Honeypot attack response method and device based on large model
Through the honeypot attack response method based on the big model, intelligent attack response is built, and the problem of the lack of intelligence in the interaction process of existing honeypot technology is solved, and more efficient attack response and defense capabilities are achieved.
Patent Information
- Application Number
- CN202510062082.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-30
AI Technical Summary
The existing honeypot technology lacks intelligence in the actual interaction process and cannot provide a response that can lure attackers into deep interaction.
A honeypot attack response method based on the big model is adopted. By obtaining the current attack command and historical interaction data, an attack response prompt word is constructed, and the big model is used to generate attack response results, and the historical data is updated to optimize the next round of response.
It improves the intelligence and reality of attack response results, allowing honeypots to be more adapted to complex attack methods and enhances defense capabilities.
Smart Images

Figure CN120074868A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a honeypot attack response method and device based on a large model. Background Art
[0002] With the rapid development of network technology, network security issues have become increasingly prominent. Terminal honeypots are a type of honeypot technology specifically designed to simulate real terminal systems, and are usually used to attract hackers or malware that intend to attack terminal systems. These honeypots vary in complexity, including low-interaction honeypots that simulate basic protocol or service information, high-interaction honeypots with more systems, and high-interaction honeypots that create a nearly real terminal system environment through advanced virtualization technologies such as VMware, or even deploy actual operating systems to achieve authenticity.
[0003] However, current honeypot technologies often lack intelligence in actual interactions and are unable to provide sufficient inducement for attackers to interact deeply. Summary of the Invention
[0004] The present invention provides a honeypot attack response method and device based on a large model to solve the defect that existing honeypot technologies lack intelligence in actual interactions and thus are unable to provide sufficient inducement for attackers to interact deeply.
[0005] The present invention provides a honeypot attack response method based on a large model, including: Obtaining the current attack command for the current attack round; Based on the current attack command, the historical attack interaction data set and the historical honeypot system state set in the current attack round, constructing an attack response prompt; Applying the attack response prompt based on the large model to generate an attack response result for the current attack command, and based on the attack response result of the current attack round, updating to obtain the historical attack interaction data set and the historical honeypot system state set for the next attack round.
[0006] According to the honeypot attack response method based on a large model provided by the present invention, applying the attack response prompt based on the large model to generate an attack response result for the current attack command includes: Based on the large model, applying the historical attack interaction data set to obtain a system impact result; Based on the large model, applying the system impact result, the historical honeypot system state set, and the current attack command for chain-of-thought reasoning to generate the attack response result.
[0007] A honeypot attack response method based on a large model provided by the present invention, constructing an attack response prompt word based on the current attack command, the historical attack interaction data set and the historical honeypot system state set in the current attack round, including: Construct honeypot static data based on the initial configuration of the honeypot and the honeypot response rules; Construct the attack response prompt word based on the honeypot static data, the current attack command, the historical attack interaction data set and the historical honeypot system state set.
[0008] A honeypot attack response method based on a large model provided by the present invention, constructing the attack response prompt word based on the honeypot static data, the current attack command, the historical attack interaction data set and the historical honeypot system state set, including: Construct an initial attack response prompt word based on the honeypot static data, the current attack command, the historical attack interaction data set and the historical honeypot system state set; In the case where the initial attack response prompt word is greater than a preset threshold, prune the initial attack response prompt word based on the system impact scores of the historical attack commands in the historical attack interaction data set to obtain the attack response prompt word.
[0009] A honeypot attack response method based on a large model provided by the present invention, the obtaining steps of the system impact scores of each historical attack command include: In the case of generating the attack response result by applying the attack response prompt word based on the large model, perform an aggressiveness assessment on the historical attack command based on the attack command scoring rule applied by the large model to obtain the system impact scores of each historical attack command.
[0010] A honeypot attack response method based on a large model provided by the present invention, performing an aggressiveness assessment on the historical attack command based on the attack command scoring rule applied by the large model to obtain the system impact scores of each historical attack command, including: Determine the aggressiveness score of the historical attack command based on the attack command scoring rule applied by the large model; Calculate the system impact scores of each historical attack command based on the aggressiveness score of the historical attack command and the time factor; The value of the time factor decreases as the time interval increases, and the time interval is obtained based on the current attack time and the attack time of the historical attack command.
[0011] The present invention also provides a honeypot attack response device based on a large model, including: An acquisition unit that acquires the current attack command for the current attack round; A prompt word construction unit that constructs an attack response prompt word based on the current attack command, the historical attack interaction dataset, and the historical honeypot system status set in the current attack round; An attack response unit that generates an attack response result for the current attack command by applying the attack response prompt word based on a large model, and updates the historical attack interaction dataset and the historical honeypot system status set for the next attack round based on the attack response result of the current attack round.
[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the honeypot attack response method based on a large model as described in any one of the above.
[0013] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the honeypot attack response method based on a large model as described in any one of the above.
[0014] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the honeypot attack response method based on a large model as described in any one of the above.
[0015] The honeypot attack response method and device based on a large model provided by the present invention construct an attack response prompt word through the current attack command, the historical attack interaction dataset, and the historical honeypot system status set, and apply the attack response prompt word based on a large model to generate an attack response result, realizing the transformation of the traditional attack-response processing operation into a "question-answer" text interaction based on a large model, greatly improving the intelligence and authenticity of the attack response result, and thus enabling the honeypot to be more adaptable to current complex attack techniques. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 is a flowchart of the honeypot attack response method based on a large model provided by the present invention; Figure 2 is a comparison diagram of the thought chain introduced attack response method provided by the present invention; Figure 3It is a schematic diagram of the framework of the terminal honeypot system based on large models provided by the present invention; Figure 4 It is a schematic diagram of the structure of the honeypot attack response device based on large models provided by the present invention; Figure 5 It is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed implementation manners
[0018] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.
[0019] It should be noted that, as a widely used and effective network security tool, a honeypot is designed to capture, detect and analyze malicious activities in the network. These carefully designed traps lure attackers into launching attacks, enabling the security team to collect relevant information about them, monitor their behaviors for in-depth threat analysis, and also defend against ongoing attacks.
[0020] The honeypot technology generally faces a trilemma, that is, how to achieve a balance among flexibility, interaction level and deception ability. Existing terminal honeypot designs usually have difficulty in achieving optimality in all three aspects simultaneously, resulting in defenders often having to make compromises in imperfect solutions. Existing honeypots often lack intelligence in the actual interaction process, unable to provide responses sufficient to lure attackers into deeper interactions, thereby limiting the deception ability of the honeypot and making it difficult to adapt to the continuous evolution and complexity of network attack techniques.
[0021] In view of the above problems, the present invention provides a honeypot attack response method based on large models to achieve dynamic and intelligent honeypot attack responses. Figure 1 It is a schematic flowchart of the honeypot attack response method based on large models provided by the present invention. As Figure 1 shown, the method includes: Step 110, obtaining the current attack command in the current attack round; Specifically, an attack command initiated by an attacker against the honeypot and the response of the honeypot to this attack command can be regarded as an attack round. The latest attack command can be collected through the terminal protocol proxy of the honeypot as the current attack command.
[0022] Among them, the terminal protocol agent refers to the front end of the honeypot system, which is responsible for basic protocol tasks such as establishing connections, fingerprint camouflage, message encapsulation, and parsing. In addition, the terminal protocol agent can be developed based on the protocol layer of the Cowrie honeypot and support multiple terminal protocols such as SSH and Telnet.
[0023] The current attack command here can be, for example, "uname -a". It should be noted that the attacker sends an attack command to the honeypot to modify the system state of the honeypot system, such as creating system files, viewing system files, modifying system file permissions, etc., which are operations related to the security of the honeypot.
[0024] Step 120, construct an attack response prompt based on the current attack command, the historical attack interaction dataset, and the historical honeypot system state set in the current attack round; Here, the historical attack interaction dataset refers to the set of historical attack commands and historical attack response results of each attack round between the honeypot and the attacker within a certain period before the current time. The historical attack interaction dataset can reflect the attack instruction logic of the attacker.
[0025] In addition, the historical honeypot system state set refers to the set of system state changes caused by each attack round between the honeypot and the attacker within a certain period before the current time. The historical honeypot system state set can be used to reflect the system state changes of the honeypot system after each response, enabling the large model to more accurately simulate the real state of the honeypot system, thereby generating more realistic response results.
[0026] Specifically, an attack response prompt can be constructed by first constructing a prompt template, and then filling in the current attack command, the historical attack interaction dataset, and the historical honeypot system state set in the current attack round into the pre-constructed prompt template respectively, so as to construct an attack response prompt to instruct the large model to generate an attack response result corresponding to the current attack command. In one embodiment, the historical attack interaction dataset can be recorded as a sequence: , where represents the attack command of the first attack round, represents the attack response result of the first attack round; represents the attack command of the previous attack round of the current attack round i, represents the attack response result of the previous attack round of the current attack round i. In addition, the historical honeypot system state set can be recorded as a sequence: , where represents the system change state after the honeypot system responds in one attack round; represents the system change state after the response of the previous attack round of the current attack round i.
[0027] It should be noted that the constructed attack response prompt words express the tasks that the large model needs to complete and the instructions that the tasks need to follow in natural language. The content of the attack response prompt words includes the data required by the large model when processing tasks, namely the current attack command, the historical attack interaction data set and the historical honeypot system status set under the current attack round. Among them, the historical attack interaction data set and the historical honeypot system status set under the current attack round can be used to provide the context or background information corresponding to the task of executing the current attack command. And, the prompt style of the attack response prompt words can be determined by setting role-playing or progressive reasoning to optimize the attack response results of the large model.
[0028] It can be understood that in terms of the design principle of prompt words, effective large model prompt words should meet the following basic conditions, including: clarity. To ensure the clear indication of the prompt words, the communication with the large model can be made clear by using symbol delimiters, structured output, conditional logic and "few-shot" examples. And, deliberation. Reserve time for the large model to think, and the "chain of thought" technique can be used to structure the prompt words for sequential processing and reasoning.
[0029] Step 130, apply the attack response prompt words based on the large model to generate the attack response result of the current attack command, and update the historical attack interaction data set and the historical honeypot system status set of the next attack round based on the attack response result of the current attack round.
[0030] Specifically, the attack response prompt words can be input into the large model, and the large model is used to generate the attack response result of the current attack command. The attack response result here can refer to the system execution result after the honeypot system completes the current attack command. For example, if the current attack command is to view the file directory of folder A, the attack response result can be all the files under folder A. While generating the attack response result, the historical attack interaction data set and the historical honeypot system status set of the next attack round can also be updated through the attack response result of the current attack round for the next round of honeypot attack response.
[0031] It can be understood that the large model has powerful language understanding ability, can fully understand the task description in the attack response prompt words, and combine the context or background in the attack response prompt words to generate an attack response result that meets the task description according to the response rules of the honeypot system, so as to disguise the honeypot constructed based on the large model as various vulnerable terminal services or devices, effectively attracting and capturing potential attackers in the network, thereby providing a more proactive security defense mechanism.
[0032] The method provided by the embodiments of the present invention constructs an attack response prompt word through the current attack command, the historical attack interaction dataset, and the historical honeypot system status set, and applies the attack response prompt word based on the large model to generate an attack response result, realizing the transformation of the traditional attack-response processing operation into a "question-answer" text interaction based on the large model, greatly improving the intelligence and authenticity of the attack response result, and thus enabling the honeypot to be more adaptable to the current complex attack techniques.
[0033] It should be noted that in real network confrontation scenarios, attackers often execute a series of malicious activities through multiple commands. Although traditional large models can effectively process a single command, they perform poorly in complex and interdependent extended dialogue tasks that require memory and coherence. That is, the inherent limitations of traditional large models in processing complex and extended dialogues, and effectively avoiding the limitation of the prompt context length. Furthermore, the effect of the large model in responding to the current attack command will decrease as the number of attack rounds increases.
[0034] Based on any of the above embodiments, in order to further optimize the authenticity and intelligence of the attack response result based on the honeypot, in step 130, applying the attack response prompt word based on the large model to generate the attack response result of the current attack command includes: Applying the historical attack interaction dataset based on the large model to obtain a system impact result; Performing chain-of-thought reasoning based on the large model using the system impact result, the historical honeypot system status set, and the current attack command to generate the attack response result.
[0035] Here, the system impact result can be used to reflect the impact of the attacker's attack commands on the system status of the honeypot system in historical attack rounds, so as to determine the response of the honeypot system to the current attack command.
[0036] Specifically, the large model can analyze the attack commands and the response processing results of the honeypot in each historical attack round in the historical attack interaction dataset to obtain the system impact result of the current attack round, reflecting the impact of the historical attack commands on the system status of the honeypot system, and determining whether to respond to the current attack command based on the honeypot system after the state change.
[0037] Then, the large model can perform chain-of-thought reasoning using the system impact result, the historical honeypot system status set, and the current attack command, taking the system impact result and the historical honeypot system status set as the system background information for responding to the current attack command, reasoning the expected response to the current attack command, and taking the expected response as the attack response result of the current interaction round.
[0038] For example, Figure 2It is a comparison schematic diagram of the thought chain introduction attack response method provided by the present invention. As Figure 2 shown, Figure 2 The left side exemplifies the process of the native large model without introducing the thought chain for attack response. In the first attack round , the attack command is to write the file "test", and the corresponding attack response result is to write the file "test"; in the second attack round , the attack command is to change the file "test" to have permissions 777, and the corresponding attack response result is successful permission change; in the third attack round , the attack command is to execute the file "test". At this time, when the large model generates the attack response processing result for the third attack round, it fails to consider that the file "test" was successfully written in the first attack round, resulting in an execution error for the attack response result of the third attack round.
[0039] In addition, Figure 2 the right side exemplifies the process of the native large model introducing the thought chain for attack response. During each attack response process, when generating the attack response results , , , the system state changes , , for the current attack round are also generated, as well as the system impact scores , , for the current attack command. Thus, the large model conducts thought chain reasoning on the current attack command by applying the system impact results and the historical honeypot system state set, and generates intelligent and realistic attack response results.
[0040] In one embodiment, the generation process of the attack response result may include: First, based on the current attack command, the historical attack interaction dataset, and the historical honeypot system state set in the current attack round, construct an attack response prompt, and use the attack response prompt as the input to the large model honeypot. Then, conduct thought chain data reasoning through the large model honeypot to obtain the attack response result . Then, obtain the system state change of the honeypot system based on the attack response result. In addition, obtain the system impact score of the current attack command.
[0041] Furthermore, it is possible to judge the number of words of the current attack response prompt against a preset threshold. In the case of exceeding the preset threshold, trim the historical attack interaction data in the historical attack interaction dataset until the trimmed attack response prompt meets the requirements of the preset threshold. Then, use the current attack command Attack response result Supplement the historical attack interaction dataset and record the system state changes Supplement the historical honeypot system state set for the next round of attack response.
[0042] The method provided by the embodiments of the present invention introduces the chain of thought technology into the process of generating attack response results based on large models. During each attack response, the changes in the honeypot system state after the response are generated to update the historical honeypot system state set for the next attack round, providing continuous and accurate context background information for the next attack response, thereby ensuring the intelligence and authenticity of the attack response results for each attack round.
[0043] Based on any of the above embodiments, step 120 includes: Construct the honeypot static data based on the initial honeypot configuration and the honeypot response rules; Construct the attack response prompt based on the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system state set.
[0044] Here, the initial honeypot configuration may include the hardware configuration and software configuration of the honeypot system. Among them, the hardware configuration may include configuration parameters such as the CPU type, quantity, and storage capacity. A fine-grained initial honeypot configuration can ensure the authenticity of the honeypot environment to match the system characteristics simulated by the large model terminal honeypot to cope with the attacker's review. In addition, the software configuration may include details such as system processes, resource utilization, scheduled tasks, user configurations, and file system information, and the software configuration can be adjusted based on the interaction scenario to create a customized response for each interaction.
[0045] The honeypot response rules here may include the role definition, time sensitivity, and input / output format of the large model honeypot. Among them, the role definition of the large model honeypot can be set through predefined roles, enabling the large model honeypot to accurately simulate the real terminal environment and attract and encourage attackers to conduct deeper and more persistent interactions. Time sensitivity can provide time-related information for the large model in the prompt, ensuring that the honeypot can provide accurate responses to time-related queries (such as uptime and top commands), enhancing its ability to simulate real systems. In addition, the input and output formats are crucial for the interaction between the terminal honeypot and the large model. The input format ensures that the large model can accurately understand the state of the honeypot system and the commands issued by the attacker, while the output format directly affects the operation effect of the terminal honeypot. For example, the large model can be guided to use the JSON format in the output to ensure the consistency and correctness of response parsing in each interaction with the model.
[0046] Specifically, the honeypot static data can be constructed by obtaining the initial configuration of the honeypot and the response rules of the honeypot. Then, the attack response prompt can be constructed by filling the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system status set into the corresponding prompt templates.
[0047] It should be noted that the current attack command, the historical attack interaction dataset, and the historical honeypot system status set in the attack response prompt can be dynamic indication information reflecting the current attack round, and are information that changes dynamically as the attack round progresses. Thus, by combining the honeypot static data constructed from the initial configuration of the honeypot and the response rules of the honeypot with the dynamic information constructed based on the current attack command, the historical attack interaction dataset, and the historical honeypot system status set, the final attack response prompt is constructed, achieving the construction of a prompt that is comprehensive, accurate, and can reflect context information, improving the intelligence, authenticity, and accuracy of the attack response results generated by the large model based on the indication of the attack response prompt.
[0048] It should be noted that after each attack response interaction, the relevant content can be appended to the attack response prompt by the prompt manager, resulting in the prompt for subsequent attack response interactions becoming longer and longer. However, due to limitations in computing resources, storage capacity, and model characteristics, large models based on long-term memory models have a fixed limit on the context length of the prompt. For example, once the number of tokens in the prompt exceeds this threshold, the generation performance of the large model will be affected.
[0049] To address this issue, based on any of the above embodiments, constructing the attack response prompt based on the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system status set includes: Constructing an initial attack response prompt based on the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system status set; When the initial attack response prompt is greater than a preset threshold, pruning the initial attack response prompt based on the system impact scores of each historical attack command in the historical attack interaction dataset to obtain the attack response prompt.
[0050] Here, the system impact score of a historical attack command can be used to reflect the aggressiveness and potential impact of this historical attack command on the honeypot system.
[0051] Specifically, first, the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system status set can be filled into a preset prompt template by the prompt manager to construct the initial attack response prompt. Here, Then, judge the number of words of the initial attack response prompt. When the initial attack response prompt is greater than the preset threshold, trim the initial attack response prompt based on the system impact scores of each historical attack command in the historical attack interaction dataset to obtain a concise and effective attack response prompt. For example, it can be achieved by deleting the historical attack command corresponding to the lowest system impact score and the corresponding attack response result from the historical attack interaction dataset.
[0052] The method provided by the embodiments of the present invention generates the system impact scores of historical attack commands during each attack response interaction process, so that in the process of constructing the attack response prompt for the current attack round, the historical attack interaction data in the historical attack interaction dataset can be trimmed based on the system impact scores of each historical attack command, removing the historical attack interaction data with low aggressiveness and small potential impact on the system, and retaining the historical attack interaction data with high aggressiveness and large potential impact on the system, providing concise and effective background information for generating the attack response result of the current attack round, while ensuring the intelligence and accuracy of the attack response, and also ensuring the efficiency and performance of the attack response.
[0053] Based on any of the above embodiments, the steps for obtaining the system impact scores of each historical attack command include: When using the attack response prompt based on the large model to generate the attack response result, evaluate the aggressiveness of the historical attack command based on the attack command scoring rule applied by the large model to obtain the system impact scores of each historical attack command.
[0054] Specifically, when using the attack response prompt based on the large model to generate the attack response result, the current attack command can be used as the historical attack command for the next attack round, and then the large model can be used to evaluate the aggressiveness of the historical attack command according to the attack command scoring rule. The attack command scoring rule here can be used to reflect the weights of the aggressiveness and potential impact corresponding to the preset attack command. Table 1 shows the attack command scoring rule, as shown in the following table: Table 1
[0055] As can be seen from Table 1, the scoring values of the preset attack commands for affecting services, deleting files, changing passwords, starting / stopping services, downloading files, and elevating privileges are relatively high, while the scoring values of the preset attack commands for reading files, displaying system information, creating files, and installing tools are relatively low.
[0056] For example, the attack response result and the system impact score can be implemented through the following formula, as shown in the following formula: Where \(i\) represents the current attack round, represents the attack response result of the current attack round; represents the change in the honeypot system state brought to the honeypot system based on the attack response result of the current attack round; represents the system impact score of the current attack command; represents the honeypot response rule; represents the initial configuration of the honeypot; represents the historical attack interaction dataset; represents the set of historical honeypot system states; represents the current attack command.
[0057] Based on any of the above embodiments, based on the attack command scoring rule of the large model application, the aggressiveness of the historical attack commands is evaluated, and the system impact scores of the historical attack commands are obtained, including: Based on the attack command scoring rule of the large model application, determine the aggressiveness score of the historical attack command; Based on the aggressiveness score of the historical attack command and the time factor, calculate the system impact scores of the historical attack commands; The value of the time factor decreases as the time interval increases, and the time interval is obtained based on the current attack time and the attack time of the historical attack command.
[0058] Here, the time factor can be used to quantify the influence of time on the system impact score of the historical attack command. The value of the time factor decreases as the time interval increases, and the time interval is obtained based on the difference between the current attack time and the attack time of the historical attack command. It can be understood that the longer the attack time of the historical attack command is from the current time, the smaller the corresponding time factor is, indicating that the influence of the historical attack command on the honeypot system's processing of the current attack command is smaller. Here, the time factor can be represented by the following formula, as shown below: where \(W\) represents the time factor. From the above formula, it can be seen that a newly executed attack command has a higher importance than an early high-privilege attack command.
[0059] Specifically, after determining the aggressiveness score of the historical attack command based on the attack command scoring rule of the large model application. To further improve the accuracy of the system impact score, the system impact scores of the historical attack commands can be calculated through the aggressiveness score of the historical attack command and the time factor.
[0060] It should be noted that the system impact score of historical attack commands is quantified by a time factor. That is, including the time factor ensures that newly executed attack commands are more important than earlier high-privilege attack commands, and this characteristic conforms to the characteristics among attack commands in the attack command sequence, such as "write - privilege escalation - execute". Among them, it is executed in the order of first "write", then "privilege escalation", and finally "execute". Among them, the "write" is executed earliest, but its impact on the system is the smallest, while the "execute" is executed latest, and its impact on the system is the largest.
[0061] Thus, by using a time factor that conforms to the impact degree characteristics of each attack command in the attack command sequence, the system impact score of historical attack commands is weakened, and a system impact score that conforms to the attack command characteristics is obtained. Furthermore, the accuracy of pruning attack response prompt words based on the system impact score is improved, and the ability of the honeypot system to simulate a real system is enhanced. Here, the attack response prompt words can be implemented through the following formula, as shown below: In the formula, represents the prompt word manager, which represents the honeypot response rule of the previous attack round based on the current attack round i , the initial configuration of the honeypot , the historical attack interaction dataset , the historical honeypot system status set , the system status change , the system impact score , the attack response result and the time factor , and the attack response prompt words for the current attack round are updated to obtain .
[0062] Based on any of the above embodiments, Figure 3 is a framework schematic diagram of the terminal honeypot system provided by the present invention. As shown in Figure 3 , the system includes: a terminal protocol proxy, prompt engineering, and a large model dialogue interface. In the attack response processing flow, the attack information of the network attacker, that is, the current attack command, can be obtained through the terminal protocol proxy. Then, the attack instruction (the current attack command) is transmitted to the prompt engineering, and the attack response prompt words are constructed through the prompt engineering and input into the large model dialogue interface. Then, a reply (attack response result) is output through the large model dialogue interface, and the reply information is displayed to the network attacker through the terminal protocol proxy.
[0063] Among them, through prompt engineering M, based on the current attack command, the historical attack interaction dataset, and the historical honeypot system status set in the current attack round, an attack response prompt word can be constructed. Then, it is determined whether the prompt word exceeds the length limit. If it does, the attack response prompt word is reconstructed. If it does not exceed, a honeypot reply (attack response result) is generated based on the attack response prompt word. Generate a system status update And the system impact score of the current attack instruction .
[0064] The system provided by the embodiment of the present invention, first, in view of the problem of the lack of a standardized honeypot prompt word design method in the existing honeypot system, a set of general specifications for honeypot prompt words is formulated. Secondly, to overcome the inherent thinking limitations of large language models in dealing with complex attack combinations, the present invention combines the chain of thought strategy, enabling the language model to accurately evaluate the impact of commands on the operating system in each interaction. Finally, in view of the performance degradation caused by the context length limit and forgetting mechanism of large models in dealing with long-term sessions, the session history is strategically pruned, thereby optimizing the effectiveness of the honeypot in long-term interactions.
[0065] Finally, by disguising the large model honeypot as various vulnerable terminal services or devices, potential attackers in the network can be effectively attracted and captured, thereby providing a more proactive security defense mechanism. For example, the "Techniques" section of the ATT&CK framework developed by MITRE can be used to classify the attack methods captured by the honeypot. Table 2 shows 11 attack behaviors identified by the large model terminal honeypot, which are divided into 6 ATT&CK techniques.
[0066] Table 2
[0067] Combined with the use of the ATT&CK framework, the honeypot system can dynamically adjust its response strategy. According to the severity and type of the attack, the system can implement measures ranging from simple warnings to complex defenses, such as automatically isolating attack traffic or updating firewall rules.
[0068] Based on any of the above embodiments, Figure 4 is a schematic structural diagram of the honeypot attack response device provided by the present invention. As Figure 4 shown, the device includes: An acquisition unit 410, which acquires the current attack command of the current attack round; A prompt word construction unit 420, which constructs an attack response prompt word based on the current attack command, the historical attack interaction dataset, and the historical honeypot system status set in the current attack round; The attack response unit 430 generates the attack response result of the current attack command based on the large model applying the attack response prompt word, and updates the historical attack interaction dataset and the historical honeypot system status set of the next attack round based on the attack response result of the current attack round.
[0069] The device provided by the embodiment of the present invention constructs an attack response prompt word through the current attack command, the historical attack interaction dataset and the historical honeypot system status set, and generates an attack response result by applying the attack response prompt word based on the large model, realizing the transformation of the traditional attack-response processing operation into a "question-answer" text interaction based on the large model, greatly improving the intelligence and authenticity of the attack response result, and further enabling the honeypot to be more adaptable to the current complex attack methods.
[0070] Based on any of the above embodiments, the attack response unit is specifically configured to: Apply the historical attack interaction dataset based on the large model to obtain the system impact result; Perform chain-of-thought reasoning based on the large model applying the system impact result, the historical honeypot system status set, and the current attack command to generate the attack response result.
[0071] Based on any of the above embodiments, the prompt word construction unit is specifically configured to: Construct the honeypot static data based on the honeypot initial configuration and the honeypot response rule; Construct the attack response prompt word based on the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system status set.
[0072] Based on any of the above embodiments, the prompt word construction unit is further specifically configured to: Construct the initial attack response prompt word based on the honeypot static data, the current attack command, the historical attack interaction dataset, and the historical honeypot system status set; In the case where the initial attack response prompt word is greater than the preset threshold, prune the initial attack response prompt word based on the system impact scores of the historical attack commands in the historical attack interaction dataset to obtain the attack response prompt word.
[0073] Based on any of the above embodiments, the prompt word construction unit is further specifically configured to: In the case where the attack response result is generated by applying the attack response prompt word based on the large model, perform an aggressiveness assessment on the historical attack commands based on the large model applying the attack command scoring rule to obtain the system impact scores of the historical attack commands.
[0074] Based on any of the above embodiments, the prompt construction unit is further specifically configured to: Determine the aggressiveness score of the historical attack command based on the large model application attack command scoring rule; Calculate the system impact score of each historical attack command based on the aggressiveness score of the historical attack command and the time factor; The value of the time factor decreases as the time interval increases, and the time interval is obtained based on the current attack time and the attack time of the historical attack command.
[0075] Figure 5 The schematic physical structure diagram of an electronic device is exemplified, as Figure 5 shown. The electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communication interface 520, and the memory 530 complete mutual communication through the communication bus 540. The processor 510 can call the logical instructions in the memory 530 to execute the honeypot attack response method based on the large model. The method includes: obtaining the current attack command of the current attack round; constructing an attack response prompt word based on the current attack command, the historical attack interaction data set, and the historical honeypot system status set in the current attack round; applying the attack response prompt word based on the large model to generate the attack response result of the current attack command, and updating the historical attack interaction data set and the historical honeypot system status set of the next attack round based on the attack response result of the current attack round.
[0076] In addition, when the logical instructions in the above-mentioned memory 530 are implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. And the aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical disks, etc., which can store program codes.
[0077] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the large model-based honeypot attack response method provided by the above-mentioned various methods. The method includes: obtaining the current attack command of the current attack round; constructing an attack response prompt word based on the current attack command, the historical attack interaction data set and the historical honeypot system status set in the current attack round; applying the attack response prompt word based on the large model to generate an attack response result for the current attack command, and updating the historical attack interaction data set and the historical honeypot system status set for the next attack round based on the attack response result of the current attack round.
[0078] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the large model-based honeypot attack response method provided by the above-mentioned various methods. The method includes: obtaining the current attack command of the current attack round; constructing an attack response prompt word based on the current attack command, the historical attack interaction data set and the historical honeypot system status set in the current attack round; applying the attack response prompt word based on the large model to generate an attack response result for the current attack command, and updating the historical attack interaction data set and the historical honeypot system status set for the next attack round based on the attack response result of the current attack round.
[0079] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.
[0080] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course also by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0081] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A honeypot attack response method based on a large model, characterized in that: include: Get the current attack command of the current attack round; Constructing an attack response prompt word based on the current attack command and the historical attack interaction data set and the historical honeypot system status set under the current attack round; The attack response prompt words are applied based on the large model to generate the attack response result of the current attack command, and based on the attack response result of the current attack round, the historical attack interaction data set and the historical honeypot system status set of the next attack round are updated.
2. The honeypot attack response method based on a large model according to claim 1 is characterized in that: The step of applying the attack response prompt word based on the large model to generate an attack response result of the current attack command includes: Applying the historical attack interaction data set based on the large model to obtain system impact results; Based on the large model, the system impact result, the historical honeypot system state set and the current attack command are applied to perform thought chain reasoning to generate the attack response result.
3. The honeypot attack response method based on a large model according to claim 1 is characterized in that: The constructing of attack response prompt words based on the current attack command and the historical attack interaction data set and the historical honeypot system status set under the current attack round includes: Based on the honeypot initial configuration and honeypot response rules, the static data of the honeypot is constructed; The attack response prompt word is constructed based on the honeypot static data, the current attack command, the historical attack interaction data set and the historical honeypot system status set.
4. The honeypot attack response method based on a large model according to claim 3 is characterized in that: The constructing the attack response prompt word based on the honeypot static data, the current attack command, the historical attack interaction data set and the historical honeypot system status set includes: Based on the honeypot static data, the current attack command, the historical attack interaction data set, and the historical honeypot system status set, construct an initial attack response prompt word; When the initial attack response prompt word is greater than a preset threshold, the initial attack response prompt word is pruned based on the system impact score of each historical attack command in the historical attack interaction data set to obtain the attack response prompt word.
5. The large model-based honeypot attack response method according to claim 4 is characterized in that: The steps for obtaining the system impact score of each historical attack command include: When the attack response prompt word is applied based on the large model to generate the attack response result, the attack command scoring rule is applied based on the large model to perform an offensiveness evaluation on the historical attack commands to obtain a system impact score of each historical attack command.
6. The large model-based honeypot attack response method according to claim 5, characterized in that: The step of applying the attack command scoring rule based on the large model to perform an aggressiveness evaluation on the historical attack commands to obtain a system impact score of each historical attack command includes: Applying attack command scoring rules based on the large model to determine the aggressiveness score of the historical attack command; Calculate the system impact score of each historical attack command based on the aggressiveness score and time factor of the historical attack command; The value of the time factor decreases as the time interval increases, and the time interval is obtained based on the current attack time and the attack time of the historical attack command.
7. A honeypot attack response device based on a large model, characterized in that: include: Get unit, get the current attack command of the current attack round; A prompt word construction unit, which constructs an attack response prompt word based on the current attack command and the historical attack interaction data set and the historical honeypot system status set under the current attack round; The attack response unit applies the attack response prompt words based on the large model to generate an attack response result of the current attack command, and based on the attack response result of the current attack round, updates the historical attack interaction data set and the historical honeypot system status set for the next attack round.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the honeypot attack response method based on the large model as described in any one of claims 1 to 6 is implemented.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the honeypot attack response method based on a large model as described in any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the honeypot attack response method based on a large model as described in any one of claims 1 to 6 is implemented.
Citation Information
Cited By
Honeypot interaction response generation method based on large language model
CN120750578A