An intelligent chart generation method and system based on deception defense strategy
By generating and optimizing the configuration of false assets and honey points, the problems of high resource consumption and high labor costs of deception defense technology are solved, and more efficient network defense effects are achieved.
Patent Information
- Application Number
- CN202510571105.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-05-06
AI Technical Summary
The existing deception defense technology has high defensive resource consumption and labor costs, resulting in low defense effectiveness.
By collecting and preprocessing attack data and threat intelligence data, generating structured text formats, obtaining real and false assets, monitoring network status, dividing risk areas, deploying honey points, dynamically updating spoofed array maps, using artificial intelligence technology to optimize defense strategies, and generating intelligent array maps.
It improves the defense ability against high-threat attacks, enhances the concealment and effectiveness of spoof defense strategies, and improves the effectiveness and security of network defense.
Smart Images

Figure CN120110791B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to an intelligent matrix generation method and system based on a deception defense strategy. Background Art
[0002] With the rapid development of Internet technology and the increasing complexity of the network environment, network security is facing unprecedented challenges. Traditional network defense methods, such as firewalls, intrusion detection systems, and intrusion prevention systems, mainly rely on identifying and blocking known threats. However, these methods often seem powerless when dealing with advanced and customized attacks. Especially when facing advanced persistent threats, traditional defenses are often difficult to detect and effectively respond to in a timely manner.
[0003] In recent years, deception defense technology, as an emerging security defense strategy, has gradually received attention. Different from traditional defense strategies, deception defense does not directly prevent attacks, but misleads attackers by creating false network environments and resources. The core idea of this method is to actively set "traps" to lure attackers, so that not only can attack behaviors be discovered and recorded, but also the attack pressure on real resources can be dispersed or slowed down to a certain extent. However, existing deception defense technologies require complex strategies and carefully designed matrices, usually lack authenticity when deceiving attackers, consume a large amount of defense resources, and have high labor costs, resulting in low defense effectiveness. Therefore, there is an urgent need to provide a solution to improve the above problems. Summary of the Invention
[0004] The purpose of the present invention is to provide an intelligent matrix generation method and system based on a deception defense strategy to improve the problem of low defense effectiveness caused by large consumption of defense resources and high labor costs in the prior art.
[0005] In the first aspect, an intelligent matrix generation method based on a deception defense strategy provided by the present invention adopts the following technical solution:
[0006] Collect and preprocess the attack data of the attacker to obtain target attack data, and perform path restoration on the target attack data based on a trained prediction model to obtain multiple attack behaviors, where the attack behaviors are composed of attack methods, attack paths, and attack payloads;
[0007] Collect and preprocess threat intelligence data to obtain intelligence text data, mine and extract the key features of the intelligence text data to obtain entity information, and perform structured processing on the entity information to obtain a structured text format, where the entity information includes: domain names, IP addresses, and software names;
[0008] Obtain real assets based on the structured text format and the attack behaviors, and perform simulation on the real assets to obtain false assets;
[0009] Monitor the network status to obtain monitoring information, divide the network area into multiple risk areas based on the monitoring information, and deploy the positions and quantities of honeypots according to the monitoring information and the risk areas respectively;
[0010] Perform data identification on the attack behavior and threat intelligence data to obtain a matrix deployment strategy, and update the configurations of false assets and honeypots according to the matrix deployment strategy to generate a dynamic deception matrix;
[0011] Establish a security deployment strategy based on security components, obtain the deception effect of the dynamic deception matrix according to the security deployment strategy to obtain an optimization result, and perform iteration on the dynamic deception matrix according to the optimization result to obtain the updated dynamic deception matrix.
[0012] The beneficial effects of an intelligent matrix generation method based on a deception defense strategy provided by the present invention are as follows. First, a more refined deception defense strategy is introduced to improve the defense ability against high-threat attacks. Second, the realism of false assets is enhanced by updating the configurations of false assets, and the concealment and effectiveness of the deception defense strategy are improved. Finally, according to the complexity of the network environment, artificial intelligence technology is used to improve the effectiveness and security of network defense.
[0013] Optionally, the process of generating the attack path includes the following steps:
[0014] Initialize the parameters, positions, and speeds of the pigeon flock, and update the speed, position, and fitness function value of each pigeon in the pigeon flock based on the map and compass operator until the current iteration number reaches a preset first iteration number and then stop updating, and enter the second update stage;
[0015] In the second update stage, halve the number of pigeons in the pigeon flock each time an iteration is performed, and update the positions and fitness function values of the remaining pigeons in the pigeon flock based on environmental landmarks until the current iteration number reaches a preset second iteration number and then stop updating, and output the optimal position, where the optimal position is composed of multiple key path feature points;
[0016] Smoothly connect the key path feature points in sequence to generate an attack path.
[0017] Optionally, the mathematical expression of the fitness function value is:
[0018] ;
[0019] Among them, represents the fitness function value of the pigeon flock at the current iteration, represents the performance factor based on the prediction model trained at the current iteration, Represents an attack severity function for dynamically adjusting the fitness function value , Represents the position of the th pigeon, and represents the current iteration number.
[0020] Optionally, the process of obtaining the structured text format includes:
[0021] Collect threat intelligence data according to the data source, and obtain intelligence text data after cleaning and formatting the threat intelligence data;
[0022] Mine and extract the key features of the intelligence text data, and identify the entities corresponding to the key features to obtain the structured text format.
[0023] Optionally, the false assets specifically include: simulated servers, simulated databases, and simulated configuration files. Among them, the false assets have the same content and structure as the real assets, and are used to induce attackers to perform data interactions with the false assets.
[0024] Optionally, when deploying the number of honeypots, it includes:
[0025] Generate an attack graph by combining false assets, real assets, and honeypots. The attack graph consists of multiple attack edges, multiple false assets, multiple real assets, and multiple honeypots;
[0026] Obtain the attack difficulty of each attack edge, divide the risk area into high-risk areas and low-risk areas based on the attack difficulty, increase the number of honeypots in the high-risk area, and reduce the number of honeypots in the low-risk area.
[0027] Optionally, the higher the attack difficulty of the attack edge, the smaller the regional risk index and the lower the regional risk. The lower the attack difficulty of the attack edge, the larger the regional risk index and the higher the regional risk.
[0028] In a second aspect, the present invention also provides an intelligent matrix diagram generation system based on a deception defense strategy, which is characterized in that it includes:
[0029] A data processing module for collecting, preprocessing, and storing network raw data to obtain formatted data. The network raw data includes: traffic data and honeypot log data;
[0030] An attack detection module for deeply analyzing the formatted data to obtain the potential attack methods of the attacker;
[0031] A matrix diagram generation module for generating false assets and a dynamic deception matrix diagram according to the potential attack methods;
[0032] A network coordination module is used to coordinate the deployment, configuration, and maintenance of each security component according to a security dynamic response policy formulated based on the network environment, so as to ensure that each security component can work collaboratively. The security dynamic response policy includes adjusting the matrix diagram and system backup. The adjusted matrix diagram dynamically adjusts the configuration and layout of the deception matrix diagram according to the attack pattern and target attack data, and automatically reconfigures or generates new false assets and honey points. The system backup automatically starts the backup system or restores critical data when the critical system or data is threatened.
[0033] Optionally, the attack detection module specifically includes:
[0034] A feature extraction module is used to extract the features of the formatted data to obtain feature data. The features include: traffic pattern, access behavior, and attack method;
[0035] A data analysis module is used to train the feature data to obtain a trained prediction model.
[0036] Optionally, the network coordination module specifically includes:
[0037] A policy formulation module is used to formulate a security deployment policy according to the network environment;
[0038] An attack component coordination module is used to configure each security component according to the security deployment policy.
[0039] For the beneficial effects of the second aspect, reference can be made to the description of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a flowchart of an intelligent matrix diagram generation method based on a deception defense strategy provided by the present invention;
[0041] Figure 2 is an iterative diagram of a dynamic deception matrix diagram provided by the present invention;
[0042] Figure 3 is a structural diagram of an intelligent matrix diagram generation system based on deception defense provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art to which the present invention pertains. The words such as "including" used herein mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects.
[0044] First, some terms and functions of the present invention will be explained:
[0045] Honey Array Database: Used to store and manage various versions of the deception array diagram. The detailed information of each diagram version, including diagram parameters, host features, and honeypot features, is accurately recorded in the honey array database. This not only includes the function of real-time storing the alarm logs of honeypots and performing log analysis, but also serves as a dedicated storage system for managing diagram versions.
[0046] Honey Array Controller: Responsible for functions such as diagram generation, managing diagram versions, invoking diagrams, and device linkage. By invoking the honey array controller, users can conveniently access and manage these diagram versions, and select the most suitable version for deployment according to the current network security requirements. This storage and management method greatly improves the repeatability and maintainability of the diagrams, and at the same time provides strong support for the continuous optimization of the diagrams.
[0047] False Asset: It is a fake device, service, or data, etc. in the network, similar to real assets, used to attract attackers and protect real systems and data; the false asset can be an analog server, database, and configuration file.
[0048] Honeypot: Integrates false assets, provides a more attractive target for attackers, and is used to monitor and collect the attack data of attackers.
[0049] The embodiments of the present invention provide an intelligent diagram generation method based on a deception defense strategy. Refer to Figure 1 , including:
[0050] S1. Collect and preprocess the attack data of attackers to obtain target attack data, and perform path restoration on the target attack data based on a trained prediction model to obtain multiple attack behaviors. The attack behaviors are composed of attack methods, attack paths, and attack payloads;
[0051] S2. Collect and preprocess threat intelligence data to obtain intelligence text data. Mine and extract the key features of the intelligence text data to obtain entity information, and perform structured processing on the entity information to obtain a structured text format. The entity information includes: domain names, IP addresses, and software names.
[0052] S3. Based on the structured text format and the attack behaviors, obtain real assets, and after simulating the real assets, obtain false assets.
[0053] S4. Monitor the network status to obtain monitoring information. Based on the monitoring information, divide the network area into multiple risk areas, and deploy the positions and quantities of honeypots according to the monitoring information and the risk areas respectively.
[0054] S5. Perform data identification on the attack behaviors and threat intelligence data to obtain a battle diagram deployment strategy, and update the configurations of the false assets and honeypots according to the battle diagram deployment strategy to generate a dynamic deception battle diagram.
[0055] S6. Establish a security deployment strategy based on security components. Obtain the deception effect of the dynamic deception battle diagram according to the security deployment strategy to obtain an optimization result, and perform iteration on the dynamic deception battle diagram according to the optimization result to obtain an updated dynamic deception battle diagram.
[0056] In some embodiments, in the process of obtaining multiple attack behaviors in step S1, it includes: using a machine learning algorithm, inputting target attack data into a trained prediction model, and outputting different types of attack behaviors.
[0057] In some embodiments, when performing step S1, the process of generating the attack path includes the following steps:
[0058] S1-1. Initialize the parameters, positions, and speeds of the pigeon flock, and update the speed, position, and fitness function value of each pigeon in the pigeon flock based on the map and compass operator until the current iteration number reaches a preset first iteration number, then stop updating and enter the second update stage.
[0059] S1-2. In the second update stage, halve the number of pigeons in the pigeon flock each time, and update the positions and fitness function values of the remaining pigeons in the pigeon flock based on environmental landmarks until the current iteration number reaches a preset second iteration number, then stop updating and output the optimal position, where the optimal position is composed of multiple key path feature points.
[0060] S1-3. Smoothly connect the key path feature points in sequence to generate an attack path.
[0061] Specifically, when performing step S1-1, the mathematical expression of the fitness function value is:
[0062] ;
[0063] Wherein, represents the fitness function value of the pigeon flock at the current iteration, represents the performance factor of the prediction model trained based on the current iteration, represents the attack severity function, which is used to dynamically adjust the fitness function value , represents the th position of the pigeon, represents the current iteration number.
[0064] Actually, when performing step S1-1, the parameters of the pigeon flock include: the dimension of the pigeon flock population and the preset maximum number of iterations.
[0065] Furthermore, when updating the speed and position of each pigeon in the pigeon flock based on the map and compass operator in step S1-1, the speed and position update formulas are respectively:
[0066] ;
[0067] ;
[0068] Wherein, represents the position of the pigeon flock at the represents the updated position of the pigeon flock, represents the updated speed of the pigeon flock, represents the speed of the pigeon flock at the represents a random number between 0 and 1, represents the position of the global optimal solution found by the pigeon flock at the th iteration, is the map and compass operator, which is between 0 and 1.
[0069] Furthermore, when updating the positions of the remaining pigeons in the pigeon flock based on the environmental landmarks in step S1-2, the position update formula is:
[0070] ;
[0071] ;
[0072] Wherein, represents the th iteration's halved number of pigeons, is the fitness function value of the remaining pigeons at the represents the position of the remaining pigeons at the current iteration, Indicates the positions of the remaining pigeons in the th iteration.
[0073] Furthermore, when performing step S1-2, the optimal position is: , where represents key path feature points.
[0074] Furthermore, in the process of generating an attack path when performing step S1-3, it includes: connecting key path feature points smoothly in sequence to generate an attack path.
[0075] In some embodiments, when performing step S1, the attack methods include: denial-of-service attack, tampering attack, and forgery attack. The attack path represents the complete process by which an attacker starts from a certain vulnerability or vulnerable system in the network and finally reaches the target point through a series of steps. The attack payload refers to the weapon carrier by which the attacker initiates the initial attack and establishes a network connection, and is the part that actually executes malicious functions in the attack behavior. The attack payload can be classified according to its functions and mainly includes the following types:
[0076] Delivery attack category, including: remote attack payloads, phishing emails, malicious documents, for delivering malicious code or instructions to the system.
[0077] Connection control category: including: reverse Shell, backdoor trojans, for establishing a persistent control channel in the target system to allow the attacker to remotely operate the system.
[0078] In some embodiments, in the process of performing step S2 to obtain the structured text format, it includes:
[0079] S2-1. Collect threat intelligence data according to the data source, and obtain intelligence text data after cleaning and formatting the threat intelligence data;
[0080] S2-2. Mine and extract the key features of the intelligence text data, and identify the entities corresponding to the key features to obtain the structured text format.
[0081] Actually, when performing step S2-1, the data sources include: network traffic, system logs, and honeypot logs.
[0082] Furthermore, the purpose of cleaning the threat intelligence data is to remove irrelevant and redundant threat intelligence data.
[0083] Furthermore, the threat intelligence data is sourced from public security reports and threat intelligence platforms. By analyzing the threat intelligence data, potential security threats and trends can be identified to generate analysis results, which provide data support for the design and adjustment of the matrix diagram. This enables the system to dynamically adjust the number and location of honeypots according to the real-time network status and security requirements, as well as automatically reconfigure or generate new fake assets and honeypots, thereby effectively confusing and inducing potential attackers and enhancing the overall network security defense.
[0084] Specifically, when obtaining the structured text format after identifying the entity corresponding to the key feature in step S2-2, the named entity recognition technology in natural language processing is used to identify specific types of entities from the key features to obtain extraction information, and the extraction information is combined to obtain the structured text format, which is stored in the honeypot matrix database.
[0085] Actually, when performing step S2, the IP address is the malicious attack source IP address.
[0086] In some embodiments, when performing step S3, the fake assets specifically include: simulated servers, simulated databases, and simulated configuration files. Among them, the fake assets have the same content and structure as the real assets, and are used to induce attackers to perform data interactions with the fake assets. The fake assets are similar to the real environment but are sufficiently isolated to prevent interference with the real network.
[0087] In some embodiments, when performing step S4, the locations for deploying honeypots are actually for deploying adjacent honeypots. This deployment process requires creating a professional virtual network environment or using an isolated network segment to deploy adjacent honeypots, so as to ensure that adjacent honeypots are physically or logically separated in the business network.
[0088] In some embodiments, when performing step S4, the number of deployed honeypots includes:
[0089] S4-1. Generate an attack graph by combining fake assets, real assets, and honeypots. The attack graph consists of multiple attack edges, multiple fake assets, multiple real assets, and multiple honeypots;
[0090] S4-2. Obtain the attack difficulty of each attack edge, and based on the attack difficulty, divide the risk area into a high-risk area and a low-risk area, and increase the number of honeypots in the high-risk area and decrease the number of honeypots in the low-risk area.
[0091] Specifically, when performing step S4-1, the attack edge represents the attacker's attack path.
[0092] Specifically, when performing step S4-2, the mathematical expression for the attack difficulty of the attack edge is as follows:
[0093] ;
[0094] Among them, represents the attack difficulty of each attack edge, represents the attack complexity, represents the attack path, represents the attack authentication.
[0095] Furthermore, the higher the attack difficulty of the attack edge, the smaller the regional risk index and the lower the regional risk; the lower the attack difficulty of the attack edge, the larger the regional risk index and the higher the regional risk. The specific expression is as follows:
[0096] ;
[0097] Among them, represents the regional risk index.
[0098] Actually, by dynamically deploying the positions and quantities of the honeypots, the deception matrix can be better adapted to the current network threat scenario, enabling the deception defense system to more effectively induce attackers and simultaneously collect valuable intelligence on the attackers' behaviors, thereby enhancing the overall network security defense capability.
[0099] Actually, the system can automatically reconfigure or generate new false assets and honeypots by real-time monitoring the network status and security requirements and according to the attack patterns and target attack data. This ability to coordinate and execute security deployment strategies enables the entire system to respond to various network threats in a more unified and efficient manner, thus improving the overall network security defense capability.
[0100] In some embodiments, when performing step S5, the configuration includes setting the network addresses, ports, and services of the false assets and honeypots.
[0101] In some embodiments, when performing step S6, the security deployment strategy is responsible for ensuring that all security components can work together according to the established security policies. The security components include the honeypot system, the honeycourt system, and the honeyhole system. The optimization results include the dynamic deception matrix that needs to be iterated and the dynamic deception matrix that does not need to be iterated.
[0102] Specifically, refer to Figure 2, which represents the iterative diagram of the dynamic deception matrix provided by the present invention. First, collect and analyze attack data and threat intelligence to obtain analysis results, adjust the configuration of false assets and honeypots according to the analysis results to generate deception resources, then use the deception resources to generate a dynamic deception matrix, coordinate various security components according to the generated dynamic deception matrix, execute the security deployment strategy, and finally monitor the network status with the dynamic deception matrix according to the security deployment strategy to obtain monitoring information, obtain feedback information according to the monitoring information, and judge whether it is necessary to optimize the dynamic deception matrix according to the feedback information.
[0103] Further, the feedback information specifically includes: the need to optimize the dynamic deception matrix and the need not to optimize the dynamic deception matrix. If the feedback information indicates the need to optimize the matrix, update the configuration of false assets and honeypots, and regenerate the dynamic deception matrix until the feedback information indicates that there is no need to optimize the matrix and then stop the loop; if the feedback information indicates that there is no need to optimize the matrix, save the dynamic deception matrix and end the loop.
[0104] In fact, when obtaining feedback information according to the monitoring information, the feedback information includes a continuous evaluation mechanism. This evaluation mechanism is used to monitor the interaction between the attacker and false assets, and between the attacker and honeypots to generate monitoring information, collect key performance data and user feedback according to the monitoring information, and then judge the effectiveness of the current deception strategy. If it is found that the deception effect is not as expected, or in the face of a new threat pattern, the system will automatically update the number and location of honeypots, and update the false assets. This optimization mechanism ensures that the deception defense system can adapt to the changes in the network environment and continuously provide effective security protection.
[0105] The embodiment of the present invention also provides an intelligent matrix generation system based on a deception defense strategy, which specifically includes:
[0106] A data processing module, used to collect, preprocess and store network raw data to obtain formatted data, and the network raw data includes: traffic data and honeypot log data;
[0107] An attack detection module, used to deeply analyze the formatted data to obtain the potential attack methods of the attacker;
[0108] A matrix generation module, used to generate false assets and a dynamic deception matrix according to the potential attack methods;
[0109] A network coordination module is used to coordinate the deployment, configuration, and maintenance of each security component according to a security dynamic response policy formulated based on the network environment to ensure that each security component can work collaboratively. The security dynamic response policy includes adjusting the matrix diagram and system backup. The adjusted matrix diagram dynamically adjusts the configuration and layout of the deception matrix diagram according to the attack mode and target attack data, automatically reconfigures or generates new false assets and honeypots. The system backup automatically starts the backup system or restores critical data when the critical system or data is threatened.
[0110] Actually, when the attack detection module is used to obtain potential attack methods, the attack methods include known attack methods and unknown attack methods.
[0111] Furthermore, when the matrix diagram generation module is used to generate a dynamic deception matrix diagram, it includes: integrating false assets and honeypots into a complete deception matrix diagram and performing configuration settings, dynamically adjusting the layout and features of the matrix diagram according to changes in the network state and the behavior of attackers, monitoring the effect of the deception matrix diagram, collecting interaction data between attackers and false assets and honeypots, and continuously optimizing the design and configuration of the matrix diagram based on the monitoring results and feedback information to generate a dynamic deception matrix diagram.
[0112] Furthermore, the attack detection module specifically includes:
[0113] A feature extraction module is used to extract the features of formatted data to obtain feature data. The features include: traffic patterns, access behaviors, and attack methods.
[0114] A data analysis module is used to train the feature data to obtain a trained prediction model.
[0115] Specifically, the network coordination module specifically includes:
[0116] A policy formulation module is used to formulate a security deployment policy according to the network environment.
[0117] An attack component coordination module is used to configure each security component according to the security deployment policy.
[0118] In some embodiments, refer to Figure 3 , which shows the structural diagram of an intelligent matrix diagram generation system based on deception defense provided by the present invention. Among them, the intelligent matrix diagram generation system is divided into four modules, consisting of a data processing module, an attack detection module, a matrix diagram generation module, and a network coordination module. Among them, the data processing module is used for data collection, data preprocessing, and data storage. The attack detection module is used for feature extraction and data analysis. The matrix diagram generation module is used to generate false assets and a dynamic deception matrix diagram. The network coordination module is used for policy formulation, component coordination, and matrix diagram deployment.
[0119] In summary, the present invention provides a method and system for generating an intelligent matrix diagram based on deception defense strategies, which refers to creating a dynamic and intelligent network defense system using advanced technical means. This system protects real network resources by generating and managing a false network environment, i.e., the matrix diagram, to confuse and induce potential network attackers. By creating a complex and dynamically changing deception environment, it effectively confuses and induces attackers. The core of this method lies in its dynamic nature and intelligence, which can automatically adjust defense strategies according to real-time changes in the network environment and threat situations, providing more efficient and accurate network security defenses.
[0120] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention as described in the claims. Moreover, the present invention described herein can have other embodiments and can be implemented or realized in various ways.
Claims
1. An intelligent array diagram generation method based on a deception defense strategy, characterized in that, Including: Collect and preprocess the attacker's attack data to obtain target attack data, and perform path restoration on the target attack data based on the trained prediction model to obtain multiple attack behaviors, where the attack behavior consists of an attack method, an attack path, and an attack payload; Collect and preprocess threat intelligence data to obtain intelligence text data, mine and extract the key features of the intelligence text data to obtain entity information, and perform structured processing on the entity information to obtain a structured text format, where the entity information includes: domain name, IP address, and software name; Obtain real assets based on the structured text format and the attack behavior, and simulate the real assets to obtain false assets; Monitor the network status to obtain monitoring information, divide the network area into multiple risk areas based on the monitoring information, and deploy the positions and quantities of honeypots according to the monitoring information and the risk areas respectively; Perform data identification on the attack behavior and threat intelligence data to obtain a battle map deployment strategy, and update the configurations of the false assets and honeypots according to the battle map deployment strategy to generate a dynamic deception battle map; Establish a security deployment strategy based on security components, obtain the deception effect of the dynamic deception battle map according to the security deployment strategy to obtain an optimization result, and perform iteration on the dynamic deception battle map according to the optimization result to obtain the updated dynamic deception battle map.
2. The intelligent matrix diagram generation method based on a deception defense strategy according to claim 1, wherein, The process of generating the attack path includes the following steps: Initialize the parameters, positions, and speeds of the pigeon flock, and update the speed, position, and fitness function value of each pigeon in the pigeon flock based on the map and compass operator until the current iteration number reaches the preset first iteration number and then stop updating, and enter the second update stage; In the second update stage, halve the number of pigeons in the pigeon flock at each iteration, and update the positions and fitness function values of the remaining pigeons in the pigeon flock based on the environmental landmarks until the current iteration number reaches the preset second iteration number and then stop updating, and output the optimal position, where the optimal position consists of multiple key path feature points; Smoothly connect the key path feature points in sequence to generate an attack path.
3. The method for generating an intelligent matrix diagram based on a deception defense strategy according to claim 2, wherein The mathematical expression of the fitness function value is: ; Among them, represents the fitness function value of the pigeon flock at the current iteration, represents the performance factor of the prediction model trained at the current iteration, represents the attack severity function, which is used to dynamically adjust the fitness function value , represents the position of the th pigeon, represents the current number of iterations.
4. The intelligent matrix diagram generation method based on a deception defense strategy according to claim 1, wherein The process of obtaining the structured text format includes: Collect threat intelligence data according to the data source, and clean and format the threat intelligence data to obtain intelligence text data; Mine and extract the key features of the intelligence text data, and identify the entities corresponding to the key features to obtain a structured text format.
5. A method for generating an intelligent array diagram based on a deception defense strategy according to claim 1, characterized in that, The false assets specifically include: simulated servers, simulated databases, and simulated configuration files. Among them, the false assets have the same content and structure as the real assets and are used to induce attackers to perform data interactions with the false assets.
6. A method for generating an intelligent matrix diagram based on a deception defense strategy according to claim 1, characterized in that, The quantity of deployed honeypots includes: Combine false assets, real assets, and honeypots to generate an attack graph, where the attack graph consists of multiple attack edges, multiple false assets, multiple real assets, and multiple honeypots; Obtain the attack difficulty of each attack edge, divide the risk area into a high-risk area and a low-risk area based on the attack difficulty, and increase the quantity of honeypots in the high-risk area and decrease the quantity of honeypots in the low-risk area.
7. A method for generating an intelligent array diagram based on a deception defense strategy according to claim 6, characterized in that, The higher the attack difficulty of the attack edge, the smaller the regional risk index, the lower the regional risk. The lower the attack difficulty of the attack edge, the larger the regional risk index, the higher the regional risk.
Citation Information
Patent Citations
Network spoofing defense decision-making method and system based on Flipit intelligent game
CN116962050A
Honey array defense strategy dynamic generation method and system based on large model
CN118842645A