack propagation; W ij represents the communication weight between node i and node j, which is calculated by weighting the communication flow, access frequency and connection stability between the two nodes; ∑ k R k It represents the sum of risk propagation factors of all nodes in the network, and is used to normalize the propagation probability so that the probability of each propagation path is consistent with the distribution of the overall network propagation behavior; the propagation probability is used to determine the attacker's potential next target node.

[0089] Risk propagation factor R i It is a quantitative indicator of the node's own security, which represents the risk level of the node being exploited by attackers. The higher the risk propagation factor of node i, the more attackers are inclined to propagate from this node. The risk propagation factor is calculated by comprehensively calculating the node's vulnerability score, attack complexity score, and abnormal behavior score.

[0090] Communication weight W ij Represents the connection strength between node i and node j, which is weighted by the following core indicators: (1) Communication flow: The higher the average communication flow between nodes, the more credible the path that the attacker may choose. (2) Access frequency: There may be a higher dependency between high-frequency communication nodes, and attackers tend to choose paths with high access frequencies. (3) Connection stability: Long-term stable communication links are more likely to be exploited by attackers. The weight calculation combines these three indicators to reflect the true strength of the connection between two nodes.

[0091] Normalization processing∑ k R k In order to ensure the overall consistency of the propagation probability, the sum of the risk propagation factors of all nodes is used as the denominator for normalization. This ensures that the probability value of each propagation path is in the range of [0,1] and the sum of all propagation probabilities is 1, forming a probability distribution model.

[0092] The calculation of propagation probability not only quantitatively describes the possible propagation paths of attackers, but also dynamically reflects the propagation risk relationship between different nodes in the network, providing an important basis for the deployment of trapping nodes and resource allocation of the defense system.

[0093] By calculating the propagation probability, the present invention can dynamically evaluate the possibility of an attacker propagating from one node to another, and draw a potential attack path diagram in combination with the global network situation diagram. Compared with the traditional propagation path prediction method based on static features, the present invention not only comprehensively considers the security of the node itself, but also fully considers the communication characteristics and dynamic interaction between nodes by introducing risk propagation factors and communication weights, thereby significantly improving the accuracy of propagation path prediction. In addition, through normalization processing, the propagation probability can reflect the global distribution of propagation risks of each node in the network, providing a scientific basis for resource optimization of the defense system.

[0094] In the embodiment, it is assumed that there are nodes A, B and C in a certain enterprise network, and the following parameters are obtained through the perception module and the risk calculation module:

[0095] Node A: Risk propagation factor R A =8.0; Communication weight W with node B AB =5.0; Communication weight W with node C AC =2.0.

[0096] Node B: Risk propagation factor R B =6.0; Communication weight W with node C BC =4.0.

[0097] Node C: Risk propagation factor R C =4.0.

[0098] The probability of node A propagating to node B and node C is calculated using the propagation probability formula:

[0099] Calculate the sum of risk propagation factors of all nodes: ∑ k R k =R A +R B +R C =8.0+6.0+4.0=18.0

[0100] Calculate the probability of node A spreading to node B:

[0101] Calculate the probability of node A spreading to node C:

[0102] Calculate the probability of node B spreading to node C:

[0103] From the calculation results, we can see that the probability of node A spreading to node B is the highest (2.22), indicating that node B is the preferred target for attackers to spread from node A. The probability of node A spreading to node C is lower (0.89), which may be due to the communication weight WAC The probability of node B propagating to node C is medium (1.33), indicating that node C has a certain potential risk in the propagation path.

[0104] Through this process, the system can identify the possible propagation direction of the attacker and provide precise input for the deployment of decoy nodes. For example, the system can prioritize the deployment of more decoy nodes near node B, and guide the attacker further into the high decoy density area by optimizing the feedback logic, thereby weakening its threat to the real node.

[0105] Generate a trap node based on the risk propagation data, the trap node simulates the vulnerability characteristics and high-value targets of the real node, and embeds a feedback model to capture the attacker's operation behavior and generate feedback behavior data and attack path data; adjust the deployment strategy of the trap node based on the feedback behavior data and attack path data;

[0106] The generation of decoy nodes is based on risk propagation data. Risk propagation data contains the risk propagation factor and propagation probability of the node. Through these data, key nodes and high propagation risk nodes in the attack propagation path can be identified. By deploying decoy nodes at key locations in the attack path (such as near high-risk nodes or on links with high propagation probabilities), the behavior path of the attacker is guided, thereby reducing the risk of attack on real nodes.

[0107] like Figure 2 As shown in the figure, the decoy node simulates the vulnerability characteristics and high-value targets of the real node, making it look like an important network asset (such as a database server, a financial system node, or a file storage service). The specific implementation includes configuring vulnerability information similar to that of the real node (such as simulating CVEs vulnerabilities), opening disguised service ports (such as common attack target ports 80 and 443), and forging the content of key assets (such as database tables, file system structures, etc.). These designs can effectively attract attackers to prioritize decoy nodes as attack targets.

[0108] The feedback model embedded in the trapping node is used to capture the attacker's operation behavior in real time. The role of the feedback model is to generate feedback behavior data by recording and analyzing the attacker's interaction in real time, including but not limited to: the type of vulnerability the attacker attempts to exploit (such as SQL injection, buffer overflow, etc.); the characteristics of the tools used by the attacker (such as traffic patterns, data packet characteristics); the attacker's operation sequence (such as file reading, directory browsing, command execution, etc.).

[0109] The feedback model uses a dynamic response mechanism to guide attackers to perform more in-depth operations. For example, when an attacker attempts to upload a malicious payload through an open port, the decoy node will simulate the normal file acceptance and execution process and record the complete attack process; or when an attacker attempts to brute force a user's password, the decoy node will deliberately delay the feedback time to induce the attacker to reveal more attack details.

[0110] The trapping node organizes the captured attacker's operation behavior into feedback behavior data, and analyzes the attack path in combination with the risk propagation data to generate attack path data. The attack path data further reveals the attacker's potential target nodes and path preferences by modeling the attacker's actual behavior, providing information input for global network defense.

[0111] Based on the feedback behavior data and attack path data, the system dynamically adjusts the deployment strategy of the decoy nodes. The optimized deployment strategy includes: dynamically adjusting the location of the decoy nodes, such as adding new decoy nodes to high-risk areas, or withdrawing some nodes from low-risk areas. Optimizing the feedback model logic of the decoy nodes, such as adjusting the response rules of the decoy nodes to make them closer to the behavioral characteristics of the real nodes. Strengthening the collaboration between decoy nodes based on the attack path data, and guiding the attacker to circulate in the forged path by building a decoy chain, further weakening the threat to the real nodes.

[0112] In the network environment of a large enterprise, multiple trapping nodes are deployed. The following is the specific implementation process:

[0113] (1) Analysis of risk propagation data: The system identifies two high-risk nodes (node ​​A and node B) through the calculation of the previous risk propagation factor. These two nodes have high risk propagation factors and high communication weights, making them easy to become the propagation path of attackers.

[0114] (2) Deployment of decoy nodes: Deploy a decoy node X near node A, simulate a high-value database server, configure vulnerability features (such as simulated SQL injection vulnerabilities), open ports (80 and 443), and forged key assets (such as forged customer information tables and financial data tables). Deploy a decoy node Y near node B, disguised as a file storage service node, configure a buffer overflow vulnerability, and provide multiple open directory structures to guide attackers to browse.

[0115] (3) Capture of feedback behavior: The attacker discovered the SQL injection vulnerability of the decoy node X through a scanning tool and attempted to steal forged customer data through a specific injection script. During the injection process, the decoy node recorded the script parameters and SQL injection method used by the attacker and generated feedback behavior data. The attacker attempted to brute force the user password through node Y. The decoy node recorded the password combinations it tried and the frequency of the attack, and deliberately delayed the response time to guide the attacker to continue the operation.

[0116] (4) Optimization of deployment strategy: By analyzing the feedback behavior data, the system found that attackers have a high preference for attacking file storage services. Therefore, a decoy node Z is added around node B, and its feedback model is optimized to simulate a more complex file structure. The deployment position of the decoy node X is adjusted according to the attack path data, and it is migrated to the key communication link of node A to further enhance the protection of the real node.

[0117] Through this implementation process, the system successfully captured multiple operational behaviors of the attacker, clarified the attacker's target path, and significantly improved the overall defense capability of the network by dynamically adjusting the deployment strategy.

[0118] Preferably, the trapping node dynamically responds to the attacker's operation behavior by embedding a feedback model, and the feedback model generates a feedback response according to the following formula:

[0119] F(x)=sin(k·x)+log(1+|x-μ|)

[0120] Among them, F(x) represents the feedback response value of the trapping node, which is used to interfere with and guide the attacker's behavior. The trapping node adjusts its behavior guidance strategy according to the feedback response value. For example, the feedback response value can be used to simulate the abnormal response behavior of the real node to induce the attacker to mistakenly believe that the attack has been successful; x represents the characteristic value of the attacker's operation behavior, including the complexity of uploading malicious payloads (such as payload size, file type, encryption level) and the behavioral parameters of attempting to obtain resources (such as access rights, command set complexity, etc.). The characteristic value is obtained by real-time extraction and analysis of the attacker's operation data; k represents the feedback frequency parameter of the trapping node, which is dynamically adjusted according to the current deployment strategy of the trapping node. For example, in high-risk areas, the feedback frequency may be set higher to achieve faster behavior capture; μ represents the feedback center point, which is used to set the feedback trigger threshold of the trapping node. By incorporating the difference between the characteristic value x and μ into the calculation, the trapping node can provide different degrees of feedback according to the degree of deviation of the attacker's behavior.

[0121] The feedback frequency parameter k is dynamically adjusted according to the deployment strategy of the decoy nodes. For example, in areas with high attack frequency, the k value can be increased to increase the frequency and sensitivity of the feedback response; in the case of limited resource occupation, the k value can be reduced to reduce the feedback overhead.

[0122] The feedback center point μ is used to set the sensitivity threshold of the feedback trigger. For example, when the attacker's behavior deviates less from normal operation (i.e., |x-μ| is small), the feedback response value is also correspondingly low to avoid unnecessary resource consumption; when the deviation is large, the decoy node will generate a stronger feedback response.

[0123] The feedback response value F(x) is used to simulate the behavior of real nodes to confuse attackers and further capture their operation characteristics. For example, when an attacker attempts to perform remote code injection through a malicious payload, the decoy node can simulate the file execution process through feedback response and return false execution results (such as forged system logs or error messages) to the attacker, leading the attacker to expose more attack intentions and tool characteristics.

[0124] The feedback response value can guide the attacker's behavior towards the set trap direction by dynamically adjusting the frequency and intensity. For example, the feedback model can simulate the illusion of successfully obtaining permissions, attracting attackers to further try to obtain deeper permissions, prolong the attack time, and thus capture more operation data.

[0125] The feedback response value can weaken the threat to the real node by delaying the attacker's operation process. For example, when trying to crack a password by brute force, the trapping node can increase the response time interval by adjusting the feedback frequency, significantly reducing the attacker's cracking efficiency.

[0126] By extracting features from malicious payloads uploaded by attackers and attempted operation commands, the feedback model can record the characteristic values ​​of attack behaviors in real time, providing high-value data for subsequent path analysis and defense strategy optimization.

[0127] The feedback model can automatically adapt to different attack intensities and modes according to changes in the current network situation by dynamically adjusting parameters k and μ, thereby improving the flexibility and response efficiency of the trapped nodes.

[0128] In the embodiment, it is assumed that multiple trapping nodes are deployed in the internal network of a large enterprise to protect the core database server (node ​​A) and the financial server (node ​​B). The following is the specific implementation process and scenario:

[0129] The attacker attempts to attack node A through SQL injection and uploads a complex malicious payload to steal data. The trapping node C simulates a fake database server and records the malicious payload characteristics (file type, encryption complexity) uploaded by the attacker as the characteristic value x. At this time, the trapping node calculates the feedback response value: F(x) = sin(k·x) + log(1 + |x-μ|).

[0130] Assuming that the complexity of the malicious payload x = 5.0, the feedback frequency parameter k = 0.8, and the feedback center point μ = 4.5, the feedback response value F(x) = 0.68 is calculated. According to the feedback response value, the trapping node returns a forged error log to the attacker, inducing the attacker to modify the attack payload and try again.

[0131] After the attacker failed several times, the trapping node detected a significant increase in the attack frequency, and the system dynamically adjusted the feedback frequency parameter k to 1.2 to increase the feedback response frequency, thereby capturing the attack behavior more quickly. At the same time, the feedback center point μ was adjusted to 5.0 to adapt to the changes in the complexity of the attacker's operations.

[0132] The attacker then tried to shift the target to the financial server (node ​​B). The decoy node D simulated a fake file server, returned a false file system directory structure to the attacker, and recorded the attacker's operation command feature value x = 6.3. By calculating the feedback response value F(x) = 0.92, the decoy node deliberately delayed the response time to induce the attacker to further try to obtain the file.

[0133] The feedback behavior data records the characteristics of the malicious payload uploaded by the attacker, the sequence of operations attempted, and the type of tools used. The attack path data reveals the attacker's path preference from node A to node B, providing an important reference for the subsequent optimization of the trap node deployment strategy.

[0134] like Figure 3 As shown, a global network situation map is constructed according to the attack path data and the trapping node deployment strategy, the attack path is predicted based on the situation map, the path prediction data is generated, and the network is divided into high-risk areas, medium-risk areas and low-risk areas;

[0135] The global network situation graph uses all nodes in the network (including real nodes and decoy nodes) as nodes, the communication relationship between nodes as edges, and the weight of the edge is calculated based on the risk propagation factor and communication weight of the node. The situation graph reflects the security status and communication interaction relationship of the entire network. Its specific construction process includes the following key links:

[0136] The risk propagation factor of each node (calculated by combining vulnerability score, attack complexity score and abnormal behavior score) is mapped to the security attribute of the graph node to represent the potential risk level of the node.

[0137] The weight of the edge is determined by the propagation probability and communication weight between nodes. The propagation probability represents the propagation path that the attacker may choose, while the communication weight reflects the actual interaction intensity between nodes by weighted calculation of traffic intensity, access frequency and connection stability.

[0138] The deployment strategy of the decoy nodes is mapped to the situation graph to simulate the guiding path of the attacker's behavior. For example, high-density deployment of decoy nodes forms a high-inducing path, thereby adjusting the weights of the edges in the graph to strengthen the decoy effect.

[0139] Based on the global network situation map, use the path search algorithm (such as Dijkstra algorithm or path deduction based on Bayesian network) to predict the propagation path that the attacker may take. The specific steps are as follows:

[0140] Starting from the node with high risk propagation factor, the potential propagation direction of the attacker is calculated through propagation probability and edge weight. Using recursive path search, the path prediction is extended to the entire network to generate complete path prediction data. The path prediction data includes the attacker's possible next target node and its corresponding propagation probability. Combined with the attacker's actual behavior data (feedback behavior data captured by trapping nodes), the path prediction results are dynamically adjusted to ensure that the predicted path is highly matched with the attack behavior.

[0141] Based on the path prediction data and the global network situation map, the network is divided into high-risk areas, medium-risk areas, and low-risk areas. The specific division rules are as follows:

[0142] The high-risk area contains nodes with priority scores higher than the threshold and their associated nodes, which are usually the core areas of attack propagation. The medium-risk area contains nodes with priority scores within the set range, which may have certain attack propagation potential. The low-risk area contains nodes with priority scores lower than the set threshold, which are less threatened by attacks.

[0143] Preferably, the construction of the global network situation map includes:

[0144] The real nodes and decoy nodes in the network are used as nodes of the graph;

[0145] Treat the communication relationships between nodes as edges of the graph;

[0146] The weight of the edge is calculated by the risk propagation factor and propagation probability of the node, and the weight is used to characterize the strength of the propagation relationship between the nodes.

[0147] The nodes in the global network situation diagram include real nodes and decoy nodes in the network. The two nodes are represented in the same way in the diagram, but their functions and characteristics are different:

[0148] Real nodes represent actual assets in the network (such as servers, workstations, or storage devices). The security status of real nodes is described by risk propagation factors (calculated by combining vulnerability scores, attack complexity scores, and abnormal behavior scores) to assess their potential risk as attack targets or propagation starting points.

[0149] The decoy nodes simulate the vulnerability characteristics and high-value targets of real nodes and are designed to attract attackers. The risk propagation factor of the decoy nodes is high to highlight their high guidance characteristics in the situation map, forming the core nodes of the decoy attack path. The feature data of the nodes is obtained from the previous steps (such as the perception module and the risk propagation factor calculation) and mapped to the graph model to characterize the security status of each node.

[0150] The communication relationship between nodes is abstracted as the edge in the situation diagram, which is used to describe the interaction between different nodes in the network. The modeling of communication relationship includes:

[0151] The establishment of edges: one edge is established between each pair of nodes with direct communication relationship. For example, if there is communication flow between node A and node B, an edge pointing from A to B is added to the situation graph. The direction of communication: the directionality of the edge reflects the direction of interaction between nodes. For a two-way communication relationship, two directed edges are added to the situation graph.

[0152] Calculation of edge weights. Edge weights are the core of the situation graph and are used to quantify the strength of the propagation relationship between nodes. The weights are determined by the risk propagation factor and propagation probability of the nodes:

[0153] The risk propagation factor reflects the potential risk level of the node itself. The higher the risk propagation factor of the source node, the greater its potential as an attack starting point and the higher its contribution to the edge weight. The propagation probability quantifies the possibility of an attacker propagating from the source node to the target node, and is calculated by the communication weights between nodes (such as traffic intensity, access frequency, and connection stability). The higher the propagation probability, the higher the edge weight. Comprehensive calculation, by combining the risk propagation factor with the propagation probability to calculate the edge weight, comprehensively describes the strength of the propagation relationship between nodes. For example, if the risk propagation factor of node A is 7.5 and the propagation probability of node B is 0.6, the edge weight reflects the comprehensive possibility of node A propagating to node B.

[0154] In the situation graph, the deployment strategy of the decoy nodes directly affects the calculation of edge weights. For example, by deploying decoy nodes in a path with a high propagation probability, the edge weight of the path can be significantly improved, thereby guiding the attacker to preferentially choose this path for propagation. The purpose of deployment strategy integration is to optimize the distribution and collaboration effect of decoy nodes to maximize the guidance and interference of attack behavior.

[0155] Embodiment: The following is a specific implementation process of building a global network situation map in a certain enterprise network:

[0156] Network environment and node mapping,The enterprise network contains 5 real nodes (nodes A, B, C, D, E) and 2 decoy nodes (nodes X, Y). Node A and node B are core servers, with risk propagation factors of 8.0 and 7.5 respectively; Node C and node D are user workstations, with lower risk propagation factors of 4.0 and 3.5 respectively; Node X and Y are decoy nodes, simulating databases and file servers, with risk propagation factors of 6.0.

[0157] The communication relationship between nodes in the network is as follows: there is two-way communication between node A and node B; there is one-way communication between node A and nodes C and D; there is two-way communication between node B and the trapped node X; there is one-way communication between node C and node E.

[0158] The following edges are established in the situation graph: the edge from node A to node B (the weight is calculated by the propagation factor of A and the propagation probability of A→B); the edge from node B to node A; the edge from node A to node C; the edge from node B to the trapping node X; the edge from node C to node E.

[0159] Edge weight calculation: The propagation probability from node A to node B is 0.8, the risk propagation factor of node A is 8.0, and the edge weight is 8.0·0.8=6.4; the propagation probability from node B to node A is 0.7, the risk propagation factor of node B is 7.5, and the edge weight is 7.5·0.7=5.25; the propagation probability from node B to the decoy node X is 0.9, and the edge weight is 7.5·0.9=6.75.

[0160] Deploy high-density decoy nodes (such as adding a new decoy node Z) in the communication link from node B to node X, which significantly increases the edge weight of the path, thereby guiding attackers to give priority to the decoy node path.

[0161] Preferably, risk area division is performed through a global network situation map, and the division step includes:

[0162] Calculate the priority score of each node based on the path prediction data;

[0163] Nodes with priority scores greater than the set threshold and their associated nodes are classified as high-risk areas;

[0164] Nodes with priority scores within the set threshold range are classified as medium-risk areas;

[0165] Nodes with priority scores below a set threshold are classified as low-risk areas.

[0166] The priority score of a node is a measure of its importance as a propagation target or key node in the attack path. The priority score is calculated based on the following factors:

[0167] Risk propagation factor: The risk propagation factor of a node combines the vulnerability score, attack complexity score, and abnormal behavior score to characterize the risk level of the node itself. Path prediction data: Path prediction data reflects the probability of an attacker spreading from a certain node to other nodes, and can quantify the importance of each node in the propagation path. Node relevance: The communication relationship and dependency between nodes (such as whether it is a critical server) will also affect the priority score.

[0168] The priority score is calculated by combining the above factors. For example, a node with a high risk propagation factor and frequent occurrence in path prediction will be assigned a higher priority score. Based on the priority score and the set threshold range, the network is divided into the following three risk areas:

[0169] High-risk areas: include nodes with priority scores higher than the set threshold and their directly associated nodes. These nodes are usually core nodes in the attack path or important targets in the propagation path, and trapping nodes and defense resources need to be deployed first.

[0170] Medium-risk areas: include nodes with priority scores within the set threshold range. Although these nodes are not directly the starting point of high-risk transmission, they may have certain transmission potential and need to be continuously monitored and appropriately defended.

[0171] Low-risk area: includes nodes with priority scores below the set threshold. These nodes are less vulnerable to attack and can reduce resource investment, but basic protection measures must still be retained to deal with potential threats.

[0172] The risk area division is not static, but is dynamically adjusted as the network status changes. For example, when the attack path prediction data changes (such as adding a new propagation path or adjusting the propagation probability), the priority score will be updated accordingly, triggering the redivision of the risk area.

[0173] Embodiment: The following is a specific implementation process of risk area division based on the global network situation map in a large enterprise network:

[0174] The enterprise network contains 6 real nodes (nodes A, B, C, D, E, F) and 2 decoy nodes (nodes X and Y). The following data was obtained through the global network situation map in the early stage:

[0175] The risk propagation factors of nodes are: Node A: 8.5, Node B: 7.8, Node C: 6.3, Node D: 4.0, Node E: 3.5, Node F: 2.1.

[0176] Path prediction data: The propagation probability of node A→B is 0.7, and A→C is 0.5; the propagation probability of node B→D is 0.6, and C→E is 0.4; the propagation probability of node D→F is 0.2.

[0177] Priority score of node A: Considering its high risk propagation factor (8.5) and high propagation probability (0.7 for A→B and 0.5 for A→C), the priority score is 7.0. Priority score of node B: 7.8 (risk propagation factor) × 0.6 (propagation probability) = 4.68. Priority score of node D: 4.0 × 0.2 (propagation probability) = 0.8. Priority scores of other nodes are calculated based on their propagation factors and path prediction data.

[0178] The threshold for priority score is set at 5.0 for high-risk areas and 3.0-5.0 for medium-risk areas.

[0179] High-risk area: includes node A (score 7.0), node B (score 4.68, as an associated node) and its associated trapping node X. Medium-risk area: includes node C (score 3.5) and its associated node E. Low-risk area: includes node D (score 0.8) and node F.

[0180] In the high-risk area, a new decoy node Z is deployed near node A, and the feedback strategy of decoy node X is adjusted to simulate more complex behavior patterns. In the medium-risk area, decoy node Y is retained to monitor the propagation behavior of node C. In the low-risk area, resource investment is reduced, but basic protection measures (such as traffic monitoring and access control) are retained.

[0181] Based on the path prediction data and the risk area division results, defense resources are dynamically allocated, the deployment density of the trapping nodes and the feedback chain logic are adjusted, and resource dynamic allocation data is generated to optimize the defense effect of high-risk areas.

[0182] The core of dynamic allocation of defense resources is to allocate limited resources to high-risk areas to strengthen the defense capabilities of these areas, while reasonably reducing resource input in low-risk areas. The allocation logic is based on the following key steps:

[0183] (1) Path prediction data identifies the possible propagation paths and target nodes of attackers. Resource allocation prioritizes key nodes in the path and path links with higher propagation probability to block the attack path and protect key assets. (2) Through risk area division, nodes in high-risk areas are marked as targets for priority resource allocation, medium-risk areas maintain existing defenses, and low-risk areas reduce resource investment. (3) The deployment density and feedback chain logic of decoy nodes directly affect the effect of resource allocation. By dynamically adjusting the deployment location, quantity, and feedback behavior strategy of decoy nodes, resource utilization efficiency can be further optimized.

[0184] The deployment density of decoy nodes refers to the number of decoy nodes deployed in important locations such as high-risk areas in the network and key locations on the propagation path, and their distribution density. Density adjustment is achieved through the following methods:

[0185] (1) Add new decoy nodes in high-risk areas or redeploy existing nodes to key propagation paths to form the core area of ​​the decoy network. For example, add new decoy nodes in paths with a high probability of attack propagation to strengthen the capture and guidance of attack behaviors and reduce the risk of real nodes. (2) Reduce the number of decoy nodes in low-risk areas and reallocate the released resources to high-risk areas to improve the overall efficiency of resource utilization.

[0186] Feedback chain logic refers to the coordination mode and feedback intensity adjustment of the trapping nodes when responding to attack behaviors. The goal of optimizing feedback chain logic is to enhance the coordination between the trapping nodes, so that the attacker can operate in a loop in the forged path, thereby consuming the attacker's time and resources. The optimization measures include:

[0187] (1) Increase the feedback complexity in the trapping nodes in high-risk areas, such as simulating a more realistic system log or file directory structure to extend the attacker's operation path. (2) Optimize the feedback chain strength between the trapping nodes so that the attacker's operation behavior is guided into the set path. For example, by adjusting the feedback delay and trigger conditions of the trapping nodes, the attacker's behavior is guided to a deeper level of the trapping path.

[0188] The dynamic allocation data integrates the path prediction results, risk area division information and the deployment strategy of the trapping nodes, and generates a specific plan for defense resource allocation through calculation. The generated data includes the following: the deployment density and location of the trapping nodes in each area; the adjustment parameters of the trapping node feedback logic, such as feedback frequency, trigger threshold, etc.; the defense resource enhancement measures of the real nodes, such as access control strategy, traffic monitoring rules, etc.

[0189] Preferably, the trapping nodes form a trapping chain by adjusting the deployment density and the logic of the feedback response chain. The trapping chain enhances the guidance of the attack behavior through the synergy between the nodes. The synergy is calculated according to the following formula:

[0190]

[0191] Where S(i→j) represents the collaborative optimization value between the trapping node i and the trapping node j; F i (x) and F j (x) represents the feedback function of the trapped node i and the trapped node j respectively;

[0192] The synergy effect is used to optimize the feedback chain strength between the decoy nodes to enhance the inducement of the attacker in the path.

[0193] The trapping chain is formed by adjusting the deployment density of the trapping nodes and the logic of the feedback response chain. Specifically:

[0194] Deployment density adjustment: deploy multiple decoy nodes on the attack propagation path to form a high-density decoy network covering the target area. For example, in a high-risk area, deploy at least two decoy nodes near each path node with a high probability of attack propagation to ensure that attackers are captured by multiple decoy nodes when trying to propagate.

[0195] Feedback chain logic optimization adjusts the feedback response mechanism of the trapping node to generate a continuous feedback chain, inducing the attacker to cycle between multiple trapping nodes along a preset path. For example, when the attacker triggers the feedback of trapping node i, trapping node i guides the attacker to further trigger the feedback of the adjacent trapping node j, forming a trapping chain.

[0196] Feedback function F of the decoy node i (x) is dynamically generated based on the attacker's operation behavior feature value x, which is used to describe the intensity of the trap node's response to the attacker. The feature value x includes the complexity of the attacker uploading malicious payloads, the behavioral parameters of attempting to obtain resources, etc. The output value of the feedback function determines the interference and guidance intensity of the trap node on the attacker's behavior. For example, when an attacker attempts to access a forged sensitive file directory, the trap node can simulate the illusion of successful access through the feedback function and generate false file content to guide the attacker to perform further operations.

[0197] The synergy effect S(i→j) is quantified by the strength of the feedback chain between the trapping nodes and is used to evaluate the collaboration effect between two trapping nodes. The higher the synergy effect, the stronger the trapping chain guides the attacker's behavior. The calculation formula of the synergy effect combines the feedback strength F of the two trapping nodes. i (x) and F j (x), and through the denominator |Fi (x)·F j (x)|Controls the difference in feedback between the two. When the feedback strengths of the two trapping nodes are close, the synergy effect is maximized, and a smoother guiding path can be formed.

[0198] The optimization of synergy effect is mainly achieved through the following ways: (1) Dynamically adjust the feedback strength of the trapping node to keep it consistent in the feedback chain. For example, when the feedback strength of the trapping node i is weak, the system can adjust its feedback logic to enhance its ability to interfere with the attacker's behavior. (2) Feedback trigger condition optimization: Optimize the feedback trigger conditions of the trapping node to make it more sensitive to the attacker's behavior. For example, when the complexity of the attacker's behavior reaches a certain threshold, the feedback response strength of the trapping node increases accordingly. (3) By adjusting the deployment location of the trapping node, ensure that the synergy effect covers the key nodes of the attack propagation path.

[0199] Through the synergy of the trapping chain, the system can guide the attacker to continue operating in the forged path, prolong the attack time and capture more attack behavior characteristics. For example, after the attacker tries to access the forged file directory in the trapping node, he will be guided to another trapping node to perform the next operation, thus forming a trapping loop.

[0200] The optimization of synergy effect enables the trapping chain to form a key link with high guidance and high capture rate in the attack path. The attacker's operation sequence is fully recorded, providing important data for the system to optimize the defense strategy and adjust the trapping nodes. By guiding the attacker's operation behavior through the trapping chain, the system transfers the attack traffic from the real node to the trapping node, significantly reducing the probability of the real node being attacked. The optimization of synergy effect makes the cooperation between the trapping nodes closer, which can improve the defense effect without increasing the total number of trapping nodes and maximize the efficiency of resource utilization.

[0201] Embodiment: The following is a specific implementation process of forming a trapping chain by trapping nodes in a certain enterprise network:

[0202] The enterprise network contains high-risk area nodes A and B, with risk propagation factors of 8.0 and 7.5 respectively, and the propagation path is A→B. The decoy node X is initially deployed near node A and the decoy node Y is initially deployed near node B. The feedback function of the decoy node is initially set to:

[0203] F X (x)=sin(0.8·x)+log(1+|x-5.0|)

[0204] F Y (x)=sin(0.7·x)+log(1+|x-4.8|)

[0205] Assuming that the complexity characteristic value of the malicious payload uploaded by the attacker is x=6.0, calculate the synergy between the decoy nodes X and Y:

[0206] F X (x) = 0.93

[0207] F Y (x) = 0.87

[0208]

[0209] According to the synergy calculation results, the feedback intensity of the entrapped node X is slightly higher than that of the entrapped node Y. To enhance the collaborative effect between the two, the system adjusts the feedback frequency parameters of the entrapped node Y to make it closer to the entrapped node X. A new entrapped node Z is added between nodes A and B to simulate high-value assets and optimize the feedback chain logic, extending the entrapped chain to X→Z→Y.

[0210] After the attacker triggers feedback from the trapping node X near node A, he attempts to further attack the forged sensitive file directory and is directed to node Z. Node Z simulates a real file storage server, returns fake file system content to the attacker, and records its operation behavior. Finally, the attacker is directed to node Y and attempts to crack the simulated user credentials. All operation behaviors are fully recorded by the system.

[0211] Preferably, the step of dynamically allocating defense resources includes:

[0212] Deploy more decoy nodes in high-risk areas and enhance the feedback strength of decoy nodes to guide attacker behavior;

[0213] Keep the existing decoy node deployment in medium-risk areas and adjust the feedback frequency of decoy nodes to reduce resource usage;

[0214] Reduce the deployment of decoy nodes in low-risk areas and prioritize the released resources to high-risk areas.

[0215] High-risk areas include nodes with priority scores higher than the set threshold and their directly associated nodes. These nodes are usually at the core or target of the attack path and are the attacker's preferred propagation path or target. Therefore, the resource allocation strategy for high-risk areas focuses on enhancing defense capabilities. Specific measures include:

[0216] (1) Deploy more decoy nodes in high-risk areas to cover key nodes on the attack path. For example, for links with a high probability of propagation, new decoy nodes can be deployed at both ends of the path or in the middle of the path to form a multi-layer defense. (2) Increase the complexity of the response of the decoy nodes to attack behaviors, and extend the attacker's operation time and capture more attack behavior characteristics by simulating a more realistic network environment (such as opening fake database services, file directory structures, etc.). (3) By optimizing the synergy of the decoy chain, ensure that the decoy nodes in high-risk areas can form an effective feedback chain to further guide attack behaviors.

[0217] The medium-risk area includes nodes whose priority scores are within the set threshold range. Although these nodes are not directly in the core attack path, they may have certain propagation potential or indirect risks. The resource allocation strategy in the medium-risk area focuses on optimizing the utilization efficiency of existing defense resources. Specific measures include:

[0218] (1) The decoy nodes in the medium-risk area can usually effectively monitor the propagation activities in the area. Keeping these nodes can avoid the emergence of defense loopholes. (2) By reducing the feedback frequency of the decoy nodes, the occupation of system resources can be reduced. For example, when the attack frequency is low or the regional threat is small, the response time interval of the decoy nodes can be extended to reduce system calculation and resource overhead. (3) Without affecting the monitoring effect, simplify the response logic of the decoy nodes, such as reducing the feedback complexity or reducing the coverage of the decoy nodes, so as to save resources.

[0219] The low-risk area includes nodes with priority scores below the set threshold. These nodes are less vulnerable to attack threats or have limited impact on the spread of attacks. The resource allocation strategy in the low-risk area focuses on releasing resources. Specific measures include:

[0220] (1) Gradually withdraw the decoy nodes from low-risk areas and deploy them to high-risk areas. For example, reduce the number of decoy nodes in low-risk areas or downgrade their functions to basic traffic monitoring nodes. (2) Reduce the complexity of access control rules, reduce the frequency of traffic monitoring, or shut down some redundant security services in low-risk areas to free up more computing and bandwidth resources. (3) Despite the reduction in resources, basic defense capabilities such as logging and traffic analysis must still be retained to prevent emergencies.

[0221] The dynamic resource allocation data is generated by integrating the priority scores of high-risk areas, the deployment strategy of trapping nodes, and the feedback logic optimization parameters to guide the allocation of defense resources. The generated data includes: the deployment location and number of new trapping nodes in high-risk areas; the feedback frequency adjustment parameters of trapping nodes in medium-risk areas; and the specific strategy for releasing resources in low-risk areas, such as the number and type of nodes to be withdrawn.

[0222] Preferably, the resource allocation ratio of high-risk areas is calculated by the following formula:

[0223]

[0224] Among them, R alloc (i) represents the ratio of resources allocated to node i, which is used to dynamically allocate defense resources of decoy nodes or real nodes; R i represents the risk propagation factor of node i, which is calculated by comprehensively calculating the node vulnerability score, attack complexity score and abnormal behavior score; H represents the set of nodes in the high-risk area, which is determined according to the path prediction data and the network situation diagram; ∑ j∈H R j It represents the sum of risk propagation factors of all nodes in the high-risk area and is used to normalize the resource allocation ratio;

[0225] The resource allocation ratio is used to guide the deployment density adjustment of the decoy nodes and the defense strategy optimization of the real nodes, so as to give priority to improving the defense capabilities of high-risk areas.

[0226] In high-risk areas, defense resources are limited and concentrated on key nodes, which is the focus of defense strategy. alloc (i) The calculation logic is based on the risk propagation factor R i The risk propagation factor is the core, which fully reflects the risk priority of each node. The node with a higher risk propagation factor will obtain a greater proportion of resources. For example, nodes with a higher risk propagation factor are usually important nodes or attack targets in the attack propagation path, and their priority will directly affect the allocation result.

[0227] The resource allocation in the high-risk area needs to consider the overall balance, so the risk propagation factor R of the node is normalized. i Convert to distribution ratio R alloc (i) The result of normalization is that the sum of the resource allocation ratios of all nodes in the high-risk area is equal to 1, which can ensure the total amount of resource allocation constraints and facilitate the direct calculation of the allocated resource amount of each node based on the total amount of resources.

[0228] Risk propagation factor R i It is calculated through the following three core indicators: Vulnerability score, which reflects the severity and exploitability of known vulnerabilities of the node. Attack complexity score, which indicates the expected difficulty for attackers to exploit the node, such as whether high permissions or complex exploitation paths are required. Abnormal behavior score, which reflects the current security status of the node based on abnormal behavior patterns captured by network logs, such as port scans, abnormal access requests, etc. The combination of these three indicators can comprehensively assess the potential risks of the node. The higher the risk propagation factor, the greater the threat of the node in the high-risk area.

[0229] The resource allocation ratio is mainly used to dynamically adjust the deployment density of decoy nodes and the defense strategy of real nodes. For example, nodes with a high allocation ratio can prioritize the deployment of more decoy nodes or enhance existing defense measures, while nodes with a low allocation ratio can moderately reduce resource investment.

[0230] Embodiment: The following is a specific implementation process of using the high-risk area resource allocation formula in a certain enterprise network:

[0231] The high-risk areas divided by the enterprise network include nodes A, B, and C. The risk propagation factors of the nodes are: R A =8.0 (core database server). B =6.5 (file storage server). C = 5.5 (remote access gateway). The total amount of resources is set to 100 units (which can be units of trapping nodes, access control rules, monitoring policies, etc.).

[0232] First, calculate the sum of the risk propagation factors of all nodes in the high-risk area: ∑ j∈H R j =R A +R B +R C =8.0+6.5+5.5=20.0

[0233] Calculate the resource allocation ratio of each node according to the formula:

[0234] According to the calculation results, resources are allocated as follows: Node A is allocated 100×0.4=40 units of resources: 2 new decoy nodes are deployed on the uplink and downlink communication links of node A. The access control rules of node A are enhanced, such as restricting access to high-risk IP segments. A log analysis module is added to analyze all access requests in real time.

[0235] Node B is allocated 100×0.325=32.5100\times 0.325=32.5100×0.325=32.5 units of resources: Add a new decoy node to simulate a high-value file system. Simplify access control rules, but retain the traffic monitoring function.

[0236] Node C is allocated 100×0.275=27.5 units of resources: retain the existing decoy node deployment, while reducing the response complexity to save computing resources. Set up basic traffic monitoring strategies to capture potential threats.

[0237] Assume that in a certain attack event, the abnormal behavior score of node A increases, causing its risk propagation factor to increase to RA =9.0. Recalculate the allocation ratio based on the new risk propagation factor:

[0238]

[0239] The allocation ratio of node A is increased from 40% to 42.9%, and the system increases the defense resource investment of node A accordingly, such as adding a trapping node and optimizing the feedback logic.

[0240] like Figure 4 As shown, a system for implementing the network security active security defense method based on vulnerability exploitation includes:

[0241] A perception module is deployed in the network to collect multimodal data, wherein the multimodal data includes structured data, unstructured data and semi-structured data; the perception module is further used to format, clean and standardize the collected data, and generate vulnerability feature data; the perception module is deployed at multiple key locations in the network to collect structured data (such as vulnerability scanning information), unstructured data (such as log records) and semi-structured data (such as protocol parsing data), and format, clean and standardize them to generate vulnerability feature data for subsequent analysis.

[0242] A risk calculation module is used to calculate the risk propagation factor and propagation probability of the network node based on the vulnerability feature data, and generate risk propagation data, wherein the risk propagation factor is calculated according to the vulnerability score, attack complexity score and abnormal behavior score of the node, and the propagation probability is calculated based on the communication weight between nodes and the risk propagation factor; based on the vulnerability feature data, the risk calculation module calculates the risk propagation factor by combining the vulnerability score, attack complexity score and abnormal behavior score of the node; combined with the communication weight and risk propagation factor between nodes, the propagation probability is further calculated to generate risk propagation data for evaluating attack paths and key nodes.

[0243] A trapping node generation module is used to generate a trapping node based on the risk propagation data, wherein the trapping node simulates the vulnerability characteristics and high-value targets of the real node, and captures the attacker's operation behavior through the embedded feedback model to generate feedback behavior data and attack path data; according to the risk propagation data, the trapping node generation module simulates the vulnerability characteristics and high-value targets of the real node, captures the attacker's operation behavior through the feedback model, and generates feedback behavior data and attack path data;

[0244] A deployment optimization module is used to adjust the deployment strategy of the trapping node based on the feedback behavior data and the attack path data, wherein the deployment strategy includes the optimization of the deployment position of the trapping node and the feedback response logic; the deployment optimization module dynamically adjusts the position and feedback logic of the trapping node based on these data, so that the trapping node can efficiently guide the attack behavior.

[0245] The situation awareness module is used to construct a global network situation map according to the attack path data and the trapping node deployment strategy. The situation awareness module is further used to predict the attack path based on the global network situation map, generate path prediction data, and divide the network into high-risk areas, medium-risk areas and low-risk areas according to the path prediction data; the situation awareness module uses the attack path data to construct a global network situation map, divides the network into high-risk areas, medium-risk areas and low-risk areas through path prediction and priority scoring, and provides a decision-making basis for resource allocation.

[0246] A resource allocation module is used to dynamically allocate defense resources based on the path prediction data and the risk area division results, wherein the resource allocation includes adjusting the deployment density and feedback chain logic of the trapping nodes, and generating resource dynamic allocation data to optimize the defense effect of the high-risk area; the resource allocation module combines the path prediction data with the risk area division results, dynamically allocates defense resources, optimizes the deployment density and feedback chain logic of the trapping nodes, and generates resource dynamic allocation data to enhance the defense capability of the high-risk area.

[0247] A data storage module is used to store the multimodal data, vulnerability feature data, risk propagation data, feedback behavior data, attack path data, path prediction data, and resource dynamic allocation data. The data storage module records multimodal data, vulnerability feature data, feedback behavior data, attack path data, and dynamic allocation data to support dynamic optimization and feedback adjustment of the system.

[0248] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A network security active security defense method based on vulnerability exploitation, characterized in that: The following steps are involved: Collect multimodal data through the perception module deployed in the network, pre-process and extract features from the collected multimodal data, and generate vulnerability feature data; Calculate the risk propagation factor and propagation probability of the node based on the vulnerability feature data to generate risk propagation data; Generate a trap node based on the risk propagation data, the trap node simulates the vulnerability characteristics and high-value targets of the real node, and embeds a feedback model to capture the attacker's operation behavior and generate feedback behavior data and attack path data; Adjusting the deployment strategy of the decoyed nodes based on the feedback behavior data and the attack path data; Constructing a global network situation map according to the attack path data and the trapping node deployment strategy, predicting the attack path based on the situation map, generating path prediction data, and dividing the network into high-risk areas, medium-risk areas, and low-risk areas; Based on the path prediction data and the risk area division results, defense resources are dynamically allocated, the deployment density of the trapping nodes and the feedback chain logic are adjusted, and resource dynamic allocation data is generated to optimize the defense effect of high-risk areas.

2. The method according to claim 1, characterized in that The risk propagation factor of the node is calculated by the following formula: R i =α·L i +β·Ti i +γ·A i Among them, R i represents the risk propagation factor of node i, which is used to characterize the potential risk level of the node as the starting point of attack propagation in the network; L i represents the vulnerability score of node i, which is obtained by quantifying the severity and difficulty of exploitation of the vulnerability; T i A represents the attack complexity score of node i, which is quantified by evaluating the resource investment and permission requirements required to attack the node; i represents the abnormal behavior score of node i, which is obtained by analyzing the abnormal communication behavior of the node in the network log; α, β, and γ are the weight factors of the vulnerability score, attack complexity score, and abnormal behavior score, respectively. The weight factors are tuned according to the historical attack behavior data to balance the contribution of different scores to the risk propagation factor.

3. The method according to claim 2, characterized in that The propagation probability between the nodes is calculated by the following formula: Among them, P(i→j) represents the probability of spreading the attack from node i to node j, which is used to quantify the propagation direction of the attack behavior; R i represents the risk propagation factor of node i, reflecting the risk level of the node as the starting point of attack propagation; W ij represents the communication weight between node i and node j, which is calculated by weighting the communication flow, access frequency and connection stability between the two nodes; ∑ k R k It represents the sum of risk propagation factors of all nodes in the network, and is used to normalize the propagation probability so that the probability of each propagation path is consistent with the distribution of the overall network propagation behavior; the propagation probability is used to determine the attacker's potential next target node.

4. The method according to claim 1, characterized in that: The decoy node dynamically responds to the attacker's operation behavior by embedding a feedback model, and the feedback model generates a feedback response according to the following formula: F(x)=sin(k·x)+log(1+|x-μ|) Among them, F(x) represents the feedback response value of the trapping node, which is used to interfere with and guide the attacker's behavior. The trapping node adjusts its behavior guidance strategy according to the feedback response value; x represents the characteristic value of the attacker's operation behavior, including the complexity of uploading malicious payloads and the behavior parameters of attempting to obtain resources; k represents the feedback frequency parameter of the trapping node, which is dynamically adjusted according to the current deployment strategy of the trapping node; μ represents the feedback center point, which is used to set the feedback trigger threshold of the trapping node.

5. The method according to claim 1, characterized in that: The construction of the global network situation map includes: The real nodes and decoy nodes in the network are used as nodes of the graph; Treat the communication relationships between nodes as edges of the graph; The weight of the edge is calculated by the risk propagation factor and propagation probability of the node, and the weight is used to characterize the strength of the propagation relationship between the nodes.

6. The method according to claim 1, characterized in that The risk area is divided by the global network situation map, and the division step includes: Calculate the priority score of each node based on the path prediction data; Nodes with priority scores greater than the set threshold and their associated nodes are classified as high-risk areas; Nodes with priority scores within the set threshold range are classified as medium-risk areas; Nodes with priority scores below a set threshold are classified as low-risk areas.

7. The method according to claim 1, characterized in that The trapping nodes form a trapping chain by adjusting the deployment density and the logic of the feedback response chain. The trapping chain enhances the guidance of attack behaviors through the synergy between nodes. The synergy is calculated according to the following formula: Where S(i→j) represents the collaborative optimization value between the trapping node i and the trapping node j; F i (x) and F j (x) represents the feedback function of the trapped node i and the trapped node j respectively; The synergy effect is used to optimize the feedback chain strength between the decoy nodes to enhance the inducement of the attacker in the path.

8. The method according to claim 1, characterized in that: The steps to dynamically allocate defense resources include: Deploy more decoy nodes in high-risk areas and enhance the feedback strength of decoy nodes to guide attacker behavior; Keep the existing decoy node deployment in medium-risk areas and adjust the feedback frequency of decoy nodes to reduce resource usage; Reduce the deployment of decoy nodes in low-risk areas and prioritize the released resources to high-risk areas.

9. The method according to claim 1, characterized in that: The resource allocation ratio for high-risk areas is calculated using the following formula: Among them, R alloc (i) represents the resource ratio allocated to node i, which is used to dynamically allocate defense resources of decoy nodes or real nodes; R i represents the risk propagation factor of node i, which is calculated by comprehensively calculating the node vulnerability score, attack complexity score and abnormal behavior score; H represents the set of nodes in the high-risk area, which is determined according to the path prediction data and the network situation diagram; ∑ j∈H R j It represents the sum of risk propagation factors of all nodes in the high-risk area and is used to normalize the resource allocation ratio; The resource allocation ratio is used to guide the deployment density adjustment of the decoy nodes and the defense strategy optimization of the real nodes, so as to give priority to improving the defense capabilities of high-risk areas.

10. A system for implementing the network security active security defense method based on vulnerability exploitation according to any one of claims 1 to 9, characterized in that: include: A perception module is used to be deployed in the network to collect multimodal data, wherein the multimodal data includes structured data, unstructured data and semi-structured data; the perception module is further used to format, clean and standardize the collected data, and generate vulnerability feature data; A risk calculation module, used to calculate the risk propagation factor and propagation probability of the network node based on the vulnerability feature data, and generate risk propagation data, wherein the risk propagation factor is calculated according to the vulnerability score, attack complexity score and abnormal behavior score of the node, and the propagation probability is calculated based on the communication weight between nodes and the risk propagation factor; A trapping node generation module, used to generate a trapping node based on the risk propagation data, wherein the trapping node simulates the vulnerability characteristics and high-value targets of the real node, and captures the attacker's operation behavior through an embedded feedback model to generate feedback behavior data and attack path data; A deployment optimization module, used to adjust the deployment strategy of the trapping node based on the feedback behavior data and the attack path data, wherein the deployment strategy includes the optimization of the deployment position of the trapping node and the feedback response logic; A situation awareness module is used to construct a global network situation map based on the attack path data and the trapping node deployment strategy, and the situation awareness module is further used to predict the attack path based on the global network situation map, generate path prediction data, and divide the network into high-risk areas, medium-risk areas, and low-risk areas according to the path prediction data; A resource allocation module, for dynamically allocating defense resources based on the path prediction data and the risk area division results, wherein the resource allocation includes adjusting the deployment density and feedback chain logic of the trapping nodes, and generating dynamic resource allocation data to optimize the defense effect of the high-risk area; A data storage module is used to store the multimodal data, vulnerability feature data, risk propagation data, feedback behavior data, attack path data, path prediction data and resource dynamic allocation data.

Citation Information

Patent Citations

  • Network security defense method and system based on vulnerability exploitation, and computer-readable storage medium

    CN118555134B

  • Information security risk assessment system based on block chain

    CN118965458A

  • Network defense system based on decoy technology

    CN119109671A

  • Attack trapping method and system based on network attack surface adaptive conversion

    CN119210761A

Cited By

  • College data center credible situation defense method based on virtual simulation trapping environment

    CN120524436A

  • Data security risk quantitative dynamic assessment method and system

    CN121644199A

  • A data security risk quantitative dynamic evaluation method and system

    CN121644199B

  • Active threat detection and response system based on network attack path prediction

    CN122496290A