Dynamic deception defense system and method based on service trip line technology
By adopting a dynamic spoof defense system based on service tripwire technology in network security protection, the problem of limited protection effect in the face of complex attacks is solved, intelligent analysis and dynamic deployment are achieved, and the defense effect is enhanced.
Patent Information
- Application Number
- CN202510580664.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Traditional cybersecurity protection methods are limited in the protection of complex, advanced persistent threats (APTs) and unknown attacks, and it is difficult to respond flexibly to complex attacks.
A dynamic spoof defense system based on service tripwire technology is adopted. The system scans network resources through the network management module, the log collection module monitors attacker behavior, the intelligent decision-making module generates and adjusts the deployment strategy of honey point services, the honey point warehouse module pre-stores and manages honey point service images, and the honey point management module dynamically deploys and adjusts honey point services.
It realizes intelligent analysis of network environment and attack behavior, dynamically adjusts the deployment strategy of honey point service, enhances the deception effect, delays the attack process, improves the defense effect, and buys time for the defense party.
Smart Images

Figure CN120110795A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security protection, and in particular to a dynamic deception defense system and method based on service tripwire technology. Background Art
[0002] With the rapid development of information technology, the network security situation has become increasingly complex and severe. At present, the means of network attacks have gradually evolved from traditional viruses and malware to more hidden and complex advanced persistent threats (APT), zero-day vulnerability attacks, and distributed denial of service (DDoS). In particular, APT attacks are usually targeted at specific targets, with strong concealment and long-term nature, making it difficult for defenders to detect and respond. At the same time, with the widespread application of technologies such as the Internet of Things, big data, and cloud computing, the potential attack surface in the network has expanded dramatically, making it difficult for traditional static security defense methods to fully protect, and the difficulty of network security defense has increased unprecedentedly.
[0003] In response to network attacks, traditional defense technologies such as firewalls and intrusion detection systems (IDS) perform well in the face of known threats, but their limitations are becoming increasingly apparent. These technologies rely on the update of rule bases and the identification of known attack features, and often seem powerless in the face of new, unknown attacks. In addition, traditional defense strategies are often passive and cannot flexibly adapt to the increasingly sophisticated means of attackers, allowing attackers to exploit network vulnerabilities for long-term reconnaissance and attempts to circumvent existing defense measures.
[0004] Faced with these complex forms of attack, traditional network security protection methods have gradually exposed their limitations. Passive defense technologies such as firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) are mainly based on known threats and rule bases. They can effectively defend against known attacks, but when faced with unknown attacks, such as APT and zero-day vulnerability attacks, these technologies have limited protection effects. The limitations of traditional defense methods are mainly reflected in the following aspects: Passivity: Existing defense systems are usually based on the detection of attack characteristics, that is, they can only detect and respond after the attack occurs, and lack the ability to actively discover threats.
[0005] Dependence on rule base: The defense system relies heavily on the update of the rule base and known attack features. When faced with new and unknown attacks, such as zero-day attacks, it is often unable to identify and defend against them if the rule base is not updated.
[0006] Difficulty in dealing with complex attacks: Traditional defense methods are mostly statically configured and cannot flexibly deal with complex and multi-stage attacks, especially APT attacks, which usually bypass existing defense mechanisms through multiple attempts and infiltrations.
[0007] In order to solve these problems, the field of network security has gradually introduced active defense strategies, among which network deception defense technology has become an important research direction. The core idea of deception defense technology is to deploy a false bait system in the network to attract the attention of the attacker and monitor its behavior, thereby delaying or blocking its attack path. In this way, the defender can not only obtain the attacker's behavior information, but also buy time for itself to deploy further defense measures without damaging the actual network assets.
[0008] As a typical application of deception defense technology, the honeypot system has been widely used in network security. A honeypot is a fake environment that simulates a real system, with the purpose of attracting attackers and recording their behavior. Traditional honeypot systems simulate network services, devices, or operating systems to induce attackers to waste time and resources on fake targets, thereby delaying their attacks on real targets. By analyzing the attack behavior in the honeypot, defenders can gain a deep understanding of the attack methods and strategies, providing valuable information for subsequent security protection.
[0009] Honeypot technology has been developed for a long time since its birth. With the advancement of computer technology, the ability of honeypot to imitate services has become stronger and stronger. From the initial DTK, which simply responded to requests for simulated ports, to the later Honeyd, which personalized the simulation of services on specified ports and even the fingerprint of the operating system on the TCP layer. Now, with the development of container technology, simulating a service has become easier and more flexible. However, even with the ability to easily generate fake services, today's honeypot system still has many shortcomings. Through the analysis of the entire honeypot deployment process, it is not difficult to find that the shortcomings of modern honeypots are mainly reflected in the following aspects: 1) Honeypot configuration is relatively fixed and difficult to integrate into the surrounding network environment: The honeypot templates used by modern honeypots are usually prepared from the beginning, and the target environment to be deployed is almost not considered. In this way, when an attacker probes, he can easily identify this system that is "incompatible" with the environment, and then see through the disguise of the honeypot, making it difficult to trap the attacker.
[0010] 2) The deployment and maintenance of honeypots require administrators to invest a lot of time: For current honeypots, whether they are independent, master-slave or distributed, the deployment and maintenance of honeypots are highly dependent on the participation of administrators. Therefore, whether the honeypot can play a good role is almost linked to the ability of the administrator. Even if a high-level administrator can come up with an excellent deployment strategy, facing the network environment that may change at any time, it takes a lot of time to adjust the strategy at all times, and every adjustment is accompanied by the exposure of the weakest point of the system.
[0011] 3) Honeypot deployment is not flexible enough: There are generally two ways to deploy modern honeypots. The first is to directly read the configuration file and deploy it according to the requirements in the configuration file; the second is to provide an operation interface for the administrator to deploy the honeypot on the operation interface. For the first deployment method, the administrator needs to spend time learning the various rules in the configuration file, which undoubtedly increases the difficulty for inexperienced users. The second deployment method has too low deployment efficiency and is almost useless in situations where a large number of honeypots need to be started quickly. Summary of the invention
[0012] The object of the present invention is to provide a dynamic deception defense system and method based on service tripwire technology to solve at least one problem in the background technology.
[0013] In a first aspect, the present invention provides a dynamic deception defense system based on service tripwire technology, the system comprising: The network management module is used to scan network resources, build a network topology map based on the network resource perception data obtained through the scan, and build a honeypot network; A log collection module, used to monitor the interaction between the honey spot service and the attacker to collect log data, and to obtain the attacker's behavior data based on the log data analysis; An intelligent decision-making module, used to obtain the network resource perception data, generate and adjust the deployment strategy of the service tripwire honeypot according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in a configuration file; A honey spot warehouse module is used to pre-store honey spot service images corresponding to each server, honey spot service images generated by large language model simulation, and customized honey spot service images; The honey spot management module is used to receive and parse the configuration file, and obtain the honey spot service requirements according to the parsing results, so as to retrieve the corresponding honey spot service image from the honey spot warehouse according to the honey spot service requirements.
[0014] In summary, according to the above-mentioned dynamic deception defense system based on service tripwire technology, this system will scan the resource information in the network environment to obtain network resource perception data, and then generate the configuration strategy of the honey spot service according to the network resource perception data. At the same time, the system will also accept the changes in the network environment and the information of the interaction between the attacker and the honey spot service, and dynamically change the configuration strategy of the honey spot service. In addition, the system also supports directly reading the honey spot service deployment strategy from the configuration file, making the deployment method of the honey spot service more flexible. This dynamic adjustment capability makes it difficult for attackers to detect and identify, thereby effectively delaying the attack process, improving the defense effect, and buying time for the defender in the network attack.
[0015] Furthermore, the network management module also includes: A first scanning unit is used to scan the entire network environment to obtain all subnets contained in the network environment, all devices running on each subnet, and the device type of each device; The second scanning unit is used to traverse all devices on any subnet to determine online devices and record IP addresses and MAC addresses of online devices; The third scanning unit is used to scan the online devices according to the IP address and the MAC address to obtain the service name run by each online device and the port number and version information corresponding to the service name.
[0016] Furthermore, the network management module also includes: A network topology map construction unit, used to generate a network topology map according to all scanning results, wherein the network topology map includes the connection status of each device and the service type corresponding to each device; A honey spot network construction unit, used to construct a virtual double bridge structure, the virtual double bridge structure includes an upper layer bridge and a lower layer bridge, the upper layer bridge is used to connect the Docker containers of multiple honey spots, and the lower layer bridge is used to connect the honey spot network with the physical network; Each honeypot is assigned an independent network namespace through a virtual network interface.
[0017] Furthermore, the intelligent decision-making module also includes: A deployment strategy generating unit, configured to obtain at least one service type of the corresponding subnet according to all devices running on each subnet, the device type and version information of each device, and generate a deployment strategy according to the at least one service type of the corresponding subnet; The deployment strategy includes service tripwire honeypot information and port numbers, the service tripwire honeypot information includes honeypot IPs simulating device addresses, honeypot services simulating all service types, and service-IP association relationships; Map the honey spot service to the corresponding honey spot IP according to the service-IP association relationship; The configuration file generating unit is used to generate a configuration file that corresponds one-to-one with the sweet spot IP, the sweet spot service and the service-IP association relationship.
[0018] Furthermore, the honey spot management module also includes: A configuration file parsing unit, used to parse the configuration file to extract a honey spot service image corresponding to the honey spot service from the honey spot warehouse according to the parsing result; The deployment execution unit is used to deploy the honey spot service image on the corresponding honey spot IP and bind the corresponding port number.
[0019] Furthermore, the log collection module also includes: The monitoring and alarm unit is used to obtain the attack request uploaded by the honey spot service, identify the attack request, obtain the identification result, and the identification result includes the attacker's IP address, request path, attack content, and timestamp, and then issue an alarm message within the first preset time.
[0020] Furthermore, the monitoring and alarm unit is also used for: Malicious SQL statements in the attack request are identified based on the pre-trained large model to analyze the content contained in the attack request, identify malicious SQL injection patterns, and determine the attacker's intentions.
[0021] In a second aspect, the present invention provides a dynamic deception defense method based on service tripwire technology, the method comprising: Scan network resources, build a network topology map based on the network resource perception data obtained from the scan, and build a honeypot network; Monitoring the interaction between the honey spot service and the attacker to collect log data, and obtaining the attacker's behavior data based on the log data analysis; Acquire the network resource perception data, generate and adjust a deployment strategy of a service tripwire honeypoint according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in a configuration file; Pre-store the honey spot service images corresponding to each server, the honey spot service images generated by large language model simulation, and the customized honey spot service images; The configuration file is received and parsed, and the honey spot service requirement is obtained according to the parsing result, so as to retrieve the corresponding honey spot service image from the honey spot warehouse according to the honey spot service requirement.
[0022] In a third aspect, the present invention provides a storage medium storing one or more programs, which, when executed by a processor, implement the above-mentioned dynamic deception defense method based on service tripwire technology.
[0023] In a fourth aspect, the present invention provides an electronic device, the electronic device comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor is used to execute the computer program stored in the memory, the above-mentioned dynamic deception defense method based on service tripwire technology is implemented.
[0024] In addition, compared with the prior art, the present invention also has the following advantages: 1. The present invention proposes a service tripwire honey spot to achieve a design of separating the honey spot IP from the honey spot service. The honey spot IP, as a bait resource visible to attackers, can be quickly generated and deployed, so the system can flexibly respond and deploy multiple bait targets in a short time.
[0025] 2. By combining the logic deduction and code generation capabilities of a large language model, the system of the present invention can perform high-quality simulation of protection services, realize the dynamic generation and precise simulation of multiple high-simulation services, and make them appear as hosts running various real services from the attacker's perspective, greatly enhancing the deception effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 A schematic diagram of the structure of a dynamic deception defense system based on service tripwire technology proposed in one embodiment of the present invention; Figure 2 It is a flow chart of a honey spot warehouse module in one embodiment of the present invention; Figure 3 A flowchart of a network management module in one embodiment of the present invention; Figure 4 A flowchart of an intelligent decision-making module in one embodiment of the present invention; Figure 5 It is a structural schematic diagram of a service tripwire honeypot in one embodiment of the present invention; Figure 6 It is a flow chart of a honey spot management module in one embodiment of the present invention; Figure 7 This is a flow chart of a log collection module in one embodiment of the present invention; Figure 8 The flowchart of the dynamic deception defense method based on service tripwire technology proposed in one embodiment of the present invention.
[0027] The following specific implementation manner will further illustrate the present invention in conjunction with the above-mentioned drawings. DETAILED DESCRIPTION
[0028] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be understood by people with general skills in the field to which the present invention belongs. "Including" and similar words used in this article mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects.
[0029] Embodiment 1
[0030] See also Figure 1 , which is a schematic diagram of the structure of a dynamic deception defense system based on service tripwire technology proposed in the first embodiment of the present invention, the system includes: The network management module 10 is used to scan network resources, build a network topology map based on the network resource perception data obtained by the scan, and build a honey spot network; It should be noted that in the network management module, the network management module senses and maintains the current network environment through automated network resource scanning and IP management functions to ensure seamless integration of the honey spot with the real network. At the same time, through the OVS virtual dual bridge technology, the module flexibly builds the honey spot network to achieve effective isolation and forwarding of honey spot traffic, while ensuring the rapid deployment, dynamic adjustment and secure communication of honey spot services with external networks, thereby enhancing the flexibility and stability of network defense.
[0031] A log collection module 20, used to monitor the interaction between the honey spot service and the attacker to collect log data, and to obtain the attacker's behavior data according to the log data analysis; In the log collection module, this module is responsible for recording, storing and analyzing the interaction between the honey spot service and the attacker in the service tripwire system (a dynamic deception defense system based on service tripwire technology). Its function is to monitor the running status of the honey spot service, collect the attacker's behavior data, and conduct in-depth analysis of this data to help the security team identify attack patterns, understand attack methods, and formulate effective security defense strategies. The automatic feedback adjustment mechanism dynamically adjusts the configuration and deployment strategy of the honey spot by monitoring the interaction data between the honey spot service and the attacker in real time and combining the analysis results of the log collection module. This mechanism can automatically identify attack patterns and abnormal behaviors, and automatically optimize the running status and defense strategy of the honey spot service based on the analysis feedback, ensuring that the honey spot service can continue to deceive attackers and improve the protection effect, thereby enhancing the overall security of the system.
[0032] An intelligent decision-making module 30, for acquiring the network resource perception data, and generating and adjusting a deployment strategy of a service tripwire honeypot according to the network resource perception data and the attacker's behavior data, and recording the deployment strategy in a configuration file; In the intelligent decision-making module, the module automatically generates and adjusts the deployment strategy of service tripwire honeypots by analyzing the network environment and attacker behavior. It combines attack feedback information to dynamically adjust the configuration and service deployment of honeypots to respond to constantly changing threats. Through intelligent decision-making capabilities, the module optimizes defense effects, ensures that honeypot deployment is synchronized with attack behavior, and improves the response efficiency and security of the entire system.
[0033] A honey spot warehouse module 40 is used to pre-store honey spot service images corresponding to each server, honey spot service images generated by large language model simulation, and customized honey spot service images; In the honey spot warehouse module, this module is responsible for managing and storing various service images, providing diversified virtual service support for the deployment of honey spots. This module not only pre-fabricates a variety of common service images, but also supports the generation of simulated service images through large language models (such as ChatGPT). Administrators can also manually upload customized images. By flexibly calling services of different versions and types, the honey spot warehouse module ensures that the honey spot service can respond and adjust quickly according to attacker behavior and network requirements. Using large language models (such as ChatGPT) in the honey spot warehouse module, the characteristics of the target web page can be automatically analyzed and decoy services can be generated based on these characteristics. Through the natural language processing capabilities of the large language model, the system can dynamically generate honey spots that meet the attacker's expectations and simulate the front-end and back-end interactions in the real system. The large language model can understand and extract key elements of the target website, such as page layout, color, font, etc., to generate honey spot services that are highly similar to the actual business, thereby increasing deception and flexibility. In addition, the large language model can dynamically adjust the configuration of the honey spot service according to changes in attack behavior, ensuring that attackers are continuously misled and improving defense effectiveness.
[0034] In some embodiments, see Figure 2 The honeyspot warehouse module pre-stores a variety of common service images, such as web servers, database servers, file servers, etc. Each service image has multiple versions (such as different versions of Apache or MySQL) so that it can be called according to the attacker's behavior or the needs of the network environment. These images can be quickly loaded into the honeyspot to ensure that when the attacker enters the honeyspot, they can simulate the services in the real environment and confuse the attacker.
[0035] This module also supports the generation of simulated honeypot service images based on large language models (such as ChatGPT). Through the semantic reasoning ability of large models, the honeypot warehouse can automatically generate virtual services that match the services expected by the attacker, further enhancing the deception. For example, the system can dynamically generate a honeypot similar to the real service based on the attacker's input or behavior, providing a more personalized simulation service.
[0036] At the same time, administrators can manually upload customized honeypot service images according to specific needs. For example, in a specific security test, some customized configurations or services with specific vulnerabilities may be required, and these images can be quickly loaded and deployed through the warehouse module.
[0037] The honeypot warehouse works closely with the intelligent decision-making module and the honeypot management module. When the system decides to deploy a new honeypot, the warehouse module calls the appropriate service image according to the deployment strategy and deploys it to the specified honeypot IP. At the same time, the honeypot service can be dynamically adjusted according to the attacker's behavior. For example, the warehouse can replace the service image in the honeypot at any time to ensure that the attacker encounters different honeypot services at different stages, increasing their confusion.
[0038] In summary, the honey spot warehouse module is the core part of the system responsible for managing the honey spot service image. Its main task is to provide rich and flexible virtual service support for honey spot deployment, ensure that the system can quickly respond to attacker behavior, and adjust the content of honey spot services at any time according to the network environment and attack requirements. This module can provide strong support for the flexible deployment of honey spots through a rich service image library, automatic update mechanism, and service generation function based on a large language model. It ensures that the honey spot service can respond quickly according to attacker behavior and network requirements, and improves the adaptability and defense capabilities of the system through multi-version management and customization options.
[0039] The sweet spot management module 50 is used to receive and parse the configuration file, and obtain the sweet spot service requirements according to the parsing results, so as to retrieve the corresponding sweet spot service image from the sweet spot warehouse according to the sweet spot service requirements.
[0040] The honey point management module is responsible for the dynamic deployment and adjustment strategy of honey points. It realizes the flexible scheduling and configuration of honey points through the management of honey point IP and services. This module can not only dynamically adjust the honey point IP and service combination according to the changes in the network environment, but also control the start, stop and update of honey points in real time, ensuring that the interaction between honey point services and attackers continues to confuse each other, while reducing manual intervention and improving defense effectiveness.
[0041] In summary, according to the above-mentioned dynamic deception defense system based on service tripwire technology, this system will scan the resource information in the network environment to obtain network resource perception data, and then generate the configuration strategy of the honey spot service according to the network resource perception data. At the same time, the system will also accept the changes in the network environment and the information of the interaction between the attacker and the honey spot service, and dynamically change the configuration strategy of the honey spot service. In addition, the system also supports directly reading the honey spot service deployment strategy from the configuration file, making the deployment method of the honey spot service more flexible. This dynamic adjustment capability makes it difficult for attackers to detect and identify, thereby effectively delaying the attack process, improving the defense effect, and buying time for the defender in the network attack.
[0042] Embodiment 2
[0043] See also Figure 3 This embodiment is basically the same as the first embodiment, except that the network management module further includes: A first scanning unit is used to scan the entire network environment to obtain all subnets contained in the network environment, all devices running on each subnet, and the device type of each device; The second scanning unit is used to traverse all devices on any subnet to determine online devices and record IP addresses and MAC addresses of online devices; The third scanning unit is used to scan the online devices according to the IP address and the MAC address to obtain the service name run by each online device and the port number and version information corresponding to the service name.
[0044] A network topology map construction unit, used to generate a network topology map according to all scanning results, wherein the network topology map includes the connection status of each device and the service type corresponding to each device; A honey spot network construction unit, used to construct a virtual double bridge structure, the virtual double bridge structure includes an upper layer bridge and a lower layer bridge, the upper layer bridge is used to connect the Docker containers of multiple honey spots, and the lower layer bridge is used to connect the honey spot network with the physical network; Each honeypot is assigned an independent network namespace through a virtual network interface.
[0045] It should be pointed out that, in this embodiment, the main function of the network management module is to be responsible for network environment perception and the construction of the honey spot network.
[0046] First, in the network environment perception part, the network management module will automatically scan and collect key information in the mobile network environment, including subnets, devices, services, traffic, and related logs in the current network. Its purpose is to help the system understand the current network environment and provide basic data support for the deployment of honey spots.
[0047] For example, an enterprise contains multiple subnets, each of which runs different services and devices, such as file servers, databases, web servers, etc. After the resource scanning module is started, the first scanning unit in it scans the entire enterprise network and obtains the following information: The entire enterprise network includes subnet A, subnet B, and subnet C, where: There are 10 devices running on subnet A, of which 5 are employee workstations, 3 are web servers, and 2 are file servers.
[0048] There are 6 devices running on subnet B, 2 of which are database servers and 4 are mail servers.
[0049] There are five devices running on subnet C, one of which is a backup server and the other four are network monitoring devices.
[0050] Then, the second scanning unit of the network management module uses a technology such as SYN scanning to identify devices in each subnet, determine which devices are online, and record the IP addresses and MAC addresses of these devices.
[0051] Next, the resource scanning module performs an in-depth scan on each online device to identify the services running on them. For example, but not limitation, the third scanning unit therein performs an in-depth scan on the online device to obtain the following information: In subnet A, three devices were identified running HTTP services (web servers), and two other devices provided file sharing services. In subnet B, a device running MySQL database service and a device running mail server were found. Through tools such as Nmap, the second scanning unit can collect the port numbers and version information of these services, for example: Web server 1: running Apache 2.4, port number 80. Database server: running MySQL 5.7, port number 3306.
[0052] Subsequently, the network topology construction unit generates a network topology map based on the scan results, showing the connection status of each device and its service type. For example, the web server in subnet A frequently communicates with the database server in subnet B. The monitoring device in subnet C has regular traffic interaction with the mail server in subnet B.
[0053] During the construction of the honey spot network, the honey spot network construction unit will use virtual network technology to create an independent and isolated network environment for the honey spot, ensuring that the interaction between the honey spot and the real network can be controlled without affecting the actual system.
[0054] In the honey spot network construction part, the system tripwire uses OVS technology to build a virtual dual bridge structure to provide a flexible and scalable architecture for the honey spot network. As a virtual switch, OVS can forward traffic between different network interfaces to ensure that the communication between the honey spot and the attacker can be effectively isolated and controlled. The virtual dual bridge structure specifically includes: Upper bridge (br-server): Responsible for connecting multiple honeypots’ Docker containers. Honeypot containers are connected to the br-server bridge through the ovs-veth interface. All honeypot traffic passes through br-server for unified management and control.
[0055] Lower-layer bridge (br-0): Connects the honey spot network to the physical network. br-0 is connected to the physical network card (such as eth0) to ensure that the virtual traffic of the honey spot can communicate with the external network and achieve the effect of deceiving attackers.
[0056] At the same time, each honey point is assigned an independent network namespace through a virtual network interface (such as veth), which means that each honey point has its own independent network stack, thus completely isolating the honey point from the real network. Even if an attacker successfully breaks into the honey point, it cannot pose a threat to the actual production environment.
[0057] Embodiment 3
[0058] See also Figure 4 This embodiment is basically the same as the first embodiment, except that the intelligent decision-making module further includes: A deployment strategy generating unit, configured to obtain at least one service type of the corresponding subnet according to all devices running on each subnet, the device type and version information of each device, and generate a deployment strategy according to the at least one service type of the corresponding subnet; The deployment strategy includes service tripwire honeypot information and port numbers, the service tripwire honeypot information includes honeypot IPs simulating device addresses, honeypot services simulating all service types, and service-IP association relationships; Map the honey spot service to the corresponding honey spot IP according to the service-IP association relationship; The configuration file generating unit is used to generate a configuration file that corresponds one-to-one with the sweet spot IP, the sweet spot service and the service-IP association relationship.
[0059] It should be noted that in this embodiment, the intelligent decision-making module is one of the core modules of the adaptive dynamic deception system. Its main function is to dynamically adjust the deployment strategy of the honey spot according to the feedback of the network environment, the interaction of the honey spot and the attack behavior to enhance the deception and defense effect. This module makes decisions in an intelligent way to ensure that the deployment of the honey spot can adapt to the ever-changing attack methods while reducing the dependence on manual management. That is to say, the intelligent decision-making module automatically generates and adjusts the deployment strategy of the service tripwire honey spot by analyzing the current network environment perception data (provided by the network management module) and the attacker's behavior data (provided by the log collection module).
[0060] By way of example and not limitation, the deployment strategy generation unit obtains the following information based on the scanning result of the entire network by the network management module: Subnet A: runs three web servers (IP addresses are 192.168.1.10, 192.168.1.11, and 192.168.1.12), using Apache version 2.4.
[0061] Subnet B: runs a MySQL database server (IP address is 192.168.2.20) using MySQL version 5.7.
[0062] The deployment strategy generation unit analyzes the service types of subnet A and subnet B and decides to replicate the Web server service in subnet A and the MySQL service in subnet B. Subsequently, the deployment strategy generation unit intelligently selects appropriate honey spot IPs and decides how to associate these honey spot services with IP addresses and ports.
[0063] Based on this analysis, the intelligent decision-making module generates the following honey spot deployment strategy: 1. Honey Spot IP: The honeypot IP assigned to subnet A is 192.168.1.13, and port 80 is open.
[0064] The honeypot IP assigned to subnet B is 192.168.2.21, and port 3306 is open.
[0065] 2. Honey spot service: Honeyspot service 1: simulates Apache 2.4 web server and uses port 80.
[0066] Honeyspot Service 2: simulates the MySQL 5.7 database service and uses port 3306.
[0067] 3. Service-IP association relationship: Honeyspot service 1 (Apache 2.4 web server) is mapped to IP address 192.168.1.13.
[0068] Honeyspot service 2 (MySQL 5.7 database service) is mapped to IP address 192.168.2.21.
[0069] These deployment strategies are recorded in three configuration files, which describe the honeypot services, honeypot IPs, and the associations between them. The examples are as follows: Honeyspot service configuration file: [ { "service_id": "service_1", "service_name": "Apache 2.4", "port": 80 }, { "service_id": "service_2", "service_name": "MySQL 5.7", "port": 3306 } ] Honeyspot IP configuration file: [ { "ip_address": "192.168.1.13", "open_ports":
[80] }, { "ip_address": "192.168.2.21", "open_ports":
[3306] } ] Service-IP association configuration file: [ { "service_id": "service_1", "ip_address": "192.168.1.13" }, { "service_id": "service_2", "ip_address": "192.168.2.21" } ] Subsequently, the intelligent decision-making module passes these configuration files to the honeyspot management module and passes the service deployment request to the honeyspot warehouse module, which dynamically creates and deploys the corresponding honeyspot services based on the configuration files.
[0070] After the attack is carried out, the intelligent decision-making module is closely linked with the log collection module to continuously receive real-time feedback information from the attacker. Once an attack is detected, the module will immediately adjust the honeypot deployment strategy. For example, when a SQL injection attack is detected, the module can dynamically generate more similar database service honeypots to attract attackers to conduct further attacks. This attack feedback adjustment mechanism ensures that the system's honeypot deployment can continuously adapt to the attacker's behavior pattern, so that every step of the attacker's operation falls into the designed deception trap, thereby greatly delaying the time it takes to discover the real network assets.
[0071] In addition, due to the separation design of the honey spot IP and the honey spot service, the intelligent decision-making module can quickly and flexibly adjust the deployment strategy. When a new attack is detected, the system can dynamically deploy a new honey spot by simply adding or changing the services associated with the IP without changing the IP. For example, in response to SQL injection attacks, the module can quickly add multiple different versions of database services based on the existing database service honey spot, or create a new honey spot service type (such as a web server) to confuse the attacker. At the same time, since the IP is separated from the service, the honey spot IP does not need to be changed when adjusting the service, which greatly shortens the deployment time and ensures that the honey spot can respond to the attacker's behavior changes in real time, so that the attacker always faces a dynamic and difficult to identify honey spot environment.
[0072] This fast and flexible adjustment capability not only enhances the system’s deception effect, but also effectively improves the persistence and confusion of the honey spots, further improving the defense against attackers.
[0073] Also, see Figure 5 In some embodiments, the honey spots deployed in the present invention are service tripwire honey spots. A service tripwire honey spot is composed of a honey spot IP and at least one honey spot service. The traffic received by different ports of the honey spot IP is forwarded to the honey spot service through traffic forwarding. In the attacker's view, such a honey spot IP is a real host running various services. Due to the design of separating the honey spot IP from the honey spot service, the system can flexibly adjust the two separately, such as dynamically modifying the honey spot IP or replacing the service combination behind it. In this way, not only can the service content be changed while maintaining the same IP to confuse the attacker, but also a variety of different bait strategies can be generated by quickly switching IPs or reorganizing service combinations, which greatly enhances the flexibility and deception effect of the system.
[0074] Specifically, a service tripwire honeypot consists of two parts: the honeypot IP and the honeypot service. The descriptions of these two parts are as follows: Honeypot IP: Honeypot IP is essentially a virtual network device created and managed at the software level. It is directly connected to the network segment where the honeypot is to be generated and can be accessed by machines in the same network segment. It can respond to some basic network requests, but does not provide any services.
[0075] Honeypot services: The service warehouse stores various prepared bait services. The customized engine can not only modify the content of these services, but also add response rules to the services to change the on / off status of the services based on the interaction with the attacker.
[0076] Embodiment 4
[0077] See also Figure 6This embodiment is basically the same as the first embodiment, except that the honey spot management module further includes: A configuration file parsing unit, used to parse the configuration file to extract a honey spot service image corresponding to the honey spot service from the honey spot warehouse according to the parsing result; The deployment execution unit is used to deploy the honey spot service image on the corresponding honey spot IP and bind the corresponding port number.
[0078] It should be pointed out that the honey spot management module is the module in the service tripwire system responsible for actually deploying and generating honey spot services according to the configuration files generated by the intelligent decision module. Its main function is to convert deployment strategies into operational honey spot services, making these services look similar to real network services, thereby attracting the attention of attackers and recording their behavior. The honey spot management module calls the required virtual services from the honey spot warehouse and deploys them according to the parameters in the configuration files.
[0079] After receiving detailed configuration files from the honeyspot configuration management module, the configuration file parsing unit will first parse the required services based on these configuration files. Then, according to the requirements in the configuration files, it will call the appropriate virtual service from the honeyspot warehouse. For example, if the configuration file requires the deployment of an Apache 2.4 version of the web server, the configuration file parsing unit will extract the corresponding web server service from the warehouse. The honeyspot warehouse stores virtualized images of various service types (such as web, database, file sharing, etc.), and the module can select different services according to requirements. Then the deployment execution unit will deploy the honeyspot service according to the requirements of the configuration file. For example, if the configuration file specifies that the Apache 2.4 service is to be run on the IP address 192.168.1.13, the module will start the service and bind it to the specified IP and port (such as port 80). The deployment execution unit ensures that the service runs normally according to the specified parameters, making the honeyspot look like a real network service.
[0080] For example, in the process of deploying a service tripwire system, the company discovered the devices and services in the network and decided to deploy a honeypot for Apache Web server in subnet A and a honeypot for MySQL database in subnet B. The honeypot management module receives two configuration files: Profile 1: Requires the Apache 2.4 web server running on IP address 192.168.1.13, port 80.
[0081] Profile 2: Requires a MySQL 5.7 database running on IP address 192.168.2.21, port 3306.
[0082] The configuration file parsing unit extracts the Apache 2.4 virtual service image from the honeyspot repository and the MySQL 5.7 database service image. The deployment execution unit deploys the Apache 2.4 service on 192.168.1.13 and binds it to port 80 as a web honeyspot service. At the same time, the deployment execution unit also deploys the MySQL 5.7 service on 192.168.2.21 and binds it to port 3306 as a database honeyspot service.
[0083] In addition, the honeypot management module continuously monitors the running status of Apache and MySQL honeypots to ensure that they are running normally and are not detected by attackers. If a honeypot service stops running, the module automatically restarts the service. The module also records all interactions between the attacker and the honeypot service for further analysis by the log collection module.
[0084] Embodiment 5
[0085] See also Figure 7 This embodiment is basically the same as the first embodiment, except that the log collection module further includes: A monitoring and alarm unit, which is used to obtain an attack request uploaded by a honey spot service, identify the attack request, obtain an identification result, which includes the attacker's IP address, request path, attack content, and timestamp, and then issue an alarm message within a first preset time; It should be noted that the first preset time is set so that an alarm can be issued in time when an attack behavior is detected.
[0086] By way of example and not limitation, a honeyspot web server is deployed in a company network to monitor and record potential attacks. The honeyspot web server runs on an IP address in the intranet and has an open HTTP service port. An attacker attempts to attack the honeyspot server through SQL injection. The attacker constructs a login request parameter containing special characters in an attempt to bypass authentication. The honeyspot service passes this request to the log collection module, causing the monitoring and alarm unit in it to record the following information: Attacker’s IP address: ***.***.***.*** Request path: / login.php Attack content: username=admin'--&password=12345 Timestamp: e.g. 2024-09-08 14:32:15 The collected attack logs will then be stored in a centralized log management system and indexed according to IP address, request type, time and other information for subsequent analysis and retrieval.
[0087] In addition, in some embodiments, when an attacker is detected trying to use SQL injection technology, the monitoring and alarm unit is also used to analyze malicious SQL statements in the attack request and identify the attack behavior. The large model will parse the SQL injection statement sent by the attacker, analyze the request content through NLP (natural language processing) technology, identify malicious SQL injection patterns, and determine the attacker's intentions. For example, the large model found that admin'-- is a typical SQL injection technique used to cut off the subsequent logic in the SQL query, and identified that the SQL statement is used to try to bypass login verification. The monitoring and alarm unit will trigger the preset alarm rules and immediately send an alarm notification to the system administrator, informing him of the possible threat of SQL injection attack, and providing the attacker's IP and request details.
[0088] In summary, the dynamic deception defense system based on the service tripwire technology according to the above embodiment has the following advantages: 1. The present invention realizes intelligent analysis of network environment and attack behavior through automated honey spot deployment strategy, and automatically generates the optimal honey spot deployment plan. This method simplifies the deployment process of honey spot services, and even if the manager lacks professional experience, the deployment can be easily completed.
[0089] 2. The present invention proposes a service tripwire honey spot to achieve a design that separates the honey spot IP from the honey spot service. The honey spot IP, as a bait resource visible to attackers, can be quickly generated and deployed, so the system can flexibly respond and deploy multiple bait targets in a short time.
[0090] 3. The present invention can automatically provide an optimal honey spot service deployment plan under the current network environment, whether it is the initial deployment or the subsequent maintenance, by sensing the deployed network. This will reduce the negative impact of the administrator on the deployment of the honey spot service and maximize the ability of the honey spot service as a deception defense strategy. At the same time, by introducing a large model, the present invention not only identifies the attacker's SQL injection behavior, but also predicts the attacker's next attack action based on the anomaly detection capability of the large model, and notifies the administrator through an intelligent alarm system. The automatic classification and cluster analysis of the large model also helps identify the behavior of the same attacker who uses the proxy IP multiple times. Finally, the system provides the security team with an intuitive display of attack behavior through the visualization function of the large model, and helps them to defend against possible future attacks in advance.
[0091] Embodiment 6
[0092] See also Figure 8 The embodiment of the present invention further provides a dynamic deception defense method based on service tripwire technology, the method comprising steps S101 to S105, wherein: Step S101: Scan network resources, build a network topology map based on the network resource perception data obtained through the scan, and build a honey spot network; Step S102: monitoring the interaction between the honey spot service and the attacker to collect log data, and obtaining the attacker's behavior data according to the log data analysis; Step S103: acquiring the network resource perception data, and generating and adjusting a deployment strategy of a service tripwire honeypoint according to the network resource perception data and the attacker's behavior data, and recording the deployment strategy in a configuration file; Step S104: pre-store the honey spot service images corresponding to each server, the honey spot service images generated by the large language model simulation, and the customized honey spot service images; Step S105: receiving and parsing the configuration file, and obtaining the honey spot service requirements according to the parsing result, so as to retrieve the corresponding honey spot service image from the honey spot warehouse according to the honey spot service requirements.
[0093] Embodiment 7
[0094] The embodiment of the present invention further provides a storage medium on which one or more programs are stored. When the programs are executed by a processor, the above-mentioned dynamic deception defense method based on service tripwire technology is implemented.
[0095] Embodiment 8
[0096] An embodiment of the present invention further proposes an electronic device, including a memory and a processor, wherein the memory is used to store computer programs, and the processor is used to execute the computer programs stored in the memory to implement the above-mentioned dynamic deception defense method based on service tripwire technology.
[0097] Those skilled in the art will appreciate that the logic and / or steps represented in the flowchart or otherwise described herein, for example, may be considered as an ordered list of executable instructions for implementing logical functions, and may be specifically implemented in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For purposes of this specification, "computer-readable medium" may be any device that can contain storage, communication, propagation or transmission of a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0098] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0099] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or a combination thereof: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0100] Although the embodiments of the present invention are described in detail above, it is obvious to those skilled in the art that various modifications and variations can be made to these embodiments. However, it should be understood that such modifications and variations are within the scope and spirit of the present invention as described in the claims. Moreover, the present invention described herein may have other embodiments and may be implemented or realized in a variety of ways.
Claims
1. A dynamic deception defense system based on service tripwire technology, characterized in that: The system comprises: The network management module is used to scan network resources, build a network topology map based on the network resource perception data obtained through the scan, and build a honeypot network; A log collection module, used to monitor the interaction between the honey spot service and the attacker to collect log data, and to obtain the attacker's behavior data based on the log data analysis; An intelligent decision-making module, used for acquiring the network resource perception data, generating and adjusting a deployment strategy of a service tripwire honeypoint according to the network resource perception data and the attacker's behavior data, and recording the deployment strategy in a configuration file; A honey spot warehouse module is used to pre-store honey spot service images corresponding to each server, honey spot service images generated by large language model simulation, and customized honey spot service images; The honey spot management module is used to receive and parse the configuration file, and obtain the honey spot service requirements according to the parsing results, so as to retrieve the corresponding honey spot service image from the honey spot warehouse according to the honey spot service requirements.
2. The dynamic deception defense system based on service tripwire technology according to claim 1 is characterized in that: The network management module also includes: A first scanning unit is used to scan the entire network environment to obtain all subnets contained in the network environment, all devices running on each subnet, and the device type of each device; The second scanning unit is used to traverse all devices on any subnet to determine online devices and record IP addresses and MAC addresses of online devices; The third scanning unit is used to scan the online devices according to the IP address and the MAC address to obtain the service name run by each online device and the port number and version information corresponding to the service name.
3. The dynamic deception defense system based on service tripwire technology according to claim 2 is characterized in that: The network management module also includes: A network topology map construction unit, used to generate a network topology map according to all scanning results, wherein the network topology map includes the connection status of each device and the service type corresponding to each device; A honey spot network construction unit, used to construct a virtual double bridge structure, the virtual double bridge structure includes an upper layer bridge and a lower layer bridge, the upper layer bridge is used to connect the Docker containers of multiple honey spots, and the lower layer bridge is used to connect the honey spot network with the physical network; Each honeypot is assigned an independent network namespace through a virtual network interface.
4. The dynamic deception defense system based on service tripwire technology according to claim 3 is characterized in that: The intelligent decision-making module also includes: A deployment strategy generating unit, configured to obtain at least one service type of the corresponding subnet according to all devices running on each subnet, the device type and version information of each device, and generate a deployment strategy according to the at least one service type of the corresponding subnet; The deployment strategy includes service tripwire honeypot information and port numbers, wherein the service tripwire honeypot information includes a honeypot IP of a simulated device address, a honeypot service simulating all service types, and a service-IP association relationship; Map the honey spot service to the corresponding honey spot IP according to the service-IP association relationship; The configuration file generating unit is used to generate a configuration file that corresponds one-to-one with the sweet spot IP, the sweet spot service and the service-IP association relationship.
5. The dynamic deception defense system based on service tripwire technology according to claim 4 is characterized in that: The honey spot management module also includes: A configuration file parsing unit, used to parse the configuration file to extract a honey spot service image corresponding to the honey spot service from the honey spot warehouse according to the parsing result; The deployment execution unit is used to deploy the honey spot service image on the corresponding honey spot IP and bind the corresponding port number.
6. The dynamic deception defense system based on service tripwire technology according to claim 1 is characterized in that: The log collection module also includes: The monitoring and alarm unit is used to obtain the attack request uploaded by the honey spot service, identify the attack request, obtain the identification result, and the identification result includes the attacker's IP address, request path, attack content, and timestamp, and then issue an alarm message within the first preset time.
7. The dynamic deception defense system based on service tripwire technology according to claim 6 is characterized in that: The monitoring and alarm unit is also used for: Malicious SQL statements in the attack request are identified based on the pre-trained large model to analyze the content contained in the attack request, identify malicious SQL injection patterns, and determine the attacker's intentions.
8. A dynamic deception defense method based on service tripwire technology, characterized in that: The method comprises: Scan network resources, build a network topology map based on the network resource perception data obtained from the scan, and build a honeypot network; Monitoring the interaction between the honey spot service and the attacker to collect log data, and obtaining the attacker's behavior data based on the log data analysis; Acquire the network resource perception data, generate and adjust a deployment strategy of a service tripwire honeypoint according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in a configuration file; Pre-store the honey spot service images corresponding to each server, the honey spot service images generated by large language model simulation, and the customized honey spot service images; The configuration file is received and parsed, and the honey spot service requirement is obtained according to the parsing result, so as to retrieve the corresponding honey spot service image from the honey spot warehouse according to the honey spot service requirement.
9. A storage medium, characterized in that: The storage medium stores one or more programs, which, when executed by the processor, implement the dynamic deception defense method based on service tripwire technology as claimed in claim 8.
10. An electronic device, comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor is used to execute the computer program stored in the memory, it implements the dynamic deception defense method based on service tripwire technology as described in claim 8.
Citation Information
Patent Citations
Dynamic honeynet system based on flow analysis
CN113328992A
Honeynet dynamic configuration strategy generation method, configuration method and storage medium
CN114499982A
Method and device for constructing deception defense honey array graph based on dynamic honey points
CN117061210A
Honeynet dynamic arrangement method and device, storage medium and computing equipment
CN118590309A
Implementing Decoys In A Network Environment
US20190253453A1
Cited By
Active defense method based on software defined deception defense balance information entropy
CN121309235A