Exploitation-based network security active security defense method and system
By using a global network situation map and path prediction, the deployment density of trapping nodes and the feedback chain logic are dynamically adjusted, solving the problem of uneven resource allocation in existing technologies, achieving efficient network security defense, and improving the protection capability and resource utilization efficiency for high-risk areas.
Patent Information
- Application Number
- CN202510090333.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2045-01-21
AI Technical Summary
Existing technologies, when dealing with advanced persistent threats, cannot adjust trapping strategies based on the attacker's real-time behavior, cannot fully utilize the collaborative effect of trapping nodes, resulting in uneven resource allocation, low computational efficiency, inability to effectively guide attacker behavior, and inability to form an efficient trapping chain.
By using a global network situation map and path prediction, resources are dynamically allocated, the deployment density of trap nodes and feedback chain logic are adjusted, and trap nodes are generated by combining multimodal data analysis to simulate the characteristics of real nodes, capture attacker behavior, construct trap chains to guide attacker behavior, and optimize resource utilization.
It significantly enhances the protection capabilities of high-risk areas, optimizes resource utilization efficiency, rapidly adapts to changes in the network environment and attack behavior, weakens the threat of attackers to real nodes, and improves the response speed and accuracy of network security.
Smart Images

Figure CN119995960B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a proactive network security defense method and system based on vulnerability exploitation. Background Technology
[0002] As cyberattacks become increasingly complex and diverse, traditional passive defense methods are no longer sufficient to address emerging advanced persistent threats (APTs). Proactive defense, by leveraging vulnerabilities to predict attack paths, guide attack behavior, and dynamically adjust defense resources, can achieve more precise and efficient cybersecurity protection. This defense model not only identifies potential threats in advance but also weakens attackers' ability to threaten core nodes through decoy mechanisms, providing a novel technical solution for cybersecurity.
[0003] Existing technologies (Chinese invention patent, publication number: CN118555134B) primarily predict attack behavior by analyzing vulnerabilities and attack indicators of target nodes, and optimize defense strategies based on the attack probability of target nodes. However, the defense deployment of existing technologies is mainly based on static vulnerability analysis and probability prediction. Although they can simulate attack paths, they cannot adjust the trapping strategy according to the attacker's real-time behavior, nor can they guide the attacker into a forged path. Existing technologies do not fully consider the risk differences of different nodes in the network, and the resource allocation mode is relatively simple, which may lead to insufficient resources in high-risk areas or waste of resources in low-risk areas. Existing technologies only simulate attack behavior and do not make full use of the cooperative effect of trapping nodes, so they cannot form an efficient trapping chain to guide the attacker's behavior. Existing technologies perform complex quantitative analysis in high-dimensional space, resulting in low computational efficiency and response speed that cannot meet the requirements of real-time defense. Summary of the Invention
[0004] To address the numerous problems existing in the prior art, this invention provides a proactive network security defense method and system based on vulnerability exploitation. Based on vulnerability exploitation, this invention dynamically allocates resources to high-risk areas in the network through global network situational mapping, path prediction, and risk area segmentation techniques. It also forms a trapping chain by adjusting the deployment density of trapping nodes and the feedback chain logic. By optimizing the synergistic effect and feedback strategy of trapping nodes, this invention can guide attacker behavior, delay the attack process, and capture more attack characteristic data, ultimately achieving dynamic network defense. This invention significantly improves the protection capabilities of high-risk areas, optimizes resource utilization efficiency, and reduces the attack risk of real nodes.
[0005] A proactive cybersecurity defense method based on vulnerability exploitation includes the following steps:
[0006] Multimodal data is collected by a sensing module deployed in the network. The collected multimodal data is preprocessed and features are extracted to generate vulnerability feature data. Based on the vulnerability feature data, the risk propagation factor and propagation probability of the node are calculated to generate risk propagation data.
[0007] Based on the risk propagation data, trap nodes are generated. These trap nodes simulate the vulnerability characteristics and high-value targets of real nodes and embed a feedback model to capture attackers' operational behaviors, generating feedback behavior data and attack path data. The deployment strategy of the trap nodes is adjusted based on the feedback behavior data and attack path data.
[0008] A global network situation map is constructed based on the attack path data and the deployment strategy of the trapping nodes. Attack paths are predicted based on the situation map, path prediction data is generated, and the network is divided into high-risk areas, medium-risk areas, and low-risk areas.
[0009] Based on the path prediction data and risk area division results, defense resources are dynamically allocated, the deployment density of trapping nodes and feedback chain logic are adjusted, and dynamic resource allocation data is generated to optimize the defense effect in high-risk areas.
[0010] Preferably, the risk propagation factor of the node is calculated using the following formula:
[0011] R i =α·L i +β·T i +γ·A i
[0012] Among them, R i L represents the risk propagation factor of node i, used to characterize the potential risk level of that node as the starting point of attack propagation in the network; i The vulnerability score for node i is quantified by assessing the severity and difficulty of exploitation of the vulnerability; T i A represents the attack complexity score for node i, quantified by assessing the resource investment and permission requirements needed to launch an attack on the node; i The abnormal behavior score of node i is derived by analyzing the abnormal communication behavior exhibited by the node in the network logs; α, β, and γ are the weighting factors of the vulnerability score, attack complexity score, and abnormal behavior score, respectively. The weighting factors are optimized based on historical attack behavior data to balance the contribution of different scores to the risk propagation factor.
[0013] Preferably, the propagation probability between the nodes is calculated using the following formula:
[0014]
[0015] Where P(i→j) represents the probability of an attack propagating from node i to node j, used to quantify the direction of attack propagation; R i W represents the risk propagation factor of node i, reflecting the risk level of the node as the starting point of attack propagation; ij The communication weight between node i and node j is calculated by weighting the communication traffic, access frequency, and connection stability between the two nodes; ∑ k R k This represents the sum of risk propagation factors for all nodes in the network, used to normalize propagation probabilities so that the probability of each propagation path is consistent with the distribution of overall network propagation behavior; the propagation probability is used to determine the attacker's potential next target node.
[0016] Preferably, the trapping node dynamically responds to the attacker's actions by embedding a feedback model, which generates the feedback response according to the following formula:
[0017] F(x)=sin(k·x)+log(1+|x-μ|)
[0018] Wherein, F(x) represents the feedback response value of the decoy node, which is used to interfere with and guide the attacker's behavior. The decoy node adjusts its behavior guidance strategy according to the feedback response value; x represents the characteristic value of the attacker's operation behavior, including the complexity of the uploaded malicious payload and the behavior parameters of attempting to obtain resources; k represents the feedback frequency parameter of the decoy node, which is dynamically adjusted according to the current deployment strategy of the decoy node; μ represents the feedback center point, which is used to set the feedback trigger threshold of the decoy node.
[0019] Preferably, the construction of the global network situation map includes:
[0020] The real nodes and the lured nodes in the network are used as nodes in the graph;
[0021] Treat the communication relationships between nodes as edges of the graph;
[0022] The weight of an edge is calculated using the risk propagation factor and propagation probability of the node, and the weight is used to characterize the strength of the propagation relationship between nodes.
[0023] Preferably, risk areas are delineated using a global network situation map, and the delineation steps include:
[0024] Calculate the priority score for each node based on the path prediction data;
[0025] Nodes with priority scores greater than a set threshold and their associated nodes are classified as high-risk areas.
[0026] Nodes whose priority scores fall within a set threshold range are classified as medium-risk areas;
[0027] Nodes with priority scores below a set threshold are classified as low-risk zones.
[0028] Preferably, the trapping nodes form a trapping chain by adjusting the deployment density and feedback response chain logic. The trapping chain enhances the guidance of attack behavior through the synergy effect between nodes, which is calculated according to the following formula:
[0029]
[0030] Where S(i→j) represents the collaborative optimization value between trap node i and trap node j; F i (x) and f j (x) represent the feedback functions of trap node i and trap node j, respectively;
[0031] The synergistic effect is used to optimize the feedback chain strength between trapping nodes to enhance the attacker's inducibility in the path.
[0032] Preferably, the steps for dynamically allocating defense resources include:
[0033] Deploy more trap nodes in high-risk areas and enhance the feedback strength of the trap nodes to guide attacker behavior;
[0034] In medium-risk areas, retain existing trapping node deployments and adjust the feedback frequency of trapping nodes to reduce resource consumption;
[0035] Reduce the deployment of trap nodes in low-risk areas and prioritize the allocation of freed resources to high-risk areas.
[0036] Preferably, the resource allocation ratio for high-risk areas is calculated using the following formula:
[0037]
[0038] Among them, R alloc (i) represents the proportion of resources allocated to node i, used for dynamically allocating defense resources for either decoy nodes or real nodes; R i ∑ represents the risk propagation factor of node i, calculated by combining node vulnerability score, attack complexity score, and abnormal behavior score; H represents the set of nodes within a high-risk area, which is defined based on path prediction data and network situation map; ∑ j∈H R j This represents the sum of risk propagation factors across all nodes within a high-risk area, used to normalize resource allocation ratios.
[0039] The resource allocation ratio is used to guide the adjustment of the deployment density of trap nodes and the optimization of the defense strategy of real nodes, so as to prioritize the improvement of the defense capabilities of high-risk areas.
[0040] A system for implementing the aforementioned proactive cybersecurity defense method based on vulnerability exploitation includes:
[0041] The perception module is deployed in the network to collect multimodal data, including structured data, unstructured data, and semi-structured data. The perception module is further used to perform formatting, data cleaning, and standardization on the collected data, and to generate vulnerability feature data.
[0042] The risk calculation module is used to calculate the risk propagation factor and propagation probability of network nodes based on the vulnerability feature data, and generate risk propagation data. The risk propagation factor is calculated based on the vulnerability score, attack complexity score and abnormal behavior score of the node, and the propagation probability is calculated based on the communication weight between nodes and the risk propagation factor.
[0043] The decoy node generation module is used to generate decoy nodes based on the risk propagation data. The decoy nodes simulate the vulnerability characteristics and high-value targets of real nodes, and capture the attacker's operation behavior through an embedded feedback model to generate feedback behavior data and attack path data.
[0044] The deployment optimization module is used to adjust the deployment strategy of the trapping nodes based on the feedback behavior data and attack path data. The deployment strategy includes the optimization of the deployment location of the trapping nodes and the feedback response logic.
[0045] The situation awareness module is used to construct a global network situation map based on the attack path data and the deployment strategy of the trapping nodes. The situation awareness module is further used to predict attack paths based on the global network situation map, generate path prediction data, and divide the network into high-risk areas, medium-risk areas and low-risk areas based on the path prediction data.
[0046] The resource allocation module is used to dynamically allocate defense resources based on the path prediction data and risk area division results. The resource allocation includes adjusting the deployment density of trap nodes and feedback chain logic, and generating dynamic resource allocation data to optimize the defense effect in high-risk areas.
[0047] The data storage module is used to store the multimodal data, vulnerability feature data, risk propagation data, feedback behavior data, attack path data, path prediction data, and dynamic resource allocation data.
[0048] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows:
[0049] This invention constructs a dynamic trapping chain by adjusting the deployment density of trapping nodes and the feedback response chain logic, guiding attackers to operate cyclically in a forged path, thus significantly reducing their threat to real nodes.
[0050] By dynamically adjusting the resource allocation ratio in conjunction with the risk propagation factor of nodes, this invention concentrates limited defense resources on key nodes and high-risk areas along the attack path, significantly improving resource utilization efficiency.
[0051] By combining path prediction and risk area delineation, this invention can update network defense strategies in real time and quickly adapt to changes in the network environment and attack behavior.
[0052] Compared to existing technologies, this invention reduces complex high-dimensional calculations and dynamically adjusts resource allocation strategies, enabling the system to respond efficiently to cybersecurity threats. Attached Figure Description
[0053] Figure 1 This is a schematic flowchart of the method of the present invention;
[0054] Figure 2 This is a schematic diagram of the trapping chain synergistic effect logic in this invention;
[0055] Figure 3 This is a schematic diagram illustrating the risk area division logic in this invention;
[0056] Figure 4 This is a structural block diagram of the system of the present invention. Detailed Implementation
[0057] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation.
[0058] like Figure 1 As shown, a proactive security defense method for network security based on vulnerability exploitation includes the following steps:
[0059] Multimodal data is collected by a sensing module deployed in the network. The collected multimodal data is preprocessed and features are extracted to generate vulnerability feature data. Based on the vulnerability feature data, the risk propagation factor and propagation probability of the node are calculated to generate risk propagation data.
[0060] As a cutting-edge component in the network environment, the perception module is deployed in multiple key locations to collect multimodal data in real time during network operation. This data includes structured data (such as vulnerability information generated by vulnerability scanning tools), unstructured data (such as abnormal behavior records in network logs), and semi-structured data (such as communication protocol data extracted by protocol analyzers). The diversity of this multimodal data ensures that the perception module can comprehensively capture potential threat information and abnormal behaviors in the network's operational state.
[0061] The collected multimodal data is first standardized and cleaned through a data preprocessing module to ensure data integrity and consistency. Specifically, preprocessing includes the following steps: formatting, converting data from different sources into a uniform format; noise filtering, removing irrelevant and redundant data by setting thresholds or models; and standardization, normalizing data values to eliminate biases caused by different data sources. This process ensures high-quality input data required for subsequent analysis.
[0062] After preprocessing, this invention further performs in-depth analysis of the multimodal data through a feature extraction module to generate vulnerability feature data. The feature extraction module employs targeted techniques based on different data types. For example, for structured data generated from vulnerability scanning, relevant features are extracted by parsing vulnerability scores, exploit complexity, and node exposure surfaces; for unstructured network logs, abnormal access sequences and attacker behavior time intervals are extracted through log mining and behavioral pattern analysis; and for semi-structured data, abnormal communication features are extracted through field analysis and pattern matching of communication protocols. Through feature extraction, the raw multimodal data is transformed into structured vulnerability feature data. This data not only reflects vulnerabilities existing in the network but also includes potential exploitation paths and possible attacker actions, providing crucial support for subsequent analysis.
[0063] Based on the aforementioned vulnerability characteristic data, the risk calculation module further calculates the risk propagation factor and propagation probability of each node, thereby generating risk propagation data. The risk propagation factor reflects the degree of risk of a node being exploited, and its calculation comprehensively considers core indicators such as the node's vulnerability score, attack complexity score, and anomalous behavior score. The attack complexity score is primarily quantified based on the resources and privileges required for an attacker to successfully exploit a node's vulnerability; the anomalous behavior score is weighted in conjunction with the anomalous communication behavior characteristics exhibited by the node in the network logs. The propagation probability characterizes the priority of the attacker's propagation path between nodes. Its calculation incorporates the communication weights between nodes, traffic characteristics, and the risk propagation factor, ensuring that the propagation probability accurately reflects the potential threat transmission relationship between nodes.
[0064] Example: Assume that in an enterprise network, the awareness module is deployed on the network interfaces of the core switch and server cluster. In a simulated attack experiment, the awareness module captures vulnerability information (structured data) generated by the attacker using a vulnerability scanning tool, as well as failed login attempts via SSH (unstructured data). Through data preprocessing and feature extraction, the system identifies a high-risk vulnerability (CVE-XXXX) on a certain server node, with a vulnerability score of 9.0. Combined with network log analysis, it is found that the attacker attempted multiple brute-force login attempts, with an abnormal behavior score of 8.5. Subsequently, the risk calculation module calculates the risk propagation factor of this server node to be 7.8 based on these characteristics, and combines it with its communication weight with other nodes to determine the target nodes and paths that the attacker may attempt to propagate to next.
[0065] Preferably, the risk propagation factor of the node is calculated using the following formula:
[0066] R i =α·L i +β·T i +γ·A i
[0067] Among them, R i L represents the risk propagation factor of node i, used to characterize the potential risk level of that node as the starting point of attack propagation in the network; i The vulnerability score for node i is quantified by assessing the severity and difficulty of exploitation of the vulnerability; T i A represents the attack complexity score for node i, quantified by assessing the resource investment and permission requirements needed to launch an attack on the node; i The abnormal behavior score of node i is derived by analyzing the abnormal communication behavior exhibited by the node in the network logs; α, β, and γ are the weighting factors of the vulnerability score, attack complexity score, and abnormal behavior score, respectively. The weighting factors are optimized based on historical attack behavior data to balance the contribution of different scores to the risk propagation factor.
[0068] This invention calculates the risk propagation factor R of nodes. i This allows for the quantitative analysis of security risks at each node in the network, providing crucial information for subsequent proactive security defense operations. The risk propagation factor calculation integrates three key indicators: vulnerability score, attack complexity score, and anomalous behavior score. Through optimization of weighting factors α, β, and γ, it flexibly adapts to different network environments and attack behavior patterns.
[0069] Vulnerability Score (L) iVulnerability scores are derived from data extracted from existing vulnerability databases (such as CVE databases) and quantified by combining the severity and exploitation difficulty of the vulnerability. Vulnerability severity is quantified based on the potential damage the vulnerability could cause, such as data breaches or system crashes; exploitation difficulty is based on the vulnerability's operability, such as whether specific conditions or complex steps are required for exploitation. Scores are typically expressed on a scale of 0 to 10, with higher values indicating that the node has a high-risk vulnerability and is easily exploited by attackers.
[0070] Attack Complexity Score (T) i The attack complexity score quantifies the resources and privileges required for an attacker to exploit a node vulnerability. For example, does the attacker need administrator privileges, a specific time window, or significant computational resources to carry out the attack? A higher complexity score indicates a lower likelihood of the node being compromised.
[0071] Abnormal Behavior Score (A) i The anomaly behavior score is based on the analysis of abnormal communication behaviors captured in network logs, such as high-frequency access requests during abnormal periods, a large number of abnormal port connections, or packet loss. The logs are analyzed using pattern recognition and machine learning models (such as random forests or LSTMs). The anomaly behavior score reflects the degree to which a node's current activity deviates from normal behavior; the higher the score, the higher the likelihood that the node has been exploited.
[0072] Weighting factors (α, β, γ) are optimized through statistical analysis of historical attack behavior data to adapt to different network scenarios. For example, in financial networks, anomalous behavior may be more important, so the weight of γ would be set higher, while the weight of vulnerability scoring, α, would be relatively lower. Weight optimization is achieved by minimizing the error between historical attack paths and actual attack paths.
[0073] By calculating the risk propagation factor of nodes, potentially high-risk nodes can be quickly identified in the network, clarifying their likelihood of serving as attack origins or key nodes in the propagation path. The calculation results of the risk propagation factor are not only used to directly assess the security status of nodes but also for calculating subsequent propagation probabilities and dynamically allocating global defense resources. Compared to traditional risk assessment methods that rely on a single indicator (such as vulnerability scoring or anomalous behavior), this invention uses multi-dimensional comprehensive calculations to make risk assessment results more targeted and accurate. Furthermore, the dynamic optimization of weighting factors enhances the solution's adaptability to diverse network environments.
[0074] In this example, assume there are three key nodes in an enterprise network: node A, node B, and node C. The following features are extracted from the multimodal data collected by the sensing module:
[0075] Node A, vulnerability score (L)A Attack Complexity Score: 8.5 (Multiple high-risk vulnerabilities exist and are easily exploitable). Attack Complexity Score (T) A ): 3.2 (low attack difficulty). Abnormal behavior score (A) A ): 7.1 (Frequent abnormal access behavior). Weighting factors: α = 0.4, β = 0.3, γ = 0.3.
[0076] The risk propagation factor of node A is calculated using the formula:
[0077] R A =0.4·8.5 + 0.3·3.2 + 0.3·7.1 = 6.46
[0078] Node B, vulnerability score (L) B ): 5.0 (Contains a medium-level vulnerability). Attack complexity score (T) B ): 6.8 (High attack difficulty). Abnormal behavior score (A) B 4.3 (Minor abnormal communication occurred). Weighting factors: α = 0.4, β = 0.3, γ = 0.3.
[0079] Risk propagation factor for compute node B:
[0080] R B =0.4·5.0 + 0.3·6.8 + 0.3·4.3 = 5.39
[0081] Node C, vulnerability score (L) C ): 2.1 (No obvious vulnerabilities). Attack complexity score (T) C ): 7.9 (Extremely high attack difficulty). Abnormal behavior score (A) C ): 2.0 (Normal behavior). Weighting factor:
[0082] α=0.4, β=0.3, γ=0.3.
[0083] Risk propagation factor of computing node C:
[0084] R C =0.4·2.1 + 0.3·7.9 + 0.3·2.0 = 3.77
[0085] The calculations above show that node A has the highest risk propagation factor and is therefore identified as a high-risk node, requiring priority allocation of defense resources or deployment of decoy nodes. Node B has a medium propagation factor and can be monitored as a medium-risk node, while node C has a low risk and can be temporarily ignored.
[0086] Preferably, the propagation probability between the nodes is calculated using the following formula:
[0087]
[0088] Where P(i→j) represents the probability of an attack propagating from node i to node j, used to quantify the direction of attack propagation; R i W represents the risk propagation factor of node i, reflecting the risk level of the node as the starting point of attack propagation; ij The communication weight between node i and node j is calculated by weighting the communication traffic, access frequency, and connection stability between the two nodes; ∑ k R k This represents the sum of risk propagation factors for all nodes in the network, used to normalize propagation probabilities so that the probability of each propagation path is consistent with the distribution of overall network propagation behavior; the propagation probability is used to determine the attacker's potential next target node.
[0089] Risk transmission factor R i This is a quantitative indicator of a node's own security, representing the degree of risk an attacker might exploit. The higher the risk propagation factor of node i, the more likely an attacker is to use that node as a starting point for propagation. The risk propagation factor is calculated by combining the node's vulnerability score, attack complexity score, and abnormal behavior score.
[0090] Communication weight W ij The connection strength between node i and node j is represented by a weighted calculation based on the following core indicators: (1) Communication traffic: The higher the average communication traffic between nodes, the more credible the path an attacker might choose. (2) Access frequency: Nodes with high-frequency communication may have higher dependencies, and attackers tend to choose paths with high access frequency. (3) Connection stability: Long-term stable communication links are more likely to be exploited by attackers. The weight calculation integrates these three indicators to reflect the true connection strength between the two nodes.
[0091] Normalization processing ∑ k R k To ensure overall consistency in propagation probabilities, the sum of risk propagation factors for all nodes is used as the denominator for normalization. This guarantees that the probability value of each propagation path is within the range of [0,1], and that the sum of all propagation probabilities is 1, forming a probability distribution model.
[0092] The calculation of propagation probability not only quantitatively describes the possible propagation paths of attackers, but also dynamically reflects the propagation risk relationship between different nodes in the network, providing an important basis for the deployment of decoy nodes and resource allocation in the defense system.
[0093] By calculating propagation probabilities, this invention can dynamically assess the likelihood of an attacker spreading from one node to another and, combined with a global network situational map, draw a potential attack path map. Compared to traditional propagation path prediction methods based on static features, this invention, by introducing risk propagation factors and communication weights, comprehensively considers not only the security of the nodes themselves but also the communication characteristics and dynamic interactions between nodes, thus significantly improving the accuracy of propagation path prediction. Furthermore, normalization processing ensures that the propagation probability reflects the global distribution of propagation risks across all nodes in the network, providing a scientific basis for resource optimization in the defense system.
[0094] In this example, assuming there are nodes A, B, and C in an enterprise network, the following parameters are obtained through the perception module and the risk calculation module:
[0095] Node A: Risk propagation factor R A =8.0; Communication weight W between node B and node B AB =5.0; Communication weight W between node C and node C AC =2.0.
[0096] Node B: Risk propagation factor R B =6.0; Communication weight W between node C and node C BC =4.0.
[0097] Node C: Risk propagation factor R C =4.0.
[0098] Calculate the probability of propagation from node A to nodes B and C using the propagation probability formula:
[0099] Calculate the sum of risk propagation factors for all nodes: ∑ k R k =R A +R B +R C =8.0 + 6.0 + 4.0 = 18.0
[0100] Calculate the probability of propagation from node A to node B:
[0101] Calculate the probability of propagation from node A to node C:
[0102] Calculate the probability of propagation from node B to node C:
[0103] The calculation results show that node A has the highest probability of propagating to node B (2.22), indicating that node B is the attacker's primary target for propagation from node A. The probability of propagation from node A to node C is relatively low (0.89), possibly due to the communication weight W.AC The probability of node B propagating to node C is relatively low (1.33), indicating that node C faces certain potential risks in the propagation path.
[0104] Through this process, the system can identify the attacker's possible propagation direction, providing precise input for the deployment of decoy nodes. For example, the system can prioritize deploying more decoy nodes near node B, and by optimizing the feedback logic, guide the attacker further into areas with high decoy density, thereby weakening their threat to the real nodes.
[0105] Based on the risk propagation data, trap nodes are generated. These trap nodes simulate the vulnerability characteristics and high-value targets of real nodes and embed a feedback model to capture attackers' operational behaviors, generating feedback behavior data and attack path data. The deployment strategy of the trap nodes is adjusted based on the feedback behavior data and attack path data.
[0106] The generation of decoy nodes is based on risk propagation data. This data includes the risk propagation factor and propagation probability of each node, which can be used to identify key nodes and high-risk nodes in the attack propagation path. Decoy nodes are deployed at key locations in the attack path (such as near high-risk nodes or on links with high propagation probability) to guide the attacker's behavior, thereby reducing the attack risk to real nodes.
[0107] like Figure 2 As shown, the decoy node simulates the vulnerability characteristics and high-value targets of a real node, making it appear as an important network asset (such as a database server, financial system node, or file storage service). Specific implementations include configuring vulnerability information similar to that of a real node (e.g., simulating CVE vulnerabilities), opening and disguising service ports (e.g., common attack target ports 80 and 443), and forging content related to critical assets (e.g., database tables, file system structures, etc.). These designs effectively attract attackers to prioritize the decoy node as their attack target.
[0108] The trapping node embeds a feedback model to capture attacker behavior in real time. The feedback model generates feedback behavior data by recording and analyzing attacker interactions in real time, including but not limited to: the types of vulnerabilities the attacker attempted to exploit (such as SQL injection, buffer overflow, etc.); the characteristics of the tools used by the attacker (such as traffic patterns, packet characteristics); and the attacker's action sequence (such as file reading, directory browsing, command execution, etc.).
[0109] The feedback model guides attackers to perform more in-depth operations through a dynamic response mechanism. For example, when an attacker attempts to upload a malicious payload through an open port, the decoy node simulates the normal file acceptance and execution process while recording the complete attack flow; or when an attacker attempts to brute-force a user's password, the decoy node deliberately delays the feedback time, inducing the attacker to expose more attack details.
[0110] The trapping node compiles captured attacker actions into feedback behavior data, and combines this with risk propagation data to analyze attack paths, generating attack path data. This attack path data, by modeling the attacker's actual behavior, further reveals the attacker's potential target nodes and path preferences, providing information input for global network defense.
[0111] Based on feedback behavior data and attack path data, the system dynamically adjusts the deployment strategy of decoy nodes. Optimized deployment strategies include: dynamically adjusting the location of decoy nodes, such as adding decoy nodes to high-risk areas or withdrawing some nodes from low-risk areas; optimizing the feedback model logic of decoy nodes, such as adjusting the response rules of decoy nodes to better reflect the behavioral characteristics of real nodes; and strengthening cooperation between decoy nodes based on attack path data, by constructing decoy chains to guide attackers through a simulated path, further weakening the threat to real nodes.
[0112] In an example, multiple trapping nodes were deployed in the network environment of a large enterprise. The specific implementation process is as follows:
[0113] (1) Analysis of risk propagation data: The system identifies two high-risk nodes (node A and node B) through the calculation of risk propagation factors in the early stage. These two nodes have high risk propagation factors and high communication weight, making them easy to become propagation paths for attackers.
[0114] (2) Deployment of decoy nodes: Deploy a decoy node X near node A, simulating a high-value database server, configuring vulnerability features (such as simulating SQL injection vulnerability), opening ports (80 and 443), and forging key assets (such as forged customer information tables and financial data tables). Deploy a decoy node Y near node B, masquerading as a file storage service node, configuring a buffer overflow vulnerability, and providing multiple open directory structures to guide attackers to browse.
[0115] (3) Capture of Feedback Behavior: The attacker discovers an SQL injection vulnerability in the trap node X using scanning tools and attempts to steal forged customer data through a specific injection script. During the injection process, the trap node records the script parameters and SQL injection methods used by the attacker, generating feedback behavior data. The attacker attempts to brute-force user passwords through node Y. The trap node records the password combinations attempted and the attack frequency, while deliberately delaying the response time to guide the attacker to continue operating.
[0116] (4) Deployment strategy optimization: The system analyzes feedback behavior data and finds that attackers have a high preference for attacking file storage services. Therefore, a decoy node Z is added around node B, and its feedback model is optimized to simulate more complex file structures. The deployment location of the decoy node X is adjusted according to the attack path data, and it is moved to the critical communication link of node A to further enhance the protection of the real node.
[0117] Through this implementation process, the system successfully captured multiple actions of the attacker, identified the attacker's target path, and significantly improved the overall defense capability of the network by dynamically adjusting the deployment strategy.
[0118] Preferably, the trapping node dynamically responds to the attacker's actions by embedding a feedback model, which generates the feedback response according to the following formula:
[0119] F(x)=sin(k·x)+log(1+|x-μ|)
[0120] Wherein, F(x) represents the feedback response value of the decoy node, used to interfere with and guide the attacker's behavior. The decoy node adjusts its behavior guidance strategy according to the feedback response value. For example, the feedback response value can be used to simulate the abnormal response behavior of a real node, inducing the attacker to mistakenly believe that the attack has been successful. x represents the characteristic value of the attacker's operation behavior, including the complexity of the uploaded malicious payload (such as payload size, file type, encryption level) and the behavioral parameters of attempting to obtain resources (such as access permissions, command set complexity, etc.). The characteristic value is obtained by real-time extraction and parsing of the attacker's operation data. k represents the feedback frequency parameter of the decoy node, which is dynamically adjusted according to the current deployment strategy of the decoy node. For example, in high-risk areas, the feedback frequency may be set higher to achieve faster behavior capture. μ represents the feedback center point, used to set the feedback trigger threshold of the decoy node. By incorporating the difference between the characteristic value x and μ into the calculation, the decoy node can provide different levels of feedback according to the degree of deviation of the attacker's behavior.
[0121] The feedback frequency parameter k is dynamically adjusted based on the deployment strategy of the decoy nodes. For example, in areas with high attack frequency, the value of k can be increased to improve the frequency and sensitivity of the feedback response; when resources are limited, the value of k can be decreased to reduce feedback overhead.
[0122] The feedback center point μ is used to set the sensitivity threshold for triggering feedback. For example, when the attacker's behavior deviates little from normal operation (i.e., |x-μ| is small), the feedback response value is also correspondingly low to avoid unnecessary resource consumption; when the deviation is large, the decoy node will generate a stronger feedback response.
[0123] The feedback response value F(x) is used to simulate the behavior of a real node to confuse attackers and further capture their operational characteristics. For example, when an attacker attempts to perform remote code injection via a malicious payload, the decoy node can simulate the file execution process through feedback responses, while returning false execution results (such as forged system logs or error messages) to the attacker, guiding them to expose more of their attack intentions and tool characteristics.
[0124] Feedback response values, by dynamically adjusting their frequency and intensity, can guide attackers' behavior towards a predetermined trapping direction. For example, a feedback model can simulate the illusion of successfully gaining access, enticing attackers to attempt to acquire deeper levels of privileges, extending the attack time, and thus capturing more operational data.
[0125] Feedback response values can weaken an attacker's threat to the real node by delaying the attacker's operation process. For example, when attempting to brute-force a password, a decoy node can adjust the feedback frequency to increase the response time interval, significantly reducing the attacker's cracking efficiency.
[0126] By extracting features from malicious payloads and attempted commands uploaded by attackers, the feedback model can record the feature values of attack behavior in real time, providing high-value data for subsequent path analysis and defense strategy optimization.
[0127] The feedback model can automatically adapt to different attack intensities and patterns based on changes in the current network situation by dynamically adjusting parameters k and μ, thereby improving the flexibility and response efficiency of the decoy nodes.
[0128] In this example, we assume that multiple trap nodes are deployed within the internal network of a large enterprise to protect the core database server (Node A) and the financial server (Node B). The specific implementation process and scenario are as follows:
[0129] An attacker attempts to compromise node A via SQL injection, uploading a complex malicious payload to steal data. A decoy node C simulates a fake database server, recording the characteristics of the malicious payload uploaded by the attacker (file type, encryption complexity) as a feature value x. The decoy node then calculates the feedback response value: F(x) = sin(k·x) + log(1 + |x - μ|).
[0130] Assuming a malicious payload complexity of x = 5.0, a feedback frequency parameter of k = 0.8, and a feedback centroid of μ = 4.5, the calculated feedback response value F(x) = 0.68. Based on this feedback response value, the decoy node returns a forged error log to the attacker, inducing the attacker to modify the attack payload and retry.
[0131] After multiple failed attempts by the attacker, the trapping node detected a significant increase in the attack frequency. The system dynamically adjusted the feedback frequency parameter k to 1.2 to increase the feedback response frequency, thereby capturing the attack behavior more quickly. At the same time, the feedback center point μ was adjusted to 5.0 to adapt to changes in the complexity of the attacker's operations.
[0132] The attacker then attempted to redirect the target to the financial server (node B). A decoy node D simulated a fake file server, returning a false file system directory structure to the attacker and recording the attacker's command signature value x = 6.3. By calculating the feedback response value F(x) = 0.92, the decoy node intentionally delayed its response time, inducing the attacker to further attempt to obtain files.
[0133] Feedback behavior data records the characteristics of malicious payloads uploaded by attackers, the sequence of operations attempted, and the types of tools used. Attack path data reveals the attackers' path preferences from node A to node B, providing important reference for subsequent optimization of decoy node deployment strategies.
[0134] like Figure 3 As shown, a global network situation map is constructed based on the attack path data and the deployment strategy of the trapping nodes. Attack paths are predicted based on the situation map, path prediction data is generated, and the network is divided into high-risk areas, medium-risk areas, and low-risk areas.
[0135] The global network situational awareness graph uses all nodes in the network (including real nodes and decoy nodes) as nodes, and the communication relationships between nodes as edges. The edge weights are calculated based on the node's risk propagation factor and communication weight. The situational awareness graph reflects the security status and communication interactions of the entire network, and its construction process includes the following key steps:
[0136] The risk propagation factor of each node (calculated by combining vulnerability score, attack complexity score, and abnormal behavior score) is mapped to the security attribute of the graph node to represent the potential risk level of that node.
[0137] The weight of an edge is determined by the propagation probability and communication weight between nodes. The propagation probability represents the propagation path that an attacker may choose, while the communication weight is calculated by weighting traffic intensity, access frequency and connection stability, and reflects the actual interaction intensity between nodes.
[0138] The deployment strategy of the decoy nodes is mapped onto the situation graph to simulate the guidance path of attacker behavior. For example, a high-density deployment of decoy nodes forms a highly inductive path, thereby adjusting the weights of edges in the graph to enhance the decoy effect.
[0139] Based on the global network situation map, path search algorithms (such as Dijkstra's algorithm or Bayesian network-based path deduction) are used to predict the possible propagation paths of attackers. The specific steps are as follows:
[0140] Starting with high-risk propagation factor nodes, the potential propagation direction of the attacker is calculated using propagation probability and edge weights. Recursive path search is then used to extend path prediction to the entire network, generating complete path prediction data. This data includes the attacker's possible next target node and its corresponding propagation probability. By combining this data with the attacker's actual behavioral data (feedback behavioral data captured through decoy nodes), the path prediction results are dynamically adjusted to ensure a high degree of match between the predicted path and the attack behavior.
[0141] Based on path prediction data and the global network situation map, the network is divided into high-risk, medium-risk, and low-risk areas. The specific division rules are as follows:
[0142] High-risk areas include nodes with priority scores above a threshold and their associated nodes, and are typically the core areas for attack propagation. Medium-risk areas include nodes with priority scores within a set range, and may have some attack propagation potential. Low-risk areas include nodes with priority scores below a set threshold, and are less threatened by attacks.
[0143] Preferably, the construction of the global network situation map includes:
[0144] The real nodes and the lured nodes in the network are used as nodes in the graph;
[0145] Treat the communication relationships between nodes as edges of the graph;
[0146] The weight of an edge is calculated using the risk propagation factor and propagation probability of the node, and the weight is used to characterize the strength of the propagation relationship between nodes.
[0147] The nodes in the global network situation diagram include real nodes and decoy nodes in the network. They are represented in the same way in the diagram, but their functions and characteristics are different:
[0148] Real nodes represent actual assets in the network (such as servers, workstations, or storage devices). The security status of real nodes is described by a risk propagation factor (calculated by combining vulnerability score, attack complexity score, and anomalous behavior score), used to assess their potential risk as an attack target or propagation point.
[0149] Decoy nodes simulate the vulnerability characteristics and high-value targets of real nodes, specifically designed to attract attackers. Decoy nodes have high risk propagation factors to highlight their high-guiding characteristics in the situation map, forming the core nodes of the decoy attack path. Node feature data is obtained from earlier steps (such as the perception module and risk propagation factor calculation) and mapped into a graph model to characterize the security status of each node.
[0150] The communication relationships between nodes are abstracted as edges in a situational graph, used to describe the interactions between different nodes in the network. Modeling these communication relationships includes:
[0151] Edge creation: An edge is created between each pair of nodes with a direct communication relationship. For example, if there is communication traffic between node A and node B, an edge pointing from A to B is added to the situation diagram. Communication direction: The directionality of the edges reflects the direction of interaction between nodes. For bidirectional communication relationships, two directed edges are added to the situation diagram.
[0152] Edge weights are the core of the situation diagram, used to quantify the strength of propagation relationships between nodes. The weights are determined by the node's risk propagation factor and propagation probability.
[0153] The risk propagation factor reflects the potential risk level of a node itself. A higher risk propagation factor for the source node indicates a greater potential to be the starting point of an attack, and a higher contribution to the edge weight. Propagation probability quantifies the likelihood of an attacker propagating from the source node to the target node, calculated from the communication weights between nodes (such as traffic intensity, access frequency, and connection stability). A higher propagation probability results in a higher edge weight. Comprehensive calculation, by combining the risk propagation factor and propagation probability to calculate the edge weight, comprehensively describes the strength of the propagation relationship between nodes. For example, if node A's risk propagation factor is 7.5 and node B's propagation probability is 0.6, then the edge weight reflects the overall probability of node A propagating to node B.
[0154] In the situational graph, the deployment strategy of decoy nodes directly affects the calculation of edge weights. For example, by deploying decoy nodes in paths with high propagation probability, the edge weight of that path can be significantly increased, thereby guiding attackers to prioritize that path for propagation. The purpose of deployment strategy integration is to optimize the distribution and cooperation effect of decoy nodes, maximizing the guiding and disruptive nature of attack behavior.
[0155] Example: The following is a specific implementation process for constructing a global network situation map in an enterprise network:
[0156] The network environment and node mapping: The enterprise network includes 5 real nodes (nodes A, B, C, D, and E) and 2 decoy nodes (nodes X and Y). Nodes A and B are core servers with risk propagation factors of 8.0 and 7.5, respectively; nodes C and D are user workstations with lower risk propagation factors of 4.0 and 3.5, respectively; nodes X and Y are decoy nodes, simulating a database and a file server, respectively, with a risk propagation factor of 6.0 for both.
[0157] The communication relationships between nodes in the network are as follows: there is bidirectional communication between node A and node B; there is unidirectional communication between node A and nodes C and D; there is bidirectional communication between node B and the trapping node X; there is unidirectional communication between node C and node E.
[0158] Establish the following edges in the situation diagram: the edge from node A to node B (the weight is calculated by the propagation factor of A and the propagation probability of A→B); the edge from node B to node A; the edge from node A to node C; the edge from node B to the trap node X; and the edge from node C to node E.
[0159] Edge weight calculation: The propagation probability from node A to node B is 0.8, the risk propagation factor of node A is 8.0, and the edge weight is calculated as 8.0·0.8 = 6.4; the propagation probability from node B to node A is 0.7, the risk propagation factor of node B is 7.5, and the edge weight is 7.5·0.7 = 5.25; the propagation probability from node B to the trapping node X is 0.9, and the edge weight is 7.5·0.9 = 6.75.
[0160] Deploying high-density trapping nodes (such as adding a new trapping node Z) in the communication link from node B to node X significantly increases the edge weight of this path, thereby guiding attackers to prioritize the trapping node path.
[0161] Preferably, risk areas are delineated using a global network situation map, and the delineation steps include:
[0162] Calculate the priority score for each node based on the path prediction data;
[0163] Nodes with priority scores greater than a set threshold and their associated nodes are classified as high-risk areas.
[0164] Nodes whose priority scores fall within a set threshold range are classified as medium-risk areas;
[0165] Nodes with priority scores below a set threshold are classified as low-risk zones.
[0166] A node's priority score measures its importance as a propagation target or key node in an attack path. The priority score is calculated based on the following factors:
[0167] Risk propagation factor: The risk propagation factor of a node combines vulnerability score, attack complexity score, and anomalous behavior score to characterize the node's own risk level. Path prediction data: Path prediction data reflects the probability of an attacker propagating from a certain node to other nodes, quantifying the importance of each node in the propagation path. Node correlation: The communication relationships and dependencies between nodes (such as whether they are critical servers) also affect the priority score.
[0168] Priority scores are calculated by comprehensively considering the above factors. For example, a node with a high-risk propagation factor that frequently appears in path prediction will be assigned a higher priority score. Based on the priority scores and a set threshold range, the network is divided into the following three risk zones:
[0169] High-risk areas include nodes with priority scores higher than a set threshold and their directly associated nodes. These nodes are often core nodes in the attack path or important targets in the propagation path, and should be prioritized for deployment of decoy nodes and defensive resources.
[0170] Medium-risk areas: These include nodes whose priority scores fall within the set threshold range. While these nodes are not directly the starting point of high-risk transmission, they may have some transmission potential and require continuous monitoring and appropriate preventative measures.
[0171] Low-risk areas: These include nodes with priority scores below a set threshold. These nodes are less vulnerable to attack, allowing for reduced resource investment, but basic protective measures should still be maintained to address potential threats.
[0172] Risk zone delineation is not static, but dynamically adjusted as network conditions change. For example, when attack path prediction data changes (such as adding new propagation paths or adjusting propagation probabilities), priority scores are updated accordingly, triggering a re-delineation of risk zones.
[0173] Example: The following is a specific implementation process for risk area division based on a global network situation map in a large enterprise network:
[0174] The enterprise network consists of 6 real nodes (nodes A, B, C, D, E, and F) and 2 decoy nodes (nodes X and Y). The following data was obtained initially through a global network situational awareness map:
[0175] Risk propagation factors for nodes: Node A: 8.5, Node B: 7.8, Node C: 6.3, Node D: 4.0, Node E: 3.5, Node F: 2.1.
[0176] Path prediction data: The propagation probability of node A→B is 0.7, and that of A→C is 0.5; the propagation probability of node B→D is 0.6, and that of C→E is 0.4; the propagation probability of node D→F is 0.2.
[0177] Node A's priority score: Based on its high-risk transmission factor (8.5) and high transmission probability (0.7 for A→B, 0.5 for A→C), the priority score is calculated to be 7.0. Node B's priority score: 7.8 (risk transmission factor) × 0.6 (transmission probability) = 4.68. Node D's priority score: 4.0 × 0.2 (transmission probability) = 0.8. Other nodes have their priority scores calculated based on their transmission factors and path prediction data.
[0178] The threshold for the high-risk area of the priority scoring is set at 5.0, and the range for the medium-risk area is 3.0-5.0.
[0179] High-risk area: Includes node A (score 7.0), node B (score 4.68, as an associated node), and their associated trapping node X. Medium-risk area: Includes node C (score 3.5) and its associated node E. Low-risk area: Includes node D (score 0.8) and node F.
[0180] In the high-risk area, deploy a new trap node Z near node A, and adjust the feedback strategy of trap node X to simulate more complex behavioral patterns. In the medium-risk area, retain trap node Y to monitor the propagation behavior of node C. Reduce resource investment in the low-risk area, but retain basic protective measures (such as traffic monitoring and access control).
[0181] Based on the path prediction data and risk area division results, defense resources are dynamically allocated, the deployment density of trapping nodes and feedback chain logic are adjusted, and dynamic resource allocation data is generated to optimize the defense effect in high-risk areas.
[0182] The core of dynamically allocating defense resources lies in concentrating limited resources on high-risk areas to strengthen their defense capabilities, while rationally reducing resource investment in low-risk areas. The allocation logic is based on the following key steps:
[0183] (1) Path prediction data clarifies the attacker's possible propagation paths and target nodes. Resource allocation prioritizes covering key nodes and high-probability propagation links in the path to block attack paths and protect critical assets. (2) Through risk zone division, nodes in high-risk areas are marked as targets for priority resource allocation, medium-risk areas maintain existing defenses, and low-risk areas reduce resource investment. (3) The deployment density and feedback chain logic of decoy nodes directly affect the effectiveness of resource allocation. By dynamically adjusting the deployment location, number, and feedback behavior strategies of decoy nodes, resource utilization efficiency can be further optimized.
[0184] The deployment density of decoy nodes refers to the number and distribution density of decoy nodes deployed in important locations such as high-risk areas and key locations along the propagation path in the network. Density adjustment is achieved through the following methods:
[0185] (1) Add new decoy nodes in high-risk areas or redeploy existing nodes to critical propagation paths to form the core area of the decoy network. For example, add decoy nodes in paths with a high probability of attack propagation to weaken the risk of real nodes by strengthening the capture and guidance of attack behavior. (2) Reduce the number of decoy nodes in low-risk areas and redistribute the released resources to high-risk areas to improve the overall utilization efficiency of resources.
[0186] Feedback chain logic refers to the adjustment of the cooperation mode and feedback strength of decoy nodes when responding to attacks. The goal of optimizing feedback chain logic is to enhance cooperation between decoy nodes, causing attackers to loop through forged paths, thereby consuming their time and resources. Optimization measures include:
[0187] (1) Increase the feedback complexity in the trap nodes in high-risk areas, such as simulating more realistic system logs or file directory structures, to extend the attacker's operation path. (2) By optimizing the strength of the feedback chain between trap nodes, the attacker's operation behavior can be guided to a set path. For example, by adjusting the feedback delay and triggering conditions of the trap nodes, the attacker's behavior can be guided to a deeper trap path.
[0188] The dynamic allocation data integrates path prediction results, risk area classification information, and the deployment strategy of decoy nodes to generate a specific plan for the allocation of defense resources. The generated data includes the following: the deployment density and location of decoy nodes in each area; adjustment parameters of the decoy node feedback logic, such as feedback frequency and trigger threshold; and defense resource enhancement measures for real nodes, such as access control policies and traffic monitoring rules.
[0189] Preferably, the trapping nodes form a trapping chain by adjusting the deployment density and feedback response chain logic. The trapping chain enhances the guidance of attack behavior through the synergy effect between nodes, which is calculated according to the following formula:
[0190]
[0191] Where S(i→j) represents the collaborative optimization value between trap node i and trap node j; F i (x) and F j (x) represent the feedback functions of trap node i and trap node j, respectively;
[0192] The synergistic effect is used to optimize the feedback chain strength between trapping nodes to enhance the attacker's inducibility in the path.
[0193] The trapping chain is formed by adjusting the deployment density of trapping nodes and the logic of the feedback response chain. Specifically:
[0194] Deployment density is adjusted by deploying multiple decoy nodes along the attack propagation path, forming a high-density decoy network covering the target area. For example, in high-risk areas, at least two decoy nodes are deployed near each path node with a high probability of attack propagation, ensuring that attackers are captured by multiple decoy nodes when attempting to propagate.
[0195] Feedback chain logic optimization involves adjusting the feedback response mechanism of the trap nodes to generate continuous feedback chains, inducing attackers to cycle through multiple trap nodes along a preset path. For example, when an attacker's action triggers the feedback of trap node i, trap node i guides the attacker to further trigger the feedback of the neighboring trap node j, forming a trap chain.
[0196] Feedback function F of the trap node i `(x)` is dynamically generated based on the attacker's behavioral characteristic value `x`, and is used to describe the strength of the decoy node's response to the attacker. The characteristic value `x` includes the complexity of the malicious payload uploaded by the attacker, behavioral parameters related to the attempt to acquire resources, etc. The output value of the feedback function determines the strength of the decoy node's interference and guidance of the attacker's behavior. For example, when an attacker attempts to access a fake sensitive file directory, the decoy node can simulate a successful access through the feedback function and generate false file content to guide the attacker to further operations.
[0197] The synergy effect S(i→j) is quantified by the strength of the feedback chain between the trapping nodes and is used to evaluate the cooperative effect between two trapping nodes. A higher synergy effect indicates a stronger influence of the trapping chain on the attacker's behavior. The formula for calculating the synergy effect incorporates the feedback strength F of the two trapping nodes. i (x) and F j (x), and simultaneously through the denominator |Fi (x)·F j (x)|Controls the difference in feedback between the two nodes. When the feedback strengths of the two trap nodes are similar, the synergistic effect is maximized, resulting in a smoother guiding path.
[0198] The optimization of the synergy effect is mainly achieved through the following methods: (1) Dynamically adjust the feedback intensity of the trapping node to maintain consistency in the feedback chain. For example, when the feedback intensity of trapping node i is weak, the system can adjust its feedback logic to enhance its ability to interfere with the attacker's behavior. (2) Optimize the feedback triggering conditions: Optimize the feedback triggering conditions of the trapping node to make it more sensitive to the attacker's behavior. For example, when the complexity of the attacker's behavior reaches a certain threshold, the feedback response intensity of the trapping node will increase accordingly. (3) By adjusting the deployment position of the trapping node, ensure that the synergy effect covers the key nodes of the attack propagation path.
[0199] Through the synergistic effect of the trapping chain, the system can guide attackers to continuously operate within the forged path, extending the attack time and capturing more attack behavior characteristics. For example, after an attacker attempts to access a forged file directory in one trapping node, they will be guided to another trapping node to perform the next operation, thus forming a trapping loop.
[0200] The optimization of synergy enables the trapping chain to form a critical link with high guidance and high capture rate in the attack path. The attacker's operation sequence is fully recorded, providing important data for subsequent optimization of defense strategies and adjustment of trapping nodes. By guiding the attacker's operation behavior through the trapping chain, the system diverts attack traffic from real nodes to trapping nodes, significantly reducing the probability of real nodes being attacked. The optimization of synergy makes the cooperation between trapping nodes closer, improving the defense effect without increasing the total number of trapping nodes and maximizing resource utilization efficiency.
[0201] Example: The following is a specific implementation process of forming a trap chain through trapping nodes in a certain enterprise network:
[0202] The enterprise network includes high-risk nodes A and B, with risk propagation factors of 8.0 and 7.5 respectively, and a propagation path of A→B. Initially, a decoy node X is deployed near node A, and a decoy node Y is deployed near node B. The initial feedback function of the decoy nodes is set as follows:
[0203] F X (x)=sin(0.8·x)+log(1+|x-5.0|)
[0204] F Y (x)=sin(0.7·x)+log(1+|x-4.8|)
[0205] Assuming the attacker uploads a malicious payload with a complexity feature value of x = 6.0, calculate the synergistic effect between the trapping nodes X and Y:
[0206] F X (x) = 0.93
[0207] F Y (x) = 0.87
[0208]
[0209] Based on the synergy calculation results, the feedback strength of the trapping node X is slightly higher than that of the trapping node Y. To enhance the synergy between the two, the system adjusts the feedback frequency parameter of the trapping node Y to make it closer to that of the trapping node X. A new trapping node Z is added between node A and node B to simulate high-value assets and optimize the feedback chain logic, extending the trapping chain to X→Z→Y.
[0210] After the attacker triggers a response at the lured node X near node A, they attempt to further attack the fake sensitive file directory but are redirected to node Z. Node Z simulates a real file storage server, returning fake file system content to the attacker and recording their actions. Ultimately, the attacker is redirected to node Y to attempt to crack the simulated user credentials; all actions are fully recorded by the system.
[0211] Preferably, the steps for dynamically allocating defense resources include:
[0212] Deploy more trap nodes in high-risk areas and enhance the feedback strength of the trap nodes to guide attacker behavior;
[0213] In medium-risk areas, retain existing trapping node deployments and adjust the feedback frequency of trapping nodes to reduce resource consumption;
[0214] Reduce the deployment of trap nodes in low-risk areas and prioritize the allocation of freed resources to high-risk areas.
[0215] High-risk areas include nodes with priority scores exceeding a set threshold and their directly associated nodes. These nodes are typically located at the core or target positions of the attack path, making them the attacker's preferred propagation path or target. Therefore, resource allocation strategies for high-risk areas focus on enhancing defense capabilities, with specific measures including:
[0216] (1) Deploy more decoy nodes in high-risk areas to cover key nodes in the attack path. For example, for links with a high probability of propagation, additional decoy nodes can be deployed at both ends or in the middle of the path to form a multi-layered defense. (2) Increase the complexity of the decoy nodes' response to attack behaviors by simulating a more realistic network environment (such as open fake database services, file directory structures, etc.) to extend the attacker's operation time and capture more attack behavior characteristics. (3) Optimize the synergistic effect of the decoy chain to ensure that the decoy nodes in high-risk areas can form an effective feedback chain to further guide attack behaviors.
[0217] Medium-risk areas include nodes whose priority scores fall within a set threshold range. While these nodes are not directly located on the core attack path, they may possess propagation potential or pose indirect risks. Resource allocation strategies in medium-risk areas focus on optimizing the utilization efficiency of existing defense resources. Specific measures include:
[0218] (1) Decoy nodes in medium-risk areas are usually able to effectively monitor the propagation activities in that area, and retaining these nodes can prevent the emergence of defense vulnerabilities. (2) By reducing the feedback frequency of decoy nodes, the occupation of system resources can be reduced. For example, when the attack frequency is low or the regional threat is small, the response time interval of decoy nodes can be extended to reduce system computation and resource overhead. (3) Without affecting the monitoring effect, the response logic of decoy nodes can be simplified, such as reducing the feedback complexity or reducing the coverage of decoy nodes, thereby saving resources.
[0219] Low-risk areas include nodes with priority scores below a set threshold; these nodes are less threatened by attacks or have limited impact on attack propagation. Resource allocation strategies in low-risk areas focus on releasing resources, and specific measures include:
[0220] (1) Gradually withdraw trap nodes from low-risk areas and deploy them to high-risk areas. For example, reduce the number of trap nodes in low-risk areas or downgrade their functionality to basic traffic monitoring nodes. (2) Reduce the complexity of access control rules, reduce the frequency of traffic monitoring, or shut down some redundant security services in low-risk areas to free up more computing and bandwidth resources. (3) Despite the reduction in resources, basic defense capabilities, such as logging and traffic analysis, should still be retained to prevent emergencies.
[0221] The dynamic resource allocation data is generated by combining the priority scores of high-risk areas, the deployment strategies of trap nodes, and the optimization parameters of feedback logic, and is used to guide the allocation of defense resources. The generated data includes: the deployment locations and numbers of newly added trap nodes in high-risk areas; the feedback frequency adjustment parameters of trap nodes in medium-risk areas; and the specific strategies for releasing resources in low-risk areas, such as the number and type of nodes withdrawn.
[0222] Preferably, the resource allocation ratio for high-risk areas is calculated using the following formula:
[0223]
[0224] Among them, R alloc (i) represents the proportion of resources allocated to node i, used for dynamically allocating defense resources for either decoy nodes or real nodes; R i ∑ represents the risk propagation factor of node i, calculated by combining node vulnerability score, attack complexity score, and abnormal behavior score; H represents the set of nodes within a high-risk area, which is defined based on path prediction data and network situation map; ∑ j∈H R j This represents the sum of risk propagation factors across all nodes within a high-risk area, used to normalize resource allocation ratios.
[0225] The resource allocation ratio is used to guide the adjustment of the deployment density of trap nodes and the optimization of the defense strategy of real nodes, so as to prioritize the improvement of the defense capabilities of high-risk areas.
[0226] In high-risk areas, the key to defense strategy is to concentrate limited defense resources on critical nodes. Resource allocation ratio R alloc (i) The calculation logic is based on the risk transmission factor R i With this as the core, the risk priority of each node is fully reflected. Nodes with higher risk propagation factors receive a larger proportion of resources. For example, nodes with high risk propagation factors are usually important nodes or targets in the attack propagation path, and their priority directly affects the allocation results.
[0227] Resource allocation within high-risk areas needs to consider overall balance; therefore, a normalization operation is used to reduce the risk propagation factor R of nodes. i Convert to allocation ratio R alloc (i) The result of normalization is that the sum of the resource allocation ratios of all nodes in the high-risk area is equal to 1. This ensures the total resource allocation constraint and facilitates the direct calculation of the allocated resources for each node based on the total resources.
[0228] Risk transmission factor R i The following three core metrics are used to comprehensively calculate the following: Vulnerability Score, reflecting the severity and exploitability of known vulnerabilities on the node; Attack Complexity Score, indicating the expected difficulty for an attacker to exploit the node, such as whether high privileges or complex exploit paths are required; and Anomaly Behavior Score, based on abnormal behavior patterns captured in network logs, such as port scanning and unusual access requests, reflecting the node's current security status. Combining these three metrics allows for a comprehensive assessment of the node's potential risks; a higher risk propagation factor indicates a greater threat to the node in a high-risk area.
[0229] Resource allocation ratios are primarily used to dynamically adjust the deployment density of decoy nodes and the defense strategies of real nodes. For example, nodes with high allocation ratios can prioritize deploying more decoy nodes or enhancing existing defenses, while nodes with low allocation ratios can moderately reduce resource investment.
[0230] Example: The following is a specific implementation process for using a high-risk area resource allocation formula in an enterprise network:
[0231] The high-risk areas identified in the enterprise network include nodes A, B, and C, with risk propagation factors of R for each node. A =8.0 (Core Database Server). R B =6.5 (file storage server). R C =5.5 (Remote Access Gateway). The total resource limit is set to 100 units (which can be units such as trap nodes, access control rules, monitoring policies, etc.).
[0232] First, calculate the sum of risk propagation factors for all nodes within the high-risk area: ∑ j∈H R j =R A +R B +R C =8.0 + 6.5 + 5.5 = 20.0
[0233] Calculate the resource allocation ratio for each node using the formula:
[0234] Based on the calculation results, the resources are allocated as follows: Node A is allocated 100 × 0.4 = 40 units of resources: Two new trapping nodes are added, deployed on the uplink and downlink communication links of Node A respectively. Access control rules for Node A are enhanced, such as restricting access from high-risk IP ranges. A log analysis module is added to analyze all access requests in real time.
[0235] Node B is allocated 100 × 0.325 = 32.5 units of resources: One new trap node is added to simulate a high-value file system. Access control rules are simplified, but traffic monitoring functionality is retained.
[0236] Node C is allocated 100 × 0.275 = 27.5 units of resources: This retains the existing trapping node deployment while reducing response complexity to save computational resources. Basic traffic monitoring policies are set up to capture potential threats.
[0237] Suppose that in a certain attack event, node A's anomalous behavior score increases, causing its risk propagation factor to rise to R.A =9.0. The allocation ratio is recalculated based on the new risk transmission factor:
[0238]
[0239] The allocation ratio of node A was increased from 40% to 42.9%, and the system correspondingly increased the defense resources invested in node A, such as adding a new trapping node and optimizing the feedback logic.
[0240] like Figure 4 As shown, a system for implementing the aforementioned proactive security defense method for network security based on vulnerability exploitation includes:
[0241] The perception module is deployed in the network to collect multimodal data, including structured data, unstructured data, and semi-structured data. The perception module further performs formatting, data cleaning, and standardization on the collected data to generate vulnerability feature data. By deploying the perception module at multiple key locations in the network, it collects structured data (such as vulnerability scanning information), unstructured data (such as log records), and semi-structured data (such as protocol parsing data), and formats, cleans, and standardizes this data to generate vulnerability feature data for subsequent analysis.
[0242] The risk calculation module is used to calculate the risk propagation factor and propagation probability of network nodes based on the vulnerability feature data, and generate risk propagation data. The risk propagation factor is calculated based on the vulnerability score, attack complexity score, and abnormal behavior score of the node, and the propagation probability is calculated based on the communication weight between nodes and the risk propagation factor. Based on the vulnerability feature data, the risk calculation module calculates the risk propagation factor by combining the vulnerability score, attack complexity score, and abnormal behavior score of the node. Combining the communication weight between nodes and the risk propagation factor, the propagation probability is further calculated to generate risk propagation data for evaluating attack paths and key nodes.
[0243] The decoy node generation module is used to generate decoy nodes based on the risk propagation data. The decoy nodes simulate the vulnerability characteristics and high-value targets of real nodes, and capture the attacker's operation behavior through an embedded feedback model to generate feedback behavior data and attack path data.
[0244] The deployment optimization module is used to adjust the deployment strategy of the trapping nodes based on the feedback behavior data and attack path data. The deployment strategy includes the optimization of the deployment location of the trapping nodes and the feedback response logic. The deployment optimization module dynamically adjusts the location and feedback logic of the trapping nodes based on these data, so that the trapping nodes can efficiently guide attack behavior.
[0245] The situation awareness module is used to construct a global network situation map based on the attack path data and the deployment strategy of the decoy nodes. The situation awareness module is further used to predict attack paths based on the global network situation map, generate path prediction data, and divide the network into high-risk areas, medium-risk areas, and low-risk areas based on the path prediction data. The situation awareness module uses the attack path data to construct a global network situation map, and divides the network into high, medium, and low-risk areas through path prediction and priority scoring, providing a basis for resource allocation decisions.
[0246] The resource allocation module is used to dynamically allocate defense resources based on the path prediction data and risk area division results. The resource allocation includes adjusting the deployment density of trap nodes and the feedback chain logic, and generating dynamic resource allocation data to optimize the defense effect of high-risk areas. The resource allocation module combines path prediction data and risk area division results to dynamically allocate defense resources, optimize the deployment density of trap nodes and the feedback chain logic, and generate dynamic resource allocation data to improve the defense capability of high-risk areas.
[0247] The data storage module is used to store the multimodal data, vulnerability characteristic data, risk propagation data, feedback behavior data, attack path data, path prediction data, and dynamic resource allocation data. The data storage module records multimodal data, vulnerability characteristic data, feedback behavior data, attack path data, and dynamic allocation data, supporting dynamic optimization and feedback adjustments of the system.
[0248] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A proactive security defense method for network security based on vulnerability exploitation, characterized in that, Includes the following steps: Multimodal data is collected by a sensing module deployed in the network. The collected multimodal data is preprocessed and features are extracted to generate vulnerability feature data. Based on the vulnerability feature data, the risk propagation factor and propagation probability of the node are calculated to generate risk propagation data. The propagation probability between the nodes is calculated using the following formula: in, Indicates from node To the node The probability of an attack propagating is used to quantify the direction in which the attack behavior propagates. Represents a node The risk propagation factor reflects the risk level of a node as the starting point for attack propagation. Represents a node With nodes The communication weight between the two nodes is calculated by weighting the communication traffic, access frequency, and connection stability between the two nodes. This represents the sum of risk propagation factors across all nodes in the network, used to normalize propagation probabilities so that the probability of each propagation path aligns with the overall network propagation behavior distribution; the propagation probability is used to determine the attacker's potential next target node. Based on the risk propagation data, trap nodes are generated. These trap nodes simulate the vulnerability characteristics and high-value targets of real nodes and embed a feedback model to capture attackers' operational behaviors, generating feedback behavior data and attack path data. The deployment strategy of the trap nodes is adjusted based on the feedback behavior data and attack path data. The trapping node dynamically responds to the attacker's actions by embedding a feedback model, which generates the feedback response according to the following formula: in, This represents the feedback function of the trapping node, which is used to interfere with and guide the attacker's behavior. The trapping node adjusts its behavior guidance strategy based on the feedback response value. Characteristic values representing attacker actions, including the complexity of uploaded malicious payloads and behavioral parameters of attempts to acquire resources; This parameter represents the feedback frequency of the trapping node, which is dynamically adjusted based on the current deployment strategy of the trapping node. This indicates the feedback center point, used to set the feedback trigger threshold for the trapping node; A global network situation map is constructed based on the attack path data and the deployment strategy of the trapping nodes. Attack paths are predicted based on the situation map, path prediction data is generated, and the network is divided into high-risk areas, medium-risk areas, and low-risk areas. Based on the path prediction data and risk area division results, defense resources are dynamically allocated, the deployment density of trapping nodes and feedback chain logic are adjusted, and dynamic resource allocation data is generated to optimize the defense effect of high-risk areas. The trapping nodes form a trapping chain by adjusting deployment density and feedback response chain logic. The trapping chain enhances the guidance of attack behavior through the synergy effect between nodes. The synergy effect is calculated according to the following formula: in, Represents the trapping node and trap nodes The collaborative optimization value between them; and These represent the trapping nodes. and trap nodes Feedback function; The synergistic effect is used to optimize the feedback chain strength between trapping nodes to enhance the attacker's inducibility in the path.
2. The method according to claim 1, characterized in that, The risk propagation factor of the node is calculated using the following formula: in, Represents a node The risk propagation factor is used to characterize the potential risk level of the node as the starting point of attack propagation in the network; Represents a node The vulnerability score is obtained by quantifying the severity and difficulty of exploitation of the vulnerability. Represents a node The attack complexity score is quantified by assessing the resource input and permission requirements required to launch an attack on a node. Represents a node The abnormal behavior score is derived by analyzing the abnormal communication behavior exhibited by nodes in the network logs; These are weighting factors for vulnerability scores, attack complexity scores, and anomalous behavior scores, respectively. These weighting factors are optimized based on historical attack behavior data to balance the contribution of different scores to the risk propagation factor.
3. The method according to claim 1, characterized in that, The construction of the global network situation map includes: The real nodes and the lured nodes in the network are used as nodes in the graph; Treat the communication relationships between nodes as edges of the graph; The weight of an edge is calculated using the risk propagation factor and propagation probability of the node, and the weight is used to characterize the strength of the propagation relationship between nodes.
4. The method according to claim 1, characterized in that, Risk areas are delineated using a global network situation map, and the delineation steps include: Calculate the priority score for each node based on the path prediction data; Nodes with priority scores greater than a set threshold and their associated nodes are classified as high-risk areas. Nodes whose priority scores fall within a set threshold range are classified as medium-risk areas; Nodes with priority scores below a set threshold are classified as low-risk zones.
5. The method according to claim 1, characterized in that, The steps for dynamically allocating defense resources include: Deploy more trap nodes in high-risk areas and enhance the feedback strength of the trap nodes to guide attacker behavior; In medium-risk areas, retain existing trapping node deployments and adjust the feedback frequency of trapping nodes to reduce resource consumption; Reduce the deployment of trap nodes in low-risk areas and prioritize the allocation of freed resources to high-risk areas.
6. The method according to claim 1, characterized in that, The resource allocation ratio for high-risk areas is calculated using the following formula: in, Indicates assignment to a node The resource ratio is used to dynamically allocate defense resources for trapping nodes or real nodes; Represents a node The risk propagation factor is calculated by combining node vulnerability score, attack complexity score, and abnormal behavior score. This refers to the set of nodes within a high-risk area, which is defined based on path prediction data and network situation diagrams. This represents the sum of risk propagation factors across all nodes within a high-risk area, used to normalize resource allocation ratios. The resource allocation ratio is used to guide the adjustment of the deployment density of trap nodes and the optimization of the defense strategy of real nodes, so as to prioritize the improvement of the defense capabilities of high-risk areas.
7. A system for implementing the proactive network security defense method based on vulnerability exploitation as described in any one of claims 1-6, characterized in that, include: The perception module is deployed in the network to collect multimodal data, including structured data, unstructured data, and semi-structured data. The perception module is further used to perform formatting, data cleaning, and standardization on the collected data, and to generate vulnerability feature data. The risk calculation module is used to calculate the risk propagation factor and propagation probability of network nodes based on the vulnerability feature data, and generate risk propagation data. The risk propagation factor is calculated based on the vulnerability score, attack complexity score and abnormal behavior score of the node, and the propagation probability is calculated based on the communication weight between nodes and the risk propagation factor. The decoy node generation module is used to generate decoy nodes based on the risk propagation data. The decoy nodes simulate the vulnerability characteristics and high-value targets of real nodes, and capture the attacker's operation behavior through an embedded feedback model to generate feedback behavior data and attack path data. The deployment optimization module is used to adjust the deployment strategy of the trapping nodes based on the feedback behavior data and attack path data. The deployment strategy includes the optimization of the deployment location of the trapping nodes and the feedback response logic. The situation awareness module is used to construct a global network situation map based on the attack path data and the deployment strategy of the trapping nodes. The situation awareness module is further used to predict attack paths based on the global network situation map, generate path prediction data, and divide the network into high-risk areas, medium-risk areas and low-risk areas based on the path prediction data. The resource allocation module is used to dynamically allocate defense resources based on the path prediction data and risk area division results. The resource allocation includes adjusting the deployment density of trap nodes and feedback chain logic, and generating dynamic resource allocation data to optimize the defense effect in high-risk areas. The data storage module is used to store the multimodal data, vulnerability feature data, risk propagation data, feedback behavior data, attack path data, path prediction data, and dynamic resource allocation data.
Citation Information
Patent Citations
Network security defense method and system based on vulnerability exploitation, and computer-readable storage medium
CN118555134B
Network defense system based on decoy technology
CN119109671A
Attack trapping method and system based on network attack surface adaptive conversion
CN119210761A