An enterprise intranet-oriented four-missile threat detection method

By constructing the four-honey threat detection method of honey court, honey spot, honey hole and honey array, the shortcomings of honeypot technology in enterprise intranet defense are solved, dynamic defense and global linkage are achieved, and the defense capability and threat perception capability of intranet security are improved.

CN119996015BActive Publication Date: 2025-10-21GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510207403.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-10-21
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

Existing technologies lack a linkage disposal system based on deception defense in enterprise intranet defense. Honeypot technology has insufficient deception and monitoring capabilities and cannot dynamically adapt to attack behaviors. Honeypot design cannot provide all-round defense and is easily circumvented. Data analysis relies on advanced technology and its application is limited.

Method used

Construct a four-honey threat detection method, including honey court, honey spot, honey hole and honey array. Through traffic identification, trip wire and tracing countermeasures, form a dynamic defense system, realize global linkage disposal and clear local perception, and use honey array for real-time strategy adjustment and resource scheduling.

Benefits of technology

It realizes global linkage disposal, has strong dynamic adaptability, can isolate real systems, quickly trace the source and countermeasures, build clear local threat perception and global perspective, and enhance the security defense capabilities of the intranet.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996015B_ABST
    Figure CN119996015B_ABST
Patent Text Reader

Abstract

The application provides a four-honey enterprise intranet-oriented threat exploration method, which comprises the following steps: constructing a honey courtyard, a honey point, a honey hole and a honey array in an enterprise intranet; the honey courtyard is used for monitoring network traffic and identifying black, white and gray traffic; the honey point is used for trap detection on network traffic passing through the honey point; the honey hole is used for collecting attacker information and counteracting according to the attacker information; the honey array is in communication connection with the honey courtyard, the honey point and the honey hole, acquires the security status of the enterprise intranet and the deployment information of the honey courtyard, the honey point and the honey hole, and performs deployment scheduling according to the security status of the enterprise intranet. The four-honey system constructed by the method is suitable for the enterprise intranet environment and has dynamic adaptability. The system can effectively isolate the real system and prevent attacks from reaching the actual network. The system can realize global linkage disposal, comprehensively share security intelligence and attack information, coordinate and adjust each deployment point, quickly trace and counteract, and build a safe enterprise-level network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a four-honeypot threat detection method for an enterprise intranet. Background Art

[0002] Internal enterprise networks contain numerous high-value information assets. Attackers often target internal networks, using various attack methods to infiltrate and obtain critical enterprise asset information. Consequently, the security of enterprise internal networks has received significant attention in recent years. Currently, there are two primary approaches to defending internal networks: one is traditional network perimeter-based defenses, which deploy security devices such as firewalls, WAFs, and IPS at the interface between internal and external networks; the other is the adoption of a zero-trust mechanism. The core concept of the zero-trust mechanism is to distrust any user, device, service, or application, whether internal or external. These users must undergo identity and access management to obtain a minimum level of trust and access rights. This is primarily intended to prevent attackers from launching attacks within the internal network through various means.

[0003] However, these defensive measures are currently facing new technical challenges. With the continuous advancement of technology and the expansion of network scale, cyberattacks targeting intranet security are becoming increasingly targeted and organized, and attackers' attack techniques and methods are becoming increasingly complex and diverse. For example, zero-day vulnerability exploits and APT attacks are becoming increasingly complex and diverse. Traditional defense technologies are almost unable to withstand these attacks, making internal defenses easily breached by attackers. In addition, the boundaries of corporate intranets are often fuzzy and unclear, making it difficult to define defense boundaries and choosing the most appropriate location for deploying security equipment.

[0004] Currently, intranet security defense primarily lacks a coordinated response system based on deception defense. While existing active deception defenses have already established a defense system based on honeypot technology, the advancement of this system has encountered several insurmountable challenges: honeypot systems are insufficient in their deception and detection capabilities for APTs and unknown threats, and lack the high degree of customizability, comprehensive concealment, and adaptability to dynamic environments—all essential features for intranet security defense. Furthermore, honeypot technology faces an irreconcilable conflict between simulation and controllability, making it difficult to achieve a compromise. Consequently, honeypot technology can only provide auxiliary support for network security to a certain extent, but cannot independently undertake comprehensive protection tasks.

[0005] Furthermore, current honeypot technology often lacks dynamic interaction with attackers, preventing them from adjusting their strategies and environment in real time based on their attack behavior. Furthermore, honeypots cover a narrow range of attacks, making them easily evaded or bypassed. Honeypots are designed to attract attackers, not prevent them from invading real systems. While honeypot systems can capture vast amounts of network traffic, attack logs, and other relevant data, transforming this massive amount of data into useful threat intelligence requires advanced data analysis techniques and expertise, limiting their practical application.

[0006] Therefore, it is necessary to provide a threat detection method that can comprehensively protect the enterprise intranet. Summary of the Invention

[0007] The purpose of the present invention is to provide a method for detecting four types of threats in an enterprise intranet, so as to provide comprehensive protection for the enterprise intranet.

[0008] In the first aspect, the present invention provides a four-honey threat detection method for enterprise intranet, including: constructing honey courts, honey spots, honey holes and honey arrays in the enterprise intranet for threat detection; setting up traffic identification strategies in the honey courts to monitor network traffic and identify black, white and gray traffic, forwarding the identified black traffic to defense equipment, continuously observing the gray traffic for further identification, and allowing the white traffic to pass; deploying trip wires in the honey spots to trap and detect network traffic passing through the honey spots, and obtain attack intelligence information in the network traffic; honey holes are used to collect attacker information and perform source tracing and countermeasures based on the attacker information; honey arrays are communicated with honey courts, honey spots and honey holes, and the honey arrays obtain the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and perform deployment scheduling based on the security status of the enterprise intranet.

[0009] The beneficial effect of the four-honey threat detection method for both inside and outside the enterprise provided by the present invention is that: based on the honey point, honey court, honey array and honey hole technologies, a complete four-honey system architecture is constructed, which has universality and credibility, fits the enterprise intranet environment, and has dynamic adaptability. It can effectively isolate the real system and prevent attacks from reaching the actual network, thereby forming a clearer local threat perception. For security threats, the solution can achieve global linkage disposal, fully share security intelligence and attack information, coordinate and adjust various deployment points, combine local perception with global mobilization, reproduce the complete attack chain, quickly trace the source and countermeasure, and build a secure enterprise-level network environment.

[0010] In one possible embodiment, the honey array obtains the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and performs deployment scheduling according to the security status of the enterprise intranet, including: when the security status of the enterprise intranet is that the attack traffic breaks through the pre-deployed defense resources in the enterprise intranet, the honey array controls the generation and deployment of new honey spots or mobilizes honey spot devices to block the attack traffic.

[0011] In another possible embodiment, the honey array builds a Bayesian attack graph based on the security status of the enterprise intranet, device deployment, and deployment information of honey courts, honey spots, and honey holes; the honey array generates or mobilizes the deployment of honey spot devices based on the Bayesian attack graph.

[0012] In other possible embodiments, deploying tripwires in the honey spot includes: deploying network tripwires and system tripwires in the honey spot, wherein: the network tripwire includes at least one of a traffic tripwire, a service tripwire, and a domain control tripwire; the system tripwire includes at least one of a file tripwire, an email tripwire, an account tripwire, a process tripwire, a command tripwire, and a path tripwire.

[0013] The enterprise intranet includes a DMZ area, a network boundary area and an Intranet area. The honey courts and honey spots constructed in the enterprise intranet include a first honey court, a second honey court, a first honey spot and a second honey spot. The first honey court and the first honey spot are deployed in the DMZ area to monitor the network traffic entering the DMZ area. When the first honey court identifies black traffic in the network traffic, it forwards the black traffic to the first honey spot. The second honey court is deployed in the network boundary area to monitor the traffic entering the network boundary area. The second honey spot is deployed before the Intranet area to set traps for network traffic.

[0014] Network tripwires and system tripwires are deployed in the first sweet spot. Network tripwires include traffic tripwires and service tripwires, and system tripwires include file tripwires, email tripwires, and account tripwires. Network tripwires and system tripwires are deployed in the second sweet spot. Network tripwires include domain control tripwires and traffic tripwires, and system tripwires include file tripwires, command tripwires, account tripwires, email tripwires, process tripwires, and path tripwires.

[0015] In a second aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the above-mentioned four-honeypot threat detection method for an enterprise intranet is implemented.

[0016] In a third aspect, the present invention also provides an electronic device comprising: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory, so that the electronic device executes the above-mentioned four-honey threat detection method for the enterprise intranet.

[0017] For the beneficial effects of the second to third aspects, please refer to the description of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of a deployment of a four-honeypot threat detection method for an enterprise intranet provided by an embodiment of the present invention;

[0019] Figure 2 A schematic diagram of the functional modules of the four honey components of the enterprise intranet-oriented four honey threat detection method provided by an embodiment of the present invention;

[0020] Figure 3 A schematic diagram of the deployment of four honey components in the DMZ area of ​​an enterprise intranet provided by an embodiment of the present invention;

[0021] Figure 4 A schematic diagram of the deployment of four honey components in the network boundary area of ​​an enterprise intranet provided by an embodiment of the present invention;

[0022] Figure 5 A schematic diagram of the deployment of the four honey components in the intranet zone of an enterprise intranet provided by an embodiment of the present invention;

[0023] Figure 6 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the present invention belongs. The words "including" and similar words used in this article mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects.

[0025] This embodiment provides a method for detecting threats based on the four honeys in an enterprise intranet. In the present invention, the four honeys refer to honey courts, honey spots, honey holes, and honey arrays.

[0026] See the instructions attached Figure 1The method includes: constructing honey courts, honey spots, honey holes, and honey arrays in the enterprise intranet for threat detection. Among them, a traffic identification strategy is set in the honey court to monitor network traffic and identify black, white, and gray traffic in network traffic, forward the identified black traffic to the defense device, continuously observe the gray traffic for further identification, and allow the white traffic to pass. A tripwire is deployed in the honey spot to set traps and detect network traffic passing through the honey spot to obtain attack intelligence information in the network traffic. The honey hole is used to collect attacker information and conduct source tracing and countermeasures based on the attacker information. The honey array is connected to the honey court, honey spot, and honey hole in communication. The honey array obtains the security status of the enterprise intranet and the deployment information of the honey court, honey spot, and honey hole, and performs deployment and scheduling based on the security status of the enterprise intranet.

[0027] In a possible embodiment, the honey hole collects attacker information including: the honey hole actively collects attacker information that may exist in network traffic by setting honey hole files, web page honey holes, etc.; the honey court can obtain attacker information that may exist in network traffic when monitoring network traffic and the honey spot sets traps for network traffic, and the honey hole can collect attacker information obtained by the honey court and the honey spot through the real-time sharing of security intelligence and attack information among the honey spot, honey court and honey hole constructed by the honey array.

[0028] In a possible embodiment, the honey array obtains the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and performs deployment scheduling according to the security status of the enterprise intranet, including: when the security status of the enterprise intranet is that the attack traffic breaks through the pre-deployed defense resources in the enterprise intranet, the honey array controls the generation and deployment of new honey spots or mobilizes honey spot devices to block the attack traffic.

[0029] In a specific embodiment, the honey array builds a Bayesian attack graph based on the security status of the enterprise intranet, device deployment, and deployment information of honey courts, honey spots, and honey holes; the honey array generates or mobilizes the deployment of honey spot devices based on the Bayesian attack graph.

[0030] In the four-honey threat detection method for enterprise intranet of the present invention, based on the analysis of the structural characteristics of the enterprise intranet, it is designed to deploy honey courts, honey spots, honey holes and honey arrays in the enterprise intranet, and to design the coordinated linkage of honey courts, honey spots, honey holes and honey arrays to form a four-honey system, thereby forming a clear local perspective and a complete global perspective in the enterprise intranet, and building a complete and dynamic active defense system in the whole process of the attacker's attack behavior.

[0031] The four-honey system designed and constructed according to the method provided by the present invention can achieve the following collaborative cooperation: forming in-depth threat perception through honey spot technology, capturing global security threat data, the honey court is deployed before the honey spot device, detecting and judging attack behaviors based on internal judgment rules, safely isolating real network assets, and forming clear local threat perception, the central honey array builds a global perspective, deploys and schedules equipment across the entire network, shares attack data, and changes deployment strategies according to security conditions, generates and changes array diagrams in real time, and uniformly manages resources, the honey hole forces network visitors to perform identity authentication, and constructs floating code, accurately delivers it to the attacker's system, obtains its identity information, and realizes sticky deterrence and countermeasure functions.

[0032] See the instructions attached Figure 2 In one possible embodiment, the deployment and coordinated linkage of the Four Honey systems within an enterprise intranet are specifically designed as follows: Honey spots are deployed around protected assets and work in conjunction with Honey Courts as the primary intelligence gathering force. To enhance honey spot simulation and dynamically adapt to real intranet environments, a honey spot generator adaptively generates different honey spot services based on the intranet's diverse network architecture and real-world service information. Honey spots are deployed in batches based on a Bayesian attack graph, placed on paths not normally accessed by legitimate users. Once a honey spot is accessed, the user can be confidently identified as a malicious attacker, achieving in-depth threat awareness.

[0033] Exemplarily, tripwires are deployed in the honeyspot to adaptively generate different honeyspot services based on the different network architectures and real service information of the intranet, thereby better being used to trap and detect network traffic and obtain attack intelligence from network traffic. Deploying tripwires in the honeyspot includes deploying network tripwires and system tripwires. Specifically, the deployed network tripwires and system tripwires can be determined based on the location of the honeyspot deployment and the architecture and real service information of the enterprise intranet. For example, the deployed network tripwire can be at least one of a traffic tripwire, a service tripwire, and a domain control tripwire, and the system tripwire can be at least one of a file tripwire, an email tripwire, an account tripwire, a process tripwire, a command tripwire, and a path tripwire.

[0034] Before being deployed at a honeypot or protected asset, the MiTing system monitors and identifies network traffic, analyzing and processing black, white, and gray traffic based on built-in policies. It directs black traffic to the honeypot while continuing to monitor gray traffic to further confirm whether it represents malicious attacks. The MiTing system collaborates with the honeypot to achieve clear local threat awareness and identification.

[0035] As the core brain and control center of the four-honey system, the honey array realizes interconnection with honey points and honey courts, and optimizes and adjusts deployment strategies in real time according to changes in the security situation, so that attack data can be analyzed and responded to in a timely manner. By uniformly dispatching resources across the entire network, it further promotes the construction of a coordinated disposal system.

[0036] Honeyholes are the core of the source tracing and countermeasures capabilities, with honeypoints and honey courts assisting in analysis. Honeyholes enforce user authentication before accessing the system and precisely deliver floating programs to attackers to collect their identity information. This allows for attack chain reconstruction and attacker profiling, enabling continuous tracking, remote control, and source tracing and countermeasures.

[0037] In a possible embodiment, the enterprise intranet includes a DMZ area, a network boundary area and an Intranet area. The honey courts and honey spots constructed in the enterprise intranet include a first honey court, a second honey court, a first honey spot and a second honey spot; the first honey court and the first honey spot are deployed in the DMZ area to monitor the network traffic entering the DMZ area. When the first honey court identifies black traffic in the network traffic, it forwards the black traffic to the first honey spot; the second honey court is deployed in the network boundary area to monitor the traffic entering the network boundary area; the second honey spot is deployed in front of the Intranet area to set traps for network traffic.

[0038] In a possible embodiment, network tripwires and system tripwires are deployed in the first sweet spot, the network tripwires include traffic tripwires and service tripwires, and the system tripwires include file tripwires, email tripwires, and account tripwires; network tripwires and system tripwires are deployed in the second sweet spot, the network tripwires include domain control tripwires and traffic tripwires, and the system tripwires include file tripwires, command tripwires, account tripwires, email tripwires, process tripwires, and path tripwires.

[0039] See also Figures 3 to 5 , provides a collaborative linkage strategy of the four-honey system designed based on the four-honey threat detection method for the enterprise intranet of the present invention, and an example of deploying the four-honey components in various areas of the enterprise intranet according to the characteristics of the enterprise intranet.

[0040] Specifically, the enterprise intranet includes the DMZ area, the network boundary area and the Intranet area. Honey courts, honey spots and honey holes are deployed according to the characteristics of each area in the enterprise intranet. The collaborative linkage strategy designed according to the four-honey threat detection method for the enterprise intranet of the present invention is interconnected with the honey courts, honey spots and honey holes through the honey array.

[0041] The DMZ, located between the intranet and the extranet, is typically used to host servers that expose external services, such as web servers, mail servers, and DNS servers. A firewall isolates the DMZ from the internal network. External users can access services within the DMZ but cannot directly access the internal network. Servers in the DMZ typically only provide limited services, such as web browsing and email, to prevent external access to internal resources. By creating a "buffer" between the internal and external networks, the DMZ allows for more effective control and monitoring of external access requests.

[0042] See the instructions attached Figure 3 Based on the characteristics of the DMZ area, honey spots and honey courts are deployed in the DMZ area for protection. The honey court is deployed before the honey spot or the protected system to simulate the explicit service agent of the real system. The honey court set up in the DMZ area is used to monitor the network traffic entering the DMZ area. The traffic identification strategy is set in the honey court to identify the black, white and gray traffic of the monitored network traffic. When the honey court determines that a certain traffic is black traffic, the honey court will guide the black traffic to the honey spot deployed in the DMZ area, and the honey spot can block the black traffic; when the honey court determines that a certain traffic is gray traffic, the honey court will continue to observe the gray traffic to further identify the traffic; when the honey court determines that a certain traffic is white traffic, the white traffic will pass normally. For example, the honey court's identification strategy for black, white and gray traffic can be: when attack traffic that is determined to be an attack behavior is detected in the network traffic, it is determined to be black traffic; when there is no attack behavior in the network traffic, it is determined to be white traffic; when there is information that cannot be clearly defined in the network traffic, it is determined to be gray traffic.

[0043] Honeyspots are protected using tripwire technology. Tripwires are deployed in honeyspots to block incoming network traffic, thereby trapping and detecting network traffic and obtaining attack intelligence, such as attacker information, from the traffic. Tripwires deployed in honeyspots include network tripwires and system tripwires.

[0044] In this embodiment, based on the characteristics of the DMZ and the services provided, network tripwires deployed in honeyspots within the DMZ include traffic tripwires and service tripwires. System tripwires include file tripwires, email tripwires, and account tripwires. Specifically, within the DMZ, traffic tripwires leverage large models to generate a large amount of simulated vulnerability-specific traffic based on specific business scenarios. This simulates vulnerability interaction scenarios, attracting and capturing attackers. This simulated traffic creates a powerful entrapment effect, particularly during information gathering, achieving multi-dimensional luring. Service tripwires implement two-way blocking for active scanning attacks at different levels within the network. First, based on host information within the defender's intranet environment, they intelligently generate a large number of simulated honeyspot services to proactively detect attacks. Second, based on the attacker's proof-of-concept exploit, they intelligently generate deceptive vulnerability response messages to create the illusion of a successful attack, further enhancing defense effectiveness. File tripwires leverage large language models to construct high-value business files, detect file theft behavior, and, using pre-set scripts, collect information about attackers attempting to steal files. Email Tripwire provides protection based on social engineering principles, while Account Tripwire uses statistical models to construct specific account numbers, preventing attackers from stealing data or logging into accounts and monitoring their transfer activity in real time. Because APT attacks often use social engineering tactics like phishing emails to breach network defenses, Email Tripwire works in conjunction with Account Tripwire to detect phishing attempts when attackers deliver them.

[0045] By deploying Honey Courtyards and Honey Points within the DMZ, and by designing a collaborative approach between them, Honey Courtyards can promptly isolate real systems, eliminate malicious payloads, and monitor traffic according to internal security rules, collaborating with Honey Points to protect the DMZ. If malicious traffic is identified, Honey Courtyards will direct it to the Honey Points. Honey Courtyard's front-end traffic monitoring and identification capabilities, combined with the Honey Points, significantly improve security threat awareness and network defense efficiency.

[0046] The area connecting the intranet and the extranet is often called the boundary zone or network perimeter. This zone controls inbound and outbound network traffic and protects the intranet's security. To ensure secure isolation and communication between the intranet and extranet, this area is typically equipped with network devices such as routers, switches, and firewalls as pre-deployed defense resources. Firewalls filter and control traffic entering and leaving the intranet, preventing unauthorized access; routers forward and route packets between the intranet and extranet; and switches connect firewalls, routers, and internal network devices to ensure efficient and secure data transmission.

[0047] See the instructions attached Figure 4 Based on the characteristics of the network boundary zone, the Honey Courtyard is deployed in the network boundary zone for protection. The Honey Courtyard is deployed before pre-configured defense resources (i.e., firewalls, routers, switches, and other network devices). The Honey Courtyard monitors and identifies network traffic entering the network boundary zone to observe attackers (hackers). In this embodiment, the Honey Courtyard's monitoring includes monitoring the flow of network browsing between various devices (firewalls, routers, switches, and other devices in the network boundary zone) to avoid missing attack traffic. A traffic identification strategy is set within the Honey Courtyard to identify black, white, and gray traffic in the monitored network traffic, and the identified black, white, and gray traffic is processed separately.

[0048] It should be noted that, because pre-deployed defense resources are also provided in the network boundary area, the specific operation of forwarding black traffic to the defense device is different from the specific operation performed by the honey court in the DMZ area. In the network boundary area, after identifying black traffic, the honey array dynamically mobilizes defense resources in real time to defend against it, and when necessary, directs black traffic to a honey spot, thereby effectively improving the security protection capabilities of the network boundary area. In a specific embodiment, after the honey court deployed in the network boundary area identifies black traffic (including attack traffic containing attack behavior), it forwards the black traffic to the firewall. By mobilizing pre-deployed defense resources (such as a firewall) for defense, the honey array can monitor the defense situation in real time. When the attack traffic breaks through the pre-deployed defense resources, the black traffic is forwarded to the honey spot. After the honey array determines that a honey spot needs to be deployed through real-time analysis, the honey spot can be a new honey spot that is controlled and deployed to block the attack traffic, or it can be a honey spot deployed elsewhere in the enterprise intranet (such as a honey spot deployed in the DMZ area) to block the attack traffic.

[0049] An intranet zone (or intranet zone) is a dedicated network environment within an enterprise or organization, primarily used to connect internal computers, servers, and other devices, supporting information and resource sharing and collaboration. Unlike DMZs and public network zones, intranet zones are typically invisible to external users and subject to strict access controls and security protections. They primarily provide functions such as file sharing, internal communications, and business applications, integrating tools such as internal email systems, instant messaging, and video conferencing to facilitate communication and collaboration among employees. Intranet zones typically run critical enterprise systems, such as ERP, CRM, financial systems, and OA systems, supporting daily business operations. Firewalls, data encryption, and access controls are used to protect internal data and prevent unauthorized external access and network attacks. The intranet zone consists of multiple sub-zones or functional modules, including the user zone, server zone, management zone, development zone, and data center zone. Each zone is divided and protected according to its function and security level. The user zone connects employee computing devices, the server zone contains various servers, the management zone manages the network and devices, the development zone isolates software development and testing activities, and the data center is responsible for storing and backing up critical data. The Intranet zone ensures the safe and stable operation of the enterprise's internal network through its closed and isolated nature, centralized management and resource sharing, flexibility and scalability, enabling employees to complete their work tasks efficiently and safely.

[0050] See the instructions attached Figure 5Based on the characteristics of the Intranet zone, honey spots and honey holes are deployed for protection, and multiple honey spots collaborate to assist in honey hole analysis. Honey spots are deployed before the Intranet zone to trap and detect network traffic before it enters the Intranet zone, thereby better preventing attack traffic from entering the Intranet zone. Honey holes force users to authenticate before entering the Intranet zone and precisely deliver floating programs to attackers to collect their identity information. Based on this collected attacker identity information, the attack chain is restored and an attacker profile is drawn, achieving continuous tracking, remote control, and source tracing countermeasures.

[0051] In this embodiment, based on the characteristics of the Intranet zone and the services provided, network tripwires deployed in the honeypots of the Intranet zone include domain control tripwires and traffic tripwires, and system tripwires include file tripwires, command tripwires, account tripwires, email tripwires, process tripwires, and path tripwires. Specifically, traffic tripwires in the Intranet zone are used to enhance the deception effect, and domain control tripwires are used to lure, identify, and block username-based lateral movement within the domain controller. By summarizing common username-based attack methods in domain penetration, virtualization technology is used to rapidly deploy domain control honeypots and simulated honeypots for vulnerability deception. Based on a real username dataset, honey username simulation is performed through high-order Markov deconstruction and generation. At the same time, simulated honeypot services with vulnerabilities are adaptively generated based on Web services in the intranet environment, making the existence of domain control tripwires (fake domain controllers) more reasonable and enriching the types of service tripwires, thereby achieving service simulation.

[0052] Command and path tripwires are implemented using dynamic scripts. By dynamically embedding executable JS script files in web systems, they detect attacker probing behavior. Traceable file tripwires are deployed in business systems and other systems to trace the source of attacks. Command tripwires simulate sensitive operations on user hosts and, using path and account tripwires, collaboratively detect attack behavior shifts and monitor unauthorized access to sensitive paths, accounts, and files. Process tripwires are generated based on in-depth analysis and matching of ransomware attack signatures. By monitoring the survival status of fake processes, they can promptly trace and locate ransomware activity paths, enabling more precise threat response and disposal.

[0053] Honeyhole technologies include file honeyholes, web honeyholes, and countermeasure honeyholes. File honeyholes deploy specific honeyhole files for different business scenarios to lure attackers into triggering them. They then connect back to the attackers through various means, collect information, and utilize disguised servers deployed on the public network to receive encrypted attacker information before transmitting it back to an internal database. Web honeyholes deploy floating code and browser plug-ins within dynamic web pages to collect and tag attackers' sensitive information. Through correlation analysis, they send a deterrent message, requiring a mobile phone verification code and ID card information for dual authentication. Countermeasure honeyholes utilize honeyhole websites capable of uploading remote control Trojan files to attract attackers. Once an attacker connects using a remote control tool, they leverage the deployed countermeasure code to obtain the tool version. MSF generates a targeted node.js file, replaces the attacker's original webshell code with an encrypted rebound shell, and ultimately, countermeasures are taken when the attacker reconnects to the honeyhole website.

[0054] In this embodiment, the honey array is configured as the operating center of the four honey systems, which can automatically and intelligently change and control the deployment strategy, configuration and location of other components of the four honeys. The deployment strategy based on the honey array detection and perception can globally dispatch network resources and flexibly adjust the deployment location of the four honey components in the intranet. According to network requirements, the honey array controls the batch generation of specific and deployed honey point devices, integrates internal defense points, gives full play to the defense advantages of each device, and builds a complete global perspective through real-time sharing of security intelligence and attack information, so that administrators can overlook the network security situation from a macro level and accurately grasp the attack trends. Based on these insights, the honey array can dynamically adjust security strategies and deployment plans, optimize resource allocation, promote the coordinated linkage of resources across the entire network, realize efficient interconnection between the four honey components, and comprehensively protect the security of the intranet.

[0055] In one possible embodiment, according to network requirements, the honey array controls the batch adaptive generation and deployment of specific honey spot devices based on a Bayesian attack graph (the Bayesian attack graph includes possible attack paths and the attack success probabilities corresponding to the paths).

[0056] The four-honey threat detection method for both inside and outside the enterprise proposed in this invention is based on honey point, honey court, honey array and honey hole technologies, and constructs a complete four-honey system architecture. Compared with existing technologies, this system has higher universality and credibility, is more suitable for the enterprise intranet environment, and has dynamic adaptability. It can effectively isolate the real system and prevent attacks from reaching the actual network, thereby forming a clearer local threat perception. For security threats, this solution can achieve global linkage disposal, comprehensively share security intelligence and attack information, coordinate and adjust various deployment points, combine local perception with global mobilization, reproduce the complete attack chain, quickly trace the source and countermeasure, and build a more secure enterprise-level network environment.

[0057] The method of the present invention is used to construct a four-honey system for threat detection. It can generate the optimal honey point deployment strategy based on the Bayesian attack graph and available defense resources. According to the characteristics of different areas of the enterprise intranet, specific honey points are generated and these honey points are deployed in a targeted manner on the paths that are most vulnerable to attack. The deployment strategy is adjusted dynamically in real time. Compared with the honeypot system, the defense is more targeted and flexible, and it can make full use of network resources and increase the attack interception rate. The whole area uses honey points and honey courts as the main force for threat intelligence collection. By deploying honey points around key assets in the intranet to actively deceive and trap attackers, it can quickly perceive attack behaviors in an all-round and multi-level manner, capture attack data and traffic, and perform automatic log analysis on honey point alarms, further forming a deeper threat perception collection range with wider information, more complete information, and more accurate information.

[0058] The enterprise intranet utilizes HoneyArray as the primary intelligence analysis tool, with HoneyPoints, HoneyCourtyards, and HoneyHoles assisting in analysis. HoneyCourtyards create outwardly identical service proxies, securely isolating real systems. They covertly observe and identify attack data traffic, analyze attackers' access trajectories, and uncover covert attacks. HoneyArray collaborates with HoneyPoints, HoneyCourtyards, and traditional security devices to centrally coordinate and adjust security devices within the intranet in real time. This allows all devices to share security intelligence and attack information in real time, creating a global perspective and understanding the attack situation across the entire intranet.

[0059] Honeyhole is the main force, while honeyspot and honey court assist in analysis, quickly tracing and countering the attacker, restoring the attacker's attack chain, drawing a portrait of the attacker, and accurately delivering floating programs to the attacker. During the entire process of the attacker's attack, "pre-emptive deterrence, in-process tracking, and post-event profiling" are achieved, effectively and quickly identifying and tracing the attacker.

[0060] In other embodiments of the present application, the present application discloses an electronic device, such as Figure 6 As shown, the electronic device 600 may include: one or more processors 601; a memory 602; a display 603; one or more applications (not shown); and one or more computer programs 604. The above components may be connected via one or more communication buses 605. The one or more computer programs 604 are stored in the above memory and configured to be executed by the one or more processors 601. The one or more computer programs 604 include instructions, which may be used to execute the following instructions: Figure 1 and each step in the corresponding embodiment.

[0061] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0062] The functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0063] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, magnetic disk or optical disk.

[0064] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for detecting four types of threats in an enterprise intranet, characterized in that: Construct honey courts, honey spots, honey holes, and honey arrays within the enterprise intranet for threat detection; The honey court sets a traffic identification strategy for monitoring network traffic and identifying black, white and gray traffic in the network traffic, forwarding the identified black traffic to the defense device, continuously observing the gray traffic for further identification, and allowing the white traffic to pass; Tripwires are deployed in the honeyspots to trap and detect network traffic passing through the honeyspots and obtain attack intelligence information from the network traffic; The honey hole is used to collect attacker information and conduct source tracing and countermeasures based on the attacker information; The honey array is in communication with the honey court, honey spot and honey hole, and the honey array obtains the security status of the enterprise intranet and the deployment information of the honey court, honey spot and honey hole and performs deployment scheduling according to the security status of the enterprise intranet; The honey array obtains the security status of the enterprise intranet and the deployment information of honey courts, honey spots and honey holes and performs deployment scheduling according to the security status of the enterprise intranet, including: when the security status of the enterprise intranet is that the attack traffic breaks through the pre-deployed defense resources in the enterprise intranet, the honey array controls the generation and deployment of new honey spots or mobilizes honey spot devices to block the attack traffic; The honey array builds a Bayesian attack graph based on the security status of the enterprise intranet, the device deployment status, and the deployment information of honey courts, honey spots, and honey holes; the honey array generates or mobilizes the deployment of honey spot devices based on the Bayesian attack graph; The enterprise intranet includes a DMZ area, a network boundary area and an Intranet area. The honey courts and honey spots constructed in the enterprise intranet include a first honey court, a second honey court, a first honey spot and a second honey spot. The first honey court and the first honey spot are deployed in the DMZ area to monitor the network traffic entering the DMZ area. When the first honey court identifies black traffic in the network traffic, the black traffic is forwarded to the first honey spot. The second honey court is deployed in the network boundary area to monitor the traffic entering the network boundary area. The second honey spot is deployed before the Intranet area to set traps for network traffic.

2. The method according to claim 1, characterized in that Deploying a tripwire within the hotspot, including: Deploy network tripwires and system tripwires within the honeyspot, wherein: The network tripwire includes at least one of a traffic tripwire, a service tripwire, and a domain control tripwire; The system tripwire includes at least one of a file tripwire, an email tripwire, an account tripwire, a process tripwire, a command tripwire and a path tripwire.

3. The method according to claim 1, characterized in that A network tripwire and a system tripwire are deployed in the first honey spot, wherein the network tripwire includes a traffic tripwire and a service tripwire, and the system tripwire includes a file tripwire, an email tripwire, and an account tripwire; Network tripwires and system tripwires are deployed in the second honey spot. The network tripwires include domain control tripwires and traffic tripwires. The system tripwires include file tripwires, command tripwires, account tripwires, email tripwires, process tripwires, and path tripwires.

4. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the four-honeypot threat detection method for an enterprise intranet according to any one of claims 1 to 3 is implemented.

5. An electronic device, characterized in that: include: processor and memory; The memory is used to store computer programs; The processor is used to execute the computer program stored in the memory, so that the electronic device executes the four-honeypot threat detection method for the enterprise intranet according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Four-honey-based integrated network attack detection method

    CN115549943A

  • High-interaction honeypot system based on attack graph

    CN118200033A