Enterprise intranet-oriented four-honey threat exploration method

By building a four honey system in the enterprise intranet, including honey court, honey dot, honey cave and honey array, and collaboratively conducting threat detection and defense, the shortcomings of existing technology in defending against complex network attacks are solved, and comprehensive protection and dynamic defense of the enterprise intranet are achieved.

CN119996015AActive Publication Date: 2025-05-13GUANGZHOU UNIVERSITY

Patent Information

Application Number
CN202510207403.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-13
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

In the current technology, it is difficult to achieve effective threat detection and defense when defending against complex and diverse network attacks from internal enterprise networks. Especially in the face of APT and unknown threats, the honeypot system has insufficient deception and monitoring capabilities, and lacks high customizability, comprehensive concealment and dynamic environmental adaptability.

Method used

Build four threat detection methods for enterprise intranets, including honey court, honey dot, honey cave and honey array. Through the coordinated linkage of these components, it can realize the monitoring and identification of network traffic, capture and traceability of attack intelligence, and dynamic adjustment of defense strategies.

Benefits of technology

It realizes comprehensive protection of the enterprise intranet, can effectively isolate the real system, prevent attacks from reaching the actual network, form clear local threat perception, and realize global linkage handling, quickly traceability and countermeasures, and build a more secure enterprise-level network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996015A_ABST
    Figure CN119996015A_ABST
Patent Text Reader

Abstract

The invention provides a four-honey threat exploration method for an enterprise intranet. The four-honey threat exploration method comprises the following steps: constructing a honey court, a honey point, a honey hole and a honey array in the enterprise intranet; the honey court is used for monitoring network traffic and carrying out black, white and grey traffic identification on the network traffic; the honey point is used for carrying out trapping detection on the network flow passing through the honey point; the honey hole is used for collecting attacker information and performing traceability countering according to the attacker information; the honey array is in communication connection with the honey court, the honey point and the honey hole, obtains the safety condition of the enterprise intranet and the deployment information of the honey court, the honey point and the honey hole, and carries out deployment scheduling according to the safety condition of the enterprise intranet. The four-honey system constructed by applying the method fits the enterprise intranet environment and has dynamic adaptive capacity. A real system can be effectively isolated, and attacks are prevented from reaching an actual network. Global linkage disposal can be realized for security threats, security intelligence and attack information can be comprehensively shared, deployment points can be coordinated and adjusted, source tracing and countering can be quickly carried out, and a secure enterprise-level network environment can be constructed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a four-honeypot threat detection method for an enterprise intranet. Background Art

[0002] The internal network of an enterprise contains many high-value information assets. Attackers often target the internal network and attempt to infiltrate the internal network through various attack methods to obtain important asset information of the enterprise. Therefore, the security of the internal network of an enterprise has received great attention in recent years. At present, there are two main means of defense against the internal network: one is the traditional defense solution based on the network boundary. Deploy security devices at the junction of the internal and external networks, including firewalls, WAF, IPS and other devices; the other is to adopt the zero trust mechanism. The central idea of ​​the zero trust mechanism is not to trust any internal or external users, devices, services or applications. Only through the identity and access management process can the lowest level of trust and access rights be obtained. It is mainly to prevent attackers from launching attacks in the internal network through various means.

[0003] However, these defense measures are currently facing new technical challenges. With the continuous development of science and technology and the continuous expansion of network scale, network attacks against intranet security are becoming more targeted and organized, and the attackers' attack techniques and methods are becoming more and more complex and diverse, such as 0day vulnerability attacks and APT attacks. Traditional defense technologies are almost unable to resist these attacks, which makes it easy for attackers to break through the internal defense line. In addition, the Intranet boundary of the enterprise intranet is often fuzzy and unclear, which makes it difficult to divide the defense boundary and choose the most appropriate place to deploy security equipment.

[0004] At present, the main thing that is lacking in intranet security defense is a linkage disposal system based on deception defense. Although the existing active deception defense has built a defense system based on honeypot technology, the promotion of this system has encountered some difficult problems that are difficult to bypass: for APT and unknown threats, the honeypot system's deception and monitoring capabilities are insufficient, and it lacks high customizability, comprehensive concealment, and dynamic environment adaptability, which are indispensable for intranet security defense. In addition, honeypot technology has irreconcilable contradictions in terms of simulation and controllability, and it is impossible to compromise and achieve a balance. Honeypot technology can only provide auxiliary support for network security to a certain extent, but cannot undertake comprehensive protection tasks alone.

[0005] In addition, current honeypot technology often cannot dynamically interact with attackers, cannot dynamically adjust strategies and environments in real time according to attackers' attack behaviors, and the types of attacks covered by honeypots are narrow and can be easily evaded or bypassed. Honeypots are designed to attract attackers, but cannot prevent attackers from invading real systems. Honeypot systems can capture a large amount of network traffic, attack logs, and other related data, but to convert these massive amounts of data into useful threat intelligence, advanced data analysis techniques and expertise must be relied upon, which limits the practical application of honeypots.

[0006] Therefore, it is necessary to provide a threat detection method that can comprehensively protect the enterprise intranet. Summary of the invention

[0007] The purpose of the present invention is to provide a four-honeypot threat detection method for an enterprise intranet, so as to provide comprehensive protection for the enterprise intranet.

[0008] In the first aspect, the present invention provides a four-honey threat detection method for an enterprise intranet, including: constructing a honey court, a honey spot, a honey hole and a honey array in the enterprise intranet for threat detection; setting a traffic identification strategy in the honey court to monitor network traffic and identify black, white and gray traffic on the network traffic, forwarding the identified black traffic to a defense device, continuously observing the gray traffic for further identification, and allowing the white traffic to pass; deploying a tripwire in the honey spot to set a trap for the network traffic passing through the honey spot and obtain attack intelligence information in the network traffic; the honey hole is used to collect attacker information and perform source tracing and countermeasures based on the attacker information; the honey array is connected to the honey court, honey spot and honey hole in communication, the honey array obtains the security status of the enterprise intranet and the deployment information of the honey court, honey spot and honey hole and performs deployment scheduling based on the security status of the enterprise intranet.

[0009] The beneficial effect of the four-honey threat detection method for both inside and outside the enterprise provided by the present invention is that: based on the honey spot, honey court, honey array and honey hole technology, a complete four-honey system architecture is constructed, which has universality and credibility, fits the enterprise intranet environment, and has dynamic adaptability. It can effectively isolate the real system and prevent attacks from reaching the actual network, thereby forming a clearer local threat perception. For security threats, the solution can achieve global linkage disposal, fully share security intelligence and attack information, coordinate and adjust various deployment points, combine local perception with global mobilization, reproduce the complete attack chain, quickly trace the source and counter, and build a safe enterprise-level network environment.

[0010] In a possible embodiment, the honey array obtains the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and performs deployment scheduling according to the security status of the enterprise intranet, including: when the security status of the enterprise intranet is that the attack traffic breaks through the pre-deployed defense resources in the enterprise intranet, the honey array controls the generation and deployment of new honey spots or mobilizes the honey spot equipment to block the attack traffic.

[0011] In another possible embodiment, the honey array builds a Bayesian attack graph based on the security status of the enterprise intranet, device deployment, and deployment information of honey courts, honey spots, and honey holes; the honey array generates or mobilizes the deployment of honey spot devices based on the Bayesian attack graph.

[0012] In other possible embodiments, deploying tripwires in the honey spot includes: deploying network tripwires and system tripwires in the honey spot, wherein: the network tripwire includes at least one of a traffic tripwire, a service tripwire and a domain control tripwire; the system tripwire includes at least one of a file tripwire, an email tripwire, an account tripwire, a process tripwire, a command tripwire and a path tripwire.

[0013] The enterprise intranet includes a DMZ area, a network boundary area and an Intranet area. The honey courts and honey spots constructed in the enterprise intranet include a first honey court, a second honey court, a first honey spot and a second honey spot. The first honey court and the first honey spot are deployed in the DMZ area to monitor the network traffic entering the DMZ area. When the first honey court identifies black traffic in the network traffic, it forwards the black traffic to the first honey spot. The second honey court is deployed in the network boundary area to monitor the traffic entering the network boundary area. The second honey spot is deployed before the Intranet area to set traps for network traffic.

[0014] Network tripwires and system tripwires are deployed in the first sweet spot. The network tripwires include traffic tripwires and service tripwires. The system tripwires include file tripwires, email tripwires and account tripwires. Network tripwires and system tripwires are deployed in the second sweet spot. The network tripwires include domain control tripwires and traffic tripwires. The system tripwires include file tripwires, command tripwires, account tripwires, email tripwires, process tripwires and path tripwires.

[0015] In a second aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the above-mentioned four-honeypot threat detection method for an enterprise intranet is implemented.

[0016] In a third aspect, the present invention also provides an electronic device, comprising: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory, so that the electronic device executes the above-mentioned four-honey threat detection method for the enterprise intranet.

[0017] For the beneficial effects of the second to third aspects, reference may be made to the description of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of the deployment of a four-honeypot threat detection method for an enterprise intranet provided by an embodiment of the present invention;

[0019] Figure 2 A schematic diagram of the functional modules of the four honey components of the four honey threat detection method for the enterprise intranet provided by an embodiment of the present invention;

[0020] Figure 3 A schematic diagram of the deployment of four honey components in the DMZ area of ​​an enterprise intranet provided by an embodiment of the present invention;

[0021] Figure 4 A schematic diagram of the deployment of four honey components in the network boundary area of ​​an enterprise intranet provided by an embodiment of the present invention;

[0022] Figure 5 A schematic diagram of the deployment of the four honey components in the Intranet zone of an enterprise intranet provided by an embodiment of the present invention;

[0023] Figure 6 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be understood by people with general skills in the field to which the present invention belongs. "Including" and similar words used in this article mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects.

[0025] This embodiment provides a four-honey threat detection method for an enterprise intranet. In the present invention, the four honeys refer to a honey court, a honey spot, a honey hole, and a honey array.

[0026] See the instruction manual Figure 1, the method includes: constructing honey courts, honey spots, honey holes and honey arrays in the enterprise intranet for threat detection. Among them, a traffic identification strategy is set in the honey court to monitor network traffic and identify black, white and gray traffic on the network traffic, forward the identified black traffic to the defense device, continuously observe the gray traffic for further identification, and allow the white traffic to pass. A tripwire is deployed in the honey spot to set traps for network traffic passing through the honey spot and obtain attack intelligence information in the network traffic. The honey hole is used to collect attacker information and trace the source and countermeasure based on the attacker information. The honey array is connected to the honey court, honey spot and honey hole in communication. The honey array obtains the security status of the enterprise intranet and the deployment information of the honey court, honey spot and honey hole, and performs deployment and scheduling according to the security status of the enterprise intranet.

[0027] In a possible embodiment, the honey hole collects attacker information including: the honey hole actively collects attacker information that may exist in network traffic by setting honey hole files, web page honey holes, etc.; the honey court can obtain attacker information that may exist in network traffic when monitoring network traffic and the honey spot can obtain attacker information when setting traps for network traffic. Through the real-time sharing of security intelligence and attack information among the honey spot, honey court and honey hole constructed by the honey array, the honey hole can collect attacker information obtained by the honey court and the honey spot.

[0028] In a possible embodiment, the honey array obtains the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and performs deployment scheduling according to the security status of the enterprise intranet, including: when the security status of the enterprise intranet is that the attack traffic breaks through the pre-deployed defense resources in the enterprise intranet, the honey array controls the generation and deployment of new honey spots or mobilizes the honey spot equipment to block the attack traffic.

[0029] In a specific embodiment, the honey array builds a Bayesian attack graph based on the security status of the enterprise intranet, device deployment, and deployment information of honey courts, honey spots, and honey holes; the honey array generates or mobilizes the deployment of honey spot devices based on the Bayesian attack graph.

[0030] In the four-honey threat detection method for enterprise intranet of the present invention, based on the analysis of the structural characteristics of the enterprise intranet, the design is to deploy honey courts, honey spots, honey holes and honey arrays in the enterprise intranet, and the coordinated linkage of honey courts, honey spots, honey holes and honey arrays is designed to form a four-honey system, thereby forming a clear local perspective and a complete global perspective in the enterprise intranet, and building a complete and dynamic active defense system in the whole process of the attacker's attack behavior.

[0031] The four-honey system designed and constructed according to the method provided by the present invention can achieve the following coordinated cooperation: forming in-depth threat perception through honey spot technology, capturing global security threat data, the honey court is deployed before the honey spot device, and the attack behavior is detected and judged based on internal judgment rules, and the real network assets are safely isolated to form a clear local threat perception. The central honey array builds a global perspective, deploys and schedules the equipment of the whole network, shares attack data, and changes the deployment strategy according to the security situation, generates and changes the array diagram in real time, and uniformly manages resources. The honey hole forces network visitors to perform identity authentication, and constructs floating code, which is accurately delivered to the attacker's system to obtain its identity information, and realizes the sticky deterrence countermeasure function.

[0032] See the instruction manual Figure 2 In a possible embodiment, the deployment and coordinated linkage of the four honey systems in the enterprise intranet are specifically designed as follows: honey spots are deployed around the protected assets and work together with honey courts as the main force of intelligence collection. In order to improve the simulation of honey spots and dynamically fit the real intranet environment, the honey spot generator will adaptively generate different honey spot services according to the different network architectures and real service information of the intranet. Honey spots are deployed in batches by honey arrays based on the Bayesian attack graph and arranged on paths that normal users will not visit. Once a honey spot is visited, it can be confirmed with extremely high confidence that the user is a malicious attacker, thereby achieving in-depth threat perception.

[0033] Exemplarily, a tripwire is deployed in a honey spot to adaptively generate different honey spot services according to different network architectures and real service information of the intranet, so as to better be used to set traps for network traffic and obtain attack intelligence in network traffic. Deploying tripwires in a honey spot includes deploying network tripwires and system tripwires. Specifically, the deployed network tripwires and system tripwires can be determined based on the location of the honey spot deployment and the architecture and real service information of the enterprise intranet. For example, the deployed network tripwire can be at least one of a traffic tripwire, a service tripwire, and a domain control tripwire, and the system tripwire can be at least one of a file tripwire, an email tripwire, an account tripwire, a process tripwire, a command tripwire, and a path tripwire.

[0034] Before being deployed at a honey spot or protected asset, the Honey Court monitors and identifies network traffic, analyzes and processes "black, white, and gray" traffic based on built-in policies, directs "black" traffic to the honey spot, and continues to monitor "gray" traffic to further confirm whether it is a malicious attack. The Honey Court and the honey spot work together to achieve clear local threat perception and identification.

[0035] As the core brain and control center of the Four Honey System, the Honey Array realizes interconnection with Honey Points and Honey Courtyards, and optimizes and adjusts deployment strategies in real time according to changes in the security situation, so that attack data can be analyzed and responded to in a timely manner. By uniformly dispatching resources across the entire network, it further promotes the construction of a linkage disposal system.

[0036] Honeyhole is the main force of the traceability countermeasure function, and honey spots and honey courts assist in analysis. Honeyhole collects attacker identity information by forcing users to authenticate before entering the system, accurately delivering floating programs to attackers, restoring attack links, and drawing attacker portraits, thus achieving continuous sticky remote control and traceability countermeasures.

[0037] In a possible embodiment, the enterprise intranet includes a DMZ zone, a network boundary zone and an Intranet zone. The honey courts and honey spots constructed in the enterprise intranet include a first honey court, a second honey court, a first honey spot and a second honey spot; the first honey court and the first honey spot are deployed in the DMZ zone to monitor the network traffic entering the DMZ zone. When the first honey court identifies black traffic in the network traffic, the black traffic is forwarded to the first honey spot; the second honey court is deployed in the network boundary zone to monitor the traffic entering the network boundary zone; the second honey spot is deployed in front of the Intranet zone to set traps for network traffic.

[0038] In a possible embodiment, a network tripwire and a system tripwire are deployed in the first sweet spot, the network tripwire includes a traffic tripwire and a service tripwire, and the system tripwire includes a file tripwire, an email tripwire, and an account tripwire; a network tripwire and a system tripwire are deployed in the second sweet spot, the network tripwire includes a domain control tripwire and a traffic tripwire, and the system tripwire includes a file tripwire, a command tripwire, an account tripwire, an email tripwire, a process tripwire, and a path tripwire.

[0039] See also Figures 3 to 5 , provides a collaborative linkage strategy of the four-honey system designed based on the four-honey threat detection method for the enterprise intranet of the present invention, and an example of deploying the four-honey components in various areas in the enterprise intranet according to the characteristics of the enterprise intranet.

[0040] Specifically, the enterprise intranet includes a DMZ area, a network boundary area and an Intranet area. Honey courts, honey spots and honey holes are deployed according to the characteristics of each area in the enterprise intranet. The collaborative linkage strategy designed according to the four-honey threat detection method for the enterprise intranet of the present invention is interconnected with honey courts, honey spots and honey holes through honey arrays.

[0041] The DMZ area is located between the intranet and the extranet, and is usually used to deploy servers that provide public external services, such as Web servers, mail servers, and DNS servers. The DMZ area is isolated from the internal network through a firewall. External users can access services in the DMZ, but cannot directly access the intranet. Servers in the DMZ usually only provide limited services, such as web browsing and email sending and receiving, to ensure that intranet resources are not easily exposed to the outside world. By establishing a DMZ area as a "buffer" between the internal and external networks, external access requests can be more effectively controlled and monitored.

[0042] See the instruction manual Figure 3 , based on the characteristics of the DMZ area, honey spots and honey courts are deployed in the DMZ area for protection. The honey court is deployed before the honey spot or the protected system to simulate the explicit service agent of the real system. The honey court set up in the DMZ area is used to monitor the network traffic entering the DMZ area. The traffic identification strategy is set in the honey court to identify the black, white and gray traffic of the monitored network traffic. When the honey court determines that a certain traffic is black traffic, the honey court will guide the black traffic to the honey spot deployed in the DMZ area, and the honey spot can block the black traffic; when the honey court determines that a certain traffic is gray traffic, the honey court will continue to observe the gray traffic to further distinguish the traffic; when the honey court determines that a certain traffic is white traffic, the white traffic will pass normally. Exemplarily, the honey court's identification strategy for black, white and gray traffic can be: when attack traffic that is determined to be an attack behavior is detected in the network traffic, it is determined to be black traffic; when it is determined that there is no attack behavior in the network traffic, it is determined to be white traffic; when there is information that cannot be clearly defined in the network traffic, it is determined to be gray traffic.

[0043] Honey spots are protected by tripwire technology, that is, tripwires are deployed in honey spots to block network traffic entering the honey spots, thereby completing the trap detection of network traffic and obtaining attack intelligence information in network traffic, such as attacker information. The tripwires deployed in honey spots include network tripwires and system tripwires.

[0044] In this embodiment, according to the characteristics of the DMZ area and the services provided, the network tripwires deployed in the honeyspots of the DMZ area include traffic tripwires and service tripwires, and the system tripwires include file tripwires, email tripwires, and account tripwires. Specifically, in the DMZ area, the traffic tripwire generates a large amount of simulated vulnerability feature business traffic with the help of a large model according to specific business scenarios, simulates vulnerability interaction scenarios, attracts and captures attackers, and especially achieves a strong trapping effect through simulated traffic when the attacker collects information, achieving the purpose of multi-dimensional inducement. The service tripwire actively scans attacks at different levels in the network and implements two-way blocking: first, based on the host information in the defender's intranet environment, a large number of simulated honeyspot services are intelligently generated to perceive attacks in advance; second, based on the POC of the attacker's vulnerability exploitation, a deceptive vulnerability response message is intelligently generated to create the illusion of "successful attack" and further improve the defense effect. The file tripwire uses a large language model to build high-value business files, perceive file theft behavior, and collect information when the attacker attempts to steal files through a preset script. The email tripwire provides protection based on the principle of social engineering, while the account tripwire uses statistical models to build specific accounts to prevent attackers from stealing data or logging into accounts, and monitor their transfer activities in real time. Since APT attacks often use social engineering methods such as phishing emails to break through network defenses, when attackers send phishing emails, the email tripwire will work together with the account tripwire to detect phishing behavior.

[0045] By deploying Honey Court and Honey Point in the DMZ area, and the designed coordination between Honey Court and Honey Point, once an attack occurs in this area, Honey Court can isolate the real system in time, eliminate malicious loads, and monitor traffic according to internal security rules, and cooperate with Honey Point to protect the security of the DMZ area. If malicious traffic is identified, Honey Court will guide it to the Honey Point. Honey Court's front-end traffic monitoring and discrimination capabilities, in conjunction with Honey Point, greatly improve the efficiency of security threat perception and network defense.

[0046] The connection area between the intranet and the extranet is usually called the boundary area or network boundary area, which is responsible for controlling the ingress and egress of network traffic and protecting the security of the intranet. In order to ensure the safe isolation and communication between the intranet and the extranet, this area usually deploys network devices such as routers, switches, and firewalls as pre-deployed defense resources. Firewalls are used to filter and control the traffic in and out of the intranet to prevent unauthorized access; routers are responsible for packet forwarding and routing between the intranet and the extranet; switches connect firewalls, routers, and internal network devices to ensure the efficiency and security of data transmission.

[0047] See the instruction manual Figure 4 Based on the characteristics of the network boundary area, the Honey Courtyard is deployed in the network boundary area for protection. The Honey Courtyard is deployed before the pre-set defense resources (i.e., firewalls, routers, switches and other network devices). The network traffic entering the network boundary area is monitored and identified through the Honey Courtyard to observe the attacker (hacker). In this embodiment, the monitoring of the Honey Courtyard includes monitoring the flow of network browsing between various devices (firewalls, routers, switches and other devices in the network boundary area) to avoid missing attack traffic. The traffic identification strategy is set in the Honey Courtyard to identify the black, white and gray traffic of the monitored network traffic, and the determined black, white and gray traffic is processed separately.

[0048] It should be noted that, since the network boundary area is also provided with pre-deployed defense resources, the specific operation of forwarding black traffic to the defense device is different from the specific operation performed by the honey court in the DMZ area. In the network boundary area, after identifying the black traffic, the honey array dynamically mobilizes the defense resources in real time for defense, and guides the black traffic to the honey spot when necessary, thereby effectively improving the security protection capability of the network boundary area. In a specific embodiment, after the honey court deployed in the network boundary area identifies the black traffic (including the attack traffic with attack behavior), the black traffic is forwarded to the firewall, and the defense is carried out by mobilizing the pre-deployed defense resources (such as the firewall). The honey array can monitor the defense situation in real time, and when the attack traffic breaks through the pre-deployed defense resources, the black traffic is forwarded to the honey spot. After the honey array obtains the result that the honey spot needs to be deployed through real-time analysis, the honey spot can be a new honey spot that controls the generation and deployment of the attack traffic, or it can be a honey spot deployed at other locations in the enterprise intranet (for example, a honey spot deployed in the DMZ area) to block the attack traffic.

[0049] The Intranet zone (internal network zone) is a dedicated network environment within an enterprise or organization, mainly used to connect computers, servers and other devices within the company to support the sharing and collaboration of information and resources. Unlike the DMZ zone and the public network zone, the Intranet zone is usually invisible to external users and is subject to strict access control and security protection. It mainly provides functions such as file sharing, internal communication and business applications, and integrates tools such as internal mail systems, instant messaging, video conferencing, etc. to promote communication and collaboration among employees. The Intranet zone usually runs the company's key business systems, such as ERP, CRM, financial systems and OA systems, to support daily business operations. The Intranet zone protects the company's internal data through measures such as firewalls, data encryption and access control to prevent unauthorized external access and network attacks. The Intranet zone consists of multiple sub-areas or functional modules, including the user zone, server zone, management zone, development zone and data center zone, each of which is divided and protected according to function and security level. The user zone connects employee computing devices, the server zone contains various servers, the management zone is used for network and equipment management, the development zone isolates software development and testing activities, and the data center zone is responsible for storing and backing up important data. The Intranet area ensures the safe and stable operation of the enterprise's internal network through characteristics such as closedness and isolation, centralized management and resource sharing, flexibility and scalability, allowing employees to complete their work tasks efficiently and safely.

[0050] See the instruction manual Figure 5, based on the characteristics of the Intranet zone, honey spots and honey holes are deployed for protection, and multiple honey spots are coordinated for defense to assist in honey hole analysis. Among them, the honey spot is deployed in front of the Intranet zone to set up traps before the network traffic enters the Intranet zone, so as to better prevent the attack traffic from entering the Intranet zone; the honey hole forces the user to authenticate before entering the Intranet zone, and accurately delivers floating programs to the attacker to collect the attacker's identity information. Based on the collected attacker's identity information, the attack link is restored and the attacker's portrait is drawn to achieve continuous sticky remote control and tracing countermeasures.

[0051] In this embodiment, according to the characteristics of the Intranet zone and the services provided, the network tripwires deployed in the honey spot of the Intranet zone include domain control tripwires and traffic tripwires, and the system tripwires include file tripwires, command tripwires, account tripwires, email tripwires, process tripwires and path tripwires. Specifically, in the Intranet zone, the traffic tripwire is used to enhance the deception effect, and the domain control tripwire lures, identifies and blocks the lateral movement based on the user name in the domain control. By summarizing the common attack methods based on the user name in the domain penetration, the domain control honey spot and the simulated honey spot are quickly deployed using virtualization technology to deceive the vulnerability, and based on the real user name data set, the honey user name is simulated by high-order Markov deconstruction and generation. At the same time, based on the Web service in the intranet environment, the simulated honey spot service with vulnerabilities is adaptively generated, which makes the existence of the domain control tripwire (fake domain controller) more reasonable, and enriches the types of service tripwires, thereby realizing service simulation.

[0052] Command tripwires and path tripwires are implemented based on dynamic scripts. By dynamically embedding executable JS script files in the Web system, attacker probing behavior is detected, and traceable file tripwires are deployed in business systems to trace the source of the attack. Command tripwires simulate sensitive operations on the user's host, and use path and account tripwires to collaboratively detect the transfer of attack behavior and monitor unauthorized sensitive paths, accounts, and file access behaviors. Process tripwires are generated based on in-depth analysis and matching of ransomware attack features. By monitoring the survival status of fake processes, the ransomware activity path can be traced and located in a timely manner, achieving more accurate threat response and disposal.

[0053] Honeyhole technology includes three types: file honeyhole, web honeyhole, and counter honeyhole. File honeyhole deploys specific honeyhole files for different business scenarios to lure attackers to trigger, and connects back to attackers in various ways to collect information. It also uses a disguised server deployed in the public network to receive encrypted attacker information and then transmits it back to the internal database. Web honeyhole deploys floating code and browser plug-ins in dynamic pages to collect attackers' sensitive information, mark it, and send deterrent information through correlation analysis, requiring the input of mobile phone verification code and ID card information for double verification. Counter honeyhole uses honeyhole websites that can upload remote control Trojan files to attract attackers to connect. When the attacker uses the remote control tool to connect, the deployed counter code is used to obtain the tool version, and MSF is used to generate a targeted node.js file, and the encrypted rebound shell replaces the attacker's original webshell code, and finally the attacker's host is counter-controlled when the attacker reconnects to the honeyhole website.

[0054] In this embodiment, the honey array is configured as the operation center of the four honey system, which can automatically and intelligently change and control the deployment strategy, configuration and location of other components of the four honeys. The deployment strategy based on the detection and perception of the honey array can globally dispatch network resources and flexibly adjust the deployment location of the four honey components in the intranet. According to network requirements, the honey array controls the batch generation of specific and deployed honey point devices, integrates various internal defense points, gives full play to the defense advantages of each device, and builds a complete global perspective through real-time sharing of security intelligence and attack information, so that administrators can overlook the network security situation from a macro level and accurately grasp the attack trend. Based on these insights, the honey array can dynamically adjust security strategies and deployment plans, optimize resource allocation, promote the coordinated linkage of resources across the entire network, realize efficient interconnection between the four honey components, and comprehensively protect the security of the intranet.

[0055] In a possible embodiment, according to network requirements, the honey array controls batch adaptive generation and deployment of specific honey spot devices based on a Bayesian attack graph (the Bayesian attack graph includes possible attack paths and attack success probabilities corresponding to the paths).

[0056] The four-honey threat detection method for both inside and outside the enterprise proposed in the present invention is based on the honey spot, honey courtyard, honey array and honey hole technology, and constructs a complete four-honey system architecture. Compared with the existing technology, this system has higher universality and credibility, is more suitable for the enterprise intranet environment, and has dynamic adaptability. It can effectively isolate the real system and prevent attacks from reaching the actual network, thereby forming a clearer local threat perception. For security threats, this solution can realize global linkage disposal, comprehensively share security intelligence and attack information, coordinate and adjust various deployment points, combine local perception with global mobilization, reproduce the complete attack chain, quickly trace the source and counter, and build a safer enterprise-level network environment.

[0057] The method of the present invention is used to construct a four-honey system for threat detection. It can generate the optimal honey point deployment strategy based on the Bayesian attack graph and available defense resources. According to the characteristics of different regions of the enterprise intranet, specific honey points are generated, and these honey points are deployed on the paths that are most vulnerable to attack in a targeted manner. The deployment strategy is adjusted dynamically in real time. Compared with the honeypot system, the defense is more targeted and flexible, and network resources can be fully utilized to increase the attack interception rate. The whole domain uses honey points and honey courts as the main force for threat intelligence collection. By deploying honey points around key assets in the intranet, attackers are actively deceived and trapped, and attack behaviors are quickly and comprehensively perceived in multiple levels, attack data and traffic are captured, and automatic log analysis is performed on honey point stepping honey alarms, further forming a deeper threat perception collection range with a wider range, more complete and more accurate information.

[0058] The enterprise intranet uses Honey Array as the main force for intelligence analysis, while Honey Point, Honey Courtyard and Honey Hole assist in analysis. Honey Courtyard builds a service proxy with the same appearance, safely isolates the real system, observes and identifies attack data traffic in secret, analyzes the attacker's access trajectory, and discovers hidden attacks. Honey Array coordinates Honey Point, Honey Courtyard and traditional security protection equipment, unifies scheduling and adjusts security equipment in the intranet in real time, so that each device can share security intelligence and attack information in real time, build a global perspective, and grasp the attack situation of the entire intranet.

[0059] Honeyhole is the main force, while honeyspot and honey court assist in analysis. They can quickly trace and counter attackers, restore the attacker's attack chain, draw a portrait of the attacker, and accurately deliver floating programs to the attacker. During the entire process of the attacker's attack, they can achieve "deterrence before the attack, follow-up during the attack, and portrait after the attack", effectively and quickly identifying and tracing the attacker.

[0060] In other embodiments of the present application, the present application discloses an electronic device, such as Figure 6 As shown, the electronic device 600 may include: one or more processors 601; a memory 602; a display 603; one or more applications (not shown); and one or more computer programs 604. The above components may be connected via one or more communication buses 605. The one or more computer programs 604 are stored in the above memory and configured to be executed by the one or more processors 601. The one or more computer programs 604 include instructions, which may be used to execute the following: Figure 1 And each step in the corresponding embodiment.

[0061] Through the description of the above implementation methods, technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0062] Each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units.

[0063] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, disk or optical disk.

[0064] The above is only a specific implementation of the embodiment of the present application, but the protection scope of the embodiment of the present application is not limited thereto, and any changes or replacements within the technical scope disclosed in the embodiment of the present application should be included in the protection scope of the embodiment of the present application. Therefore, the protection scope of the embodiment of the present application should be based on the protection scope of the claims.

Claims

1. A method for detecting four types of threats in an enterprise intranet, characterized in that: Construct honey courts, honey spots, honey holes and honey arrays in the enterprise intranet for threat detection; The honey court is provided with a flow identification strategy for monitoring network flow and identifying black, white and gray flow of the network flow, forwarding the identified black flow to the defense device, continuously observing the gray flow for further identification, and allowing the white flow to pass; Tripwires are deployed in the honey spot to trap and detect network traffic passing through the honey spot and obtain attack intelligence information in the network traffic; The honey hole is used to collect attacker information and perform source tracing and countermeasures based on the attacker information; The honey array is in communication connection with the honey courtyard, honey spot and honey hole. The honey array obtains the security status of the enterprise intranet and the deployment information of the honey courtyard, honey spot and honey hole and performs deployment scheduling according to the security status of the enterprise intranet.

2. The method according to claim 1, characterized in that The honey array obtains the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and performs deployment scheduling according to the security status of the enterprise intranet, including: When the security status of the enterprise intranet is that the attack traffic breaks through the pre-deployed defense resources in the enterprise intranet, the honey array controls the generation and deployment of new honey spots or mobilizes honey spot devices to block the attack traffic.

3. The method according to claim 1, characterized in that The honey array constructs a Bayesian attack graph according to the security status of the enterprise intranet, the equipment deployment status, and the deployment information of honey courts, honey spots, and honey holes; The honey array generates or mobilizes the deployment of honey spot devices according to the Bayesian attack graph.

4. The method according to claim 1, characterized in that: Deploying a tripwire within the honeyspot, including: A network tripwire and a system tripwire are deployed within the honey spot, wherein: The network tripwire includes at least one of a traffic tripwire, a service tripwire and a domain control tripwire; The system tripwire includes at least one of a file tripwire, a mail tripwire, an account tripwire, a process tripwire, a command tripwire and a path tripwire.

5. The method according to claim 1, characterized in that The enterprise intranet includes a DMZ zone, a network boundary zone and an Intranet zone, and the honey courts and honey spots constructed in the enterprise intranet include a first honey court, a second honey court, a first honey spot and a second honey spot; The first honey court and the first honey spot are deployed in the DMZ area, and are used to monitor the network traffic entering the DMZ area. When the first honey court identifies black traffic in the network traffic, the black traffic is forwarded to the first honey spot; The second honeypot is deployed in the network boundary area and is used to monitor the traffic entering the network boundary area; The second sweet spot is deployed before the Intranet zone and is used to perform trap detection on network traffic.

6. The method according to claim 5, characterized in that A network tripwire and a system tripwire are deployed in the first honey spot, wherein the network tripwire includes a traffic tripwire and a service tripwire, and the system tripwire includes a file tripwire, an email tripwire and an account tripwire; A network tripwire and a system tripwire are deployed in the second honey spot. The network tripwire includes a domain control tripwire and a traffic tripwire. The system tripwire includes a file tripwire, a command tripwire, an account tripwire, an email tripwire, a process tripwire and a path tripwire.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the four-honeypot threat detection method for an enterprise intranet described in any one of claims 1 to 6 is implemented.

8. An electronic device, characterized in that: include: Processor and memory; The memory is used to store computer programs; The processor is used to execute the computer program stored in the memory so that the electronic device executes the four-honeypot threat detection method for an enterprise intranet as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Four-honey-based integrated network attack detection method

    CN115549943A

  • High-interaction honeypot system based on attack graph

    CN118200033A

  • Control and defense graph construction method for four-honey dynamic defense system

    CN118233223A

Cited By

  • Public network-oriented global threat perception method and system

    CN120834966A

  • Threat hunting method and device based on linkage of honey court and honey hole

    CN121283783A

  • A threat hunting method and device based on honeycomb and honeycomb linkage

    CN121283783B

  • Active defense method based on software defined deception defense balance information entropy

    CN121309235A