Threat intelligence capturing method and device based on honeypot, storage medium and equipment

By using the attack data captured by honeypots in the intelligence sharing platform, extracting and marking threat indicators, downloading attack sample files, and conducting intelligence correlation analysis, the problem of attack data in the existing technology is solved, and high-quality intelligence data sharing is achieved.

CN120017317APending Publication Date: 2025-05-16SHANGHAI GUAN AN INFORMATION TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510026924.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When the prior art outputs the attack data captured by honeypots to the intelligence sharing platform, it lacks further mining of the attack data and cannot form effective intelligence data.

Method used

By obtaining honeypots deployed by each node of the Internet, the reported attack data is captured in real time, the preset attack data analysis rules are used to extract threat indicators, and the threat label is determined, the corresponding attack sample files are downloaded, and the threat indicators are analyzed in intelligence association, and the relevant data is finally provided to the intelligence sharing platform as intelligence data.

Benefits of technology

The full mining of attack data has been achieved, and accurate and effective intelligence data has been formed for use by the intelligence sharing platform, which has improved the accuracy and availability of intelligence data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017317A_ABST
    Figure CN120017317A_ABST
Patent Text Reader

Abstract

The invention discloses a threat intelligence capturing method and device based on a honeypot, a storage medium and equipment. Relates to the technical field of network security. The method comprises the following steps: acquiring attack data captured and reported by honeypots deployed by nodes of the Internet in real time; utilizing a preset attack data analysis rule to extract a threat index of the attack data, and determining a threat label corresponding to the threat index; downloading a corresponding attack sample file according to a uniform resource locator in the threat index; performing intelligence association analysis on the threat index to obtain an intelligence association analysis result of the threat index; and providing the threat index, the threat label corresponding to the threat index, the attack sample file and the intelligence association analysis result as intelligence data to an intelligence sharing platform. The attack data can be fully mined, so that effective intelligence data can be formed to be used by an intelligence sharing platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a threat intelligence capture method, device, storage medium and equipment based on a honeypot. Background Art

[0002] The intelligence sharing platform collects intelligence data from different sources, obtains valuable security intelligence information, and shares it with enterprises or organizations in need to help them prevent and resolve security incidents.

[0003] At present, many enterprises or organizations usually directly output the massive attack data captured by honeypots as intelligence data to the intelligence sharing platform. However, this method of existing technology lacks further mining of attack data and cannot form effective intelligence data for use by the intelligence sharing platform. Summary of the invention

[0004] In view of this, the present application provides a honeypot-based threat intelligence capture method, apparatus, storage medium and device, which are mainly capable of fully mining attack data, thereby forming effective intelligence data for use by the intelligence sharing platform.

[0005] According to a first aspect of the present application, a honeypot-based threat intelligence capture method is provided, the method comprising:

[0006] Obtain attack data captured and reported in real time by honeypots deployed at various Internet nodes;

[0007] Using preset attack data analysis rules, extracting threat indicators of the attack data, and determining threat labels corresponding to the threat indicators;

[0008] Downloading a corresponding attack sample file according to the uniform resource locator in the threat indicator;

[0009] Performing intelligence correlation analysis on the threat indicators to obtain intelligence correlation analysis results of the threat indicators;

[0010] The threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result are provided to the intelligence sharing platform as intelligence data.

[0011] According to a second aspect of the present application, a threat intelligence capture device based on a honeypot is provided, comprising:

[0012] An acquisition unit is used to acquire attack data captured and reported in real time by honeypots deployed at various nodes of the Internet; an extraction and labeling unit is used to extract threat indicators of the attack data using preset attack data analysis rules, and determine threat labels corresponding to the threat indicators;

[0013] A downloading unit, used to download a corresponding attack sample file according to the uniform resource locator in the threat indicator;

[0014] An analysis unit, configured to perform intelligence correlation analysis on the threat indicator to obtain an intelligence correlation analysis result of the threat indicator;

[0015] The determination unit is used to provide the threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result as intelligence data to the intelligence sharing platform.

[0016] According to a third aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned honeypot-based threat intelligence capture method is implemented.

[0017] According to the fourth aspect of the present application, an electronic device is provided, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned honeypot-based threat intelligence capture method when executing the program.

[0018] By means of the above technical scheme, the threat intelligence capture method, device, storage medium and equipment based on honeypot provided by the present application, compared with the prior art, firstly use the preset attack data analysis rules to extract the threat indicators of the attack data, and determine the threat labels corresponding to the threat indicators, and then download the corresponding attack sample files according to the uniform resource locator in the threat indicators, and at the same time, perform intelligence correlation analysis on the threat indicators to obtain the intelligence correlation analysis results of the threat indicators, and finally provide the threat indicators, the threat labels corresponding to the threat indicators, the attack sample files and the intelligence correlation analysis results as intelligence data to the intelligence sharing platform. It can be seen from this that the present application can fully mine the attack data by marking the threat indicators, automatically tracking and downloading the corresponding attack sample files, and performing intelligence correlation analysis on the threat indicators, so as to form accurate and effective intelligence data for use by the intelligence sharing platform.

[0019] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0021] Figure 1A schematic diagram of a process of capturing threat intelligence based on a honeypot provided in an embodiment of the present application is shown;

[0022] Figure 2 A schematic diagram of the structure of a sensitive data annotation system based on multiple models provided in an embodiment of the present application is shown;

[0023] Figure 3 The overall process diagram of capturing intelligence data provided by the embodiment of the present application is shown;

[0024] Figure 4 A schematic diagram of the process of marking threat indicators provided in an embodiment of the present application is shown;

[0025] Figure 5 A schematic diagram of the structure of another honeypot-based threat intelligence capture device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0026] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.

[0027] The existing technology lacks further mining of attack data generated by honeypots and cannot form effective intelligence data for use by intelligence sharing platforms.

[0028] In order to solve the above problems, an embodiment of the present invention provides a threat intelligence capture method based on a honeypot, such as Figure 1 As shown, the method includes:

[0029] Step 10: Obtain the attack data captured and reported in real time by the honeypots deployed at each node of the Internet.

[0030] The attack data of the honeypot includes attack records and attack payloads. The attack payload is usually a piece of binary code, which can contain malware, viruses, worms, Trojans, encrypted codes, malicious scripts, etc. Attackers can inject these payloads into the attacked system, network or application, and perform harmful operations and control the victim system by exploiting existing vulnerabilities or existing security weaknesses in the system. The attack payload can include attack requests for various protocols and services, such as http, telnet, ssh, mysql, smtp, etc.

[0031] In order to capture effective and accurate threat intelligence, an embodiment of the present invention provides a threat intelligence capture system based on a honeypot, such as Figure 2As shown in FIG. 1 , the system mainly includes a honeypot simulation module, a data storage processing module, an offline extraction module, a rule label module, a sample file download module and an intelligence aggregation analysis module. The honeypot simulation module is used to absorb and trap various types of attack data transmitted in real time on the Internet, which may include attack requests of various protocols and services, such as http, telnet, ssh, mysql, smtp, etc. The service simulation can be either a high-interaction type or a low-interaction type. The data storage processing module is used to process the attack data reported by the honeypot simulation module, that is, to parse and process the attack data into a unified field type, store it in an unstructured database, and use the uniformly processed attack data as the data input of the offline extraction module. The offline extraction module is used to create an offline extraction task to extract threat indicators (IOCs) from the data in the unstructured database. The offline extraction module flexibly selects the specified data in a task manner. According to the scope and specific rules, the sample file download module is called at the same time to obtain sample files in real time, and the threat indicator IOC is output to the intelligence aggregation analysis module; the rule label module is the core processing module, which is used to label the extracted threat indicators with threat labels. This module supports botnets, mining and other types as threat labels, and also supports Trojan names, CVE names, etc. as threat labels; the sample file download module is used to download attack sample files in threat indicators in real time, and can perform multi-threaded downloads on downloaders, mining sample files, Trojan sample files and other sample files, that is, download and obtain available sample files in real time; the intelligence aggregation analysis module is used to process the threat indicators extracted by the offline extraction module, that is, to correlate the extracted threat indicator IOC, such as correlating the IP with the URL and the sample file, and provide intelligence data download and sharing API interfaces to deliver intelligence data to other intelligence sharing platforms. The overall intelligence data capture process is as follows: Figure 3 shown.

[0032] Based on the above system structure, when capturing intelligence data, the embodiment of the present invention first uses the honeypot simulation module to absorb and trap the massive attack data that is transmitted in real time on the Internet, and then fully mines the massive attack data to obtain accurate and effective intelligence data.

[0033] Step 20: Using preset attack data analysis rules, extract threat indicators of the attack data, and determine threat labels corresponding to the threat indicators.

[0034] The preset attack data analysis rules include preset attack data matching rules and preset threat indicator extraction rules. Threat indicators include IP addresses, uniform resource locators (URLs), domain names, and usernames and passwords. Threat tags include built-in threat tags and custom threat tags. Built-in threat tags can be directly configured when creating rules, including remote control, botnets, hijacking, puppet machines, spam, suspicious, compromised hosts, brute force cracking, and proxies. Custom threat tags can be added based on the specific capture scenarios of the rules. For example, when capturing newly disclosed vulnerabilities, the CVE number is added as a threat tag. For another example, when capturing the botnet "Mozi", "Mozi" can be used as a threat tag.

[0035] For the embodiment of the present invention, after acquiring the attack data, the data storage processing module will parse the attack data into JSON data and process it uniformly, and then output the uniformly processed attack data to the offline extraction module. The offline extraction module will create an offline extraction task to extract threat indicators from the uniformly processed attack data, and call the rule labeling module to label the extracted threat indicators. For the extraction and labeling process of threat indicators, Figure 4 As shown, including:

[0036] Step 21: Filter out target attack data from the attack data using the preset attack data matching rule.

[0037] For the embodiments of the present invention, since the honeypot captures a large amount of raw attack data, and some of the raw attack data are often irrelevant to the threat indicator IOC, in order to improve the efficiency of extracting threat indicators, it is necessary to first filter out the attack data that meets the preset attack data matching rules from the large amount of raw attack data as target attack data, and then extract threat indicators from the target attack data.

[0038] For example, the preset attack data matching rule is set to only match the data containing "wget" in the attack data. By using the preset attack data matching rule, the target attack data that matches the downloader such as "wget" can be filtered out from the attack data.

[0039] It should be noted that there may be multiple preset attack data matching rules in the embodiment of the present invention, and the target attack data may satisfy all preset attack data matching rules or only satisfy one preset attack data matching rule.

[0040] Step 22: Extract the threat indicator of the target attack data using the preset threat indicator extraction rule.

[0041] For the embodiment of the present invention, after the target attack data is screened out, the threat indicators of the target attack data are extracted using the preset threat indicator extraction rules. Regarding the construction process of the preset threat indicator extraction rules, the method includes: determining the key fields to be extracted; constructing a regular expression according to the key fields, and determining the tag type corresponding to the regular expression; based on the regular expression and the tag type corresponding to the regular expression, determining the preset threat indicator extraction rule and the tag type corresponding to the preset threat indicator extraction rule.

[0042] Specifically, the extracted key fields include IP address field, URL field, domain name field, user name field, password field, etc. Based on the key fields determined above, a regular expression is constructed, and the number of regular expressions is multiple. The corresponding label type can be determined according to the key fields involved in the regular expression. For example, the corresponding label type can be determined as remote control or botnet according to the specific URL field involved in the regular expression. Finally, the constructed regular expression is determined as the preset threat indicator extraction rule.

[0043] After the preset threat indicator extraction rules are constructed, the target attack data is first decoded to obtain decoded target attack data, such as base64, URLdecode, etc. If a decoded target attack data meets the preset threat indicator extraction rules, the preset threat indicator extraction rules are used to extract the threat indicators in the target attack data.

[0044] It should be noted that a preset threat indicator extraction rule may correspond to one, two or more threat label types.

[0045] Step 23: Determine a label type corresponding to the preset threat indicator extraction rule, and determine the label type as a threat label corresponding to the threat indicator.

[0046] For the embodiment of the present invention, during the extraction process, the threat indicator is labeled using a label type corresponding to a preset threat indicator extraction rule.

[0047] The embodiments of the present invention can fully mine the information in the attack data by extracting threat indicators from the attack data and marking the threat indicators, thereby forming effective and accurate intelligence data for use by the intelligence sharing platform.

[0048] Step 30: Download the corresponding attack sample file according to the uniform resource locator in the threat indicator.

[0049] The uniform resource locator may specifically refer to a URL in a threat indicator.

[0050] In order to fully mine attack data, the embodiment of the present invention can also download corresponding attack sample files, that is, according to the uniform resource locator in the threat indicator, the attack sample files are downloaded in multiple threads. Since the embodiment of the present invention adopts a multi-threaded method in the process of downloading the attack sample files, the download efficiency can be improved.

[0051] During the download process, an asynchronous task can be used to monitor file information. If a successful download task is found, it will be skipped. At the same time, the downloaded attack sample files are used to continuously update intelligence information.

[0052] Step 40: Perform intelligence correlation analysis on the threat indicators to obtain intelligence correlation analysis results of the threat indicators.

[0053] For the embodiment of the present invention, in order to fully mine the attack data, it is also necessary to perform intelligence association on the extracted threat indicators. For this process, the method includes: establishing a first association relationship between the threat indicator and the original log information, so as to query the corresponding attack data based on the first association relationship; establishing a second association relationship within the threat indicator; and determining the intelligence association analysis result based on the first association relationship and the second association relationship.

[0054] When establishing the second association relationship within the threat indicator, a third association relationship is established between the IP address in the threat indicator and the uniform resource locator; a fourth association relationship is established between the attack sample file and the uniform resource locator; a fifth association relationship is established between the attack sample file and the IP address or domain name in the threat indicator; and the second association relationship is determined based on the third association relationship, the fourth association relationship and the fifth association relationship.

[0055] Specifically, each threat indicator is first associated with the original log information to ensure that detailed attack data can be found based on the threat indicator. Then, an internal association of the threat indicator is established, that is, an association relationship between the IP address and the uniform resource locator URL is established, that is, the relevant URL is displayed in the IP intelligence. An association relationship between the attack sample file and the uniform resource locator URL can also be established, that is, the relevant URL is displayed in the sample file intelligence. An association relationship between the attack sample file and the C2 server (that is, the IP address or domain name) can also be established, that is, the relevant IP address and domain name are displayed in the sample file intelligence.

[0056] It should be noted that the association relationships within the threat indicators in the embodiment of the present invention are not limited to the above examples, and other association relationships may also be established.

[0057] The embodiment of the present invention can fully mine the implicit information in the attack data by establishing the association relationship between the threat indicator and the original log information, as well as the association relationship within the threat indicator, thereby facilitating the use of the intelligence sharing platform.

[0058] Step 50: Provide the threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result as intelligence data to the intelligence sharing platform.

[0059] The embodiment of the present invention can not only mark the threat indicators, but also supplement the threat labels of the threat indicators. For this process, the method includes: based on the threat indicators, querying the third-party intelligence platform; if there is other label information corresponding to the threat indicators in the third-party intelligence platform, then based on the other label information, supplementing the threat label to obtain the supplemented threat label. At the same time, the threat indicators, the supplemented threat labels corresponding to the threat indicators, the attack sample files and the intelligence correlation analysis results are provided to the intelligence sharing platform as intelligence data.

[0060] Specifically, the IP addresses, URLs, domain names, etc. in the threat indicators and attack sample files can be supplemented with labels by querying the third-party intelligence library, thereby ensuring the accuracy of the intelligence.

[0061] The embodiment of the present invention provides a honeypot-based threat intelligence capture method, which first uses preset attack data analysis rules to extract threat indicators of attack data and determine threat labels corresponding to threat indicators, and then downloads corresponding attack sample files according to the uniform resource locator in the threat indicator. At the same time, intelligence correlation analysis is performed on the threat indicator to obtain the intelligence correlation analysis results of the threat indicator, and finally the threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis results are provided to the intelligence sharing platform as intelligence data. It can be seen that the embodiment of the present invention can fully mine the attack data by marking the threat indicator, automatically tracking and downloading the corresponding attack sample file, and performing intelligence correlation analysis on the threat indicator, so as to form accurate and effective intelligence data for use by the intelligence sharing platform.

[0062] Further, as Figure 1 and Figure 4 The specific implementation of the method shown in the embodiment provides a threat intelligence capture device based on a honeypot, such as Figure 5 As shown, the device includes: an acquisition unit 101, an extraction and marking unit 102, a downloading unit 103, an analysis unit 104 and a determination unit 105.

[0063] The acquisition unit 101 may be used to acquire attack data captured and reported in real time by honeypots deployed at various nodes on the Internet.

[0064] The extraction and labeling unit 102 may be configured to extract threat indicators of the attack data using preset attack data analysis rules, and determine threat labels corresponding to the threat indicators.

[0065] The downloading unit 103 may be used to download a corresponding attack sample file according to a uniform resource locator in the threat indicator.

[0066] The analysis unit 104 may be configured to perform intelligence correlation analysis on the threat indicator to obtain an intelligence correlation analysis result of the threat indicator.

[0067] The determining unit 105 may be configured to provide the threat indicator, the threat label corresponding to the threat indicator, the attack sample file, and the intelligence correlation analysis result as intelligence data to the intelligence sharing platform.

[0068] In some embodiments, the preset attack data analysis rules include preset attack data matching rules and preset threat indicator extraction rules. The extraction and labeling unit 102 can be specifically used to use the preset attack data matching rules to filter out target attack data from the attack data; use the preset threat indicator extraction rules to extract threat indicators of the target attack data; determine the label type corresponding to the preset threat indicator extraction rules, and determine the label type as the threat label corresponding to the threat indicator.

[0069] In some embodiments, the device further comprises: a construction unit.

[0070] The construction unit can be used to determine the key fields to be extracted; construct a regular expression based on the key fields, and determine the tag type corresponding to the regular expression; based on the regular expression and the tag type corresponding to the regular expression, determine the preset threat indicator extraction rule and the tag type corresponding to the preset threat indicator extraction rule.

[0071] In some embodiments, the downloading unit 103 may be specifically configured to download the attack sample file in multiple threads according to the uniform resource locator in the threat indicator.

[0072] In some embodiments, the analyzing unit 104 includes: an establishing module and a determining module.

[0073] The establishing module may be used to establish a first association relationship between the threat indicator and the original log information, so as to query corresponding attack data based on the first association relationship.

[0074] The establishing module may also be used to establish a second association relationship within the threat indicator.

[0075] The determination module can be used to determine the intelligence association analysis result based on the first association relationship and the second association relationship.

[0076] In some embodiments, the establishment module can be specifically used to establish a third association relationship between the IP address in the threat indicator and the uniform resource locator; establish a fourth association relationship between the attack sample file and the uniform resource locator; establish a fifth association relationship between the attack sample file and the IP address or domain name in the threat indicator; and determine the second association relationship based on the third association relationship, the fourth association relationship and the fifth association relationship.

[0077] The determining unit 105 may be specifically configured to query a third-party intelligence platform based on the threat indicator;

[0078] If other label information corresponding to the threat indicator exists in the third-party intelligence platform, the threat label is supplemented based on the other label information to obtain a supplemented threat label; the threat indicator, the supplemented threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result are provided to the intelligence sharing platform as intelligence data.

[0079] It should be noted that for other corresponding descriptions of the functional units involved in the honeypot-based threat intelligence capture device provided in this embodiment, please refer to Figure 1 and Figure 4 The corresponding description in will not be repeated here.

[0080] Based on the above Figure 1 and Figure 4 The method shown in the embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the above-mentioned Figure 1 and Figure 4 The honeypot-based threat intelligence capture method shown.

[0081] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), including a number of instructions for enabling an electronic device (which can be a personal computer, server, or network device, etc.) to execute the methods of various implementation scenarios of the present application.

[0082] Based on the above Figure 1 and Figure 4 The method shown, and Figure 5 In order to achieve the above-mentioned purpose, the embodiment of the present application also provides an electronic device, which can be a personal computer, a tablet computer, a server, or other network equipment, etc. The device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to achieve the above-mentioned Figure 1 and Figure 4 The honeypot-based threat intelligence capture method shown.

[0083] Optionally, the above-mentioned physical device may also include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a WI-FI module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and the optional user interface may also include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface), etc.

[0084] Those skilled in the art will appreciate that the above-mentioned physical device structure provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or a combination of certain components, or different arrangements of components.

[0085] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the above-mentioned physical device, and supports the operation of the information processing program and other software and / or programs. The network communication module is used to realize the communication between the components inside the storage medium, and the communication with other hardware and software in the information processing physical device.

[0086] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform, or by hardware.

[0087] The embodiment of the present invention first uses the preset attack data analysis rules to extract the threat indicators of the attack data and determine the threat labels corresponding to the threat indicators. Then, according to the uniform resource locator in the threat indicator, the corresponding attack sample file is downloaded. At the same time, the threat indicator is subjected to intelligence correlation analysis to obtain the intelligence correlation analysis results of the threat indicator. Finally, the threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis results are provided to the intelligence sharing platform as intelligence data. It can be seen that the embodiment of the present invention can fully mine the attack data by marking the threat indicator, automatically tracking and downloading the corresponding attack sample file, and conducting intelligence correlation analysis on the threat indicator, so as to form accurate and effective intelligence data for use by the intelligence sharing platform.

[0088] Those skilled in the art will appreciate that the accompanying drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily necessary for implementing the present application. Those skilled in the art will appreciate that the modules in the devices in the implementation scenario can be distributed in the devices of the implementation scenario according to the description of the implementation scenario, or can be changed accordingly and located in one or more devices different from the present implementation scenario. The modules of the above-mentioned implementation scenario can be combined into one module, or can be further split into multiple submodules.

[0089] The above serial numbers of this application are only for description and do not represent the advantages and disadvantages of the implementation scenarios. The above disclosure is only a few specific implementation scenarios of this application, but this application is not limited to them, and any changes that can be thought of by technicians in this field should fall within the scope of protection of this application.

Claims

1. A threat intelligence capture method based on honeypot, characterized in that: include: Obtain attack data captured and reported in real time by honeypots deployed at various Internet nodes; Using preset attack data analysis rules, extracting threat indicators of the attack data, and determining threat labels corresponding to the threat indicators; Downloading a corresponding attack sample file according to the uniform resource locator in the threat indicator; Performing intelligence correlation analysis on the threat indicators to obtain intelligence correlation analysis results of the threat indicators; The threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result are provided to the intelligence sharing platform as intelligence data.

2. The method according to claim 1, characterized in that The preset attack data analysis rule includes a preset attack data matching rule and a preset threat indicator extraction rule. The preset attack data analysis rule is used to extract the threat indicator of the attack data and determine the threat label corresponding to the threat indicator, including: Filtering target attack data from the attack data using the preset attack data matching rule; Extracting the threat indicator of the target attack data using the preset threat indicator extraction rule; Determine a label type corresponding to the preset threat indicator extraction rule, and determine the label type as a threat label corresponding to the threat indicator.

3. The method according to claim 2, characterized in that The method further comprises: Determine the key fields to extract; Constructing a regular expression according to the key field, and determining a tag type corresponding to the regular expression; Based on the regular expression and the tag type corresponding to the regular expression, the preset threat indicator extraction rule and the tag type corresponding to the preset threat indicator extraction rule are determined.

4. The method according to claim 1, characterized in that: According to the uniform resource locator in the threat indicator, download the corresponding attack sample file, including: According to the uniform resource locator in the threat indicator, the attack sample file is downloaded in multiple threads.

5. The method according to claim 1, characterized in that The performing intelligence correlation analysis on the threat indicator to obtain the intelligence correlation analysis result of the threat indicator includes: Establishing a first association relationship between the threat indicator and the original log information, so as to query corresponding attack data based on the first association relationship; Establishing a second correlation relationship within the threat indicator; The intelligence association analysis result is determined according to the first association relationship and the second association relationship.

6. The method according to claim 5, characterized in that The establishing of the second association relationship within the threat indicator includes: Establishing a third association relationship between the IP address in the threat indicator and the uniform resource locator; Establishing a fourth association relationship between the attack sample file and the uniform resource locator; Establishing a fifth association relationship between the attack sample file and the IP address or domain name in the threat indicator; The second association relationship is determined based on the third association relationship, the fourth association relationship and the fifth association relationship.

7. The method according to claim 1, characterized in that Providing the threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result as intelligence data to the intelligence sharing platform includes: Based on the threat indicators, query the third-party intelligence platform; If other label information corresponding to the threat indicator exists in the third-party intelligence platform, the threat label is supplemented based on the other label information to obtain a supplemented threat label; The threat indicator, as well as the supplemented threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result are provided to the intelligence sharing platform as intelligence data.

8. A threat intelligence capture device based on honeypot, characterized in that: include: An acquisition unit is used to acquire attack data captured and reported in real time by honeypots deployed at various nodes on the Internet; An extraction and labeling unit, used to extract threat indicators of the attack data by using preset attack data analysis rules, and determine threat labels corresponding to the threat indicators; A downloading unit, used to download a corresponding attack sample file according to the uniform resource locator in the threat indicator; An analysis unit, configured to perform intelligence correlation analysis on the threat indicator to obtain an intelligence correlation analysis result of the threat indicator; The determination unit is used to provide the threat indicator, the threat label corresponding to the threat indicator, the attack sample file and the intelligence correlation analysis result as intelligence data to the intelligence sharing platform.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. An electronic device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Behavior analysis-based unknown threat detection method and system

    CN120378232A