Dynamic Deception Defense System and Method Based on Service Tripwire Technology
Through the dynamic spoof defense system of service tripwire technology, the problem of fixed configuration of traditional honeypot system is solved, the rapid generation and flexible deployment of honeypot services are realized, the strategy is dynamically adjusted, the network attack defense effect is enhanced, and the administrator's dependence is reduced.
Patent Information
- Application Number
- CN202510580664.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Traditional network security protection methods are difficult to deal with complex and multi-stage cyber attacks, especially APT attacks. Honeypot system deployment and maintenance rely on administrator experience, and fixed configurations are difficult to integrate into the network environment, and deployment efficiency is inefficient.
The dynamic spoof defense system based on service tripwire technology is adopted, and the network topology diagram is built through the network management module, the log collection module monitors interactive data, the intelligent decision module generates dynamic deployment strategies, the Midian Warehouse module provides diversified service images, and the Midian Management module realizes flexible deployment, separating Midian IP and services to enhance the deception effect.
It realizes the rapid generation and flexible deployment of honey point services, dynamically adjusts honey point strategies, enhances the deception effect against attackers, delays the attack process, improves defense capabilities, and reduces administrator intervention.
Smart Images

Figure CN120110795B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security protection technologies, and in particular, to a dynamic deception defense system and method based on service tripwire technology. Background Art
[0002] With the rapid development of information technology, the network security situation has become increasingly complex and severe. Currently, network attack means have gradually evolved from traditional viruses and malware to more concealed and complex advanced persistent threats (APTs), zero-day vulnerability attacks, and distributed denial of service (DDoS), etc. Especially APT attacks, which usually target specific targets and have strong concealment and long-term nature, making it difficult for the defense side to detect and respond. At the same time, with the wide application of technologies such as the Internet of Things, big data, and cloud computing, the potential attack surfaces in the network have increased sharply, making it difficult for traditional static security defense means to provide comprehensive protection, and the difficulty of network security defense has increased unprecedentedly.
[0003] In dealing with network attacks, traditional defense technologies such as firewalls and intrusion detection systems (IDSs) perform well in the face of known threats, but their limitations are also becoming increasingly apparent. These technologies rely on the update of the rule base and the identification of known attack characteristics, and are often unable to cope in the face of new and unknown attacks. In addition, traditional defense strategies are often passive and cannot flexibly adapt to the increasingly complex means of attackers, allowing attackers to use network vulnerabilities for long-term reconnaissance and attempts to circumvent existing defense measures.
[0004] Facing these complex attack forms, the limitations of traditional network security protection means have gradually emerged. Passive defense technologies such as firewalls, intrusion detection systems (IDSs), and intrusion prevention systems (IPSs) mainly work based on known threats and rule bases. They can effectively defend against known attacks, but in the face of unknown attacks such as APTs and zero-day vulnerability attacks, the protection effect of these technologies is limited. The limitations of traditional defense means are mainly reflected in the following aspects:
[0005] Passivity: Existing defense systems usually detect based on attack characteristics, that is, they can only detect and respond after an attack behavior occurs, lacking the ability to actively discover threats.
[0006] Dependence on rule base: The defense system highly depends on the update of the rule base and known attack characteristics. In the face of new and unknown attacks such as zero-day attacks, it is often unable to identify and defend when the rule base has not been updated.
[0007] Difficulty in coping with complex attacks: Traditional defense means are mostly statically configured and are difficult to flexibly cope with complex and multi-stage attacks, especially APT attacks, which usually bypass existing defense mechanisms through multiple attempts and penetrations.
[0008] To address these issues, the field of network security has gradually introduced proactive defense strategies, among which network deception defense technology has become an important research direction. The core idea of deception defense technology is to deploy false decoy systems in the network to attract the attention of attackers, monitor their behaviors, and delay or block their attack paths. By doing so, the defense side can not only obtain information about the attackers' behaviors but also gain time for itself to deploy further defense measures without actual network assets being damaged.
[0009] As a typical application of deception defense technology, honeypot systems have been widely used in network security. A honeypot is a false environment that mimics a real system, aiming to attract attackers and record their behaviors. Traditional honeypot systems induce attackers to waste time and resources on false targets by simulating network services, devices, or operating systems, thereby delaying their attacks on real targets. By analyzing the attack behaviors in the honeypot, defenders can gain in-depth understanding of attack means and strategies, providing valuable information for subsequent security protection.
[0010] Honeypot technology has been developed for a long time since its birth. With the progress of computer technology, the ability of honeypots to imitate services has become stronger and stronger. At first, DTK only made simple responses to requests for simulated ports, and later Honeyd personalized the simulation of services on specified ports and even the operating system fingerprints at the TCP layer. Now, with the development of container technology, it has become easier and more flexible to simulate a service. However, even with the ability to easily generate false services, today's honeypot systems still have many drawbacks. By analyzing the entire honeypot deployment process, it is not difficult to find that the deficiencies of modern honeypots are mainly reflected in the following aspects:
[0011] 1) The honeypot configuration is relatively fixed and difficult to integrate into the surrounding network environment: The honeypot templates used in modern honeypots are usually prepared at the beginning and hardly consider the target environment where they will be deployed. In this way, when attackers probe, they can easily identify such a system that "stands out" from the environment, thus seeing through the disguise of the honeypot and making it difficult to achieve the purpose of trapping attackers.
[0012] 2) Deploying and maintaining honeypots requires a large amount of time from administrators: For current honeypots, whether they are standalone, master-slave, or distributed, the deployment and maintenance of honeypots highly rely on the participation of administrators. Therefore, whether a honeypot can achieve good results is almost related to the ability of the administrator. Even a highly skilled administrator can come up with an excellent deployment strategy, but in the face of a network environment that may change at any time, adjusting the strategy at all times requires a large amount of time, and with each adjustment, the weakest points of the system are exposed.
[0013] 3) The deployment of honeypots is not flexible enough: There are generally two common deployment methods for modern honeypots. First, directly read the configuration file and deploy according to the requirements in the configuration file; second, provide an operation interface for administrators to deploy the honeypots on the operation interface. For the first deployment method, administrators need to spend time learning various rules in the configuration file, which undoubtedly increases the difficulty of getting started for inexperienced users. For the second deployment method, the deployment efficiency is too low and it is almost useless in situations where a large number of honeypots need to be quickly launched. Summary of the Invention
[0014] The purpose of the present invention is to provide a dynamic deception defense system and method based on service tripwire technology to solve at least one of the problems in the background technology.
[0015] In a first aspect, the present invention provides a dynamic deception defense system based on service tripwire technology, and the system includes:
[0016] A network management module for scanning network resources, constructing a network topology map based on the network resource perception data obtained from the scan, and constructing a honeypot network;
[0017] A log collection module for monitoring the interaction between the honeypot service and the attacker to collect log data, and analyzing the attacker's behavior data based on the log data;
[0018] An intelligent decision-making module for obtaining the network resource perception data, generating and adjusting the deployment strategy of the service tripwire honeypot based on the network resource perception data and the attacker's behavior data, and recording the deployment strategy in the configuration file;
[0019] A honeypot repository module for pre-storing honeypot service images corresponding to each type of server, honeypot service images generated by large language model simulation, and custom honeypot service images;
[0020] A honeypot management module for receiving and parsing the configuration file, obtaining the honeypot service requirements according to the parsing result, and retrieving the corresponding honeypot service image from the honeypot repository according to the honeypot service requirements.
[0021] In summary, according to the above dynamic deception defense system based on service tripwire technology, this system will scan the resource information in the network environment to obtain network resource perception data, and then generate a configuration strategy for the honeypot service based on this network resource perception data. At the same time, the system will also accept changes in the network environment and information on the interaction between attackers and the honeypot service, and dynamically change the configuration strategy of the honeypot service. In addition, the system also supports directly reading the honeypot service deployment strategy from the configuration file, making the deployment method of the honeypot service more flexible. This dynamic adjustment ability makes it difficult for attackers to detect and identify, thus effectively delaying the attack process, improving the defense effect, and buying time for the defense side in network attacks.
[0022] Furthermore, the network management module further includes:
[0023] The first scanning unit is used to scan the entire network environment to obtain all subnets included in the network environment, all devices running on each subnet, and the device type of each device;
[0024] The second scanning unit is used to traverse all devices on each subnet to determine online devices, and record the IP addresses and MAC addresses of the online devices;
[0025] The third scanning unit is used to scan the online devices according to the IP addresses and the MAC addresses to obtain the service names run by each online device and the port numbers and version information corresponding to the service names.
[0026] Furthermore, the network management module further includes:
[0027] The network topology diagram construction unit is used to generate a network topology diagram according to all the scanning results. The network topology diagram includes the connection status of each device and the service type corresponding to each device;
[0028] The honeypot network construction unit is used to construct a virtual double-bridge structure. The virtual double-bridge structure includes an upper bridge and a lower bridge. The upper bridge is used to connect Docker containers of multiple honeypots, and the lower bridge is used to connect the honeypot network to the physical network;
[0029] Allocate an independent network namespace for each honeypot through a virtual network interface.
[0030] Furthermore, the intelligent decision-making module further includes:
[0031] The deployment strategy generation unit is used to obtain at least one service type of the corresponding subnet according to all devices running on each subnet, the device type of each device, and the version information, and generate a deployment strategy according to at least one service type of the corresponding subnet;
[0032] The deployment strategy includes service tripwire honeypot information and port numbers. The service tripwire honeypot information includes honeypot IPs that simulate device addresses, honeypot services that simulate all service types, and service-IP association relationships.
[0033] Map the honeypot services to the corresponding honeypot IPs according to the service-IP association relationships.
[0034] The configuration file generation unit is used to generate configuration files that correspond one-to-one with the honeypot IPs, honeypot services, and service-IP association relationships.
[0035] Furthermore, the honeypot management module further includes:
[0036] The configuration file parsing unit is used to parse the configuration files to extract the honeypot service images corresponding to the honeypot services from the honeypot repository according to the parsing results.
[0037] The deployment execution unit is used to deploy the honeypot service images on the corresponding honeypot IPs and bind the corresponding port numbers.
[0038] Furthermore, the log collection module further includes:
[0039] The monitoring and alarm unit is used to obtain the attack requests uploaded by the honeypot services, identify the attack requests to obtain identification results. The identification results include the attacker's IP address, request path, attack content, and timestamp, and then send an alarm message within the first preset time.
[0040] Furthermore, the monitoring and alarm unit is also used to:
[0041] Identify malicious SQL statements in the attack requests according to a pre-trained large model to analyze the content included in the attack requests, identify malicious SQL injection patterns, and judge the attacker's intention.
[0042] In a second aspect, the present invention provides a dynamic deception defense method based on service tripwire technology. The method includes:
[0043] Scan network resources, construct a network topology map according to the network resource perception data obtained from the scan, and construct a honeypot network.
[0044] Monitor the interaction between the honeypot services and the attacker to collect log data, and obtain the attacker's behavior data according to the analysis of the log data.
[0045] Obtain the network resource perception data, generate and adjust the deployment strategy of the service tripwire honeypots according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in the configuration file.
[0046] Pre-store honeypot service images corresponding to each type of server respectively, honeypot service images generated by large language model simulation, and custom honeypot service images;
[0047] Receive and parse the configuration file, and obtain the honeypot service requirements according to the parsing result, so as to retrieve the corresponding honeypot service image from the honeypot repository according to the honeypot service requirements.
[0048] Thirdly, the present invention provides a storage medium storing one or more programs, which when executed by a processor implement the above-mentioned dynamic deception defense method based on service tripwire technology.
[0049] Fourthly, the present invention provides an electronic device, which includes a memory and a processor, wherein:
[0050] The memory is used for storing computer programs;
[0051] The processor is used for implementing the above-mentioned dynamic deception defense method based on service tripwire technology when executing the computer programs stored on the memory.
[0052] In addition, compared with the prior art, the present invention also has the following advantages:
[0053] 1. By proposing service tripwire honeypots, the present invention realizes the design of separating honeypot IP from honeypot services. The honeypot IP, as the bait resource visible to attackers, can be quickly generated and deployed. Therefore, the system can flexibly respond and deploy multiple bait targets in a short time.
[0054] 2. By combining the logical deduction and code generation capabilities of large language models, the system can perform high-quality simulation on protected services, realize the dynamic generation and precise simulation of multiple high-fidelity services, making it appear as a host running various real services from the perspective of attackers, greatly enhancing the deception effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 It is a schematic structural diagram of a dynamic deception defense system based on service tripwire technology proposed in an embodiment of the present invention;
[0056] Figure 2 It is a flowchart of the honeypot repository module in an embodiment of the present invention;
[0057] Figure 3 It is a flowchart of the network management module in an embodiment of the present invention;
[0058] Figure 4 It is a flowchart of the intelligent decision-making module in an embodiment of the present invention;
[0059] Figure 5Schematic diagram of the structure of the service tripwire honeypot in an embodiment of the present invention;
[0060] Figure 6 Flowchart of the honeypot management module in an embodiment of the present invention;
[0061] Figure 7 Flowchart of the log collection module in an embodiment of the present invention;
[0062] Figure 8 Flowchart of the dynamic deception defense method based on the service tripwire technology proposed in an embodiment of the present invention.
[0063] The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. Specific Embodiments
[0064] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art in the field to which the present invention belongs. The words such as "including" used herein mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects.
[0065] Embodiment 1
[0066] Please refer to Figure 1 , which shows the schematic diagram of the structure of the dynamic deception defense system based on the service tripwire technology proposed in the first embodiment of the present invention. The system includes:
[0067] A network management module 10, configured to scan network resources, construct a network topology map according to the network resource perception data obtained by the scan, and construct a honeypot network;
[0068] It should be noted that in the network management module, through the automated network resource scanning and IP management functions, the network management module perceives and maintains the current network environment to ensure seamless integration of the honeypot with the real network. At the same time, through the OVS virtual double bridge technology, this module flexibly constructs the honeypot network, realizes effective isolation and forwarding of the honeypot traffic, and at the same time ensures the rapid deployment, dynamic adjustment, and secure communication with the external network of the honeypot service, thereby enhancing the flexibility and stability of network defense.
[0069] The log collection module 20 is used to monitor the interaction between the honey point service and the attacker to collect log data, and analyze the attacker's behavior data based on the log data;
[0070] In the log collection module, this module is the module in the service tripwire system (a dynamic deception defense system based on service tripwire technology) responsible for recording, storing, and analyzing the interaction behavior between the honey point service and the attacker. Its role is to monitor the running status of the honey point service, collect the attacker's behavior data, and conduct in-depth analysis on this data to help the security team identify attack patterns, understand attack means, and formulate effective security defense strategies. The automatic feedback adjustment mechanism dynamically adjusts the configuration and deployment strategy of the honey point by real-time monitoring the interaction data between the honey point service and the attacker and combining the analysis results of the log collection module. This mechanism can automatically identify attack patterns and abnormal behaviors, and automatically optimize the running status and defense strategy of the honey point service according to the analysis feedback, ensuring that the honey point service can continuously deceive the attacker and improve the protection effect, thereby enhancing the overall security of the system.
[0071] The intelligent decision-making module 30 is used to obtain the network resource perception data, generate and adjust the deployment strategy of the service tripwire honey point according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in the configuration file;
[0072] In the intelligent decision-making module, this module automatically generates and adjusts the deployment strategy of the service tripwire honey point by analyzing the network environment and the attacker's behavior. It combines the attack feedback information to dynamically adjust the configuration and service deployment of the honey point to cope with the continuously changing threats. Through the intelligent decision-making ability, this module optimizes the defense effect, ensures that the honey point deployment is synchronized with the attack behavior, and improves the response efficiency and security of the entire system.
[0073] The honey point warehouse module 40 is used to pre-store the honey point service images corresponding to each type of server, the honey point service images generated by the large language model simulation, and the custom honey point service images;
[0074] In the honeypot repository module, this module is responsible for managing and storing various service images, providing diverse virtual service support for the deployment of honeypots. This module not only prefabricates a variety of common service images but also supports generating emulated service images through large language models (such as ChatGPT). Administrators can also manually upload customized images. By flexibly invoking different versions and types of services, the honeypot repository module ensures that the honeypot service can quickly respond and adjust according to the attacker's behavior and network requirements. Using large language models (such as ChatGPT) in the honeypot repository module can automatically analyze the characteristics of the target web page and generate decoy services based on these characteristics. Through the natural language processing capabilities of large language models, the system can dynamically generate honeypots that meet the attacker's expectations and simulate the front-end and back-end interactions in a real system. Large language models can understand and extract key elements of the target website, such as page layout, color, font, etc., and generate honeypot services highly similar to the actual business, thereby increasing deception and flexibility. In addition, large language models can also dynamically adjust the configuration of honeypot services according to changes in attack behavior to ensure that attackers are continuously misled and improve the defense effect.
[0075] In some embodiments, refer to Figure 2 , the honeypot repository module pre-stores a variety of common service images, such as web servers, database servers, file servers, etc. Each service image has multiple versions (such as different versions of Apache or MySQL) for invocation according to the attacker's behavior or the requirements of the network environment. These images can be quickly loaded into the honeypot to ensure that when an attacker enters the honeypot, it can simulate the services in a real environment and deceive the attacker.
[0076] This module also supports generating emulated honeypot service images based on large language models (such as ChatGPT). Through the semantic reasoning capabilities of large models, the honeypot repository can automatically generate virtual services that match the services expected by the attacker, further enhancing deception. For example, the system can dynamically generate a honeypot similar to a real service according to the attacker's input or behavior, providing a more personalized emulated service.
[0077] At the same time, administrators can manually upload customized honeypot service images according to specific requirements. For example, in specific security tests, services with certain customized configurations or specific vulnerabilities may be required, and these images can be quickly loaded and deployed through the repository module.
[0078] The honeypot repository works closely with the intelligent decision-making module and the honeypot management module. When the system decides to deploy a new honeypot, the repository module calls the appropriate service image according to the deployment strategy and deploys it to the specified honeypot IP. At the same time, the honeypot service can be dynamically adjusted according to the attacker's behavior. For example, the repository can replace the service image in the honeypot at any time to ensure that the attacker encounters different honeypot services at different stages, increasing its confusion factor.
[0079] In summary, the honeypot repository module is the core part of this system responsible for managing honeypot service images. Its main task is to provide rich and flexible virtual service support for honeypot deployment, ensuring that the system can quickly respond to the attacker's behavior and adjust the content of the honeypot service at any time according to the network environment and attack requirements. This module can provide strong support for the flexible deployment of honeypots through a rich service image library, an automated update mechanism, and a service generation function based on large language models. It ensures that the honeypot service can quickly respond to the attacker's behavior and network requirements, and improves the adaptability and defense capabilities of the system through multi-version management and customization options.
[0080] The honeypot management module 50 is used to receive and parse the configuration file, and obtain the honeypot service requirements according to the parsing result, so as to retrieve the corresponding honeypot service image from the honeypot repository according to the honeypot service requirements.
[0081] The honeypot management module is responsible for the dynamic deployment and adjustment strategy of the honeypot. Through the management of honeypot IP and services, it realizes the flexible scheduling and configuration of the honeypot. This module can not only dynamically adjust the honeypot IP and service combination according to the changes in the network environment, but also control the start, stop and update of the honeypot in real time to ensure that the interaction between the honeypot service and the attacker continues to confuse the other party, while reducing manual intervention and improving the defense effect.
[0082] In summary, according to the above dynamic deception defense system based on service tripwire technology, this system will scan the resource information in the network environment to obtain network resource perception data, and then generate the configuration strategy of the honeypot service according to this network resource perception data. At the same time, this system will also accept the changes in the network environment and the information of the interaction between the attacker and the honeypot service, and dynamically change the configuration strategy of the honeypot service. In addition, this system also supports directly reading the honeypot service deployment strategy from the configuration file, making the deployment method of the honeypot service more flexible. This dynamic adjustment ability makes it difficult for the attacker to detect and identify, thus effectively delaying the attack process and improving the defense effect, buying time for the defense side in network attacks.
[0083] Embodiment 2
[0084] Please refer to Figure 3 , this embodiment is basically the same as the first embodiment, and the difference is that: the network management module further includes:
[0085] A first scanning unit for scanning the entire network environment to obtain all subnets included in the network environment, all devices running on each subnet, and the device type of each device.
[0086] A second scanning unit for traversing all devices on each subnet to determine online devices and record the IP addresses and MAC addresses of the online devices.
[0087] A third scanning unit for scanning the online devices according to the IP addresses and the MAC addresses to obtain the service names run by each online device, as well as the port numbers and version information corresponding to the service names.
[0088] A network topology diagram construction unit for generating a network topology diagram according to all the scanning results, where the network topology diagram includes the connection status of each device and the service type corresponding to each device.
[0089] A honeypot network construction unit for constructing a virtual double-bridge structure, where the virtual double-bridge structure includes an upper-layer bridge and a lower-layer bridge. The upper-layer bridge is used to connect Docker containers of multiple honeypots, and the lower-layer bridge is used to connect the honeypot network to the physical network.
[0090] Allocate an independent network namespace for each honeypot through a virtual network interface.
[0091] It should be noted that in this embodiment, the main function of the network management module is mainly responsible for network environment perception and the construction of the honeypot network.
[0092] First, in the network environment perception part, the network management module will automatically scan and collect key information in the network environment. These key information include subnets, devices, services, traffic, and related logs in the current network. Its purpose is to help the system understand the current network environment and provide basic data support for the deployment of honeypots.
[0093] By way of example and not limitation, for example, an enterprise contains multiple subnets, and different services and devices are running in each subnet, such as file servers, databases, Web servers, etc. After the resource scanning module is started, the first scanning unit therein will scan the entire enterprise network and obtain the following information:
[0094] The entire enterprise network includes subnet A, subnet B, and subnet C, where:
[0095] 10 devices are running on subnet A, among which 5 devices are of the type of employees' workstations, 3 devices are of the type of Web servers, and the other 2 devices are of the type of file servers.
[0096] There are 6 devices running on Subnet B, among which 2 are database servers and 4 are mail servers.
[0097] There are 5 devices running on Subnet C, among which 1 is a standby server and the other four are network monitoring devices.
[0098] Subsequently, the second scanning unit of the network management module uses technologies such as SYN scanning to identify the devices in each subnet, determine which devices are online, and record the IP addresses and MAC addresses of these devices.
[0099] Next, the resource exploration module will conduct in-depth scans on each online device to identify the services running on them. By way of example, but not limitation, the third scanning unit inside it conducts in-depth scans on the online devices and obtains the following information:
[0100] In Subnet A, it is identified that 3 devices are running HTTP services (Web servers), and the other 2 devices provide file sharing services. In Subnet B, a device running MySQL database service and a device running mail server are found. Through tools such as Nmap, the second scanning unit can collect the port numbers and version information of these services. For example: Web server 1: running Apache 2.4, port number 80. Database server: running MySQL 5.7, port number 3306.
[0101] Subsequently, the network topology graph construction unit will generate a network topology graph based on the scanning results, showing the connection status of each device and its service type. For example: The Web server in Subnet A has frequent communication with the database server in Subnet B. The monitoring devices in Subnet C have regular traffic interactions with the mail servers in Subnet B.
[0102] During the construction of the honeypot network, the honeypot network construction unit will use virtual network technology to create an independent and isolated network environment for the honeypot, ensuring that the interaction between the honeypot and the real network can be controlled without affecting the actual system.
[0103] In the part of the honeypot network construction, the system tripwire uses OVS technology to construct a virtual dual-bridge structure, providing a flexible and scalable architecture for the honeypot network. As a virtual switch, OVS can forward traffic between different network interfaces, ensuring that the communication between the honeypot and the attacker can be effectively isolated and controlled. The specific virtual dual-bridge structure includes:
[0104] Upper - layer bridge (br - server): Responsible for connecting Docker containers of multiple honeypots. The honeypot containers are connected to the br - server bridge through ovs - veth interfaces. All traffic of the honeypots passes through br - server to achieve unified management and control.
[0105] Lower - layer bridge (br - 0): Connects the honeypot network to the physical network. Br - 0 is connected to the physical network card (such as eth0) to ensure that the virtual traffic of the honeypots can communicate with the external network, achieving the effect of deceiving external attackers.
[0106] At the same time, an independent network namespace is assigned to each honeypot through a virtual network interface (such as veth). This means that each honeypot has its own independent network stack, thus achieving complete isolation between the honeypots and the real network. Even if an attacker successfully breaks into a honeypot, it cannot pose a threat to the actual production environment.
[0107] Embodiment Three
[0108] Please refer to Figure 4 , this embodiment is basically the same as the first embodiment, and the difference is that the intelligent decision - making module further includes:
[0109] A deployment policy generation unit, which is used to obtain at least one service type of the corresponding subnet according to all devices running on each subnet, the device type of each device, and the version information, and generate a deployment policy according to at least one service type of the corresponding subnet;
[0110] The deployment policy includes service trip - wire honeypot information and port numbers. The service trip - wire honeypot information includes the honeypot IPs that simulate device addresses, the honeypot services that simulate all service types, and the service - IP association relationship;
[0111] Map the honeypot services to the corresponding honeypot IPs according to the service - IP association relationship;
[0112] A configuration file generation unit, which is used to generate a configuration file that corresponds one - to - one with the honeypot IPs, honeypot services, and service - IP association relationships.
[0113] It should be noted that in this embodiment, the intelligent decision-making module, as one of the core modules of the adaptive dynamic deception system, its main function is to dynamically adjust the honeypot deployment strategy according to the network environment, honeypot interaction situation, and feedback of attack behaviors, so as to enhance the deception and defense effects. This module makes decisions in an intelligent way to ensure that the honeypot deployment can adapt to the constantly changing attack means and reduce the dependence on manual management. That is to say, the intelligent decision-making module will automatically generate and adjust the deployment strategy of the service tripwire honeypot by analyzing the current network environment perception data (provided by the network management module) and the attacker's behavior data (provided by the log collection module).
[0114] By way of example and not limitation, the deployment strategy generation unit obtains the following information according to the scanning result of the network management module for the entire network:
[0115] Subnet A: There are 3 Web servers running (IP addresses are 192.168.1.10, 192.168.1.11, 192.168.1.12), using Apache version 2.4.
[0116] Subnet B: There is one MySQL database server running (IP address is 192.168.2.20), using MySQL version 5.7.
[0117] The deployment strategy generation unit analyzes the service types of Subnet A and Subnet B, and decides to replicate the Web server service in Subnet A and replicate the MySQL service in Subnet B. Subsequently, the deployment strategy generation unit intelligently selects appropriate honeypot IPs and decides how to associate these honeypot services with IP addresses and ports.
[0118] Based on this analysis, the intelligent decision-making module generates the following honeypot deployment strategy:
[0119] 1. Honeypot IP:
[0120] The honeypot IP assigned to Subnet A is 192.168.1.13, and port 80 is open.
[0121] The honeypot IP assigned to Subnet B is 192.168.2.21, and port 3306 is open.
[0122] 2. Honeypot service:
[0123] Honeypot service 1: Simulate an Apache 2.4 Web server, using port 80.
[0124] Honeypot service 2: Simulate a MySQL 5.7 database service, using port 3306.
[0125] 3. Service-IP association relationship:
[0126] The HoneyPoint Service 1 (Apache 2.4 Web server) is mapped to the IP address 192.168.1.13.
[0127] The HoneyPoint Service 2 (MySQL 5.7 database service) is mapped to the IP address 192.168.2.21.
[0128] These deployment strategies are recorded in three configuration files, which respectively describe the HoneyPoint services, HoneyPoint IPs, and their associations. The example is as follows:
[0129] HoneyPoint Service Configuration File:
[0131] {
[0132] "service_id": "service_1",
[0133] "service_name": "Apache 2.4",
[0134] "port": 80
[0135] },
[0136] {
[0137] "service_id": "service_2",
[0138] "service_name": "MySQL 5.7",
[0139] "port": 3306
[0140] }
[0142] HoneyPoint IP Configuration File:
[0144] {
[0145] "ip_address": "192.168.1.13",
[0146] "open_ports":
[80]
[0147] },
[0148] {
[0149] "ip_address": "192.168.2.21",
[0150] "open_ports":
[3306]
[0151] }
[0153] Service-IP Association Configuration File:
[0155] {
[0156] "service_id": "service_1",
[0157] "ip_address": "192.168.1.13"
[0158] },
[0159] {
[0160] "service_id": "service_2",
[0161] "ip_address": "192.168.2.21"
[0162] }
[0164] Subsequently, the intelligent decision-making module passes these configuration files to the honeypot management module and passes the service deployment request to the honeypot repository module, which dynamically creates and deploys the corresponding honeypot services according to the configuration files.
[0165] After an attack occurs, the intelligent decision-making module closely cooperates with the log collection module and continuously receives real-time feedback information from the attacker. Once an attack is detected, the module will immediately adjust the honeypot deployment strategy. For example, when a SQL injection attack is detected, the module can dynamically generate more similar database service honeypots to attract the attacker to conduct further attacks. This attack feedback adjustment mechanism ensures that the honeypot deployment of the system can continuously adapt to the attacker's behavior pattern, making every step of the attacker fall into the designed deception trap, thus greatly delaying the time for the attacker to discover real network assets.
[0166] In addition, due to the separate design of the honeypot IP and the honeypot service, the intelligent decision-making module can quickly and flexibly adjust the deployment strategy. When a new attack is detected, the system can dynamically deploy new honeypots by only adding or changing the services associated with the IP without changing the IP. For example, for an SQL injection attack, the module can quickly add multiple database services of different versions or create new honeypot service types (such as a web server) on the basis of the existing database service honeypot to confuse the attacker. At the same time, since the IP is separated from the service, the honeypot IP does not need to be changed when adjusting the service, which greatly shortens the deployment time and ensures that the honeypot can respond immediately to the behavior changes of the attacker, making the attacker always face a dynamic and difficult-to-identify honeypot environment.
[0167] This fast and flexible adjustment ability not only enhances the deception effect of the system, but also effectively improves the persistence and confusion of the honeypot, further enhancing the defense ability against attackers.
[0168] In addition, please refer to Figure 5 , in some embodiments, the honeypots deployed in the present invention are service tripwire honeypots. A service tripwire honeypot is composed of a honeypot IP and at least one honeypot service. The traffic received by different ports of the honeypot IP is forwarded to the honeypot service through traffic forwarding. In the view of the attacker, such a honeypot IP is a real host running various services. Due to the design of separating the honeypot IP from the honeypot service, the system can flexibly adjust the two respectively. For example, the honeypot IP can be dynamically modified or the service combination behind it can be replaced. This can not only change the service content to confuse the attacker while maintaining the same IP, but also generate a variety of different decoy strategies by quickly switching the IP or reorganizing the service combination, greatly enhancing the flexibility and deception effect of the system.
[0169] Specifically, a service tripwire honeypot consists of two parts: a honeypot IP and a honeypot service. The descriptions of these two parts are as follows:
[0170] Honeypot IP: The honeypot IP is essentially a virtual network device created and managed at the software level. It directly accesses the network segment where the honeypot is to be generated and can be accessed by machines in the same network segment. It can respond to some basic network requests but has no services.
[0171] Honeypot service: Various prepared decoy services are stored in the service repository. The customization engine can not only modify the content of these services, but also add response rules to the services to change the on / off state of the services according to the interaction with the attacker.
[0172] Embodiment 4
[0173] Please refer to Figure 6, this embodiment is basically the same as the first embodiment, except that the honeypot management module further includes:
[0174] A configuration file parsing unit, which is used to parse the configuration file to extract the honeypot service image corresponding to the honeypot service from the honeypot repository according to the parsing result;
[0175] A deployment execution unit, which is used to deploy the honeypot service image on the corresponding honeypot IP and bind the corresponding port number.
[0176] It should be noted that the honeypot management module is the module in the service tripwire system that is responsible for actually deploying and generating honeypot services according to the configuration file generated by the intelligent decision-making module. Its main function is to convert the deployment strategy into operable honeypot services, making these services look similar to real network services, so as to attract the attention of attackers and record their behaviors. The honeypot management module calls the required virtual services from the honeypot repository and deploys them according to the parameters in the configuration file.
[0177] After receiving the detailed configuration file from the honeypot configuration management module, the configuration file parsing unit will first parse out the required services according to these configuration files. Then, according to the requirements in the configuration file, it will call the appropriate virtual services from the honeypot repository. For example, if the configuration file requires deploying an Apache 2.4 version of the Web server, the configuration file parsing unit will extract the corresponding Web server service from the repository. The honeypot repository stores virtualized images of various service types (such as Web, database, file sharing, etc.), and the module can select different services according to the requirements. Subsequently, the deployment execution unit will deploy the honeypot service according to the requirements of the configuration file. For example, if the configuration file specifies to run the Apache 2.4 service on the IP address 192.168.1.13, the module will start the service and bind it to the specified IP and port (such as port 80). The deployment execution unit ensures that the service runs normally according to the specified parameters, making the honeypot look like a real network service.
[0178] For example, during the deployment of a service tripwire system, devices and services in the company's network are discovered, and it is decided to deploy a honeypot of an Apache Web server in subnet A and a honeypot of a MySQL database in subnet B. The honeypot management module receives two configuration files:
[0179] Configuration file 1: Require running the Apache 2.4 Web server on the IP address 192.168.1.13, port 80.
[0180] Configuration file 2: Require running the MySQL 5.7 database on the IP address 192.168.2.21, port 3306.
[0181] The configuration file parsing unit extracts the virtual service image of Apache 2.4 and the database service image of MySQL 5.7 from the honeypot repository. The deployment execution unit deploys the Apache 2.4 service on 192.168.1.13 and binds it to port 80 as the Web honeypot service. Meanwhile, the deployment execution unit also deploys the MySQL 5.7 service on 192.168.2.21 and binds it to port 3306 as the database honeypot service.
[0182] In addition, the honeypot management module continuously monitors the running status of the Apache and MySQL honeypots to ensure their normal operation and prevent attackers from detecting any abnormalities. If the honeypot service stops running, the module will automatically restart the service. The module also records all interactions between the attacker and the honeypot service for in-depth analysis by the log collection module.
[0183] Embodiment Five
[0184] Please refer to Figure 7 , this embodiment is basically the same as the first embodiment, except that the log collection module further includes:
[0185] A monitoring and alarm unit, which is used to obtain the attack requests uploaded by the honeypot service, identify the attack requests, and obtain the identification results. The identification results include the attacker's IP address, request path, attack content, and timestamp, and then send an alarm message within the first preset time.
[0186] It should be noted that the first preset time is set to enable timely alarm when an attack behavior is detected.
[0187] By way of example rather than limitation, a honeypot Web server is deployed in the company network to monitor and record potential attack behaviors. The honeypot Web server runs on an internal network IP address and opens the HTTP service port. An attacker attempts to attack this honeypot server through SQL injection. The attacker constructs a login request parameter containing special characters to try to bypass authentication. The honeypot service will pass this request to the log collection module, and the monitoring and alarm unit therein will record the following information:
[0188] The attacker's IP address: ***.***.***.***
[0189] Request path: / login.php
[0190] Attack content: username=admin'--&password=12345
[0191] Timestamp: For example, 2024-09-08 14:32:15
[0192] Subsequently, the collected attack logs will be stored in a centralized log management system and indexed according to information such as IP address, request type, and time for subsequent analysis and retrieval.
[0193] In addition, in some embodiments, when it is detected that an attacker attempts to use SQL injection technology, the monitoring and alarm unit is also used to analyze the malicious SQL statements in the attack requests to identify the attack behavior. The large model will parse the SQL injection statements sent by the attacker, analyze the request content through NLP (Natural Language Processing) technology, identify malicious SQL injection patterns, and judge the attacker's intention. For example, the large model discovers that 'admin'-- is a typical SQL injection technique used to truncate the subsequent logic in an SQL query and identifies that this SQL statement is used to attempt to bypass the login verification. The monitoring and alarm unit will trigger a preset alarm rule and immediately send an alert notification to the system administrator, informing of the possible threat of an SQL injection attack and providing the attacker's IP and request details.
[0194] In summary, the dynamic deception defense system based on the service tripwire technology according to the above embodiments has the following advantages:
[0195] 1. Through the automated honeypot deployment strategy, the present invention realizes the intelligent analysis of the network environment and attack behaviors and automatically generates an optimal honeypot deployment plan. This method simplifies the deployment process of the honeypot service, enabling even managers without professional experience to easily complete the deployment.
[0196] 2. By proposing the service tripwire honeypot, the present invention realizes the design of separating the honeypot IP from the honeypot service. The honeypot IP, as the bait resource visible to the attacker, can be quickly generated and deployed. Therefore, the system can flexibly respond and deploy multiple decoy targets in a short time.
[0197] 3. Through the perception of the deployed network, whether it is the initial deployment or subsequent maintenance, it can automatically give an optimal honeypot service deployment plan under the current network environment, thus reducing the negative impact of the administrator on the honeypot service deployment and giving full play to the ability of the honeypot service as a deception defense strategy as much as possible. At the same time, by introducing the large model, the present invention not only identifies the attacker's SQL injection behavior but also predicts the attacker's next attack action based on the anomaly detection ability of the large model and notifies the administrator through the intelligent alarm system. The automatic classification and clustering analysis of the large model also helps to identify the behavior of the same attacker who repeatedly uses proxy IPs. Finally, the system provides an intuitive display of attack behaviors for the security team through the visualization function of the large model and helps them defend against possible future attacks in advance.
[0198] Example Six
[0199] Please refer to Figure 8 , this embodiment of the present invention also provides a dynamic deception defense method based on service tripwire technology. This method includes steps S101 to S105, where:
[0200] Step S101: Scan network resources, construct a network topology map based on the network resource perception data obtained from the scan, and construct a honeypot network;
[0201] Step S102: Monitor the interaction between the honeypot service and the attacker to collect log data, and analyze the attacker's behavior data based on the log data;
[0202] Step S103: Obtain the network resource perception data, generate and adjust the deployment strategy of the service tripwire honeypot according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in a configuration file;
[0203] Step S104: Pre-store the honeypot service images corresponding to each type of server, the honeypot service images generated by large language model simulation, and the custom honeypot service images;
[0204] Step S105: Receive and parse the configuration file, obtain the honeypot service requirements according to the parsing result, and retrieve the corresponding honeypot service images from the honeypot repository according to the honeypot service requirements.
[0205] Example Seven
[0206] This embodiment of the present invention also proposes a storage medium, on which one or more programs are stored. When the program is executed by a processor, it implements the above-mentioned dynamic deception defense method based on service tripwire technology.
[0207] Example Eight
[0208] This embodiment of the present invention also proposes an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor is used to execute the computer program stored on the memory to implement the above-mentioned dynamic deception defense method based on service tripwire technology.
[0209] Those skilled in the art will understand that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device or in combination with these instruction execution systems, apparatus, or devices.
[0210] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection portion having one or more wirings (electronic device), a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.
[0211] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0212] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention as described in the claims. Moreover, the present invention described herein can have other embodiments and can be implemented or realized in various ways.
Claims
1. A dynamic deception defense system based on service tripwire technology, characterized in that, The system includes: A network management module, which is used to scan network resources, construct a network topology map according to the network resource perception data obtained by scanning, and construct a honeypot network; A log collection module, which is used to monitor the interaction between the honeypot service and the attacker to collect log data, and analyze the attacker's behavior data according to the log data; An intelligent decision-making module, which is used to obtain the network resource perception data, generate and adjust the deployment strategy of the service tripwire honeypot according to the network resource perception data and the attacker's behavior data, and record the deployment strategy in the configuration file; The intelligent decision-making module further includes: A deployment strategy generation unit, which is used to obtain at least one service type of the corresponding subnet according to all the devices running on each subnet, the device type of each device, and the version information, and generate a deployment strategy according to at least one service type of the corresponding subnet; The deployment strategy includes service tripwire honeypot information and port numbers, and the service tripwire honeypot information includes the honeypot IP that simulates the device address, the honeypot service that simulates all service types, and the service-IP association relationship; Map the honeypot service to the corresponding honeypot IP according to the service-IP association relationship; A configuration file generation unit, which is used to generate a configuration file that corresponds one-to-one with the honeypot IP, the honeypot service, and the service-IP association relationship; A honeypot repository module, which is used to pre-store the honeypot service images corresponding to each type of server respectively, the honeypot service images generated by the simulation of the large language model, and the custom honeypot service images; A honeypot management module, which is used to receive and parse the configuration file, obtain the honeypot service requirements according to the parsing result, and retrieve the corresponding honeypot service image from the honeypot repository according to the honeypot service requirements.
2. The dynamic deception defense system based on the service tripwire technology according to claim 1, characterized in that The network management module further includes: A first scanning unit, which is used to scan the entire network environment to obtain all subnets included in the network environment, all devices running on each subnet, and the device type of each device; A second scanning unit, which is used to traverse all devices on each subnet to determine the online devices, and record the IP addresses and MAC addresses of the online devices; A third scanning unit, which is used to scan the online devices according to the IP addresses and the MAC addresses to obtain the service names run by each online device and the port numbers and version information corresponding to the service names.
3. The dynamic deception defense system based on the service tripwire technology according to claim 2, wherein, The network management module further includes: A network topology map construction unit, which is used to generate a network topology map according to all the scanning results, and the network topology map includes the connection status of each device and the service type corresponding to each device; A honeypot network construction unit, which is used to construct a virtual double-bridge structure, and the virtual double-bridge structure includes an upper bridge and a lower bridge. The upper bridge is used to connect the Docker containers of multiple honeypots, and the lower bridge is used to connect the honeypot network to the physical network; Assign an independent network namespace to each honeypot through a virtual network interface.
4. The dynamic deception defense system based on the service tripwire technology according to claim 1, wherein The honeypot management module further includes: A configuration file parsing unit, which is used to parse the configuration file to extract the honeypot service image corresponding to the honeypot service from the honeypot repository according to the parsing result; A deployment execution unit for deploying the honeypot service image on the corresponding honeypot IP and binding the corresponding port number.
5. The dynamic deception defense system based on the service tripwire technology according to claim 1, wherein The log collection module further includes: A monitoring and alarm unit for obtaining an attack request uploaded by the honeypot service, identifying the attack request to obtain an identification result, where the identification result includes the attacker's IP address, request path, attack content, and timestamp, and sending an alarm message within a first preset time.
6. The dynamic deception defense system based on service tripwire technology according to claim 5, characterized in that The monitoring and alarm unit is further used for: Identifying malicious SQL statements in the attack request according to a pre-trained large model to analyze the content included in the attack request, identifying malicious SQL injection patterns, and judging the attacker's intention.
7. A dynamic deception defense method based on service tripwire technology, characterized in that, The method includes: Scanning network resources, constructing a network topology map according to the network resource perception data obtained by the scanning, and constructing a honeypot network; Monitoring the interaction between the honeypot service and the attacker to collect log data, and analyzing the attacker's behavior data according to the log data; Obtaining the network resource perception data, generating and adjusting the deployment strategy of the service tripwire honeypot according to the network resource perception data and the attacker's behavior data, and recording the deployment strategy in a configuration file, including: obtaining at least one service type of the corresponding subnet according to all devices running on each subnet, the device type of each device, and the version information, and generating a deployment strategy according to at least one service type of the corresponding subnet; the deployment strategy includes service tripwire honeypot information and port numbers, the service tripwire honeypot information includes the honeypot IP simulating the device address, the honeypot service simulating all service types, and the service-IP association relationship; mapping the honeypot service to the corresponding honeypot IP according to the service-IP association relationship; a configuration file generation unit for generating a configuration file corresponding one-to-one to the honeypot IP, the honeypot service, and the service-IP association relationship; Pre-storing the honeypot service image corresponding to each server respectively, the honeypot service image generated by the large language model simulation, and the custom honeypot service image; Receiving and parsing the configuration file, and obtaining the honeypot service requirements according to the parsing result, so as to retrieve the corresponding honeypot service image from the honeypot repository according to the honeypot service requirements.
8. A storage medium, characterized in that, The storage medium stores one or more programs, and when the program is executed by a processor, it implements the dynamic deception defense method based on the service tripwire technology as claimed in claim 7.
9. An electronic device, the electronic device includes a memory and a processor, wherein: The memory is used for storing a computer program; When the processor executes the computer program stored on the memory, it implements the dynamic deception defense method based on the service tripwire technology as claimed in claim 7.
Citation Information
Patent Citations
Honeynet dynamic configuration strategy generation method, configuration method and storage medium
CN114499982A
Method and device for constructing deception defense honey array graph based on dynamic honey points
CN117061210A