Network security defense method and system based on intrusion modeling trapping
By building a virtual asset map driven by dynamic topological disturbance factor and building a dynamic trapping interface with controllable protocol stack level, the node reorganization strategy is triggered using topological correlation parameters, and the problems of passive static defense and lagging response in the existing technology are solved, and efficient network security defense is achieved.
Patent Information
- Application Number
- CN202510481174.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-13
AI Technical Summary
Existing network security defense methods have problems such as passive static defense, protocol feature leakage and response lag in advanced network attack and defense scenarios.
By building a virtual asset map driven by dynamic topology perturbation factor, using the protocol fingerprint obfuscation mechanism to generate virtual nodes and interactive links that can interchange protocol response characteristics, build a dynamic trapping interface with controllable protocol stack level and service response logic, and extract topology correlation parameters based on the attacker's interaction behavior, triggering node restructuring policies and attack path diversion rules.
It significantly improves the attacker's path detection error judgment rate, optimizes the efficiency of defense resource utilization, and forms a closed-loop defense capability of "virtual trapping-path concealment-dynamic countermeasure", which enhances the system's dynamic interference and countermeasure capabilities to advanced threats.
Smart Images

Figure CN119996093A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security defense methods, and in particular to a network security defense method and system based on intrusion modeling trapping. Background Art
[0002] In advanced network attack and defense scenarios, attackers can accurately locate and laterally migrate to key assets through means such as protocol fingerprinting, topology mapping, and covert instruction flow penetration. The defender needs to dynamically hide the real asset characteristics, confuse the protocol interaction logic in real time, and block the attacker's ability to reversely deduce the network path. At the same time, it is necessary to achieve real-time dynamic confrontation between defense strategies and attack behaviors to prevent static rules from being bypassed by adaptive attacks.
[0003] The current mainstream solution uses active trapping technology based on dynamic protocol stack simulation. This solution deploys a protocol stack simulation engine in a virtual node through a predefined multi-protocol interaction template library to generate a trapping interface with variable response characteristics. It analyzes the matching degree between the attack traffic and the protocol template and triggers the preset protocol state jump rules, thereby interfering with the attacker's mapping of the network topology. In addition, the system will dynamically switch the protocol stack layer of the virtual node based on the traffic session characteristics, such as performing protocol stack camouflage between the transport layer and the application layer, to increase the difficulty of protocol reversal for attackers.
[0004] However, since the protocol simulation template relies on a predefined fingerprint feature library, it is impossible to dynamically confuse the attacker's adaptive protocol variants (such as custom field filling and non-standard state machine jumps), which makes the protocol features of the trapping interface easy for the attacker to identify through differential analysis. In addition, the protocol stack layer switching rules lack a dynamic association with the network topology state, making it difficult to adjust the jump strategy in real time according to the contextual features of the attack link (such as instruction flow timing and topological correlation), resulting in a lag in the game between defense actions and attack behaviors, ultimately reducing the concealment and deception effectiveness of the trapping interface. Summary of the invention
[0005] The embodiment of the present invention provides a network security defense method and system based on intrusion modeling trapping, which is used to solve the problems of passive static defense, protocol feature leakage and delayed response in the prior art.
[0006] In a first aspect, an embodiment of the present invention provides a network security defense method based on intrusion modeling trapping, comprising: A virtual asset map driven by dynamic topology disturbance factors is constructed using a real network environment topology image. The virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism. Based on the network session context features, the interactive link is processed by interface deformation rule implantation, and a dynamic trapping interface with controllable protocol stack layer and service response logic is constructed; Utilizing the attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link to obtain a topology correlation parameter, the topology correlation parameter triggers the node reorganization strategy of the virtual asset graph, and constructs an attack path diversion rule; Performing path obfuscation processing on the intrusion instruction stream based on the protocol stack mirror tunnel, constructing an attack path obfuscation network dynamically configured by the attack path diversion rule, and the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; According to the topology correlation parameter and the attack path confusion network real-time status collaborative defense strategy, when the topology correlation parameter reaches the threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
[0007] Optionally, a topology correlation parameter is obtained by using an attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link, and the topology correlation parameter triggers a node reorganization strategy of the virtual asset graph, and constructs an attack path diversion rule, including: Performing protocol fingerprint and time series analysis on the attacker's operation sequence in the interactive link, and extracting an operation feature vector including a source-target port mapping relationship and an instruction interval duration; Generate a dynamic weight vector according to the node distribution state of the operation feature vector in the virtual asset map, and obtain the topology correlation parameter through interactive calculation between the dynamic weight vector and the protocol stack behavior mode; The topology correlation parameter is used to analyze the protocol stack behavior pattern of the virtual asset map, and a node reorganization strategy matching the protocol stack layer of the dynamic trapping interface is activated; The protocol camouflage strength of the interactive links of the virtual asset map is adjusted based on the node reorganization strategy to generate an attack path diversion rule including a protocol stack hierarchical mapping relationship.
[0008] Optionally, the topology correlation parameter is subjected to a protocol stack behavior pattern analysis of the virtual asset map, and a node reorganization strategy matching the protocol stack layer of the dynamic trapping interface is activated, including: Performing protocol stack level feature extraction on the topology correlation parameters, separating the protocol fingerprint matching degree, the node connection density threshold and the protocol camouflage strength gradient, and generating a protocol stack behavior pattern feature vector; Compare the protocol stack behavior pattern feature vector with the protocol stack layer of the dynamic trapping interface by fingerprint library, and select the protocol stack layer matching subset with a matching degree higher than a threshold according to the port mapping rule of the protocol layer; Based on the protocol stack layer matching subset, poll the protocol stack layer activation status of the dynamic trapping interface, detect the protocol camouflage response delay and session context integrity mark of the interface at the transport layer / application layer, and obtain the real-time status matrix of the dynamic trapping interface; According to the session integrity mark in the real-time state matrix of the dynamic trapping interface, the node connection density adjustment coefficient and the protocol camouflage weight are calculated to generate a node reorganization strategy parameter table; The node reorganization strategy parameter table is analyzed, and the node connection density adjustment and protocol camouflage weight loading of the corresponding layer are activated according to the protocol stack layer priority to complete the activation of the node reorganization strategy.
[0009] Optionally, based on the node reorganization strategy, the protocol camouflage strength of the interactive links of the virtual asset map is adjusted to generate an attack path diversion rule containing a protocol stack layer mapping relationship, including: Performing protocol camouflage strength gradient analysis processing on the protocol stack layer migration rule in the node reorganization strategy to generate camouflage strength gradient parameters that match the dynamic trapping interface protocol stack layer; Performing protocol stack layer matching processing on the interactive links of the virtual asset map according to the camouflage strength gradient parameter, and generating a protocol stack layer mapping table including the correlation relationship between protocol stack depth and camouflage strength; Performing dynamic allocation processing of camouflage strength on the protocol response logic of the interactive link based on the protocol stack layer mapping table, generating link camouflage configuration parameters including protocol stack layer priority tags; Inputting the link camouflage configuration parameters into the protocol stack diversion engine of the attack path obfuscation network to generate a path diversion decision instruction linked to the dynamic trapping interface protocol stack layer; The protocol stack response path reconstruction processing is performed on the interactive links of the virtual asset map through the path diversion decision instruction to form an attack path diversion rule including a protocol camouflage strength gradient constraint.
[0010] Optionally, the link camouflage configuration parameters are input into a protocol stack diversion engine of the attack path obfuscation network to generate a path diversion decision instruction linked to the dynamic trapping interface protocol stack layer, including: Performing protocol stack level analysis on the link camouflage configuration parameters, extracting dynamic attributes bound to the protocol stack level in the link camouflage configuration parameters, and generating camouflage level features; Perform dynamic weight adaptation based on the camouflage level feature and the protocol stack layer of the dynamic trapping interface to generate linkage matching parameters; Performing path diversion optimization on the linkage matching parameters, and generating path diversion optimization features in combination with the dynamic path selection strategy of the attack path obfuscation network; Reconstruct the path diversion optimization feature and the obfuscation rule of the attack path obfuscation network through rule constraints to generate a path obfuscation feature; The path obfuscation features are fused with decision instructions, the dynamic parameters of the protocol stack layer linkage and the jump logic of the path camouflage sequence are integrated to generate dynamic path diversion decision instructions.
[0011] Optionally, according to the topology correlation parameter and the attack path confusion network real-time state collaborative defense strategy, when the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism, including: Performing dynamic correlation analysis on the topological correlation parameters, extracting the real-time change characteristics of the dynamic connection strength between nodes and the topological evolution path, and generating real-time topological correlation characteristics; Dynamically adapt the defense strategy of the real-time topology association feature and the real-time state of the attack path obfuscated network to generate collaborative defense parameters; Perform multi-dimensional threshold triggering judgment based on the collaborative defense parameter, and generate a dynamic reorganization triggering instruction when the topology correlation parameter reaches a preset threshold; According to the dynamic reorganization trigger instruction, the node connection relationship of the attack path obfuscation network is strategically reconstructed to generate a node reorganization strategy, wherein the node reorganization strategy includes a real-time switching logic of a redundant path dynamic allocation rule and an interface deformation rule; The node reorganization strategy and the interface deformation rule are dynamically integrated to form an attack and defense strategy, and the node reorganization logic and the interface deformation constraint conditions are integrated to generate a dynamic attack and defense game mechanism.
[0012] Optionally, path obfuscation processing is performed on the intrusion instruction stream based on the protocol stack mirror tunnel, and an attack path obfuscation network dynamically configured by the attack path diversion rule is constructed, and the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directionally manner, including: Based on the protocol stack mirror tunnel, the transmission path of the intrusion instruction stream is analyzed by layer features, the path jump rules and dynamic camouflage parameters of each layer of the protocol stack are extracted, and the obfuscated path features are generated; Dynamically adapting the obfuscated path features to the attack path diversion rules, analyzing the dynamic coupling relationship between the path disguise priority and the diversion rules, and generating dynamic diversion parameters; Based on the dynamic diversion parameters, a multi-level path obfuscation process is performed on the transmission path of the intrusion instruction flow to build an attack path obfuscation network framework; Performing protocol stack layer linkage adaptation on the attack path obfuscation network framework and the protocol stack layer of the dynamic trapping interface to generate linkage transmission parameters; Based on the linkage transmission parameters, the attack path obfuscation network framework is dynamically configured and optimized, and the path camouflage sequence and the directional transmission rules are integrated to generate an attack path obfuscation network.
[0013] In a second aspect, an embodiment of the present invention provides a network security defense system based on intrusion modeling trapping, including: A construction module is used to construct a virtual asset map driven by dynamic topology disturbance factors using a real network environment topology image, wherein the virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism; A deformation module, used to perform interface deformation rule implantation processing on the interactive link based on network session context features, and to build a dynamic trapping interface with controllable protocol stack layer and service response logic; A trigger module, used to obtain a topology correlation parameter by using an attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link, wherein the topology correlation parameter triggers a node reorganization strategy of the virtual asset graph and constructs an attack path diversion rule; An obfuscation module is used to perform path obfuscation processing on the intrusion instruction stream based on the protocol stack mirror tunnel, and to construct an attack path obfuscation network dynamically configured by the attack path diversion rule, wherein the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; The collaborative module is used to confuse the real-time status of the network with the topology correlation parameter and the attack path to coordinate the defense strategy, and when the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
[0014] In a third aspect, an embodiment of the present invention provides a computing device, comprising a processor and a memory, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute any method described in the first aspect.
[0015] In a fourth aspect, an embodiment of the present invention provides a computer storage medium having computer program instructions stored thereon, wherein the computer program instructions, when executed by a processor, implement any one of the methods described in the first aspect.
[0016] In an embodiment of the present application, a virtual asset map driven by a dynamic topology disturbance factor is constructed using a real network environment topology mirror, and the virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism; the interactive link is implanted with interface deformation rules based on network session context features, and a dynamic trapping interface with controllable protocol stack layer and service response logic is constructed; a topology correlation parameter is obtained by an attacker operating the protocol stack layer of the dynamic trapping interface in the interactive link, and the topology correlation parameter triggers the node reorganization strategy of the virtual asset map, and an attack path diversion rule is constructed; the intrusion instruction stream is path-confused based on a protocol stack mirror tunnel, and an attack path obfuscation network dynamically configured by the attack path diversion rule is constructed, and the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; according to the topology correlation parameter and the real-time status collaborative defense strategy of the attack path obfuscation network, when the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
[0017] The technical solution of this application has the following beneficial effects: This application constructs a virtual asset map through a protocol fingerprint obfuscation mechanism, combines the interface deformation rule implantation to generate a highly simulated dynamic trapping interface, and extracts topological correlation parameters based on the attacker's interactive behavior to trigger the node reorganization strategy. Relying on the protocol stack mirror tunnel, multi-level path obfuscation is implemented to build an attack path obfuscation network directional diversion instruction flow. Through the dynamic attack and defense game mechanism, the node reorganization and interface deformation rules are updated in real time, which significantly improves the attacker's path detection misjudgment rate, optimizes the utilization efficiency of defense resources, and forms a closed-loop defense capability of "virtual trapping-path hiding-dynamic countermeasures".
[0018] Furthermore, this solution extracts the attacker's operation feature vector through protocol fingerprint and time series analysis, generates a dynamic weight vector in combination with the node distribution state of the virtual asset map, and drives the protocol stack behavior pattern to calculate the topological correlation parameter. Based on this parameter, the node reorganization strategy is activated, the interactive link of the virtual asset map is reconstructed, and the attack path diversion rules are generated through the gradient adjustment of the protocol camouflage strength, so as to achieve accurate diversion and dynamic concealment of the attack path, effectively extend the attacker's port mapping relationship identification cycle and improve the protocol fingerprint obfuscation strength. Through the coordinated response mechanism of the protocol stack hierarchical mapping relationship and the node reorganization strategy, a closed-loop defense system of "feature analysis-topology reconstruction-path obfuscation" is constructed to intercept complex penetration behaviors under the multi-level dynamic interference of the protocol stack, and enhance the active defense and attack countermeasure capabilities of key business links.
[0019] These and other aspects of the present invention will become more apparent from the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0021] Figure 1 A flowchart of a big data processing method for implementing hybrid data analysis provided by an embodiment of the present invention; Figure 2 A schematic diagram of the structure of a big data processing system for implementing hybrid data analysis provided by an embodiment of the present invention; Figure 3 A schematic diagram of the structure of a computing device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0022] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention.
[0023] In some of the processes described in the specification and claims of the present invention and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., do not represent the order of precedence, and do not limit the "first" and "second" to be different types.
[0024] This application aims to generate a highly simulated virtual asset map through a real network environment mirror, use the protocol fingerprint obfuscation mechanism to achieve dynamic interchange of virtual node protocol features, and combine the interface deformation rule implantation to form a controllable trapping interface at the protocol stack level, and establish the ability to actively induce attack behaviors and capture features. Extract topological correlation parameters through the interaction between attackers and virtual assets, drive the generation of node reorganization and attack path diversion rules, and build a multi-level path obfuscation network in combination with the protocol stack mirror tunnel to achieve dynamic concealment and precise diversion of intrusion instruction flows. Finally, a dynamic attack and defense game mechanism based on the coordination of real-time topological correlation and network status is formed, breaking through the limitations of the response lag and rule solidification of traditional defense solutions, and improving the adaptive defense and active countermeasure capabilities of network systems in complex attack scenarios.
[0025] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0026] Figure 1 A flowchart of a big data processing method for implementing hybrid data analysis is provided for an embodiment of the present invention. Figure 1 As shown, the method includes: 101. Using the real network environment topology image to build a virtual asset map driven by dynamic topology disturbance factors, the virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism; In this step, the dynamic topology disturbance factor refers to the network disturbance parameter that drives the dynamic changes of the virtual asset graph.
[0027] Protocol fingerprint obfuscation mechanism refers to the technology of dynamically replacing protocol response characteristics to interfere with attackers.
[0028] The interchangeable protocol response feature refers to the node response logic that supports dynamic switching of multiple protocols.
[0029] In the embodiment of the present application, a dynamically disturbed virtual asset map is generated through the topology mirroring of the real network environment. Based on the network topology crawler technology, the node and link information of the physical network (such as IP address, port open status) is collected in real time, and the genetic algorithm (GA) is used to inject dynamic topology disturbance factors (such as randomly increasing or decreasing the number of virtual node connections, adjusting the BGP routing weight) to construct a virtual asset map. The protocol fingerprint obfuscation mechanism generates interchangeable protocol response features through a deep learning model (such as LSTM): dynamically replaces the protocol header fields (such as User-Agent, Content-Type) such as HTTP / 1.1 and gRPC (distortion rate 15-30%), and ensures the compatibility of the interactive link protocols between virtual nodes through a hash consistency algorithm. Key parameters such as node connection density (0.1-0.9) and protocol distortion strength (0-1) are generated through historical attack data training, and finally output a virtual asset map containing dynamic protocol features.
[0030] In the network attack and defense drills in the financial industry, the network topology image of the real core trading system is used to generate a virtual asset map. The IP addresses, port distribution and BGP routing information of entities such as trading servers and clearing nodes are captured in real time through the SDN controller, and the OpenFlow protocol is rewritten using the protocol fingerprint obfuscation engine. For example, the version identification field of the SSH protocol is randomly replaced with a hybrid fingerprint of Cisco IOS 15.2 to Juniper JunOS 18.4, and a virtual link with a dynamic session ID is generated based on the multiplexing feature of the QUIC protocol. These virtual nodes form a topology mapping with the physical network through VXLAN tunnels. When the attacker scans, the HTTP / 2 protocol stack of the virtual node will randomly return a response header combination of Nginx 1.25 or Apache 2.4, realizing an automatically reconstructed mirror environment every 15 minutes.
[0031] 102. Based on the network session context features, the interactive link is subjected to interface deformation rule implantation processing, and a dynamic trapping interface with controllable protocol stack layer and service response logic is constructed; In this step, the interface deformation rule refers to the logic rule for dynamically adjusting the interface protocol characteristics.
[0032] A dynamic trapping interface refers to a trapping node interface that can dynamically adjust the behavior of the protocol stack.
[0033] In an embodiment of the present application, interface deformation rules are implanted into the interactive link based on network session context features (such as TCP handshake timing, HTTP request interval). A time series clustering algorithm (such as DTW-KMeans) is used to extract session feature patterns (such as heartbeat packet period, request response time difference), and the protocol stack hierarchical configuration (such as switching TLS version, modifying TCP window size) is dynamically loaded through Docker container hot migration technology. The service response logic is controlled by a state machine model (such as a Mealy machine), for example, simulating database query delay (±20ms) or HTTP error code return ratio (such as 404 response accounting for 30%). Parameters such as protocol stack switching delay (≤5ms) and logic control error rate (<3%) are optimized through reinforcement learning models, and finally a high-simulation trapping interface that can dynamically adjust protocol behavior is generated.
[0034] In response to the APT attack suffered by a certain government cloud platform, a protocol stack deformation engine was deployed in the MySQL database trapping node of the virtual asset map. The libmysqlclient.so library function was hijacked through the Hook technology, and the protocol response logic was dynamically adjusted according to the timing characteristics in the TCP session. When three consecutive failed login requests were detected, the TLS 1.3 handshake process was automatically enabled but the Vmess protocol features were nested, and a simulated X.509 certificate chain was inserted into the ServerHello extension field. At the same time, a dynamic port hopping sequence was generated based on the Markov chain model, so that port 3306 changed according to the Fibonacci sequence in the range of 600-800 seconds, and the port change trajectory was concealed by the perturbation of the IPID field entropy value.
[0035] 103. Utilize the attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link to obtain a topology correlation parameter, wherein the topology correlation parameter triggers a node reorganization strategy of the virtual asset graph and constructs an attack path diversion rule; In this step, the topology correlation parameter refers to the quantitative value of the correlation strength between the attack behavior and the virtual asset topology.
[0036] Node reorganization strategy refers to the defense rules for adjusting the connection relationship of virtual nodes.
[0037] In an embodiment of the present application, the topological correlation parameters are extracted through the attacker's operation on the dynamic trapping interface in the interactive link (such as port scanning, protocol fingerprint detection). A graph neural network (GNN) is used to analyze the interaction mode between the attack behavior and the virtual node (such as connection frequency, protocol distortion feedback), and the correlation strength between nodes is calculated (range 0-1). When the parameter exceeds the threshold (such as 0.85), the node reorganization strategy is triggered: the network flow optimization model (such as the Ford-Fulkerson improved algorithm) is used to dynamically allocate redundant paths (such as switching to the backup link when the main path load is >80%), and the interface rules (such as randomized MAC addresses, IP fragmentation rules) are modified in real time through the eBPF program. The diversion rules are generated based on the protocol characteristics of the attack path (such as the HTTP / 2 stream ID conflict rate), and ultimately form an accurate traffic steering strategy.
[0038] In the power SCADA system defense scenario, when the attacker infiltrates the virtual PLC node through the Modbus protocol, the protocol stack probe captures an abnormal function code call sequence. The topology correlation parameters are calculated based on the hidden Markov model, and the node reorganization strategy is triggered when the illegal write register operation accounts for more than 32%. In the specific implementation, the attacked virtual PLC node is split into three honeypot instances, which simulate the characteristics of Schneider Modicon M340, Siemens S7-1200 and AB ControlLogix protocol stacks respectively, and the simulated topology information is injected through OSPF routing to guide the attack traffic into the preset path diversion rules. This process calculates the reachability matrix between nodes in real time through the graph neural network to ensure service continuity after the topology change.
[0039] 104. Perform path obfuscation processing on the intrusion instruction stream based on the protocol stack mirror tunnel, and construct an attack path obfuscation network dynamically configured by the attack path diversion rule, wherein the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; In this step, the protocol stack mirror tunnel refers to a virtual channel for performing path obfuscation on the protocol stack layer.
[0040] Attack path obfuscation network refers to a dynamic network architecture that implements attack path obfuscation.
[0041] In the embodiment of the present application, multi-level obfuscation processing is performed on the intrusion instruction flow based on the protocol stack mirror tunnel. The transport layer interferes with path tracking through the TCP sequence number random offset algorithm (offset ±10%), the network layer adopts the IP fragmentation reorganization strategy (fragmentation ID conflict rate 25%) to increase the parsing complexity, and the application layer injects pseudo-business logic (such as simulating API call delay). The attack path diversion rules dynamically configure the flow table (such as OpenFlow Group Table) through the SDN controller, and deploy virtualized firewall rules in combination with NFV technology. Key parameters such as path hopping frequency (such as switching every 5 seconds) and protocol distortion gradient (0.1-0.5) are generated through a multi-objective optimization algorithm (such as NSGA-II), and finally a confused network framework covering the entire protocol stack is constructed.
[0042] In response to the supply chain attack suffered by an e-commerce platform, a two-layer protocol obfuscation mechanism was deployed in the mirror tunnel. The outer layer uses Cloudflare's MASQUE framework to establish an HTTP / 3 tunnel, and the inner layer dynamically redirects the attacker's SQL injection instruction stream to the sandbox environment through protocol stack mirroring technology. When characteristic statements such as UNION SELECT are detected, the obfuscation engine immediately activates the 0-RTT session recovery mechanism of TLS 1.3, and switches the traffic to the trap node deployed with the WebLogic vulnerability environment while maintaining the TCP connection appearance. By calculating the Shannon entropy and KL divergence of the instruction stream in real time, the MTU value of the obfuscated tunnel is dynamically adjusted (fluctuating between 1280-1500 bytes), effectively interfering with the attacker's path mapping.
[0043] 105. A collaborative defense strategy is established based on the topology correlation parameter and the real-time status of the attack path obfuscated network. When the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
[0044] In this step, the dynamic attack and defense game mechanism refers to the collaborative rule system of dynamic confrontation between attack and defense strategies.
[0045] In the embodiment of the present application, a real-time collaborative strategy based on topological correlation parameters and obfuscated network status (such as node load, path exposure rate) is used to optimize attack and defense decisions using a game theory model (such as the Stackelberg game). When the parameter reaches a threshold (such as node correlation>0.9), the attacker's behavior pattern is predicted through a Bayesian network, and the node reorganization strategy (such as adjusting path redundancy) and interface deformation rules (such as protocol distortion intensity ±20%) are dynamically updated. Parameter synchronization uses a distributed consensus algorithm (such as Raft) to ensure consistency, and ultimately generates a dynamic attack and defense game mechanism containing a strategy probability distribution (such as 80% enabling path obfuscation and 20% enabling protocol deformation) to achieve a dynamic confrontation closed loop.
[0046] In the network defense system of a multinational enterprise, when the topology correlation parameter detects that more than 72% of SSH cracking attempts originate from the same BGP autonomous domain, the collaborative defense engine simultaneously activates a triple response mechanism: first, the black hole routing policy is sent to the border router through BGP Flowspec; second, the SSH node in the virtual asset map is reconstructed, and its protocol stack is switched to the OpenSSH 8.9p1 version containing the CVE-2023-38408 vulnerability feature; at the same time, the interface deformation rules are dynamically updated, and a 32-bit rainbow table identifier is implanted in the TCP window scaling factor field. This process continuously optimizes the policy parameters through the reinforcement learning model, extending the node survival time by 18.6% after each attack and defense interaction, effectively improving the adaptive ability of the defense system.
[0047] In summary, through steps 101 to 105, a virtual asset map driven by dynamic topological disturbance is constructed, and a protocol fingerprint obfuscation mechanism is combined to generate highly simulated virtual nodes and interactive links, and interface deformation rules are implanted based on session context features to form a dynamic trapping interface group with controllable protocol stack layer and service logic, so as to realize active induction of attack behavior and deep disguise of protocol features. The topological correlation parameters are extracted by using the protocol stack interaction between the attacker and the trapping interface to trigger the node reorganization and attack path diversion rules of the virtual asset map, and a path obfuscation network is constructed through the protocol stack mirror tunnel to divert the intrusion instruction flow to the dynamic trapping interface protocol stack layer, so as to form multi-hop concealment of the attack path and precise control of the instruction flow. Based on the collaborative defense strategy of topological correlation parameters and obfuscated network status, the node reorganization and interface deformation rules are updated in real time to build a closed-loop defense system of "attack induction-path obfuscation-strategy iteration", which significantly improves the complexity of attacker network mapping and protocol fingerprint recognition, enhances the system's dynamic interference and countermeasure capabilities against advanced threats such as APT attacks and multi-protocol penetration, and realizes the paradigm upgrade of network defense from passive response to active game.
[0048] In order to build an intelligent, adaptive and efficient network defense system, we deeply analyze the protocol fingerprint and time series characteristics of attackers, and combine the dynamic weight calculation and node reorganization strategy of virtual asset maps to achieve accurate identification and dynamic defense of attack behaviors. By adjusting the protocol camouflage strength and attack path diversion rules, we can confuse the attacker's detection path, improve the system's active defense capabilities, reduce the threat of network attacks, and ensure the security of key assets and business continuity.
[0049] In some examples, as described in step 103, the topology correlation parameter is obtained by using the attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link, and the topology correlation parameter triggers the node reorganization strategy of the virtual asset map and constructs the attack path diversion rule, including: 201. Perform protocol fingerprint and time series analysis on the attacker's operation sequence in the interactive link, and extract an operation feature vector including a source-target port mapping relationship and an instruction interval duration; In step 201, protocol fingerprint refers to a technology for identifying the type of network protocol through protocol header features.
[0050] Time series analysis refers to the method of analyzing the interval regularity of operation instructions in chronological order.
[0051] The source-destination port mapping relationship refers to the correspondence between the source port and the destination port in the attack traffic.
[0052] The instruction interval refers to the time difference between the attacker's operation instructions.
[0053] The operational feature vector refers to a multidimensional vector that fuses the port mapping and timing features.
[0054] In the embodiment of the present application, the attack traffic is parsed by deep packet inspection (DPI) technology and time series analysis algorithm. First, the protocol type of the network data packet is identified based on the predefined protocol fingerprint library (such as the Suricata rule set), and metadata such as the source port, target port and protocol flag are extracted to construct a port mapping relationship matrix. Subsequently, the dynamic time warping (DTW) algorithm is used to divide the operation instruction stream into time windows (the window size is 5ms), and the time series characteristics such as the mean, variance and kurtosis of the instruction interval are counted. The co-occurrence frequency of the port mapping is calculated by hash aggregation of the traffic session, and the coefficient of variation of the instruction interval is generated based on the ratio of the standard deviation to the mean in the sliding window. Finally, the discrete port relationship and the continuous time series data are integrated into a 37-dimensional operation feature vector through feature fusion technology as the input primitive for subsequent analysis.
[0055] 202. Generate a dynamic weight vector according to the node distribution state of the operation feature vector in the virtual asset map, and obtain the topology correlation parameter through interactive calculation of the dynamic weight vector and the protocol stack behavior mode; In step 202, the virtual asset map refers to the logical topology map of the network assets (including nodes and connection relationships).
[0056] The node distribution state refers to the attribute distribution of the node in the graph (such as information entropy value).
[0057] The dynamic weight vector refers to the weight matrix generated based on the node information entropy.
[0058] The protocol stack behavior model refers to the algorithm module that analyzes the protocol interaction logic.
[0059] The topological correlation parameter refers to the quantitative value of the matching degree between attack behavior and asset topology.
[0060] In the embodiment of the present application, the topological correlation calculation is realized based on the operation feature vector using the graph embedding model and the dynamic weight allocation mechanism. First, the attributes (protocol type, number of historical connections) of the nodes (such as hosts, services) in the virtual asset graph are embedded with the operation feature vector by the graph neural network (GNN) to generate a node vector representation. The node distribution state is quantified by information entropy (entropy range 0.68-1.24), and the correlation weight between the feature vector and the node is calculated by combining the attention mechanism. The protocol stack behavior pattern adopts a matrix decomposition algorithm to perform singular value decomposition (SVD) on the node vector and the weight vector to extract the potential correlation pattern. Finally, the matching degree between the node relationship and the protocol stack behavior characteristics is calculated by cosine similarity, and the topological correlation parameter in the range of 0-1 is output (the calculation error rate is ≤8%), which is used to measure the coupling strength between the attack behavior and the asset logical topology.
[0061] 203. Analyze the protocol stack behavior pattern of the virtual asset map using the topology correlation parameter, and activate a node reorganization strategy that matches the protocol stack layer of the dynamic trapping interface; In step 203, the protocol stack layer matching refers to the consistency comparison between the attack traffic and the trapping interface in the protocol layer.
[0062] Dynamic trapping interface refers to a virtual interface that simulates a real service.
[0063] Node reorganization strategy refers to the defense rules that optimize node connection relationships.
[0064] In the embodiment of the present application, dynamic topology reconstruction is achieved through reverse matching of the protocol stack level and reinforcement learning. Based on the topology correlation parameters, the OSI seven-layer protocol reverse parsing technology (such as TCP / IP state machine modeling) is used to extract the behavioral characteristics of the attack traffic at the transport layer (SYN retransmission rate) and the application layer (HTTP method distribution), and the similarity is compared with the protocol stack configuration of the dynamic trapping interface (such as the simulated TLS handshake process). If the similarity exceeds the threshold (such as 0.85), the node reorganization engine based on the Q-Learning algorithm is triggered: the defense benefits of different node connection strategies (such as trapping success rate, resource consumption ratio) are evaluated through the reward function, and the logical connection relationship of the nodes in the virtual asset map is dynamically adjusted (such as generating abnormal ICMP redirection messages and injecting virtual DNS resolution records). Finally, a network view that is inconsistent with the attacker's expected topology is generated, forcing the attacker to enter the preset trapping area.
[0065] 204. Adjust the protocol camouflage strength of the interactive links of the virtual asset map based on the node reorganization strategy, and generate an attack path diversion rule including a protocol stack layer mapping relationship.
[0066] In step 204, protocol spoofing strength adjustment refers to a technique of dynamically modifying a protocol field to interfere with an attacker's identification.
[0067] The protocol stack layer mapping relationship refers to the logical correspondence rules between different protocol layers.
[0068] Attack path diversion rules refer to the flow table strategy that directs attack traffic to the honeypot.
[0069] In the embodiment of the present application, based on the topological structure after the node reorganization, the protocol field dynamic obfuscation and path decision model are used to realize the attack traffic control. In the protocol camouflage layer, the attacker's protocol fingerprint recognition is interfered by randomizing the IP identifier field, dynamically adjusting the TCP window size and sequence number offset (distortion rate 15-30%), and the camouflage strength coefficient is dynamically adjusted according to the topological correlation parameter. The attack path diversion uses the hidden Markov model (HMM) to predict the attacker's detection path, combined with the protocol stack layer mapping relationship (such as disguising HTTP traffic as gRPC protocol), and sends OpenFlow rules through the SDN controller to guide suspicious traffic to the honeypot cluster or traffic cleaning node. The generation of attack path diversion rules depends on a multi-objective optimization algorithm (such as NSGA-II). Under the constraints of the number of path branches ≥ 5 and the misjudgment rate < 6%, the balance between attack path concealment and lossless transmission of business flows is achieved, and the diversion strategy table containing the protocol stack layer mapping label is finally output.
[0070] Here is a specific example: In the scenario of financial system defense against advanced persistent threat (APT) attacks, the virtual asset map deployed by a bank detected abnormal interactive links. The attacker launched a multi-stage penetration of the core database node by disguising as legitimate HTTPS traffic (source port 443). The operation sequence was identified in the protocol fingerprint analysis as non-standard TLS handshake characteristics and abnormal heartbeat packet intervals (the standard deviation of the instruction interval duration reached 0.8 seconds), forming an operation feature vector containing 32 dimensions. When the vector was mapped to the virtual asset map, the node distribution status showed that 80% of the attacker's detection behavior was concentrated on the transaction settlement module-related nodes. The system embedded the information entropy of the calculation node (reaching 1.15) through the graph neural network, generated a dynamic weight vector and interacted with the protocol stack behavior pattern, and output a topology correlation parameter of 0.92, indicating that the attack path is highly coupled with the business logic. Based on this parameter, the system activated the node reorganization strategy of the dynamic trapping interface, replaced the real database service node with a honeypot node that simulates the Oracle protocol at the application layer, and injected a virtual TCP window scaling factor (distortion rate 25%) at the transport layer. Finally, by adjusting the strength of the protocol disguise, the attacker's SQL injection traffic is diverted to the sandbox environment disguised as the SWIFT gateway, and a diversion rule containing the mapping relationship between TLS1.3 and HTTP / 2 protocol stack is generated to achieve full induction and traceability of attacker behavior. This embodiment integrates threat intelligence association, protocol stack dynamic obfuscation and topology deception technology, and completely covers the closed loop of attack chain disposal from feature extraction to path control.
[0071] In summary, through steps 201 to 204, the multi-dimensional operation feature vector is extracted through the protocol fingerprint and time series analysis of the attacker's operation sequence, and the dynamic weight vector is generated in combination with the node distribution of the virtual asset map, the protocol stack behavior mode is driven to accurately calculate the topology correlation parameter, and the dynamic mapping relationship between the attack behavior and the network topology is constructed. Based on the topology correlation parameter, the node reorganization strategy of the protocol stack layer matching is activated, the virtual asset interaction link is dynamically reconstructed and the protocol camouflage intensity gradient is adjusted, and the attack path diversion rule integrating the protocol stack layer mapping relationship is generated. This technology realizes the intelligent generation and real-time optimization of the attack path diversion rule through the synergistic mechanism of deep analysis of attack features and dynamic adaptation of topological states, significantly improves the complexity of attacker protocol fingerprint identification and port mapping relationship tracing, enhances the dynamic interference and covert countermeasure capability of the virtual asset map to the attack behavior, and forms a closed-loop defense system of "feature extraction-weight adaptation-topology reconstruction-path diversion", effectively responds to multi-protocol penetration and advanced persistent threats, and provides dynamic and hierarchical active defense support for network attack and defense confrontation.
[0072] In order to build a protocol stack-level adaptive defense system for complex attack chains, the limitations of traditional static defense strategies are broken through the deep integration of protocol stack-level feature extraction and dynamic trapping interface state feedback. Based on the multi-dimensional analysis of protocol fingerprint matching, node connection density threshold and protocol camouflage intensity gradient, combined with the real-time state matrix of the dynamic trapping interface, the node reorganization strategy parameters are accurately calculated to achieve priority-driven adjustment at the protocol stack level, improve the system's active interference capability against advanced threats and the attack path concealment effect, and finally form an integrated intelligent defense closed loop of "feature extraction-state feedback-strategy activation".
[0073] In some examples, as described in step 203, the topology correlation parameter is subjected to a protocol stack behavior pattern analysis of the virtual asset map, and a node reorganization strategy matching the protocol stack layer of the dynamic trapping interface is activated, including: 301. Perform protocol stack level feature extraction on the topology correlation parameter, separate the protocol fingerprint matching degree, the node connection density threshold and the protocol camouflage strength gradient, and generate a protocol stack behavior pattern feature vector; In step 301, the protocol fingerprint matching degree refers to the quantitative value of the similarity between the attack traffic and the standard protocol features.
[0074] The node connection density threshold refers to the critical value of the node connection strength in the graph.
[0075] The protocol camouflage strength gradient refers to the dynamic adjustment step size of the protocol camouflage strength.
[0076] The protocol stack behavior pattern feature vector refers to a multi-dimensional vector that integrates protocol layer features.
[0077] In the embodiment of the present application, it is implemented through the protocol stack hierarchical feature decomposition technology. First, the topological correlation parameters are hierarchically parsed, and the protocol fingerprint matching algorithm (such as protocol field matching based on Jaccard similarity) is used to calculate the similarity between the attack traffic and the standard protocol (matching range 0-1). The node connection density threshold quantifies the connection strength of the node in the graph through the degree centrality algorithm in graph theory (such as the PageRank improved model) (threshold range 0.1-0.9). The protocol camouflage strength gradient is dynamically adjusted according to the historical attack data through the gradient descent optimization algorithm (gradient step size 0.15). Finally, the principal component analysis (PCA) is used to reduce the dimensionality of the three types of features into a protocol stack behavior pattern feature vector (dimension 16) as input for subsequent analysis.
[0078] 302. Compare the protocol stack behavior pattern feature vector with the protocol stack layer of the dynamic trapping interface in a fingerprint library, and select a protocol stack layer matching subset with a matching degree higher than a threshold according to a port mapping rule of the protocol layer; In step 302, the protocol stack layer of the dynamic trapping interface refers to the protocol stack configuration that simulates the real service.
[0079] Port mapping rules refer to the correspondence between ports and protocol layers.
[0080] The protocol stack layer matching subset refers to the set of protocol stack layers that match the attack traffic.
[0081] In an embodiment of the present application, based on the protocol stack behavior pattern feature vector, a pattern matching engine (such as a combination of regular expressions and hidden Markov models) is used to compare with the protocol stack hierarchical fingerprint library of the dynamic trapping interface. The fingerprint library contains port mapping rules (such as port 80 only allows GET / POST) for the transport layer (such as TCP window scaling rules) and the application layer (such as HTTP method whitelist). The matching threshold (such as 0.85) is set by a dynamic threshold algorithm (adaptively adjusted based on historical attack success rates) to filter out protocol layer matching subsets (such as allowing HTTPS but intercepting abnormal TLS versions). Finally, a list of matching subsets is generated (such as {transport layer: 0.91, application layer: 0.78}) for subsequent interface status polling.
[0082] 303. Based on the protocol stack layer matching subset, poll the protocol stack layer activation status of the dynamic trapping interface, detect the protocol masquerade response delay and session context integrity mark of the interface at the transport layer / application layer, and obtain the dynamic trapping interface real-time status matrix; In step 303, the protocol masquerade response delay refers to the time difference of the dynamic trapping interface responding to the attack traffic.
[0083] The session context integrity tag is a verification mark for the continuity of session data packets.
[0084] The real-time status matrix of the dynamic trapping interface refers to the storage matrix of the status of each protocol layer of the interface.
[0085] In the embodiment of the present application, based on the protocol layer matching subset, active detection technology is used to poll the dynamic trapping interface. The transport layer camouflage response delay is calculated by the difference between the ICMP delay echo and the TCP handshake timestamp (delay ≤ 5ms), and the application layer session context integrity mark verifies the continuity of the data packet through the session hash chain algorithm (such as SHA-256 iterative hash) (integrity mark accuracy ≥ 92%). The detection results are stored in the form of a matrix, including the status of each protocol layer (such as transport layer delay 4ms, application layer integrity mark 0x9a3f), forming a dynamic trapping interface real-time state matrix (dimension N×M) for policy parameter generation.
[0086] 304. Calculate the node connection density adjustment coefficient and the protocol camouflage weight according to the session integrity mark in the real-time state matrix of the dynamic trapping interface, and generate a node reorganization strategy parameter table; In step 304, the node connection density adjustment coefficient refers to a dynamic adjustment factor of the node connection strength.
[0087] The protocol masquerade weight refers to the assigned value of the protocol masquerade strength.
[0088] The node reorganization strategy parameter table refers to a table containing reorganization strategy parameters.
[0089] In the embodiment of the present application, the node connection density adjustment coefficient (range 0.5-1.2) is calculated using the entropy weight method according to the session integrity mark in the real-time state matrix to reflect the node credibility (such as the coefficient drops to 0.6 when the integrity mark error rate is greater than 15%). The protocol camouflage weight is dynamically allocated (weight range 0.3-0.7) through a linear regression model (based on historical attack characteristics and camouflage success rate training). Finally, the integrated parameters generate a node reorganization strategy parameter table (such as {transport layer: connection coefficient 0.8, camouflage weight 0.6}) as the basis for policy activation.
[0090] 305. Analyze the node reorganization strategy parameter table, activate the node connection density adjustment and protocol camouflage weight loading of the corresponding layer according to the protocol stack layer priority, and complete the activation of the node reorganization strategy.
[0091] In step 305, the protocol stack layer priority refers to the activation order of different protocol layers.
[0092] Node connection density adjustment refers to the operation of dynamically adjusting the node connection strength.
[0093] Protocol masquerade weight loading refers to the process of applying masquerade weights to the protocol stack.
[0094] In the embodiment of the present application, the policy parameter table is sorted by a hierarchical priority decision tree algorithm (such as a C4.5 classification tree), and the protocol stack layer with a high threat level is activated first (such as transport layer priority > application layer). The node connection density is adjusted using SDN flow table dynamic injection technology (such as OpenFlow's Group Table modification), and the protocol camouflage weight loading is achieved through kernel-mode protocol stack hot patching (such as eBPF program dynamically modifying TCP option fields). Finally, the activation of the node reorganization strategy is completed (such as a 30% increase in the transport layer TCP sequence number offset), forming a dynamic defense closed loop.
[0095] Here is a specific example: In the scenario of the securities industry responding to the targeted attack of the high-frequency trading system by the cross-border APT organization, a securities company detected an abnormal instruction flow disguised as the FIX protocol (Financial Information Exchange Standard) to penetrate the core matching engine. The attack traffic broke through the boundary protection through the non-standard TCP window scaling factor (the protocol fingerprint matching degree was only 0.62) and the abnormal heartbeat interval (standard deviation 1.2 seconds). The system generated a feature vector containing a 128-dimensional behavior pattern through the protocol stack layer feature extraction. The dynamic trapping interface found that 80% of the attacker's probing behavior focused on the Level2 market interface (port 50010) in the fingerprint library comparison, triggering the transport layer camouflage response (delay ≤ 3ms) and injecting a TCP sequence number offset with a distortion rate of 18%. At the same time, the application layer dynamically generated a pseudo market data packet containing a SHA3-512 hash chain to maintain the integrity of the session context. According to the sudden increase in transport layer delay (8ms) and the hash break mark of the application layer in the real-time state matrix, the system calculates the node connection density coefficient from 0.9 to 0.5, and increases the protocol disguise weight to 0.78, generating a reorganization strategy including TCP retransmission timeout parameters (200ms→50ms) and FIX session ID obfuscation rules. Finally, the transport layer flow table rules are activated according to the protocol stack priority, and the attack traffic is diverted to the honeypot cluster simulating the Nasdaq ITCH protocol. The distorted market field (amplitude ±15%) is dynamically loaded at the application layer at the same time, successfully inducing the attacker to trigger 20 abnormal orders and capturing its C2 server fingerprint. This solution realizes full-link dynamic confrontation from protocol obfuscation, behavior trapping to attack countermeasures.
[0096] In summary, through steps 301 to 305, the protocol stack hierarchical feature extraction separates the protocol fingerprint matching degree, the node connection density threshold and the camouflage strength gradient, generates a multi-dimensional behavior pattern feature vector, combines the protocol stack hierarchical fingerprint library of the dynamic trapping interface to compare and screen the high-matching hierarchical subset, and establishes a dynamic mapping relationship between the protocol stack hierarchical behavior characteristics and the network topology. Based on the polling detection of the protocol camouflage response delay and the session context integrity mark of the dynamic trapping interface, the interface real-time state matrix is constructed, and the node connection density adjustment coefficient and the protocol camouflage weight calculation are driven by the session integrity mark to generate a refined node reorganization strategy parameter table. This technology realizes the dynamic adjustment of node connection density and the adaptive loading of camouflage weights through the protocol stack hierarchical priority strategy activation mechanism, forms a deep coupling of the protocol stack hierarchical features and the topology reconstruction strategy, significantly improves the protocol stack hierarchical interference accuracy and response real-time performance of the virtual asset map to the attack behavior, and enhances the multi-level collaborative defense capability of the attack path obfuscated network. Its core value lies in building a closed-loop control system of "feature analysis-state assessment-strategy generation". Through the precise linkage of dynamic adaptation of the protocol stack level and node reorganization strategy, it can achieve deep concealment of attack paths and continuous confusion of protocol fingerprints, providing multi-dimensional and adaptive active defense support for complex network attack and defense confrontation.
[0097] In order to build a dynamic defense mechanism of adaptive protocol stack camouflage and path obfuscation, the defect of traditional static rule base that it is difficult to deal with protocol layer jump attacks is solved. Through the dynamic analysis of protocol stack layer migration rules and camouflage strength gradient, combined with the deep mapping relationship of virtual asset map, the attack path diversion strategy and protocol stack behavior are accurately matched, breaking through the attacker's reverse modeling ability of network topology. Relying on the gradient constraints of protocol response logic (such as the coordination of transport layer and application layer camouflage strength) and the real-time decision-making of the diversion engine, a closed-loop defense system of "protocol obfuscation-path interference-resource optimization" is formed to improve the active defense efficiency against complex threats such as APT attacks and lateral penetration.
[0098] In some examples, as described in step 204, adjusting the protocol camouflage strength of the interactive links of the virtual asset map based on the node reorganization strategy to generate an attack path diversion rule including a protocol stack layer mapping relationship includes: 401. Perform protocol camouflage strength gradient analysis on the protocol stack layer migration rule in the node reorganization strategy to generate camouflage strength gradient parameters that match the dynamic trapping interface protocol stack layer; In step 401, the protocol stack layer migration rule refers to the state transfer logic between the layers of the protocol stack.
[0099] The protocol camouflage strength gradient refers to the dynamic adjustment step size of the protocol camouflage strength.
[0100] The camouflage strength gradient parameter refers to the camouflage strength value that matches the dynamic trapping interface.
[0101] In an embodiment of the present application, camouflage parameters are generated by dynamic analysis of protocol stack layer migration rules. First, a layer migration matching algorithm (such as state transition probability calculation based on a hidden Markov model) is used to analyze the migration logic of each layer of the protocol stack (such as the transport layer and the application layer) in the node reorganization strategy, and the camouflage strength requirements of different layers are calculated in combination with the protocol stack configuration of the dynamic trapping interface (such as a simulated TLS version or HTTP method set). The gradient step size (such as 0.05-0.3) is determined by the balance between the protocol distortion efficiency and resource consumption in the historical attack data. Finally, the camouflage strength of each layer is iteratively adjusted through the gradient descent optimization algorithm to generate a gradient parameter table that matches the dynamic trapping interface protocol stack layer (such as a transport layer strength of 0.7 and an application layer strength of 0.5) as the basis for subsequent mapping.
[0102] 402. Perform protocol stack layer matching processing on the interactive links of the virtual asset map according to the camouflage strength gradient parameter to generate a protocol stack layer mapping table including the correlation relationship between protocol stack depth and camouflage strength; In step 402, the protocol stack depth refers to the number of layers in the protocol stack (such as the OSI seven-layer model).
[0103] The protocol stack layer mapping table refers to a correlation table between the protocol stack depth and the camouflage strength.
[0104] In the embodiment of the present application, based on the camouflage strength gradient parameter, the interactive links of the virtual asset map are traversed using graph database query technology (such as Neo4j's Cypher language) to extract the protocol stack depth (such as the number of OSI layers) and link attributes (such as port open status, service type). The linear relationship between the protocol stack depth and the camouflage strength is calculated through a hierarchical correlation algorithm (such as the Pearson correlation coefficient), and links with a correlation higher than a threshold (such as 0.8) are screened out. Finally, a protocol stack hierarchical mapping table is generated, which contains fields such as "protocol level (transport layer) - camouflage strength (0.7) - associated service (HTTPS)" for dynamically allocating camouflage logic.
[0105] 403. Performing dynamic allocation processing of camouflage strength on the protocol response logic of the interactive link based on the protocol stack layer mapping table, and generating a link camouflage configuration parameter including a protocol stack layer priority tag; In step 403, the protocol response logic refers to the processing rules of the protocol stack for attack traffic.
[0106] Link masquerade configuration parameters refer to the configuration values of link masquerade strength and priority.
[0107] The protocol stack layer priority tag refers to the activation order identification of different protocol layers.
[0108] In the embodiment of the present application, in combination with the protocol stack layer mapping table, a dynamic priority marking algorithm (such as weight allocation based on Q-Learning) is used to allocate camouflage strength to the protocol response logic of the interactive link. The transport layer camouflage strength is smoothed by sliding window mean filtering for historical attack interference data (such as TCP sequence number distortion rate), and the application layer dynamically adjusts the weight according to the session context integrity mark (such as the number of hash chain breaks). The key parameter "protocol stack layer priority mark" (such as transport layer priority 1, application layer priority 2) is generated through a threat level classification model (such as random forest), and finally outputs a link camouflage configuration parameter table (such as {transport layer: strength 0.7, priority 1}) for the diversion engine to call.
[0109] 404. Input the link camouflage configuration parameters into the protocol stack diversion engine of the attack path obfuscation network to generate a path diversion decision instruction linked to the dynamic trapping interface protocol stack layer; In step 404, the attack path obfuscation network refers to a network architecture used to interfere with the attacker's detection path.
[0110] The protocol stack traffic diversion engine refers to an algorithm module that generates traffic diversion decisions based on the protocol stack hierarchy.
[0111] Path diversion decision instructions refer to the set of rules for redirecting attack traffic.
[0112] In an embodiment of the present application, the link camouflage configuration parameters are input into the protocol stack diversion engine of the attack path obfuscation network, and the engine balances path anonymity and resource consumption based on a multi-objective optimization model (such as the NSGA-II algorithm). Through the protocol stack layer linkage rules (such as forcing TCP window scaling to be enabled when the transport layer camouflage strength is greater than 0.6), combined with the protocol stack status of the dynamic trapping interface (such as response delay ≤ 5ms), a path diversion decision instruction set is generated. For example, the instruction includes "redirecting 80% of the attack traffic to the honeypot cluster, and increasing the TCP sequence number distortion rate to 25%", and is sent to the network device through the API interface of the SDN controller (such as OpenDaylight).
[0113] 405. Perform protocol stack response path reconstruction processing on the interactive links of the virtual asset map through the path diversion decision instruction to form an attack path diversion rule including a protocol camouflage strength gradient constraint.
[0114] In step 405, the protocol stack response path reconstruction refers to dynamically adjusting the path of the protocol stack to process the attack traffic.
[0115] The protocol camouflage strength gradient constraint refers to the dynamic adjustment restriction condition of the camouflage strength.
[0116] Attack path diversion rules refer to a set of rules that direct attack traffic to a specific path.
[0117] In the embodiment of the present application, the diversion decision instruction is executed by the protocol stack response path reconstruction engine, and the protocol field dynamic replacement technology (such as eBPF program to modify the IP ID field in real time) and the path probability confusion algorithm (such as random jump based on Poisson distribution) are adopted. The transport layer reconstruction includes dynamic compression of TCP retransmission timeout parameters (such as 200ms→50ms), and the application layer injects pseudo-business logic (such as simulating database query delay). The final generated diversion rules contain gradient constraints (such as protocol camouflage strength gradient step ≤ 0.2), and are synchronized to the entire network devices based on the BGP flow specification (FlowSpec), forming a strong obfuscation and precise control capability of the attack path.
[0118] Here is a specific example: In the cloud-native environment, in the defense of supply chain attacks against container orchestration systems, a financial technology company detected that attackers used Kubernetes API Server vulnerabilities to inject malicious Pods and infiltrate the cluster control plane by simulating gRPC protocol metadata (protocol fingerprint matching degree 0.55) and abnormal etcd query frequency (120 times per second). The system performs camouflage strength gradient analysis based on protocol stack layer migration rules (such as the HTTP / 2 frame layer jump mode of API requests), and uses zero-knowledge proof technology to generate transport layer TLS1.3 session key camouflage gradients (strength 0.7) and application layer Protobuf serialization distortion gradients (strength 0.6). Through the virtual asset graph traversal (including 200 nodes and 1,500 cross-namespace links), combined with the OSI seven-layer protocol depth to establish a hierarchical mapping table (such as the network layer Calico policy associated camouflage strength 0.8), dynamically allocate link camouflage configuration parameters-the transport layer enables TCP timestamp random offset (±15ms) and marks priority 1, and the application layer injects pseudo CRD (Custom Resource Definition) response logic with priority 2. The attack path obfuscation network's traffic diversion engine generates decision instructions based on the hypergraph backbone extraction algorithm: redirect 75% of abnormal API requests to a honeypot cluster simulating the Istio service mesh, forcibly enable the QUIC protocol (camouflage strength 0.75) at the transport layer and compress the TLS handshake delay to 20ms, and dynamically generate pseudo ConfigMap data containing the SHA-256 checksum chain at the application layer. Finally, the protocol stack response path is reconstructed through the eBPF program, the distortion identifier (offset ±8 bytes) is implanted at the IP fragmentation layer, and the pseudo stream ID is injected into the HTTP / 2 frame header (conflict rate 22%), forming a gradient constraint rule - the transport layer camouflage strength fluctuation threshold ≤ 0.15, and the application layer distortion field update cycle ≤ 5 seconds. This solution causes the attacker to misjudge 47% of the cluster nodes as the real control plane, successfully captures 3 hidden C2 channels, and extends the lateral movement time from 8 minutes to 32 minutes, realizing adaptive topology obfuscation defense in a cloud-native environment.
[0119] In summary, through steps 401 to 405, a dynamic defense system that links the protocol stack camouflage strength gradient with the attack path obfuscation is implemented. The camouflage strength parameters that match the dynamic trapping interface are generated by parsing the protocol stack layer migration rules, and the link camouflage configuration parameters are dynamically allocated in combination with the protocol stack depth mapping of the virtual asset map, driving the protocol stack diversion engine of the attack path obfuscation network to generate path diversion decision instructions. Based on the protocol stack response path reconstruction, a gradient-constrained diversion rule is formed to increase the misjudgment rate of attacker network detection, while reducing the consumption of defense resources, and achieving the coordinated optimization of attack path concealment and defense efficiency.
[0120] In order to build an adaptive path obfuscation system for multi-protocol layer hopping attacks, the defect that traditional static rule bases are difficult to cope with dynamic switching of protocol stack layers is solved. Through protocol stack layer feature extraction and dynamic weight adaptation, the camouflage parameters and attack paths are accurately matched; relying on path diversion optimization and obfuscation rule reconstruction technology, the attacker's reverse modeling ability of network topology is broken; based on the multi-dimensional fusion of decision instructions (protocol stack linkage parameters, path hopping logic), a closed-loop defense link of "dynamic analysis-intelligent decision-making-precise control" is formed, which improves the active interference efficiency of high-level threats such as zero-day vulnerability exploits and cross-layer penetration, and ensures the concealment and stability of key business links.
[0121] In some examples, as described in step 404, the link camouflage configuration parameters are input into the protocol stack diversion engine of the attack path obfuscation network to generate a path diversion decision instruction linked to the dynamic trapping interface protocol stack layer, including: 501. Perform protocol stack level analysis on the link masquerade configuration parameter, extract dynamic attributes bound to the protocol stack level in the link masquerade configuration parameter, and generate masquerade level features; In step 501, the link masquerade configuration parameters refer to the configuration values of the link masquerade strength and priority.
[0122] Protocol stack layer analysis refers to the decomposition and extraction of features at each layer of the protocol stack.
[0123] Dynamic attributes refer to the changing characteristics of camouflage strength that are bound to the protocol stack layer.
[0124] The camouflage level feature refers to the feature matrix that integrates the protocol stack level and camouflage attributes.
[0125] In an embodiment of the present application, the dynamic attributes in the link camouflage configuration parameters are extracted by protocol stack hierarchical parsing technology. First, protocol reverse engineering (such as protocol field parsing based on Wireshark) is used to deeply parse the link camouflage configuration parameters (such as TCP timestamp offset, HTTP header distortion rules) to separate the features bound to the OSI layer (such as transport layer, application layer). The dynamic attributes (such as the frequency of change of the TCP window scaling factor) are calculated by the sliding window statistics method (window size 1 second) and the principal component analysis (PCA) dimensionality reduction processing is combined to eliminate redundant features. Finally, a camouflage hierarchical feature matrix containing hierarchical labels (such as transport layer labels 0x01) and attribute strengths (such as distortion rate 18%) is generated as the input for dynamic weight adaptation.
[0126] 502. Perform dynamic weight adaptation based on the camouflage level feature and the protocol stack layer of the dynamic trapping interface to generate linkage matching parameters; In step 502, the protocol stack layer of the dynamic trapping interface refers to the protocol stack configuration that simulates the real service.
[0127] Dynamic weight adaptation refers to the weight allocation based on masquerade features and interface level matching.
[0128] The linkage matching parameters refer to the parameter table after the masquerade features are matched with the interface level.
[0129] In the embodiment of the present application, based on the camouflage level characteristics, a dynamic weight adaptation algorithm is used to achieve protocol stack level matching with the dynamic trapping interface. The graph neural network (GNN) is used to embed the protocol stack level of the dynamic trapping interface (such as the simulated TLS handshake process), and the matching items are screened by cosine similarity calculation (threshold ≥ 0.85) combined with the attribute strength in the camouflage level characteristics. The weight allocation quantifies the node information entropy (such as the transport layer information entropy 0.75) and the camouflage strength requirement (such as the application layer requires a strength of 0.6) through the entropy weight method to generate a linkage matching parameter table (such as {transport layer: weight 0.7, application layer: weight 0.5}). The parameter table eliminates dimensional differences through matrix normalization to ensure the comparability of weights across protocol levels.
[0130] 503. Optimize the path diversion of the linkage matching parameters, and generate path diversion optimization features in combination with the dynamic path selection strategy of the attack path obfuscation network; In step 503, path diversion optimization refers to optimizing the attack path diversion ratio based on a multi-objective optimization model.
[0131] The dynamic path selection strategy refers to the path hopping rules of the attack path obfuscating network.
[0132] The path diversion optimization feature refers to the optimization result including the diversion ratio and camouflage strength.
[0133] In an embodiment of the present application, the linkage matching parameters are optimized for path diversion through a multi-objective optimization model (such as the NSGA-III algorithm). Combined with the dynamic path selection strategy of the attack path obfuscation network (such as path hopping decision based on reinforcement learning Q-Learning), the optimal diversion ratio (such as 80% traffic redirected to the honeypot) is calculated with minimizing the attack path exposure rate and maximizing resource utilization as the objective function. The path diversion optimization features include protocol stack layer weights (such as transport layer weight 0.8), number of path branches (≥5) and camouflage strength gradient (step size 0.1). Finally, the optimal solution set is determined through Pareto front screening, and an optimized feature vector containing diversion ratio, camouflage strength and path topology is generated.
[0134] 504. Reconstruct the path diversion optimization feature and the obfuscation rule of the attack path obfuscation network according to rule constraints to generate a path obfuscation feature; In step 504, the obfuscation rule refers to a path masquerading rule of the attack path obfuscation network.
[0135] Rule-constrained reconstruction refers to the dynamic integration process of optimization features and obfuscation rules.
[0136] Path obfuscation features refer to the final result of integrating optimization features and obfuscation rules.
[0137] In the embodiment of the present application, the obfuscation rules of the path diversion optimization feature and the attack path obfuscation network are reconstructed with rule constraints. Formal verification technology (such as BAN logic model) is used to check the consistency of obfuscation rules (such as IP fragmentation randomization rate, TLS session ID obfuscation period), and eliminate conflicting rules (such as disabling TCP retransmission when the fragmentation randomization rate is greater than 40%). The diversion ratio and camouflage strength in the optimization feature are dynamically loaded through a rule engine (such as Drools), and the path obfuscation features (such as IP fragmentation offset ±10 bytes, HTTP / 2 stream ID conflict rate 22%) are reconstructed, and a priority list of obfuscation rules is generated (such as the transport layer rule has a higher priority than the application layer). Finally, the path obfuscation feature matrix is output to ensure that there is no conflict between the rules and they are executable.
[0138] 505. Perform decision instruction fusion on the path obfuscation feature, integrate the dynamic parameters of the protocol stack layer linkage and the jump logic of the path camouflage sequence, and generate a dynamic path diversion decision instruction.
[0139] In step 505, decision instruction fusion refers to the process of integrating protocol stack linkage parameters and path jump logic.
[0140] Dynamic path diversion decision instructions refer to the final instruction set that controls the attack path diversion.
[0141] In the embodiment of the present application, the protocol stack linkage parameters and path camouflage jump logic in the path obfuscation feature are integrated through the decision fusion engine. A reinforcement learning framework (such as Deep Q-Network) is used to model the long-term benefits of the path jump sequence (such as extended attack residence time and reduced resource consumption), and the Markov decision process (MDP) is combined to predict the attacker's behavior pattern. Dynamic parameters (such as protocol stack layer weights, camouflage intensity gradients) and jump logic (such as switching path branches every 5 seconds) are used to generate a decision instruction set through a matrix fusion algorithm (such as Kronecker product), including flow table rules (such as OpenFlow's GroupBucket modification instructions) and protocol field distortion parameters (such as TCP sequence number offset ±15%). Finally, it is sent to the SDN controller to achieve dynamic concealment and precise control of the attack path.
[0142] Here is a specific example: In the scenario of smart grid defense against covert APT attacks on SCADA systems, a provincial power company discovered that attackers used the supply chain vulnerability of smart meter firmware to tamper with the time synchronization field of the MMS message of the IEC 61850 protocol, disguised themselves as legitimate distribution automation terminals to infiltrate the power dispatching system, and injected virtual PMU phasor measurement data to destroy the dynamic stability of the power grid. The system first performs protocol stack layer analysis on the link camouflage configuration parameters, extracts dynamic attributes such as the DL / T 860-6 TLS session key rotation period (45 seconds) of the transport layer and the namespace distortion factor (24%) of the IEC 61850-7-2 data set in the application layer, and constructs a camouflage layer feature matrix containing power-specific protocol stack labels. Based on the abnormal GOOSE message features captured by the power grid situation awareness platform, the Modbus TCP polling mechanism of the dynamic trapping interface is feature embedded through the spatiotemporal graph convolutional network, and the weight ratio of the transport layer and the data link layer (0.7:0.3) is calculated by the gray correlation analysis method, and a linkage matching table containing the SV message camouflage priority parameters is generated. Combined with the deep Q-Learning strategy of the attack path obfuscation network, with the goal of minimizing the exposure rate of substation nodes, 72% of abnormal power flow is intelligently diverted, and the wide-area measurement system delay constraint and protection device action logic verification threshold (≥4 levels) are embedded in the path diversion optimization feature. The compatibility of the IPsec tunnel encapsulation rules and the IEEE C37.118.2 data frame obfuscation strategy is verified by the Alloy formal modeling tool, and the path obfuscation feature containing the dynamic message signature (national secret SM9) and the synchronous phasor data concentrator (PDC) authentication mechanism is reconstructed. Finally, the federated reinforcement learning framework is used to integrate the dynamic parameters of the power protocol stack and the path jump sequence of the RTU device to generate power routing decisions based on the P4 programmable switch-forcing the OPC UA protocol to enable the MMS connection that has not passed the TEE trusted verification, and injecting pseudo measurement identifiers in the IEC 62351-3 encrypted message, successfully redirecting 29% of malicious control instructions to the digital twin substation cluster, and increasing the failure rate of the virtual data injection attack (FDI) constructed by the attacker to 93%.
[0143] In summary, through steps 501 to 505, a collaborative defense system of dynamic adaptation of the protocol stack layer and intelligent decision-making on path diversion is realized. The dynamic attributes in the link camouflage configuration parameters are extracted through protocol stack layer analysis, and the camouflage layer features are generated. Combined with the protocol stack layer weight adaptation of the dynamic trapping interface, the linkage matching parameters are generated. Based on the dynamic path selection strategy, combined with the reconstruction of the obfuscation rule constraints, the path diversion optimization features are generated. Finally, the dynamic path diversion instructions are generated through the fusion of decision instructions, so that the attacker's path detection misjudgment rate is improved, the defense response delay is compressed, and the global optimization of attack path concealment and resource consumption is achieved.
[0144] In order to build an intelligent defense system for dynamic topology evolution, we need to break through the lag in the response of traditional static rule bases to complex attack paths. Through real-time topology association analysis and dynamic adaptation of collaborative defense parameters, we can achieve accurate state perception of the attack path confusion network; relying on multi-dimensional threshold triggering and node reorganization strategy reconstruction technology, we can enhance the ability to respond quickly to topology mutation attacks; based on the attack and defense game mechanism, we can integrate multiple strategies (redundant path allocation, interface deformation rules) to form a closed-loop control system of "topology perception-strategy linkage-attack and defense confrontation", and improve the dynamic defense effectiveness against new threats such as APT attacks and lateral penetration.
[0145] In some examples, as described in step 105, according to the topology correlation parameter and the attack path confusion network real-time state collaborative defense strategy, when the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism, including: 601. Perform dynamic correlation analysis on the topological correlation parameters, extract the real-time change characteristics of the dynamic connection strength between nodes and the topological evolution path, and generate real-time topological correlation characteristics; In step 601, the topological association parameter refers to a quantitative index of the strength of the connection relationship between nodes.
[0146] Dynamic association analysis refers to the process of real-time analysis of topological association parameters.
[0147] The dynamic connection strength between nodes refers to the real-time changing strength of the connection between nodes.
[0148] The topology evolution path refers to the path trajectory of network topology changes over time.
[0149] Real-time topology-related features refer to a set of features that reflect dynamic changes in topology.
[0150] In the embodiment of the present application, first, the topological correlation parameters are analyzed in real time based on the dynamic graph convolutional network (DGCN), and the changing trend of the connection strength between nodes (such as the frequency of TCP session establishment and the BGP route update interval) is captured using a sliding time window (window size of 5 seconds), and the spatiotemporal pattern of the topological evolution path is identified through a time series clustering algorithm (such as DTW-KMeans). The dynamic connection strength is quantified by the traffic entropy value (calculated based on the source-destination IP quintuple distribution), and the topological evolution path is generated by comparing historical path fragments through a path similarity algorithm (such as the Jaccard index). Finally, the node connection strength matrix (dimension N×N) and the path evolution probability graph are integrated to construct a real-time topological correlation feature vector (containing 32 dynamic indicators) for subsequent policy adaptation.
[0151] 602. Dynamically adapt the defense strategy of the real-time topology association feature and the real-time state of the attack path obfuscated network to generate collaborative defense parameters; In step 602, the real-time status of the attack path obfuscation network refers to the current operating status of the attack path obfuscation network.
[0152] Dynamic defense strategy adaptation refers to the process of adjusting the defense strategy based on real-time status.
[0153] Collaborative defense parameters refer to the set of parameters after the strategy matches the network status.
[0154] In the embodiment of the present application, a multi-agent reinforcement learning framework is used to dynamically adapt the real-time topology-related features to the state of the attack path confusion network (such as node load and path hopping frequency). First, the real-time state features of the attack path confusion network (such as abnormal fluctuation rate of the number of node connections) are extracted through the graph attention mechanism (GAT), and tensor splicing is performed with the topology-related features to form a joint feature space. The collaborative defense parameters are calculated through the dual-depth Q network (DDQN) model, with the goal of maximizing defense benefits (attack path confusion success rate) and minimizing resource consumption. The output parameters include path redundancy allocation weights (0-1) and interface deformation rule switching cycles (50-200ms). Finally, a parameter matrix (dimension M×K) is generated to ensure real-time matching of defense strategies and network states.
[0155] 603. Perform multi-dimensional threshold triggering judgment based on the collaborative defense parameter, and generate a dynamic reorganization triggering instruction when the topology correlation parameter reaches a preset threshold; In step 603, the multi-dimensional threshold trigger determination refers to the process of combining multiple conditions to determine whether to trigger a reorganization instruction.
[0156] The preset threshold refers to a preset critical value that triggers policy adjustment.
[0157] The dynamic reorganization trigger instruction refers to the instruction signal that triggers the node reorganization strategy.
[0158] In the embodiment of the present application, first, the collaborative defense parameters are normalized (such as Min-Max standardization) and compared with preset thresholds (such as topological correlation parameter threshold 0.85, path confusion coverage threshold 90%). A fuzzy logic controller (such as the Mamdani model) is used to comprehensively determine multi-dimensional conditions (such as "node connection strength decline rate > 10% / s" and "path evolution deviation > 0.7") to trigger dynamic reorganization instructions. Key parameters are trained through historical attack data (such as logistic regression model prediction threshold sensitivity), and finally generate binary trigger instructions (0 / 1) and reorganization priority labels (levels 1-5) to drive subsequent strategy reconstruction.
[0159] 604. Performing strategy reconstruction on the node connection relationship of the attack path obfuscation network according to the dynamic reorganization trigger instruction to generate a node reorganization strategy, wherein the node reorganization strategy includes a real-time switching logic of a redundant path dynamic allocation rule and an interface deformation rule; In step 604, the node connection relationship strategy reconstruction refers to the strategy design for adjusting the connection relationship between nodes.
[0160] The redundant path dynamic allocation rule refers to the rule for dynamically allocating backup paths.
[0161] The real-time switching logic of interface deformation rules refers to the rule switching mechanism that dynamically adjusts interface characteristics.
[0162] The node reorganization strategy refers to the reorganization plan including path allocation and interface deformation.
[0163] In the embodiment of the present application, the node connection relationship is reconstructed through policy gradient reinforcement learning (PGRL). According to the trigger instruction priority, the network flow optimization algorithm (such as the Ford-Fulkerson improved model) is used to dynamically allocate redundant paths (such as enabling the backup path when the main path load is greater than 80%), and the interface deformation engine (such as hot replacement of protocol fields based on eBPF) is used to implement rule switching (such as rotating MAC address obfuscation rules every 100ms). The node reorganization strategy parameters (such as redundant path bandwidth ratio, interface deformation rule library version) are dynamically adjusted through the Bayesian optimization algorithm, and finally the policy file containing the path allocation rule table (JSON format) and the interface deformation instruction set (priority queue) is output and injected into the SDN controller for execution.
[0164] 605. The node reorganization strategy and the interface deformation rule are dynamically integrated into an attack and defense strategy, and the node reorganization logic and the interface deformation constraint condition are integrated to generate a dynamic attack and defense game mechanism.
[0165] In step 605, the interface deformation constraint condition refers to the restriction condition of the interface feature change.
[0166] Dynamic attack and defense strategy fusion refers to the coordination mechanism that integrates the strategies of both the attack and defense sides.
[0167] The dynamic attack and defense game mechanism refers to the rule system for the dynamic confrontation between the attacking and defending strategies.
[0168] In the embodiment of the present application, the node reorganization strategy and interface deformation rules are integrated based on the game theory model. The Stackelberg game framework is used to model the interaction between the offensive and defensive strategies. The defender calculates the optimal response strategy through a mixed strategy Nash equilibrium solver (such as the Lemke-Howson algorithm), and dynamically adjusts the node reorganization logic (such as the path switching frequency) and the interface deformation constraints (such as the upper limit of the protocol distortion rate). Key parameters (such as the attacker's profit matrix and the defense cost coefficient) are dynamically updated through adversarial sample generation technology (such as FGSM attack simulation), and finally generate an offensive and defensive decision tree containing a strategy probability distribution (such as 80% enabling path obfuscation and 20% enabling protocol deformation) and a real-time feedback mechanism to achieve a dynamic defense closed loop.
[0169] Here is a specific example: In the scenario of defending against cross-domain APT attacks in the urban rail transit power system, a subway power supply network discovered that attackers invaded the communication module of the train energy feedback device, tampered with the topology synchronization message of the IEC 61375-3 train bus protocol, simulated the connection status of the nodes in the adjacent power supply section (similarity 83%), and injected virtual traction substation load data (harmonic distortion rate 7.5%) to destroy the power supply stability. The system first dynamically correlated and analyzed the topological correlation parameters, extracted the dynamic connection strength between the power supply nodes and the real-time change characteristics of the topological evolution path based on the dynamic graph spatiotemporal network (DGSN), and generated a real-time topological correlation feature matrix containing the dynamic coupling coefficient of the power supply unit. Subsequently, the real-time topological features were dynamically adapted to the real-time state of the attack path confusion network through the federated deep reinforcement learning framework, and the Nash equilibrium optimization algorithm was used to calculate the weight ratio of the traction power supply layer and the signal control layer, and a collaborative defense parameter table containing the priority parameters of the redundant power supply path was generated. Based on the multi-dimensional fuzzy threshold model, when the connection strength of the power supply node drops sharply (>15% / s) and the virtual path deviation is >0.75, the dynamic reorganization instruction is triggered to start the strategy reconstruction. During the reconstruction process, redundant power supply paths are dynamically allocated through a mixed integer linear programming model, and a node reorganization strategy including power supply topology reorganization logic and communication protocol distortion rate (≤12%) is generated based on the real-time deformation interface rules of the protocol stack hot replacement engine. Finally, a dynamic Bayesian game model is used to integrate the power supply path reorganization logic and protocol deformation constraints, and the evolution of attack strategies is simulated through adversarial generation networks. An attack and defense game mechanism including power supply topology jump sequences and dynamic confusion of communication protocols is generated, which successfully redirects 73% of malicious control instructions to the digital twin power supply cluster, increasing the failure rate of the virtual load fluctuation attack constructed by the attacker to 96%.
[0170] In summary, through steps 601 to 605, an adaptive defense system that links dynamic topology association with attack and defense strategies is realized. Through the dynamic adaptation of real-time topology association features and attack path confusion network status, multi-dimensional threshold judgment is triggered to generate node reorganization strategies. Based on the dynamic fusion of node reorganization logic and interface deformation constraints, an attack and defense game mechanism is constructed to increase the misjudgment rate of attacker path detection and reduce defense resource consumption, thereby achieving synergistic efficiency of dynamic confusion of network topology and active interference of attack behaviors.
[0171] In order to build a multi-protocol layer collaborative obfuscation defense system for advanced threats, we solve the defense blind spot problem caused by the fragmentation of the protocol stack in traditional path obfuscation technology. Through the multi-level feature analysis and dynamic diversion parameter adaptation of the protocol stack mirror tunnel, we break through the attacker's reverse modeling ability for encrypted traffic; relying on the collaborative optimization of the protocol stack layer linkage and the dynamic trapping interface, we achieve the precise matching of the path camouflage sequence and the network topology evolution; based on the dynamic configuration mechanism of the attack path obfuscation network, we form a closed-loop defense link of "protocol analysis-path obfuscation-dynamic feedback", improve the active interference and precise control capabilities of new threats such as APT attacks and zero-day vulnerability exploits, and ensure the anti-attack resilience of key business links.
[0172] In some examples, as described in step 104, path obfuscation processing is performed on the intrusion instruction stream based on the protocol stack mirror tunnel, and an attack path obfuscation network dynamically configured by the attack path diversion rule is constructed, and the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner, including: 701. Performing hierarchical feature analysis on the transmission path of the intrusion instruction stream based on the protocol stack mirror tunnel, extracting path jump rules and dynamic camouflage parameters of each layer of the protocol stack, and generating obfuscated path features; In step 701, the protocol stack mirror tunnel refers to a virtual channel for performing feature analysis on each layer of the protocol stack.
[0173] Hierarchical feature analysis refers to the decomposition and extraction of path features at each level of the protocol stack.
[0174] Path hopping rules refer to the logical rules for dynamic changes in paths.
[0175] The dynamic masquerade parameter refers to the dynamic adjustment value of the protocol masquerade strength.
[0176] The confusion path feature refers to a multidimensional vector reflecting the path confusion feature.
[0177] In the embodiment of the present application, multi-level path feature analysis is achieved through protocol stack mirror tunnel technology. First, the deep packet inspection (DPI) engine is used to disassemble the transmission path of the intrusion instruction stream at the protocol stack level (such as IP layer TTL value jump, TCP sequence number offset mode), and the protocol reverse engineering is used to extract the path jump rules of each level (such as HTTP / 2 stream ID conflict rate threshold 18%). The dynamic camouflage parameters (such as TCP window scaling factor distortion rate ±15%) are calculated through the sliding window statistics method. The distribution characteristics (mean, variance) of historical attack data are combined with the principal component analysis (PCA) dimensionality reduction to generate a confusion path feature matrix (including 32-dimensional protocol stack features) as the basic input for subsequent dynamic adaptation.
[0178] 702. Dynamically adapt the obfuscated path feature to the attack path diversion rule, analyze the dynamic coupling relationship between the path disguise priority and the diversion rule, and generate dynamic diversion parameters; In step 702, the attack path diversion rule refers to a rule set for redirecting attack traffic.
[0179] Dynamic adaptive processing refers to the process of adjusting strategies according to real-time status.
[0180] Path masquerading priority refers to the importance of masquerading at the protocol stack level.
[0181] The dynamic coupling relationship refers to the correlation between path masquerade and diversion rules.
[0182] Dynamic traffic diversion parameters refer to the set of parameters after the strategy is matched with the path characteristics.
[0183] In the embodiment of the present application, based on the obfuscated path features, a multi-agent reinforcement learning (MARL) framework is used for dynamic adaptation processing. First, the attack path diversion rules (such as SDN flow table priority, number of path branches) are encoded as state vectors, and tensor splicing is performed with the obfuscated path features to construct a joint feature space. The path camouflage priority is quantified by the hierarchical analysis method (AHP) of the protocol stack layer weights (such as transport layer weight 0.7, application layer weight 0.3), and the coupling relationship of the diversion rules is analyzed by the Pearson correlation coefficient. Dynamic correlation. Finally, the dual deep Q network (DDQN) model is used to generate dynamic diversion parameters (such as diversion ratio 0.8, camouflage intensity gradient step 0.05) to ensure the balance between path obfuscation and resource consumption.
[0184] 703. Perform multi-level path obfuscation processing on the transmission path of the intrusion instruction flow based on the dynamic diversion parameters to build an attack path obfuscation network framework; In step 703, the multi-level path obfuscation process refers to performing path obfuscation operations at each level of the protocol stack.
[0185] The attack path obfuscation network framework refers to the network architecture that implements path obfuscation.
[0186] In the embodiment of the present application, multi-level path obfuscation processing is implemented through software-defined network (SDN) controller and network function virtualization (NFV) technology. Dynamic diversion parameters are input into the path obfuscation engine, the transport layer uses the TCP sequence number random offset algorithm (offset ±10%), the network layer uses the IP fragmentation randomization strategy (fragmentation ID conflict rate 25%) to confuse the path characteristics, and the application layer injects pseudo-business logic (such as simulating database query delay). Key parameters (such as the number of path branches ≥ 7, flow table synchronization error rate <2%) are optimized through a mixed integer programming model, and finally an attack path obfuscation network framework including a path jump rule base and a protocol camouflage strategy set is constructed, which supports dynamic policy loading and real-time updates.
[0187] 704. Performing protocol stack layer linkage adaptation on the attack path obfuscation network framework and the protocol stack layer of the dynamic trapping interface to generate linkage transmission parameters; In step 704, the protocol stack layer of the dynamic trapping interface refers to the protocol stack configuration that simulates the real service.
[0188] Protocol stack layer linkage adaptation refers to the dynamic matching process between the network framework and the interface protocol.
[0189] The linkage transmission parameters refer to the parameter set after the network framework and the interface protocol are matched.
[0190] In the embodiment of the present application, a protocol stack hierarchical linkage adaptation engine is used to realize the coordination between the network framework and the dynamic trapping interface. First, the protocol stack hierarchical configuration of the dynamic trapping interface (such as TLS1.3 key exchange mode, HTTP / 2 header compression rules) is parsed, and the hierarchical characteristics of the obfuscated network framework (such as the synchronization of TCP retransmission timeout parameters and interface response delay) are matched through protocol stack state machine modeling. The linkage transmission parameters are generated through cross-node training of the federated learning framework, including the protocol stack distortion synchronization rate (≥90%), interface rule switching delay (≤3ms), etc., and finally the linkage parameter configuration file in JSON format is output to drive the policy coordination between the network framework and the interface.
[0191] 705. Based on the linkage transmission parameters, dynamically configure and optimize the attack path obfuscation network framework, integrate the path camouflage sequence and the directional transmission rules, and generate an attack path obfuscation network.
[0192] In step 705, dynamic configuration optimization refers to the process of optimizing network configuration according to linkage parameters.
[0193] The path camouflage sequence refers to the dynamically changing sequence of path obfuscation.
[0194] Directed transport rules are sets of rules that direct traffic along a specific path.
[0195] The attack path obfuscation network refers to the final network architecture that achieves attack path obfuscation.
[0196] In the embodiment of the present application, based on the linkage transmission parameters, the path camouflage sequence and the directional transmission rules are integrated through the dynamic configuration optimization engine. The genetic algorithm (GA) is used to optimize the path hopping frequency (such as switching the path branch every 5 seconds), the camouflage strength gradient (such as the TCP sequence number distortion rate step of 0.1), and the BGP flow specification (FlowSpec) is combined to synchronize the directional transmission rules of the entire network equipment (such as the black hole routing injection ratio). The attack path obfuscation network finally generated supports the linkage between the protocol stack layers (such as the coordinated distortion of IP fragmentation rules and TLS session keys), and realizes the kernel state real-time policy loading through the eBPF program, forming a full-stack obfuscation capability covering the transport layer to the application layer, so that the attacker's path detection misjudgment rate is increased to more than 85%.
[0197] Here is a specific example: In the scenario of defending the smart grid substation automation system against ransomware attacks, a 110kV smart substation detected that an attacker exploited the vulnerability of the IEC 61850 protocol MMS, tampered with the protection device sampling value message, simulated the MAC address of the interval layer device, and injected distorted current data to trigger the relay protection malfunction. The system first performed hierarchical feature analysis on the intrusion instruction stream through the protocol stack mirror tunnel, and extracted the application layer session ID offset mode and the dynamic perturbation coefficient of the transport layer TCP window scaling factor of the station control layer MMS protocol based on the ERSPANv3 composite header encapsulation technology, and generated a confusion path feature matrix containing the MAC address jump cycle. Subsequently, a multi-agent game model was used to dynamically adapt the confusion features to the attack path diversion rules, and the weight ratio of the physical layer GOOSE message and the station control layer MMS message was calculated through the Q-Learning algorithm to generate a dynamic diversion parameter set containing the virtual VLAN priority parameter. Based on the adaptive fuzzy threshold model, when the SV message delay jitter is detected to be greater than 12ms and the MAC address conflict rate is greater than 0.8, the multi-level path confusion engine is triggered, and the MAC address random drift is implemented at the data link layer, and the IP fragment ID dynamic reorganization strategy is adopted at the network layer to build an attack path confusion network framework containing redundant protection channels. The framework is adapted to the IEC 61850-8-1 protocol stack of the dynamic trapping interface through the protocol stack hot-swap engine, and the protocol state machine synchronization algorithm is used to generate a linkage transmission rule table containing sampling value distortion compensation parameters. Finally, the genetic algorithm optimization engine dynamically adjusts the path camouflage sequence, and combines the SDN flow table injection technology to direct 83% of malicious control instructions to the digital twin protection cluster, so that the failure probability of the virtual tripping instructions constructed by the attacker is increased to 94%.
[0198] In summary, through steps 701 to 705, multi-level dynamic obfuscation and precise diversion of the intrusion instruction stream are achieved, the path jump rules are extracted through the protocol stack mirror tunnel, and the obfuscation framework with camouflage priority coupling is generated by dynamic adaptation combined with the attack path diversion rules. Based on the protocol stack hierarchical linkage, the obfuscated network configuration is optimized, and the path camouflage and directional transmission rules are integrated to form a collaborative defense system of instruction stream concealment and controllable redirection. This technology enhances the dynamic response capability of attack path obfuscation through real-time matching of protocol stack features and diversion rules, improves the difficulty of attacker protocol tracking and reverse mapping, breaks through the bottlenecks of protocol solidification and path rigidity of traditional solutions, and builds an active confrontation mechanism with dynamic topology evolution and multi-level linkage, providing deep concealment and precise countermeasure capabilities for advanced threat defense.
[0199] Figure 2 A schematic diagram of a big data processing system for implementing hybrid data analysis is provided for an embodiment of the present invention. Figure 2 As shown, the system includes: A construction module is used to construct a virtual asset map driven by dynamic topology disturbance factors using a real network environment topology image, wherein the virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism; A deformation module, used to perform interface deformation rule implantation processing on the interactive link based on network session context features, and to build a dynamic trapping interface with controllable protocol stack layer and service response logic; A trigger module, used to obtain a topology correlation parameter by using an attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link, wherein the topology correlation parameter triggers a node reorganization strategy of the virtual asset graph and constructs an attack path diversion rule; An obfuscation module is used to perform path obfuscation processing on the intrusion instruction stream based on the protocol stack mirror tunnel, and to construct an attack path obfuscation network dynamically configured by the attack path diversion rule, wherein the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; The collaborative module is used to confuse the real-time status of the network with the topology correlation parameter and the attack path to coordinate the defense strategy, and when the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
[0200] Figure 2 The network security defense system based on intrusion modeling trapping can be executed Figure 1The implementation principle and technical effect of the network security defense method based on intrusion modeling trapping described in the illustrated embodiment will not be described in detail. The specific manner in which each module and unit performs operations in the network security defense system based on intrusion modeling trapping in the above embodiment has been described in detail in the embodiment of the method, and will not be described in detail here.
[0201] In one possible design, Figure 2 A network security defense system based on intrusion modeling trapping of the illustrated embodiment can be implemented as a computing device, such as Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32; The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32 .
[0202] The processing component 32 is used for: Figure 1 The embodiment provides a multi-dimensional data processing method for intelligent scoring of emergency patients.
[0203] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components to perform the above method.
[0204] The storage component 31 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0205] Of course, the computing device may also include other components, such as input / output interfaces, display components, communication components, etc.
[0206] The input / output interface provides an interface between the processing component and the peripheral interface module, which may be an output device, an input device, etc.
[0207] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.
[0208] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.
[0209] The embodiment of the present invention further provides a computer storage medium storing a computer program, which can achieve the above-mentioned Figure 1 A method of the illustrated embodiment.
[0210] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0211] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0212] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0213] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A network security defense method based on intrusion modeling trapping, characterized in that: include: A virtual asset map driven by dynamic topology disturbance factors is constructed using a real network environment topology image. The virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism. Based on the network session context features, the interactive link is processed by interface deformation rule implantation, and a dynamic trapping interface with controllable protocol stack layer and service response logic is constructed; Utilizing the attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link to obtain a topology correlation parameter, the topology correlation parameter triggers the node reorganization strategy of the virtual asset graph, and constructs an attack path diversion rule; Performing path obfuscation processing on the intrusion instruction stream based on the protocol stack mirror tunnel, constructing an attack path obfuscation network dynamically configured by the attack path diversion rule, and the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; According to the topology correlation parameter and the attack path confusion network real-time status collaborative defense strategy, when the topology correlation parameter reaches the threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
2. The method according to claim 1, characterized in that The attacker operates the protocol stack layer of the dynamic trapping interface in the interactive link to obtain a topology correlation parameter, which triggers the node reorganization strategy of the virtual asset map and constructs an attack path diversion rule, including: Performing protocol fingerprint and time series analysis on the attacker's operation sequence in the interactive link, and extracting an operation feature vector including a source-target port mapping relationship and an instruction interval duration; Generate a dynamic weight vector according to the node distribution state of the operation feature vector in the virtual asset map, and obtain the topology correlation parameter through interactive calculation between the dynamic weight vector and the protocol stack behavior mode; The topology correlation parameter is used to analyze the protocol stack behavior pattern of the virtual asset map, and a node reorganization strategy matching the protocol stack layer of the dynamic trapping interface is activated; The protocol camouflage strength of the interactive links of the virtual asset map is adjusted based on the node reorganization strategy to generate an attack path diversion rule including a protocol stack hierarchical mapping relationship.
3. The method according to claim 2, characterized in that The topology correlation parameter is used to analyze the protocol stack behavior pattern of the virtual asset map, and a node reorganization strategy matching the protocol stack level of the dynamic trapping interface is activated, including: Performing protocol stack level feature extraction on the topology correlation parameters, separating the protocol fingerprint matching degree, the node connection density threshold and the protocol camouflage strength gradient, and generating a protocol stack behavior pattern feature vector; Compare the protocol stack behavior pattern feature vector with the protocol stack layer of the dynamic trapping interface by fingerprint library, and select the protocol stack layer matching subset with a matching degree higher than a threshold according to the port mapping rule of the protocol layer; Based on the protocol stack layer matching subset, poll the protocol stack layer activation status of the dynamic trapping interface, detect the protocol camouflage response delay and session context integrity mark of the interface at the transport layer / application layer, and obtain the real-time status matrix of the dynamic trapping interface; According to the session integrity mark in the real-time state matrix of the dynamic trapping interface, the node connection density adjustment coefficient and the protocol camouflage weight are calculated to generate a node reorganization strategy parameter table; The node reorganization strategy parameter table is analyzed, and the node connection density adjustment and protocol camouflage weight loading of the corresponding layer are activated according to the protocol stack layer priority to complete the activation of the node reorganization strategy.
4. The method according to claim 2, characterized in that: The protocol camouflage strength of the interactive links of the virtual asset map is adjusted based on the node reorganization strategy to generate an attack path diversion rule containing a protocol stack layer mapping relationship, including: Performing protocol camouflage strength gradient analysis processing on the protocol stack layer migration rule in the node reorganization strategy to generate camouflage strength gradient parameters that match the dynamic trapping interface protocol stack layer; Performing protocol stack layer matching processing on the interactive links of the virtual asset map according to the camouflage strength gradient parameter, and generating a protocol stack layer mapping table including the correlation relationship between protocol stack depth and camouflage strength; Performing dynamic allocation processing of camouflage strength on the protocol response logic of the interactive link based on the protocol stack layer mapping table, generating link camouflage configuration parameters including protocol stack layer priority tags; Inputting the link camouflage configuration parameters into the protocol stack diversion engine of the attack path obfuscation network to generate a path diversion decision instruction linked to the dynamic trapping interface protocol stack layer; The protocol stack response path reconstruction processing is performed on the interactive links of the virtual asset map through the path diversion decision instruction to form an attack path diversion rule including a protocol camouflage strength gradient constraint.
5. The method according to claim 4, characterized in that Inputting the link camouflage configuration parameters into the protocol stack diversion engine of the attack path obfuscation network to generate a path diversion decision instruction linked to the dynamic trapping interface protocol stack layer, including: Performing protocol stack level analysis on the link camouflage configuration parameters, extracting dynamic attributes bound to the protocol stack level in the link camouflage configuration parameters, and generating camouflage level features; Perform dynamic weight adaptation based on the camouflage level feature and the protocol stack level of the dynamic trapping interface to generate linkage matching parameters; Performing path diversion optimization on the linkage matching parameters, and generating path diversion optimization features in combination with the dynamic path selection strategy of the attack path obfuscation network; Reconstruct the path diversion optimization feature and the obfuscation rule of the attack path obfuscation network through rule constraints to generate a path obfuscation feature; The path obfuscation features are fused with decision instructions, the dynamic parameters of the protocol stack layer linkage and the jump logic of the path camouflage sequence are integrated to generate dynamic path diversion decision instructions.
6. The method according to claim 1, characterized in that According to the topology correlation parameter and the attack path confusion network real-time state collaborative defense strategy, when the topology correlation parameter reaches the threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism, including: Performing dynamic correlation analysis on the topological correlation parameters, extracting the real-time change characteristics of the dynamic connection strength between nodes and the topological evolution path, and generating real-time topological correlation characteristics; Dynamically adapt the defense strategy of the real-time topology association feature and the real-time state of the attack path obfuscated network to generate collaborative defense parameters; Perform multi-dimensional threshold triggering judgment based on the collaborative defense parameter, and generate a dynamic reorganization triggering instruction when the topology correlation parameter reaches a preset threshold; According to the dynamic reorganization trigger instruction, the node connection relationship of the attack path obfuscation network is strategically reconstructed to generate a node reorganization strategy, wherein the node reorganization strategy includes a real-time switching logic of a redundant path dynamic allocation rule and an interface deformation rule; The node reorganization strategy and the interface deformation rule are dynamically integrated to form an attack and defense strategy, and the node reorganization logic and the interface deformation constraint conditions are integrated to generate a dynamic attack and defense game mechanism.
7. The method according to claim 1, characterized in that Based on the protocol stack mirror tunnel, path obfuscation processing is performed on the intrusion instruction stream, and an attack path obfuscation network dynamically configured by the attack path diversion rule is constructed, and the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner, including: Based on the protocol stack mirror tunnel, the transmission path of the intrusion instruction stream is analyzed by layer features, the path jump rules and dynamic camouflage parameters of each layer of the protocol stack are extracted, and the obfuscated path features are generated; Dynamically adapting the obfuscated path features to the attack path diversion rules, analyzing the dynamic coupling relationship between the path disguise priority and the diversion rules, and generating dynamic diversion parameters; Based on the dynamic diversion parameters, a multi-level path obfuscation process is performed on the transmission path of the intrusion instruction flow to build an attack path obfuscation network framework; Performing protocol stack layer linkage adaptation on the attack path obfuscation network framework and the protocol stack layer of the dynamic trapping interface to generate linkage transmission parameters; Based on the linkage transmission parameters, the attack path obfuscation network framework is dynamically configured and optimized, and the path camouflage sequence and the directional transmission rules are integrated to generate an attack path obfuscation network.
8. A network security defense system based on intrusion modeling trapping, characterized in that: include: A construction module is used to construct a virtual asset map driven by dynamic topology disturbance factors using a real network environment topology image, wherein the virtual asset map generates virtual nodes and interactive links with interchangeable protocol response characteristics through a protocol fingerprint obfuscation mechanism; A deformation module, used to perform interface deformation rule implantation processing on the interactive link based on network session context features, and to build a dynamic trapping interface with controllable protocol stack layer and service response logic; A trigger module, used to obtain a topology correlation parameter by using an attacker's operation on the protocol stack level of the dynamic trapping interface in the interactive link, wherein the topology correlation parameter triggers a node reorganization strategy of the virtual asset graph and constructs an attack path diversion rule; An obfuscation module is used to perform path obfuscation processing on the intrusion instruction stream based on the protocol stack mirror tunnel, and to construct an attack path obfuscation network dynamically configured by the attack path diversion rule, wherein the attack path obfuscation network transmits the instruction stream to the protocol stack layer of the dynamic trapping interface in a directional manner; The collaborative module is used to confuse the real-time status of the network with the topology correlation parameter and the attack path to coordinate the defense strategy, and when the topology correlation parameter reaches a threshold, the node reorganization strategy and the interface deformation rule are synchronously updated to form a dynamic attack and defense game mechanism.
9. A computing device, characterized in that It comprises a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a network security defense method based on intrusion modeling trapping as described in any one of claims 1 to 7.
10. A computer storage medium, characterized in that: A computer program is stored, and when the computer program is executed by a computer, a network security defense method based on intrusion modeling trapping as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Novel DDOS attack defense system and method based on IP and topology confusion
CN116389120A
Network intrusion active defense method and system based on mobile attack surface
CN117375961A
Link flooding attack active defense system based on network topology confusion
CN118353647A
Method and system for network topology obfuscation
EP4231589A1
Cited By
Flow control method based on segmented flight route splicing data
CN120128496A
A traffic control method based on spliced data of segmented flight routes
CN120128496B
Control method and system of multi-source intelligent power manager based on 5G communication
CN120301042A
A control method and system for a multi-source intelligent power manager based on 5G communication
CN120301042B
Network traffic auditing optimization defense method based on traffic feature camouflage
CN120546982A