Network security active defense honeypot system

By integrating centralized control modules and threat perception modules in the network security active defense honeypot system, the problem of insufficient in traditional network security protection systems in dealing with new special attacks is solved, and efficient attack detection and emergency response are achieved.

CN120050070APending Publication Date: 2025-05-27INTEGRITY TECH GRP INC +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510115849.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Traditional network security protection systems are insufficient in dealing with new special attacks and cannot monitor and discover hidden attacks in a timely and effective manner, resulting in frequent occurrence of major security risks such as intranet information leakage.

Method used

It provides a network security active defense honeypot system, including centralized control module and threat perception module, which improves emergency response and defense levels through camouflage, zero false alarms, high disposal and traceability capabilities.

Benefits of technology

It has achieved seamless integration into the actual defense network, automated simulation of business scenarios, built a fragile environment to attract intruders, extended attack time, improved defense initiative, achieved zero false alarm detection, and improved emergency response speed and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050070A_ABST
    Figure CN120050070A_ABST
Patent Text Reader

Abstract

The invention relates to a network security active defense honeypot system, which comprises a centralized management and control module and a threat sensing module, and is characterized in that the centralized management and control module is used for monitoring, maintaining and querying honeypots in a centralized manner and providing an access entrance; the threat sensing module comprises a honeynet management module, a threat analysis module, a report generation module and a linkage cooperative defense module; the honeynet management module is used for managing a honeypot simulation scene, a honeypot virtual machine, a honeypot mirror image, trapping node equipment, disguise agent node equipment, network asset equipment and honeypot bait release; the threat analysis module is used for analyzing threat data reported by the honeypot; the report generation module makes a report according to the analysis data; and the linkage cooperative defense module shares the threat data with the third-party security system for cooperative defense. According to the method, the high-sweetness honeypot is deployed in an enterprise network, the emergency response and defense level is improved by means of disguising, zero false alarm, high handling and traceability, and multi-scene independent deployment can be realized without influencing services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology. More specifically, the present invention is a network security active defense honeypot system. Background Art

[0002] In the digital age, the rapid development and wide application of information technology have made the network a key infrastructure for social operation. However, the traditional network security protection system shows obvious deficiencies in dealing with new types of special attacks, unable to detect and discover hidden attack behaviors in a timely and effective manner, resulting in frequent occurrence of major security risks such as internal network information leakage. Currently, network security technical solutions mainly include firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and antivirus software, etc. A firewall restricts the in and out of network traffic by setting access control policies, but its ability to identify complex application layer attacks and internal-initiated attacks is limited. An IDS discovers potential intrusion behaviors by monitoring and analyzing network traffic, but it usually can only issue alarms and cannot actively prevent attacks. Although an IPS can perform blocking operations when detecting an intrusion, its detection accuracy and defense effect are limited in the face of new and evolving attack characteristics. Antivirus software mainly detects known viruses and malware and often cannot effectively deal with unknown or targeted attacks. Most of these traditional technical solutions rely on feature libraries for detection, and it is difficult to detect and defend against attacks lacking obvious features or with constantly changing features in a timely and accurate manner, resulting in a passive defense state in the current complex and changeable network attack environment. Summary of the Invention

[0003] To solve the technical problems in the background art, the present invention innovatively provides a network security active defense honeypot system, a high-sweetness honeypot deployed in an enterprise network, which can improve the emergency response and defense level with the capabilities of disguise, zero false positives, high disposal, and traceability, and can be independently deployed in multiple scenarios without affecting the business.

[0004] To achieve the above-mentioned technical objectives, an embodiment of the present invention discloses a network security active defense honeypot system, including a centralized control module and a threat perception module. The centralized control module is used to centrally monitor, maintain and query the honeypots deployed in the honeynet, and provide an access portal to the centralized control module; the threat perception module includes a honeynet management module, a threat analysis module, a report generation module and a linkage defense module. The honeynet management module is used to manage honeypot simulation scenarios, honeypot virtual machines, honeypot images, trapping node devices, camouflage proxy node devices, network asset devices and honeypot bait delivery; the threat analysis module is used to receive threat data reported by the honeypot in the honeynet management module to monitor and analyze the threat status of the protected network and the behavior and status of the intruder; the report generation module is used to receive the analysis data output by the threat analysis module to generate an analysis report; the linkage defense module is used to upload the threat data to a third-party security protection system for linkage defense.

[0005] Furthermore, the present invention provides a network security active defense honeypot system, wherein the centralized management and control module includes a honeynet monitoring module, a honeynet maintenance module, a honeynet query module and an access entry configuration module, the honeynet monitoring module is used to monitor the operating status of the honeypot in the honeynet, display the cascade relationship and node information of the current honeynet in the form of nodes, and display the operating information of the honeypots in the honeynet; the honeynet maintenance module is used to add a new honeypot to the honeynet by means of an authorization code, modify the honeypot name of any honeypot, and display the authorization information of the current honeypot; the honeynet query module is used to query the authorization information of the current honeypot by means of an authorization code; and the access entry configuration module is used to configure the IP address for accessing the honeynet.

[0006] Further, for a network security active defense honeypot system of the present invention, the honeynet management module includes a scenario simulation module, a honeypot configuration module, an image management module, a decoy node management module, a camouflage proxy management module, an asset identification module, and a decoy deployment module. The scenario simulation module is used to monitor the simulation scenario environment, describe the simulation scenario information, configure the simulation scenario entrance, start and stop the services provided in the honeypot, deactivate, reset, and disconnect the network of the currently running simulation scenario, replace the honeypots running in the simulation scenario, and control the connection permission of the externally connected honeypots and the externally connected blacklist. The honeypot configuration module is used to display the configuration information of the honeypot virtual machines, perform various status function operations on each honeypot virtual machine, view the startup status of each honeypot, filter the honeypots according to different dimensions, create honeypots, and update the decoys with one key. The image management module is used to implement operations such as honeypot image production, display, release, screening, and modification based on the built-in monitoring engine base image. The decoy node management module is used to view the device configuration information of the decoy nodes, restart, shut down, and delete the decoy node devices, bind the decoy node devices to the corresponding honeypots, configure the network information of the decoy node devices, and provide a remote maintenance entrance for the decoy node devices. The camouflage proxy management module is used to view the device configuration information of the camouflage proxy nodes and shut down or delete the camouflage proxy node devices. The asset identification module is used to identify, display, and maintain the information of network asset devices. The decoy deployment module is used to deploy various decoy files into the honeypots in the honeynet simulation scenario to lure intruders to access the honeypots.

[0007] Further, for a network security active defense honeypot system of the present invention, the threat analysis module includes a threat source module, an event analysis module, a behavior analysis module, a countermeasure module, and a traceability module. The threat source module is used to display threat source data from multiple regional dimensions. The event analysis module is used to analyze the event type, threat source, threatened asset, threatened scenario, threatened honeypot, and threat time of the attack event. The behavior analysis module is used to analyze the behavior type, threat source, threat port, threatened asset, threatened scenario, threatened honeypot, threatened port, threat technique, threat behavior, and threat time of the attack behavior. The countermeasure module is used to trigger a countermeasure mechanism for intruders accessing the decoy files. The traceability module is used to integrate traceability tags driven by the threat IP to display various element information supporting traceability.

[0008] Further, a network security active defense honeypot system according to the present invention, wherein the report generation module includes a risk analysis report module, a hacker profile report module, a threat event report module, and a behavior analysis report module. The risk analysis report module is used to generate a report on the security status and attack situation of the honeynet based on the threats suffered by the honeynet; the hacker profile report module is used to generate a report on the characteristics and attack methods of intruders based on the collected fingerprints and attack processes; the threat event report module is used to generate a report on the threatened situation and the attack methods of intruders when the honeypot and network asset devices are threatened in terms of the honeypot and network asset devices; the behavior analysis report module is used to generate a report on the threatened situation of the honeypot and network asset devices based on the attack methods of intruders in terms of intruders.

[0009] Further, a network security active defense honeypot system according to the present invention, wherein the linkage and co-defense module includes an event reporting module, a threat replay module, and a threat handling module. The event reporting module is used to synchronize the threat data in a normalized manner to a third-party security protection system through a selected communication protocol; the threat replay module is used to extract the post request containing data in the threat data and replay it to the third-party security protection system to reproduce the attack traffic; the threat handling module is used to view the handling status, whitelisting status, and threat intelligence of the threat IP, report the captured threat IP to the front-end security device for handling or canceling the handling, and perform ignore or whitelisting operations on the threat IP.

[0010] Further, a network security active defense honeypot system according to the present invention, wherein the threat perception module further includes a security situation display module, a risk situation display module, a ransomware situation display module, and a ransomware event statistics module. The security situation display module is used to dynamically display the network security situation based on network security data; the risk situation display module is used to display the overall security situation of the honeypot according to the set number of days and count the threat data; the ransomware situation module is used to analyze and monitor the overall security situation of ransomware in real time; the ransomware event statistics module is used to count the ransomware events, screen the ransomware events from multiple dimensions, and statistically analyze the threat depth of the honeypot by ransomware.

[0011] Furthermore, for a network security active defense honeypot system of the present invention, the threat perception module further includes a device management module, a threat intelligence management module, a simulation application management module, a simulation vulnerability management module, a tool resource management module, and a system settings module. The device management module is used to view the working status and resource occupancy rate of the honeypot online and manage the start and stop of the honeypot, SSH, and SNMP; the threat intelligence management module is used to manage threat intelligence in the threat intelligence library; the simulation application management module is used to manage simulation applications in the honeypot system; the simulation vulnerability management module is used to manage simulation vulnerabilities in the honeypot system; the tool resource management module is used to implant tool resources into the honeypot and query and edit the tool resources; the system settings module is used to configure the NTP server to synchronize the device time, add a specified IP address to the whitelist, adjust the frequency of threat traffic simulation, directionally capture preset types of threats, send alarm messages through multiple channels, import or export system configuration information, perform network tests, and set up traceability and countermeasures.

[0012] Furthermore, for a network security active defense honeypot system of the present invention, it further includes a whitelist configuration module, an access security configuration module, a system upgrade module, and a user management module. The whitelist configuration module is used to restrict the access rights of IP addresses other than those in the whitelist; the access security configuration module is used to configure the login session timeout time, the maximum login limit, the prohibited login time limit, and the password expiration time; the system upgrade module is used to upgrade the honeypot system and update the authorization; the user management module is used to maintain the login users of the honeypot system.

[0013] Furthermore, for a network security active defense honeypot system of the present invention, it further includes a log audit module. The log audit module is used to display all the logs of the administrator's login and operation behaviors, and allows filtering and querying of the logs according to the operation status, log level, recording time, input behavior, or behavior object. The content of the logs includes the log level, the operator, the operator's IP, the behavior object, the previous name of the object, the recording time, and the operation status, and supports exporting the filtered or queried results.

[0014] The beneficial effects of the present invention are as follows: The present invention has the "high sweetness" disguise characteristic, can seamlessly integrate into the actual defense network, automatically simulate business scenarios, and construct diverse vulnerable environments to attract intruders. When the intruders penetrate into the honeypot scenario, their motives and technical means will be continuously exposed, thus prolonging the attack time, enabling the defense side to gain the initiative, and improving the emergency response speed to sudden network security incidents. The present invention also has the "zero false alarm" detection ability, and its built-in honeypot trapping mechanism can accurately locate and analyze any behavior of contacting and entering the honeypot. Therefore, it can achieve zero false alarms for network intrusion, accurately identify high-risk attack behaviors, and effectively improve the emergency response efficiency of enterprises to sudden network security incidents. Adopting the "high disposal" defense strategy, the present invention effectively complements traditional boundary defense means through a deception defense mode. Based on the fusion and mining of threat data, targeted rapid and efficient disposal strategies are proposed. Through security joint defense settings, the present invention can provide threat samples for traditional security facilities, achieve joint defense, and improve the network security monitoring and defense system. The present invention also has the "traceability analysis" intelligence function. Through a highly concealed full-volume data collection mechanism, information such as the addresses, samples, behaviors, and hacker fingerprints of intruders who invade the honeypot is comprehensively collected. This enables the defense side to comprehensively master the attack path, terminal fingerprints, and behavior characteristics, achieve comprehensive evidence collection and accurate traceability, real-time monitor the attack situation, quickly obtain evidence and trace the source, and ensure the security of core information assets. The present invention can be independently deployed in a variety of network scenarios, simulating environments such as multiple independent office networks, cross-regional networks, DMZ zone networks, server networks, etc. It can be independently deployed without business connection, so it will not interfere with the normal operation of the business, and has the advantages of multi-scenario independent deployment and no business risk. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a schematic structural diagram of a network security active defense honeypot system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] The following will explain and describe in detail a network security active defense honeypot system of the present invention with reference to the accompanying drawings of the specification.

[0017] As Figure 1As shown in the figure, an embodiment of the present invention discloses a network security active defense honeypot system, which includes a centralized management and control module and a threat perception module. The centralized management and control module is used to centrally monitor, maintain, and query the honeypots deployed in the honeynet, and provide an access entrance to the centralized management and control module. A honeynet refers to a network environment composed of multiple honeypots and related support systems, which constructs a more complex and realistic virtual network trap, can simulate various network services and application scenarios, attract intruders to delve into it, and at the same time comprehensively monitor all activities of the intruders within the honeynet to obtain more comprehensive attack information. A honeypot refers to a decoy system with vulnerabilities or seemingly valuable settings in a network environment, which can simulate real systems or services, attract intruders to attack it, and at the same time record the behaviors and operations of the intruders, providing a basis for analyzing the attack methods and behavior patterns of the intruders to enhance the network security protection ability. The centralized management and control module centrally monitors, maintains, and queries the honeypots in the honeynet, and users can enter the centralized management and control module through the access entrance to understand the information of the honeypots in the honeynet. The threat perception module includes a honeynet management module, a threat analysis module, a report generation module, and a linkage and co-defense module. The honeynet management module is used to manage the honeypot simulation scenarios, honeypot virtual machines, honeypot images, trap node devices, disguised proxy node devices, network asset devices, and honeypot bait placement. The honeypot simulation scenario is a simulation of the enterprise network environment, and the honeypot virtual machine is the implementation means. The purpose of the honeypot simulation scenario is to attract intruders and collect their attack behavior information. The honeypot virtual machine is a way to create a simulation scenario. By installing an operating system and application programs in the honeypot virtual machine, it makes it look like a real target. A honeypot virtual machine can simulate different simulation scenarios according to needs. The honeypot virtual machine can be quickly created by loading the honeypot image, and the honeypot image can be updated during the operation of the honeypot virtual machine. The trap node device is a node in the network that attracts and captures intruders, and can include one or more honeypot virtual machines. The honeypot virtual machine provides the specific function of attracting intruders for the trap node device by simulating real systems and services, while the honeypot simulation scenario determines the overall layout and target of the trap node device. The disguised proxy node device and the honeypot simulation scenario are configured to enhance the concealment of the honeypot, hiding the real IP address of the honeypot so that intruders think they are attacking a network asset device located at other locations. The honeypot bait placement is the process of placing various bait files in the environments such as the honeypot virtual machines and trap node devices in the honeypot simulation scenario. By reasonably placing the honeypot bait, the attention of intruders can be attracted, increasing the interaction opportunities and residence time of the intruders with the honeypot system, so as to more comprehensively collect the threat data of the intruders. The threat analysis module is used to receive the threat data reported by the honeypots in the honeynet management module to monitor and analyze the threat status of the protected network and the behaviors and statuses of the intruders.The threat analysis module can monitor threats in real time, help security personnel grasp the network security situation in time, deeply understand the behavior of intruders, and then discover potential complex attack patterns; it can also evaluate the impact of threats on protected network assets, clarify the focus of protection, explore unknown threats and potential vulnerabilities, and warn of new attacks in advance, provide data basis for security decision-making, and assist in strategy formulation and resource allocation. Improve protection capabilities, reduce the risk of network intrusion, optimize security resource allocation, improve protection efficiency and cost-effectiveness, improve emergency response efficiency, shorten event processing time, reduce losses, accumulate threat intelligence, and enhance the intelligence and adaptive capabilities of the defense system. The report generation module is used to receive the analysis data output by the threat analysis module to generate an analysis report. The report generation module summarizes and integrates the analysis data, converts the analysis data into visual report content, reduces the difficulty of understanding, and allows personnel from different professional backgrounds to quickly obtain key information. Provide security personnel with professional reports containing detailed technical details, help in-depth analysis of problems and formulate solutions. Provide clear and accurate security information to management, help them formulate reasonable security strategies, budget planning and resource allocation decisions, and ensure the rationality and effectiveness of network security investment. The linkage defense module is used to upload threat data to a third-party security protection system for linkage defense. The third-party security protection system can be an intrusion detection system (IDS), an intrusion prevention system (IPS), a security information and event management system (SIEM), etc. The linkage defense module uploads the threat data it obtains to the third-party security protection system in a timely manner to achieve cross-platform data sharing, triggers the corresponding protection mechanism of the third-party system based on the uploaded data, and forms a collaborative defense system with its own system, and expands the overall protection boundary with the help of the resources and capabilities of the third-party system, ultimately achieving the effect of enhancing protection capabilities, improving response speed, reducing security risks, and optimizing the protection system.

[0018] In this embodiment, it can seamlessly integrate into the existing defense network system. By using automation technology to simulate various business scenarios, a diverse and vulnerable environment is constructed to attract potential network intruders. This strategy causes intruders to continuously expose their attack motives and techniques when delving deeper into the honeypot scenario. In this way, not only can the activity time of intruders in the honeypot system be effectively extended, but also the defense side can gain more initiative, thus greatly improving the emergency response speed and efficiency in dealing with sudden network security incidents. Through the built-in trapping mechanism in the honeypot, any behavior of contacting and entering the honeypot can be accurately located and deeply analyzed. This mechanism ensures a zero false alarm rate for network intrusion, can accurately identify high-risk attack behaviors, and thus effectively improves the emergency response efficiency of enterprises in dealing with sudden network security incidents. In addition, by adopting a deception-based defense mode, it effectively complements traditional boundary defense means, conducts in-depth fusion and mining based on the collected threat data, and then proposes targeted, fast, and efficient disposal strategies. Through security joint defense settings, rich threat samples are provided for traditional security facilities, realizing joint defense and further improving the network security monitoring and defense system. Through a highly concealed full-volume data collection mechanism, key information such as the addresses, samples, behaviors, and hacker fingerprints of intruders who invade the honeypot is comprehensively collected. This enables the defense side to detailedly master the attack path, terminal fingerprints, and behavior characteristics, achieve comprehensive evidence collection and accurate traceability, real-time monitor the attack situation, quickly obtain evidence and trace the source, and ensure the security of core information assets. It also has the ability to be independently deployed in various network scenarios, and can simulate environments such as multiple independent office networks, cross-regional networks, DMZ zone networks, and server networks. Since there is no need for business series connection and it can be independently deployed, it will not interfere with the normal operation of the business, ensuring the stability and security of the network.

[0019] In an embodiment of the present invention, the centralized management and control module includes a honeynet monitoring module, a honeynet maintenance module, a honeynet query module, and an access entry configuration module. Among them, the honeynet monitoring module is used to monitor the running status of the honeypots in the honeynet, display the cascading relationship and node information of the current honeynet in the form of nodes, and display the running information of the honeypots in the honeynet. The running status of the honeypots in the honeynet includes three states: honeypot online, honeypot offline, and the honeypot being attacked on the same day. The cascading relationship of the current honeynet is displayed in the form of a topology diagram. The node information includes the honeypot name, honeypot IP address, scenario entry IP address, and the running information of the honeypot. The running information includes the honeypot management background IP address, honeypot status, honeypot scenario IP address, honeypot open ports, the number of threats inside the pot in 7 days, the number of threats outside the pot in 7 days, and the latest threat IP address, etc. The honeynet maintenance module is used to add new honeypots to the honeynet in the form of authorization codes, modify the honeypot name of any honeypot, and display the authorization information of the current honeypot. The honeynet query module is used to query the authorization information of the current honeypot through the authorization code. The authorization information includes the name of the authorized honeypot, the background IP address, the authorization code, the activation time, the authorization expiration time, etc. The access entry configuration module is used to configure the IP address for accessing the honeynet. When setting the access entry, IPv6 is supported. After the setting is completed, the centralized management and control module can be accessed with the set IP address.

[0020] In this embodiment, the honeynet monitoring module displays the cascading relationship in the form of a topology diagram, presents the running status of the honeypots, nodes and running information in the form of nodes, which is convenient for the administrator to comprehensively and intuitively grasp the overall situation of the honeynet, quickly locate the problem honeypots. At the same time, by monitoring the online, offline and attacked status of the honeypots, and displaying the threat quantity and the latest threat IP, it can timely perceive security threats and take precautions in advance; the honeynet maintenance module can flexibly manage the honeypots and adjust the honeynet architecture by adding new honeypots and modifying the honeypot names through authorization codes, display the honeypot authorization information, ensure authorization management, and guarantee the security and controllability of the honeynet; the honeynet query module can quickly query the honeypot authorization information by means of the authorization code, which is convenient for permission management and maintenance, clearly displays the authorization-related information, provides accurate data for daily operation and maintenance, improves the operation and maintenance efficiency, and reduces the management cost; the access entry configuration module supports IPv6 to configure the access entry, enabling the honeynet to adapt to the development trend of network technology, meet the future network access requirements, and can also freely configure the IP address, flexibly adjust the access entry according to different security policies and network environments, and enhance the security and manageability of the honeynet.

[0021] In an embodiment of the present invention, the honeynet management module includes a scenario simulation module, a honeypot configuration module, an image management module, a decoy node management module, a spoofing proxy management module, an asset identification module, and a decoy deployment module. The scenario simulation module is used to monitor the simulation scenario environment, describe the simulation scenario information, configure the simulation scenario entrance, start and stop the services provided in the honeypot, deactivate, reset, and disconnect the network of the currently running simulation scenario, replace the honeypots running in the simulation scenario, and control the connection permissions of external honeypots and external blacklists. The honeypot configuration module is used to display the configuration information of the honeypot virtual machines (honeypot name, honeypot description, honeypot type, operating system, deployment location, running status, IP address, etc.) of the honeypot virtual machines, perform various status function operations on each honeypot virtual machine (restore to factory snapshot, snapshot creation, restore snapshot, honeypot shutdown control, honeypot restart, honeypot forced restart, honeypot NAT setting, honeypot simulation, and honeypot external connection permission), view the startup status of each honeypot (started or not started), filter honeypots by different dimensions (simulation scenario, industry, application type, support simulation, status), create honeypots, and update decoys with one key. The image management module is used to implement operations such as honeypot image production, display, release, filtering, and modification based on built-in monitoring engines (such as Windows, Windows Server, Centos, RedHat, Debian, etc.) base images. Specifically, the honeypot image information is displayed in the form of a list, and the honeypot image information includes information such as image name, image description, operating system, honeypot type, support sandbox, application type, simulation service, simulation vulnerability, associated honeypot, etc.; after the honeypot is produced, it is directly released to the running simulation scenario; filter images by conditions such as industry, application type, vulnerability type, etc.; directly modify and save and release the honeypot image with WebVNC; through the system toolkit download function, implant it into the image being produced to provide a decoy resource grabber for the high sweetness of the honeypot; download the honeypot image to the local for content modification. The decoy node management module is used to view the decoy node device configuration information (management IP address, exit IP address, whitelist IP address, number of network interfaces, running status, ARP record, etc.), restart, shut down, and delete the decoy node devices, bind the decoy node devices to the corresponding honeypots, configure the network information of the decoy node devices (enable IPv4 / IPv6, device IP address, subnet mask, default gateway, VLAN, etc.), and provide a remote maintenance entrance for the decoy node devices. The spoofing proxy management module is used to view the spoofing proxy node device configuration information (main IP address, number of proxy IPs, running status, etc.), and shut down or delete the spoofing proxy node devices. The asset identification module is used to identify, display, and maintain (edit, delete, batch delete) network asset device information (IP address, name, MAC address, region, whether it has fallen, and remarks information of the network asset device).The decoy delivery module is used to deliver various decoy files (account decoys, domain name decoys, log decoys, certificate decoys, email decoys, source code decoys, library decoys, browser decoys, official account decoys) to the honeypots within the honeynet emulation scenario to lure intruders into accessing the honeypots. The account decoy can integrate the account information of each honeypot host within the scenario. The account information includes key data such as IP address, operating system version, system account, login password, and delivery location, etc. By downloading the decoy account file and deploying it to the customer's real assets, it can attract intruders to access the relevant honeypots and trigger the alarm mechanism. The domain name decoy resolves a specific domain name to the entry IP of the honeypot scenario, guiding intruders into the honeypot. The log decoy involves storing log files with specific content on the business server. Intruders discover the entry IP of the honeypot scenario through the logs and are thus introduced into the honeypot. All log decoy information can be downloaded to the local in a fixed format. For the certificate decoy, a certificate file with specific content is stored on the business server. Intruders discover the entry IP of the honeypot scenario through this certificate file and are also introduced into the honeypot. All certificate decoy information can also be downloaded to the local in a fixed format. The email decoy includes sending emails with specific content to multiple recipients. Intruders can obtain information such as the entry IP of the honeypot scenario, system account, and password from the emails. The source code decoy involves downloading files containing source code and publishing them to GitHub. Intruders discover the entry IP of the scenario and account information through the source code and are thus introduced into the honeypot. The library decoy is to click on the download link to obtain the "System Test Report.docx" file, log in to Baidu Library (Baidu Hao) to publish graphic information. Intruders can discover the entry IP and port number of the honeypot scenario from the document and are thus introduced into the honeypot. The browser decoy includes selecting a business host to deliver the decoy, installing the Chrome browser, and entering "chrome: / / version / " in the address bar to view the profile path; filling in the website name, website address, access time, and clicking the "Add" button to add browser access record decoys; clicking the "Download Decoy" button to obtain the decoy file, closing the Chrome browser on the business host, and manually placing the decoy file into the profile path of the browser; when the business host is compromised, intruders can discover the entry IP of the honeypot scenario from the Chrome browser's history and are thus introduced into the honeypot. The official account decoy involves clicking on the download link to obtain the "Notice on the Official Launch of the Office Automation System.docx" file. Log in to the official website of the WeChat official account, publish graphic messages, and mass-send the content of the decoy file to all users who follow the official account. Intruders can discover the entry IP of the honeypot scenario from the official account messages and are thus introduced into the honeypot.

[0022] In this embodiment, the scenario simulation module can comprehensively control the simulation scenario, flexibly adjust the honeypot service and status, effectively isolate risks through controlling connection permissions, create a realistic environment for intruders to improve the deception effect; the honeypot configuration module facilitates the administrator to master the status of the honeypot virtual machine, flexibly operate the honeypot, quickly screen and create honeypots, and the one-key update of baits can timely enhance the attractiveness and defense ability of the honeypot; the image management module performs honeypot image operations based on the basic image, improves the efficiency and standardization of image production, facilitates the management and update of honeypot images, and ensures the consistency and maintainability of the honeypot system; the trap node management module is convenient for understanding the situation of trap node devices, flexibly managing devices, realizing accurate binding with the honeypot, and providing a remote maintenance entry to improve the operation and maintenance efficiency; the spoofing proxy management module enables the administrator to clearly master the status of spoofing proxy nodes, timely close or delete abnormal devices, and ensure the stability and security of the spoofing proxy system; the asset identification module can accurately master the status of network assets, facilitate the reasonable allocation of resources, provide a basis for formulating security policies, and reduce the risk of assets being attacked; the bait delivery module attracts intruders by delivering bait files, increases the chance of discovering potential threats, buys time for security defense, and facilitates the analysis of attack behaviors and means.

[0023] In an embodiment of the present invention, the threat analysis module includes a threat source module, an event analysis module, a behavior analysis module, a countermeasure module, and a traceability module. The threat source module is used to display threat source data (such as through a bar chart or a map) from multiple regional dimensions (intranet threat dimension, domestic location dimension, foreign threat dimension). The event analysis module is used to analyze the event type, threat source, threatened asset, threatened scenario, threatened honeypot, and threat time of an attack event (an attack within 24 hours by the same IP is defined as an attack event). The behavior analysis module is used to analyze the behavior type, threat source, threat port, threatened asset, threatened scenario, threatened honeypot, threatened port, threat technique, threat behavior, and threat time of an attack behavior (any single attack is defined as an attack behavior) and can analyze the attack intention through the ATT&CK model. The countermeasure module is used to trigger a countermeasure mechanism against an intruder who accesses the bait file. For example, after an intruder accesses the bait file, countermeasures are taken against the intruder through means such as office documents, EXE, communication protocol, and scanning tool vulnerabilities. The traceability module is used to integrate traceability tags driven by the threat IP to display various element information supporting traceability. The traceability tags include real IP, virtual account, clipboard, listening port, port connection, screen capture, person photo, sample retention, Weibo identity, 51CTO, NetEase identity, Sogou identity, Renren identity, Youku identity, WeChat identity, etc. The element information includes IP basic information, virtual identity account list, clipboard text data, listening port list, port connection record list, intruder person photo, intruder screen capture list (which can be previewed online or downloaded for viewing), threat sample retention list (which can be downloaded), etc.

[0024] In this embodiment, the threat source module displays threat source data from multiple regional dimensions, helping security personnel to fully perceive the threat situation and provide a basis for resource allocation and protection strategy formulation; the event analysis module analyzes attack events from multiple dimensions, allowing security personnel to clearly grasp the overall picture of the event, facilitating event classification and statistics; the behavior analysis module deeply analyzes attack behaviors to achieve real-time monitoring and early warning; the countermeasure module triggers a countermeasure mechanism for intruders who access bait files, achieving active defense and deterrence, and can also collect attack evidence; the traceability module uses threat IP as a driver to integrate traceability tags to display various element information, accurately locate intruders, and improve the security system. In this way, the threat analysis module conducts comprehensive and in-depth analysis and processing of threats from multiple aspects, forming a complete threat analysis and response system, effectively improving network security protection capabilities, and protecting network and data security.

[0025] In one embodiment of the present invention, the report generation module includes a risk analysis report module, a hacker portrait report module, a threat event report module and a behavior analysis report module. The risk analysis report module is used to generate a report on the security status and attack status of the honeynet based on the threats suffered by the honeynet. The hacker portrait report module is used to generate a report on the characteristics and attack methods of the intruder based on the collected fingerprints and attack process. The threat event report module is used to generate a report on the threat status and the intruder attack methods in the honeypot and network asset device dimensions when the honeypot and network asset device are threatened. The behavior analysis report module is used to generate a report on the threat status of the honeypot and network asset device based on the intruder attack methods in the intruder dimension.

[0026] In this embodiment, the risk analysis report module generates a report based on the threats suffered by the honeynet, enabling security personnel to quickly grasp the overall security status and attack situation of the honeynet from a macroscopic level, providing basic data for formulating protection strategies. For example, the key protection directions are determined based on the attack frequency and types of the honeynet; the hacker profiling report module generates a report based on the collected fingerprints and attack processes, accurately depicting the characteristics of the intruder and the attack methods, helping the security team understand the behavior patterns of the intruders, so as to set protection rules in advance and focus on monitoring similar attack behaviors; the threat event report module generates reports at the dimensions of honeypots and network asset devices, clearly presenting the threatened situations and the intruders' methods, enabling security personnel to identify the threatened assets and threat methods, so as to timely protect and repair the threatened assets, and quickly deploy protection patches or strategies for specific attack methods suffered by specific assets; the behavior analysis report module starts from the perspective of the intruder and generates a report on the threatened situations of honeypots and network asset devices according to their attack methods, comprehensively examining the impact of attack behaviors on different assets from the perspective of the intruder, providing a more comprehensive idea for optimizing the security protection system. For example, if it is found that a certain attack method poses a serious threat to multiple network asset devices, the overall network's protection mechanism against this method is strengthened. The reports with different focuses generated by each module jointly form a multi-angle and all-round network security analysis system, providing rich and valuable information for security decision-making, formulating protection measures, threat tracking and prevention, etc., greatly improving the efficiency and effectiveness of network security management, and effectively ensuring the security of the network and assets.

[0027] In an embodiment of the present invention, the linkage co-defense module includes an event reporting module, a threat replay module, and a threat handling module. The event reporting module is used to synchronize the threat data after being normalized (for example, processed into JSON format) to a third-party security protection system through a selected communication protocol (syslog, socket, or customized HTTP protocol). The threat replay module is used to extract the post requests containing data in the threat data and replay them to the third-party security protection system to reproduce the attack traffic. The threat handling module is used to view the handling status, whitelisting status, and threat intelligence of the threat IP, report the captured threat IP to the front-end security device for handling or canceling the handling, and perform ignore or whitelisting operations on the threat IP.

[0028] In this embodiment, the event reporting module normalizes the threat data and synchronizes it to the third-party security protection system to achieve information sharing, break information silos, enable all parties to timely understand the threat situation, and provide a data basis for collaborative defense. At the same time, the third-party security protection system further analyzes and processes threats based on this data combined with its own capabilities and strategies to enhance the overall defense capabilities. Standardized reporting also helps the security management center to uniformly manage and dispatch the threat situations of each region and each system, reasonably allocate security resources, and improve the protection efficiency and pertinence. The threat replay module replays the POST request containing data to the third-party security protection system to reproduce the attack traffic. It can not only verify the protection effect, discover vulnerabilities and weak links in the protection system and repair and optimize them in a timely manner, but also help security personnel deeply analyze the behavior patterns and means of intruders according to the reproduced situation, optimize the protection strategy. It can also simulate real attack scenarios, provide a practical emergency drill environment for the security team, improve the reaction speed and handling ability of security personnel in the face of actual attacks, and enhance the team's emergency response coordination. The threat handling module enables security personnel to view the handling status, whitelisting status, and threat intelligence of the threat IP, comprehensively understand the threat IP situation, accurately handle threats, avoid misjudgment and misprocessing, and can also report the captured threat IP to the front-end security device for handling or canceling the handling, perform ignore or whitelisting operations on the threat IP, flexibly adjust the strategy, adapt to the changing network security environment, minimize the harm of threats to the network system and data, protect the stable operation of network security, and reduce losses.

[0029] In an embodiment of the present invention, the threat perception module further includes a security situation display module, a risk situation display module, a ransomware situation display module, and a ransomware event statistics module. The security situation display module is used to dynamically display the network security situation based on network security data. For example, it displays the number of protected assets, the number of isolated threats, the security assessment score, the ranking of threatened assets, the distribution of threat event levels (low risk, medium risk, high risk, ultra-high risk), the trend of the total threat volume, the ranking of threat source locations, the ranking of threat techniques, and displays the threat time, threat type, threat source, threatened assets, threatened honeypots, and threat techniques each time a threat occurs in the form of a list. The risk situation display module is used to display the overall security situation of the honeypot and count threat data according to the set number of days. The set number of days can be the current day, the last 7 days, the last 30 days, or a custom event segment. The counted threat data includes the real-time threat level, the number of threats, the total number of threat IPs, the depth of honeypot threats, the total number of threat behaviors, the total duration of threat delay, and the number of attached decoy nodes. For the statistical analysis of security events, forms such as line charts, bar charts, and pie charts are used to statistically display the system security assessment, risk rating, threat delay time, detection / intrusion event quantity statistics, asset threat times, honeypot threat times, event analysis comparison, top 5 threat techniques, threat volume trend, top 5 threat volumes of source IPs, threat source location distribution, threat behavior classification, etc. within a specified time. The ransomware situation module is used to analyze and monitor the overall security situation of ransomware in real time. Specifically, the ransomware situation module is used to perceive, analyze, and monitor the degree of threat of ransomware to the protected network. The display of the overall security situation of ransomware includes the real-time ransomware attack degree, the number of isolated ransomware events, the number of days of ransomware delay, the number of hacker fingerprints collected, and the number of ransomware samples. For the statistical analysis of ransomware, forms such as line charts, bar charts, and pie charts are used to statistically display the distribution of ransomware degrees, the distribution of ransomware families, the trend of ransomware events, top 5 ransomware source locations, top 5 threat techniques, etc. within a specified time. The ransomware event statistics module is used to count ransomware events, screen ransomware events from multiple dimensions, and statistically analyze the depth of the threat of ransomware to the honeypot. Specifically, the ransomware event statistics module is used to conduct a detailed statistics on the threat ransomware events of the protected network, and supports filtering ransomware including: virus family, event type, risk level, threatened assets, threatened scenarios, threatened honeypots, threat IPs, threat time, etc.; supports statistical analysis of the depth of threat of ransomware (ATT&CK).

[0030] In this embodiment, the security situation display module dynamically displays the network security situation based on network security data, helping security personnel to gain real-time insight into the overall status and changing trends of network security, timely detect potential security threats and take precautions in advance. In the event of a surge in network attack traffic, network protection can be quickly strengthened; the risk situation display module displays the overall security situation of the honeypot based on the set number of days and counts threat data, allowing security personnel to grasp the security situation of the honeypot within a specific time, analyze the threat development trend, and provide strong data support for the formulation of long-term security strategies. For example, if a certain type of threat is found to appear frequently in a specific period of time through analysis, security monitoring of that period can be strengthened in a targeted manner; the ransomware situation display module analyzes and monitors ransomware in real time. The overall security situation of ransomware enables security personnel to be aware of the activities of ransomware in the first place, promptly capture its outbreak signs and spread trends, and then quickly take countermeasures, such as isolating and detecting ransomware in the early stages of an outbreak to effectively prevent its large-scale spread; the ransomware event statistics module counts ransomware events, screens and statistically analyzes the threat depth of ransomware to honeypots from multiple dimensions, which helps security personnel to fully understand the threat level and impact range of ransomware to honeypots, find out the patterns and characteristics of its attacks, and provide a solid basis for formulating targeted ransomware prevention and response plans, such as determining which honeypots are more vulnerable to ransomware attacks, thereby focusing on strengthening the protection of these honeypots.

[0031] In an embodiment of the present invention, the threat perception module further includes a device management module, a threat intelligence management module, a simulation application management module, a simulation vulnerability management module, a tool resource management module, and a system settings module. The device management module is used to view the working status and resource occupancy rate of the honeypot online and manage the start and stop of the honeypot, SSH, and SNMP. The threat intelligence management module is used to manage the threat intelligence in the threat intelligence library. For example, it displays the IP address of each threat intelligence, whether it has been used for denial of service, whether it has been used for a scanner, whether it has been used for blasting, whether it has been used as a jump server, whether it has been used for fraud, whether it has been used for a botnet, the suspected hacker organization name, network type, brief description, and update time in the form of a list. The simulation application management module is used to manage the simulation applications in the honeypot system. A simulation application refers to a software module or functional component that simulates real network applications or services in the honeypot environment, aiming to attract intruders and collect information about their attack behaviors. Specifically, the simulation application management module can view the information of the simulation applications, and the information of the simulation applications includes application name, application category, application interaction, application type, application description, included vulnerabilities, creation time, etc., and can operate on the simulation applications, including adding applications and batch deletion. The simulation vulnerability management module is used to manage the simulation vulnerabilities in the honeypot system. A simulation vulnerability refers to a defect or weakness consciously created and simulated in the honeypot environment, similar to real system vulnerabilities, used to attract intruders and obtain their attack information to assist in improving network security protection capabilities. Specifically, the simulation vulnerability management module can query and view the vulnerability information of the simulation vulnerabilities, and the vulnerability information includes vulnerability name, vulnerability category, vulnerability level, affected system, CVE number, vulnerability description, and creation time; and can operate on the vulnerability information, including adding vulnerabilities, batch deletion, editing vulnerabilities, downloading POCs, downloading EXPs, etc. The tool resource management module is used to implant tool resources into the honeypot, query and edit the tool resources. Specifically, the tool resource management module can upload the tool resources to the honeypot system as decoy resources and implant them into the honeypot, and make full use of the tool resources in the honeypot through the custom image function; display the basic information of the tool resources in the form of a list, and the information display includes tool name, applicable system, installation package name, installation package size, installation package MD5, installation times, most recent installation time, creation time, etc.; and can perform basic operations such as editing, uploading, downloading, and deleting the tool resources.The system settings module is used to configure the NTP server to synchronize the device time, including enabling and disabling NTP to synchronize the device time, setting the NTP server, setting the synchronization frequency, etc.; adding a specified IP address to the whitelist. When an IP address in the whitelist attacks the honeypot, the honeypot system will ignore the attack behavior. Setting the whitelist of file MD5 values. When the honeypot detects operations on files in the whitelist of MD5, the honeypot system will ignore these operation behaviors; adjusting the frequency of threat traffic simulation, enabling and disabling traffic simulation. Traffic simulation means automatically constructing threat traffic. After enabling, the honeypot system will construct threat traffic of http and ssh types once a day; directionally capturing preset types of threats. The honeypot supports capturing 14 major threat methods including port scanning, attempted access, cultural operations, registry operations, code execution, brute force cracking, account operations, connection establishment, vulnerability exploitation, process operations, login operations, system control, man-in-the-middle attacks, and privilege escalation of the ontology. It is possible to set the capture of directional threat types and selectively check threat behaviors. The honeypot system will capture threats according to the checked threat behaviors. If unchecked, when the honeypot is threatened by such methods, it will no longer give an alarm; sending alarm information through multiple channels, configuring page alarms, setting alarm items, retention time, alarm frequency, and system time alarm items for different risk levels; configuring email alarms, setting alarm emails for different risk levels to be sent to specified email addresses; configuring SMS alarms, setting alarm SMS for different risk levels to be sent to specified mobile phone numbers; configuring enterprise WeChat alarms, setting alarm information for different risk levels to be sent to specified WeChats; importing or exporting system configuration information, being able to import and export system configurations, and the system will perform corresponding configurations according to the imported CONF file; network testing, being able to perform PING tests according to the input destination IP and the number of times, and displaying the response results; and traceability and countermeasure settings, being able to perform data backhaul network configuration, countermeasure function switches, uploading controlled tools, control segment network configuration, etc.

[0032] In this embodiment, on the one hand, the device management module enables the administrator to view the working status and resource occupancy rate of the honeypot online in real time, grasp the operation situation in a timely manner, discover and eliminate problems caused by insufficient resources or program anomalies in a timely manner, ensure the stable operation of the honeypot, and avoid affecting the defense effect. On the other hand, it is convenient to manage the start and stop of the honeypot, SSH, and SNMP, and flexibly operate according to security policies and actual needs, improving the operation and maintenance efficiency, reducing resource consumption and security risks when maintaining, upgrading, or adjusting policies. The threat intelligence management module can effectively manage the intelligence in the threat intelligence library, enabling security personnel to obtain comprehensive and up-to-date threat information in a timely manner, accurately identify potential threats, and take preventive measures in advance. At the same time, it provides rich data for threat analysis and security decision-making, helping the security team understand the threat sources, means, and trends, and formulate targeted strategies and emergency response plans. The simulation application management module can effectively configure and adjust the simulation applications in the honeypot system according to different security requirements and scenarios, optimize the functions of the honeypot system, improve the attractiveness and deception to intruders, ensure its stable operation and reasonable configuration, enhance the threat capture ability, and provide a strong basis for subsequent analysis and defense. The simulation vulnerability management module facilitates the centralized management of the simulation vulnerabilities in the honeypot system, enabling security personnel to discover and evaluate risks in a timely manner, take repair measures, ensure the security and reliability of the honeypot system, and at the same time feedback the vulnerability information to the overall defense system to enhance the defense ability of the entire network. The tool resource management module enables security personnel to implant tool resources into the honeypot and query and edit them, quickly allocate and use them according to actual needs, save time and improve efficiency. It can also customize the configuration of tool resources according to different honeypot scenarios and security requirements, enhancing the ability of the honeypot system to cope with complex network threats. The system settings module synchronizes the device time by configuring the NTP server, providing an accurate time reference for security event recording and analysis, adding an IP white list to ensure the security and stability of network communication; it can adjust the threat traffic simulation frequency, directionally capture preset threats, flexibly adjust the detection and defense focus, and send alarm information through multiple channels to ensure timely response; importing and exporting system configuration information facilitates system backup, recovery, and cross-platform deployment, and network testing and traceability countermeasure settings help to discover network problems, improve network reliability and stability, and enhance the traceability ability.

[0033] In an embodiment of the present invention, it further includes a whitelist configuration module, an access security configuration module, a system upgrade module, and a user management module. The whitelist configuration module is used to restrict the access rights of IP addresses other than those in the whitelist. The access security configuration module is used to configure the login session timeout time, the maximum login limit, the prohibited login time limit, and the password expiration time. The system upgrade module is used for the upgrade and authorization update of the honeypot system, and can view the product name, product model, software version, authorization code, authorization validity period, update time, update description, and can perform system upgrade and authorization update operations. The user management module is used to maintain the login users of the honeypot system, can manage the login users, add new users, can customize the roles of the users, the user roles are divided into security administrators and security auditors, and can perform operations such as modifying the login permissions, resetting the password, and deleting users for the existing users in the system.

[0034] In this embodiment, the whitelist configuration module can accurately control access, only allowing trusted IPs to access the honeypot system, blocking access attempts from unknown or untrusted IPs, enhancing security, reducing interference and false alarms caused by unauthorized access requests, and optimizing the security protection efficiency; the access security configuration module effectively manages system resources by configuring the login session timeout time and setting the maximum login limit to avoid system resource exhaustion, and also strengthens account security and access management through the settings of the prohibited login time limit and the password expiration time; the system upgrade module helps the honeypot system to be upgraded and updated in a timely manner, obtain the latest functional features, repair security vulnerabilities, maintain technological advancement and security, and cope with changing network threats, providing guarantee for the good operation of the honeypot system; the user management module centrally manages the login users of the honeypot system, including creating, deleting, and modifying user permissions, etc., ensuring account security, ensuring orderly access, avoiding security risks caused by management chaos, and can also record user operation behaviors and login information in detail, facilitating security auditing and responsibility tracing, quickly locating relevant users in case of security problems, and providing strong support for investigation and handling.

[0035] In an embodiment of the present invention, it further includes a log audit module. The log audit module is used to display all the logs of the administrator's login and operation behaviors, and allows filtering and querying of the logs according to the operation status, log level, recording time, input behavior, or behavior object. The content of the logs includes the log level, the operator, the operator's IP, the behavior object, the previous name of the object, the recording time, and the operation status, and supports exporting the filtered or queried results.

[0036] In this embodiment, the log auditing module comprehensively records all logs of the administrator's login and operation behaviors, covering log levels, operators, operator IPs, behavior objects, former names of objects, recording times, operation statuses, etc., providing detailed data support for security auditing. Once a security problem occurs or a specific operation needs to be traced, these complete logs can accurately locate key elements such as the operator, operation time, content, and object. Rich filtering conditions, such as operation status, log level, recording time, input behavior, or behavior object, can help administrators quickly locate relevant records in the vast amount of logs, greatly improving the auditing efficiency and promptly discovering potential security problems or abnormal operations. Analyzing the logs from different dimensions, such as analyzing operation logs in different time periods can reveal behavior patterns and trends, warning of abnormal operation patterns or high-frequency behaviors, and analyzing the logs of specific behavior objects can evaluate their security and potential risks. In addition, the module supports exporting the filtered or queried results, facilitating the preservation of auditing results for subsequent in-depth analysis or report generation, and can provide clear and complete log data, enhancing credibility and usability. At the same time, the complete log recording and convenient auditing functions help standardize the operations of administrators, enabling them to comply with operation specifications and security systems, providing strong support for the compliance supervision of enterprises or organizations, and meeting the requirements of information security auditing regulations and standards.

[0037] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and simple improvements made to the substantial content of the present invention shall be included in the protection scope of the present invention.

Claims

1. A network security active defense honeypot system, characterized by: It includes a centralized control module and a threat perception module. The centralized control module is used to centrally monitor, maintain and query the honeypots deployed in the honeynet, and provide an access entrance to the centralized control module; the threat perception module includes a honeynet management module, a threat analysis module, a report generation module and a linkage defense module. The honeynet management module is used to manage honeypot simulation scenarios, honeypot virtual machines, honeypot images, trapping node devices, disguised proxy node devices, network asset devices and honeypot bait delivery; the threat analysis module is used to receive threat data reported by the honeypots in the honeynet management module to monitor and analyze the threat status of the protected network and the behavior and status of the intruders; the report generation module is used to receive the analysis data output by the threat analysis module to generate an analysis report; the linkage defense module is used to upload the threat data to a third-party security protection system for linkage defense.

2. A network security active defense honeypot system according to claim 1, characterized in that: The centralized control module includes a honeynet monitoring module, a honeynet maintenance module, a honeynet query module and an access entry configuration module. The honeynet monitoring module is used to monitor the operating status of the honeypot in the honeynet, display the cascade relationship and node information of the current honeynet in the form of nodes, and display the operating information of the honeypot in the honeynet; the honeynet maintenance module is used to add a new honeypot to the honeynet by means of an authorization code, modify the honeypot name of any honeypot, and display the authorization information of the current honeypot; the honeynet query module is used to query the authorization information of the current honeypot by means of an authorization code; The access entry configuration module is used to configure the IP address for accessing the honeynet.

3. A network security active defense honeypot system according to claim 1, characterized in that: The honeynet management module includes a scene simulation module, a honeypot configuration module, a mirror management module, a trapping node management module, a disguised proxy management module, an asset identification module and a bait delivery module. The scene simulation module is used to monitor the simulation scene environment, describe the simulation scene information, configure the simulation scene entrance, start and stop the services provided in the honeypot, deactivate, reset and disconnect the currently running simulation scene, replace the honeypot running in the simulation scene, and control the connection permission of the external honeypot and the external blacklist; the honeypot configuration module is used to display the configuration information of the honeypot virtual machine, perform various status function operations on each honeypot virtual machine, view the startup status of each honeypot, filter honeypots according to different dimensions, create honeypots and update baits with one click; The image management module is used to implement honeypot image production, display, release, screening and modification operations based on the built-in monitoring engine basic image; the trap node management module is used to view the trap node device configuration information, restart, shut down and delete the trap node device, bind the trap node device to the corresponding honeypot, configure the network information of the trap node device and provide a remote maintenance entrance for the trap node device; the camouflage proxy management module is used to view the camouflage proxy node device configuration information, shut down or delete the camouflage proxy node device; the asset identification module is used to identify, display and maintain network asset device information; the bait delivery module is used to deliver a variety of bait files to the honeypot in the honeynet simulation scene to lure intruders to access the honeypot.

4. A network security active defense honeypot system according to claim 1, characterized in that: The threat analysis module includes a threat source module, an event analysis module, a behavior analysis module, a countermeasure module and a tracing module. The threat source module is used to display threat source data from multiple regional dimensions; the event analysis module is used to analyze the event type, threat source, threatened assets, threatened scenarios, threatened honeypots and threat time of attack events; the behavior analysis module is used to analyze the behavior type, threat source, threat port, threatened assets, threatened scenarios, threatened honeypots, threatened ports, threat methods, threat behaviors and threat time of attack behaviors; the countermeasure module is used to trigger a countermeasure mechanism for intruders who access bait files; the tracing module is used to integrate tracing tags driven by threat IP to display various element information supporting tracing.

5. The network security active defense honeypot system according to claim 1, characterized in that: The report generation module includes a risk analysis report module, a hacker portrait report module, a threat event report module and a behavior analysis report module. The risk analysis report module is used to generate a report on the security status and attack status of the honeynet according to the threats suffered by the honeynet; The hacker portrait reporting module is used to generate a report on the intruder's characteristics and attack methods based on the collected fingerprints and attack process; the threat event reporting module is used to generate a report on the threat situation and intruder's attack methods in the honeypot and network asset device dimensions when the honeypot and network asset device are threatened; the behavior analysis reporting module is used to generate a report on the threat situation of the honeypot and network asset device based on the intruder's attack methods in the intruder dimension.

6. A network security active defense honeypot system according to claim 1, characterized in that: The linkage defense module includes an event reporting module, a threat replay module and a threat handling module. The event reporting module is used to synchronize the threat data to the third-party security protection system through the selected communication protocol after normalization processing; The threat replay module is used to extract the post request containing data in the threat data and replay it to the third-party security protection system to reproduce the attack traffic; the threat disposal module is used to check the disposal status, whitelisting status and threat intelligence of the threat IP, report the captured threat IP to the front-end security device for disposal or cancellation of disposal, and ignore or whitelist the threat IP.

7. The network security active defense honeypot system according to claim 1, characterized in that: The threat perception module also includes a security situation display module, a risk situation display module, a ransom situation display module and a ransom event statistics module. The security situation display module is used to dynamically display the network security situation based on the network security data; the risk situation display module is used to display the overall security situation of the honeypot according to the set number of days and count the threat data; the ransom situation module is used to analyze and monitor the overall security situation of the ransomware virus in real time; the ransom event statistics module is used to count the ransomware events of the ransomware virus, screen the ransomware events from multiple dimensions and statistically analyze the threat depth of the honeypot from the ransomware virus.

8. The network security active defense honeypot system according to claim 1, characterized in that: The threat perception module also includes a device management module, a threat intelligence management module, a simulation application management module, a simulation vulnerability management module, a tool resource management module and a system setting module. The device management module is used to view the working status and resource occupancy rate of the honeypot online and manage the start and stop of the honeypot, SSH and SNMP; the threat intelligence management module is used to manage the threat intelligence in the threat intelligence library; the simulation application management module is used to manage the simulation applications in the honeypot system; the simulation vulnerability management module is used to manage the simulation vulnerabilities in the honeypot system; the tool resource management module is used to implant tool resources into the honeypot, query and edit the tool resources; the system setting module is used to configure the NTP server to synchronize device time, add the specified IP address to the whitelist, adjust the frequency of threat traffic simulation, capture preset types of threats in a targeted manner, send alarm information through multiple channels, import or export system configuration information, network testing and traceability countermeasure settings.

9. The network security active defense honeypot system according to claim 1, characterized in that: It also includes a whitelist configuration module, an access security configuration module, a system upgrade module and a user management module. The whitelist configuration module is used to limit the access rights of IP addresses other than the whitelist; the access security configuration module is used to configure the login session timeout, the maximum login limit, the prohibited login time limit and the password expiration time; The system upgrade module is used for upgrading and authorizing the honeypot system; the user management module is used for maintaining the logged-in users of the honeypot system.

10. The network security active defense honeypot system according to claim 1, characterized in that: It also includes a log audit module, which is used to display all logs of administrator login and operation behaviors, and allows logs to be filtered and queried based on operation status, log level, recording time, input behavior or behavior object. The content of the log includes log level, operator, operator IP, behavior object, object's former name, recording time and operation status, and supports exporting the filtering or query results.

Citation Information

Cited By

  • Network security monitoring method and system based on artificial intelligence

    CN121792235A