Trapping system implementation method based on intelligent large model
Through the intelligent big model, false messages are generated and attackers are lured to further attack, and combined with the honeypot trapping module to conduct trapping and evidence collection, the problem of honeypot trapping technology being unable to dynamically expand and high construction cost is solved, and efficient and flexible trapping effect is achieved.
Patent Information
- Application Number
- CN202510217454.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-26
AI Technical Summary
The existing honeypot trapping technology cannot dynamically expand the honeypot function, resulting in low trapping efficiency, ineffective in attracting more aggressive behaviors, and the cost of building honeypots is high.
The trapping system based on intelligent big model is adopted to intercept attack messages through dynamic camouflage modules and send them to the intelligent big model modules to generate false messages that meet the attacker's expectations, lure attackers to further attacks, and pull attack traffic to the honeypot trap module for trapping evidence and traceability analysis.
It improves the efficiency and scope of trapping, saves huge overhead in building honeypots, realizes the diversity and dynamic expansion of honeypot functions, and improves the flexibility of honeynets.
Smart Images

Figure CN119996017A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of network security, and in particular relates to a method for realizing a trapping system based on an intelligent large model. Background Art
[0002] As the threat of cyber attacks continues to intensify worldwide, traditional passive security protection methods such as firewalls and cryptographic machines can no longer fully cope with complex, dynamic, and hidden new unknown threats. Active security protection methods such as active trapping technology are urgently needed to lure and capture diverse network threats from powerful enemies. Active trapping technology uses deception to trick attackers into launching attacks in a specific environment. On the one hand, it reduces the threat to the actual system. On the other hand, it can master attack methods, obtain attack tools, and support attack tracing. It is an important direction in the field of network security defense. At present, active trapping technology is usually achieved by building honeypots. Low-interaction honeypots, high-interaction honeypots, and hybrid honeypots are the three most common forms of honeypots:
[0003] (1) Low-interaction honeypot: It only simulates partial responses of system services and does not execute actual application code. It has low resource consumption but may not be able to capture complex attack behaviors.
[0004] (2) High-interaction honeypot: It simulates complete system services and executes actual application code. It can capture more detailed attack behaviors, but it consumes more resources and has the risk of being exploited.
[0005] (3) Hybrid honeypot: Combining the characteristics of low-interaction and high-interaction honeypots, it can be flexibly configured according to actual needs to achieve optimal security effectiveness.
[0006] However, no matter what kind of honeypot it is, it needs to be created based on a physical honeypot, and it cannot dynamically, intelligently, and proactively expand the functions beyond the honeypot itself. Therefore, the trapping efficiency is low and it cannot achieve the purpose of luring the enemy to launch more attacks. Summary of the invention
[0007] 1. Technical issues to be resolved
[0008] The technical problem to be solved by the present invention is: to improve the efficiency of trapping, expand the scope of trapping, save the huge cost of actually building honeypots, realize the diversity and dynamic expansion of trapping honeypots for complex networks, to a certain extent solve the problems of static singleness and low hit rate of traditional honeypots, and improve the flexibility of honeynet as a whole.
[0009] (II) Technical solution
[0010] In order to solve the above technical problems, the present invention provides a method for implementing a trapping system based on an intelligent large model, the system being designed to include:
[0011] The dynamic camouflage module is used to intercept the scanning, detection and other attack messages sent by the attacking host through the interception mechanism, and send the message information to the intelligent large model module; it is also used to send false message information to the attacking host to induce it to launch further attack behaviors; and it is used to pull the attack traffic to the honeypot trapping module, which realizes the trapping and source tracing analysis of network attack threats;
[0012] The intelligent large model module is used to dynamically generate a variety of false message information that meets the attacker's expectations through training and learning after receiving the message information, and return the generated false message information to the dynamic camouflage module;
[0013] The honeypot trapping module is used to construct various types of honeypot simulation environments, receive attack traffic redirected by the dynamic camouflage module, and combine it with the threat intelligence library to achieve trapping, evidence collection and source tracing analysis of network attack threats.
[0014] Preferably, the implementation method of the dynamic camouflage module is as follows:
[0015] (1) Design an interception mechanism to monitor and intercept the message information sent by the attacker to the virtual host in the dynamic camouflage module, wherein the monitored data packets are parsed using deep packet inspection technology. Once malicious code, malicious detection or attack characteristics are found, the attack message is immediately intercepted by blocking the IP address or port of the attack source;
[0016] (2) Sending the intercepted attack message information to the intelligent large model module;
[0017] (3) Receive the intelligent false message information generated by the intelligent large model module and return it to the attacking host;
[0018] (4) Repeat the above steps (1) to (3), continuously intercept the message information sent by the attacking host, and return the false information message generated by its intelligent large model module to induce the attacker to further attack;
[0019] (5) Drag the attack traffic to the honeypot trapping module.
[0020] Preferably, the implementation method of the intelligent large model module is as follows:
[0021] (1) Intelligent large model construction and training:
[0022] Dataset collection: Collect massive data from diverse data sources;
[0023] Model structure selection: Design a model architecture based on Transformer or Llama; adopt a causal decoder architecture and use a unidirectional masked attention mechanism so that each input word only pays attention to the word before it and itself in the sequence, and then predicts the output word in an autoregressive manner;
[0024] Dataset processing and model training: Process the attack messages into a sequence data format that the model can understand, and select the appropriate loss function and optimization algorithm;
[0025] Model tuning stage: Use task-specific labeled data to fine-tune the model; then, use the alignment technology of the self-game preference optimization method SPPO to optimize the model behavior through the self-game framework. According to the annotation of the preference model, the winning rate of each output is estimated, so as to further fine-tune the model parameters so that the output with a winning rate higher than the preset value has a higher probability of occurrence. The goal of self-game is to fine-tune the own model to outperform the previous round of model.
[0026] Model evaluation and verification phase: Regularly evaluate the performance of the model on the test set, and use a test set independent of the training process to evaluate the generalization ability and accuracy of the model;
[0027] (2) Application of intelligent large model:
[0028] Message input: input the attack message information intercepted by the dynamic camouflage module;
[0029] Message generation: Use the trained model to generate false message information that meets the attacker's expectations;
[0030] Message return: Return the generated false information message to the dynamic camouflage module.
[0031] The invention also provides a trapping system designed based on the method.
[0032] The invention also provides an application of the method in network security.
[0033] (III) Beneficial effects
[0034] (1) The present invention protects the real system from the attacker's attack by intercepting the attacker's attack message, thereby achieving protection of the real system;
[0035] (2) The present invention generates a variety of accurate false messages through an intelligent large model and returns them to the attacker, thereby deceiving and luring the attacker into further attacks. By generating intelligent false messages on demand, the present invention realizes unlimited intelligent expansion of existing honeypots. It has strong adaptability, flexibility and convenience, and saves the huge cost of actually building a large number of honeypots. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a diagram of the overall implementation architecture of the trapping system of the present invention;
[0037] Figure 2 Workflow diagram of the trapping system designed for the present invention. DETAILED DESCRIPTION
[0038] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below in conjunction with the drawings and examples.
[0039] The present invention provides a method for realizing a trapping system based on an intelligent large model. This method firstly protects the real system from attack by intercepting the attack message sent by the attacker, and generates a false message through the intelligent large model and returns it to the attacker, and expands the functional diversity of the existing honeypot by means of false messages, which can improve the efficiency of trapping, expand the scope of trapping, and save the huge cost of actually building honeypots, realize the diversity and dynamic expansion of trapping honeypots for complex networks, solve the problems of static singleness and low hit rate of traditional honeypots to a certain extent, and improve the flexibility of honeynet as a whole. The present invention is an active defense means taken for common complex network security threat environments, and is used for trapping known and unknown threats such as reconnaissance, access, deception, attack utilization, load delivery, information leakage, and information tampering.
[0040] The technical solution used by the present invention to solve its technical problems is: a method for realizing a trapping system based on an intelligent large model. The method comprises three parts: a dynamic camouflage module, an intelligent large model module, and a honeypot trapping module. First, the dynamic camouflage module intercepts each scanning, detection and other attack behaviors sent by the attacker by designing an interception mechanism, and sends its attack message to the intelligent large model module. The intelligent large model module generates and returns a large amount of false message information expected by the attacker through complex learning, thereby inducing the attacker to launch further attack behaviors. Finally, the dynamic camouflage module draws the attack traffic to the honeypot trapping module, and the honeypot trapping module realizes the traceability analysis and trapping evidence collection of network attack threats through a real high-interaction environment.
[0041] Figure 1 It is the module design and overall architecture of the honeypot implementation method based on the intelligent large model. The specific process is as follows:
[0042] (1) The dynamic camouflage module intercepts the scanning, detection and other attack messages sent by the attacking host through the interception mechanism, and sends the message information to the intelligent large model module;
[0043] (2) After receiving the message information, the intelligent large model module dynamically generates a variety of false message information that meets the attacker's expectations through training and learning, and returns the generated false message information to the dynamic camouflage module;
[0044] (3) The dynamic camouflage module sends false message information to the attacking host to induce it to launch further attack behaviors;
[0045] (4) The dynamic camouflage module directs the attack traffic to the honeypot trapping module, which then performs trapping, evidence collection, and source tracing analysis of network attack threats.
[0046] The intelligent large model-based trapping system implementation method of the present invention includes the following three modules:
[0047] (1) The dynamic camouflage module intercepts the message information sent by the attacking host through the interception mechanism, and returns a large number of different false message information generated by the intelligent large model module to protect the real system from attack and lure the attacker to launch further attacks.
[0048] (2) The intelligent large model module inputs the scanning, detection and other attack message information sent by the attacker, and generates a large amount of false message information expected by the attacker through complex training and learning.
[0049] (3) Honeypot trapping module: It constructs various types of highly interactive and realistic simulation environments, receives attack traffic redirected by the dynamic camouflage module, and combines it with the threat intelligence library to achieve trapping, evidence collection and source tracing analysis of network attack threats.
[0050] Figure 2 It is an overall flow chart of the implementation method of the trapping system based on the intelligent large model, which mainly involves three core modules: dynamic camouflage module, intelligent large model module, and honeypot trapping module.
[0051] The specific method includes the following steps:
[0052] 1. The implementation method of the dynamic camouflage module includes:
[0053] (1) Design an interception mechanism to monitor and intercept the message information sent by the attacker to the virtual host in the dynamic camouflage module. Specifically, use deep packet inspection technology to parse the monitored data packets. Once it is found that the data packets contain hidden malicious code, malicious detection or attack characteristics, the attack message is immediately intercepted by blocking the IP address or port of the attack source.
[0054] (2) Sending the intercepted attack message information to the intelligent large model module;
[0055] (3) Receive the intelligent false message information generated by the intelligent large model module and return it to the attacking host;
[0056] (4) Repeat the above steps to continuously intercept the message information sent by the attacking host and return the false information message generated by its intelligent large model module to induce the attacker to further attack;
[0057] (5) Drag the attack traffic to the honeypot trapping module.
[0058] 2. The implementation method of the intelligent large model module includes:
[0059] (1) Intelligent large model construction and training:
[0060] Dataset collection: Collect massive amounts of data from a variety of data sources. For example, collect a large number of attack message datasets through web crawlers and other methods; collect relevant data information through books, code libraries, web pages, dialogue corpora, etc.
[0061] Model structure selection: Design a model architecture based on Transformer or Llama; adopt a causal decoder architecture and use a unidirectional masked attention mechanism so that each input word only pays attention to the word before it and itself in the sequence, and then autoregressively predicts the output word.
[0062] Dataset processing and model training: Process the attack messages into a sequence data format that the model can understand, and select appropriate loss functions (such as cross entropy loss, mean square error loss, etc.) and optimization algorithms (such as Adam, SGD, particle swarm algorithm, cuckoo algorithm, genetic algorithm, simulated annealing algorithm, etc.).
[0063] Model tuning stage: Large models are usually trained for general tasks and are not always suitable for specific tasks. Therefore, the model is fine-tuned using labeled data for specific tasks, such as classic hacker attack messages and related messages for specific attack tasks. The fine-tuned large model has higher accuracy and efficiency on specific tasks and can reduce the total amount of data required to train the large model. Then, the alignment technology of the self-game preference optimization method (SPPO) is used to optimize the behavior of the large model through the framework of self-game. Specifically, based on the annotation of the preference model, the winning rate of each output is estimated, so as to further fine-tune the parameters of the large model so that the output with a high winning rate has a higher probability of occurrence. The goal of self-game is to fine-tune its own model to outperform the previous model.
[0064] Model evaluation and validation phase: Regularly evaluate the performance of the model on the test set, and use a test set independent of the training process to evaluate the generalization ability and accuracy of the model.
[0065] (2) Application of intelligent large model:
[0066] Message input: input the attack message information intercepted by the dynamic camouflage module;
[0067] Message generation: Use the trained large model to generate false message information that meets the attacker's expectations;
[0068] Message return: Return the generated false information message to the dynamic camouflage module.
[0069] 3. The implementation method of the honeypot trapping module includes:
[0070] Build a highly interactive and realistic honeypot simulation environment to simulate an application environment with functions similar to those of a real network, receive attack traffic redirected by the dynamic camouflage module, and combine it with the threat intelligence library to achieve trapping, evidence collection and source tracing analysis of network attack threats. The honeypot simulation environment includes but is not limited to:
[0071] (1) Common operating system simulation: Windows 7, Windows 8, Window 10, Windows 11, Windows XP, Linux, Kylin, Kylin, etc.;
[0072] (2) Common port simulation: FTP, SSH, HTTP, HTTPS, SMTP, TELNET, etc.;
[0073] (3) Common database simulation: MySQL, Oracle, SQLServer, PostgreSQL, MongDB, Redis, etc.;
[0074] (4) Common application simulation: Tomcat, Nginx, Django, HADOOP, Apache Shiro, etc.
[0075] (5) Common vulnerability simulation: SQL injection, cross-site scripting, cross-site request forgery, file inclusion vulnerability, file upload vulnerability, weak password vulnerability, etc.
[0076] It can be seen that the present invention proposes a method for implementing a trapping system based on an intelligent large model, which aims to intercept attacker messages and use the intelligent large model to generate a variety of false messages that meet the attacker's expectations and return them to the attacker, thereby luring the attacker to attack further. Finally, the attack traffic is redirected to a highly interactive and highly simulated honeypot simulation environment to trap the attacker. Using on-demand generated intelligent false messages as bait can save a lot of overhead costs for the actual construction of honeypots, and more intelligently and dynamically expand the diversity of existing honeypot functions.
[0077] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for implementing a trapping system based on an intelligent large model, characterized in that: The system is designed to include: The dynamic camouflage module is used to intercept the scanning and detecting attack messages sent by the attacking host through the interception mechanism, and send the message information to the intelligent large model module; it is also used to send false message information to the attacking host to induce it to launch further attack behaviors; and it is used to pull the attack traffic to the honeypot trapping module, which realizes the trapping and source tracing analysis of network attack threats; The intelligent large model module is used to dynamically generate a variety of false message information that meets the attacker's expectations through training and learning after receiving the message information, and return the generated false message information to the dynamic camouflage module; The honeypot trapping module is used to construct various types of honeypot simulation environments, receive attack traffic redirected by the dynamic camouflage module, and combine it with the threat intelligence library to achieve trapping, evidence collection and source tracing analysis of network attack threats.
2. The method according to claim 1, characterized in that The implementation method of the dynamic camouflage module is as follows: (1) Design an interception mechanism to monitor and intercept the message information sent by the attacker to the virtual host in the dynamic camouflage module, wherein the monitored data packets are parsed using deep packet inspection technology. Once malicious code, malicious detection or attack characteristics are found, the attack message is immediately intercepted by blocking the IP address or port of the attack source; (2) Sending the intercepted attack message information to the intelligent large model module; (3) Receive the intelligent false message information generated by the intelligent large model module and return it to the attacking host; (4) Repeat the above steps (1) to (3), continuously intercept the message information sent by the attacking host, and return the false information message generated by its intelligent large model module to induce the attacker to further attack; (5) Drag the attack traffic to the honeypot trapping module.
3. The method according to claim 2, characterized in that The implementation method of the intelligent large model module is as follows: (1) Intelligent large model construction and training: Dataset collection: Collect massive data from diverse data sources; Model structure selection: Design the model architecture based on Transformer or Llama; It uses a causal decoder architecture and a unidirectional masked attention mechanism, so that each input word only pays attention to the word before it and itself in the sequence, and then predicts the output word in an autoregressive manner. Dataset processing and model training: Process the attack messages into a sequence data format that the model can understand, and select the appropriate loss function and optimization algorithm; Model tuning stage: Use task-specific labeled data to fine-tune the model; then, use the alignment technology of the self-game preference optimization method SPPO to optimize the model behavior through the self-game framework. According to the annotation of the preference model, the winning rate of each output is estimated, so as to further fine-tune the model parameters so that the output with a winning rate higher than the preset value has a higher probability of occurrence. The goal of self-game is to fine-tune the own model to outperform the previous round of model. Model evaluation and verification phase: Regularly evaluate the performance of the model on the test set, and use a test set independent of the training process to evaluate the generalization ability and accuracy of the model; (2) Application of intelligent large models: Message input: input the attack message information intercepted by the dynamic camouflage module; Message generation: Use the trained model to generate false message information that meets the attacker's expectations; Message return: Return the generated false information message to the dynamic camouflage module.
4. The method according to claim 3, characterized in that When the intelligent large model module collects data sets, it collects attack message data sets through web crawlers; and collects relevant data information through books, code libraries, web pages, and dialogue materials.
5. The method according to claim 3, characterized in that The loss functions include cross entropy loss and mean square error loss.
6. The method according to claim 3, characterized in that Optimization algorithms include Adam, SGD, particle swarm optimization, cuckoo algorithm, genetic algorithm, and simulated annealing algorithm.
7. The method according to claim 1, characterized in that The honeypot simulation environment constructed by the honeypot trapping module includes: operating system simulation environment, port simulation environment, database simulation environment, application simulation environment, and vulnerability simulation environment.
8. The method according to claim 1, characterized in that The system is capable of trapping known and unknown threats such as reconnaissance, access, deception, exploitation, payload delivery, information leakage, and information tampering.
9. A trapping system designed based on the method according to any one of claims 1 to 8.
10. Application of the method according to any one of claims 1 to 8 in network security.
Citation Information
Patent Citations
Integrated industrial control honeypot identification system and method based on deep learning
CN111126440A
Novel honey pot system and method based on deception defense
CN115277068A
Network attack tracing method and device for honeypot trapping based on reverse proxy
CN116781331A
Network attack processing method and device based on large model honeypot, medium and equipment
CN118784346A
Method for automatic aggregating and enriching data from honeypots
US20230106071A1
Cited By
Honeypot interaction response generation method based on large language model
CN120750578A