Honey matrix local transformation method and device based on Sharpley value
Through the method of Sharple value calculation and local modification, the honey array transformation is optimized, which solves the problems of large resource consumption and degradation of defense capabilities in the existing technology, and achieves more efficient threat perception and resource conservation.
Patent Information
- Application Number
- CN202510580753.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing honey array transformation scheme is relatively large in resource consumption, and unnecessary partial replacement leads to a decrease in defense ability, and it is impossible to effectively retain effective honey points that can detect attacks.
The local honey array transformation method based on the Sharply value is used to calculate the Sharply value of the honey point, find the honey point with the lowest contribution for local modification, optimize the array diagram, and retain the effective honey point.
Reduce resource consumption of honey array transformation, improve threat perception ability of array diagram, and ensure the retention and optimization of effective honey points.
Smart Images

Figure CN120110797A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and device for local transformation of honey arrays based on Shapley values. Background Art
[0002] In the network attack and defense confrontation, the defender is in a natural disadvantageous position. The attacker will collect information by fully investigating the system, and then design a targeted invasion plan based on the collected information. However, it is difficult for the defender to predict which way the attacker will use to invade from where. Deception defense is an active defense strategy that lures attackers into a false environment or induces attackers to take specific actions in order to detect and respond to potential network threats in a timely manner. Compared with traditional defense methods, it is not just passive monitoring and blocking attacks, but actively induces attackers to expose their intentions and technologies by creating false network resources, decoy systems or decoy files. The "Four Honey System" is a typical active defense threat perception system. It is guided by the idea of "deception, trapping and detection". It focuses on four aspects: trapping detection, attack exploration, security linkage and deterrence tracing. It covers honey spot technology that supports deep threat perception, honey court technology that supports attack observation and discrimination, honey array technology that supports collaborative linkage, and honey hole technology that supports network deterrence and attack mapping. In the four-honey system, by deploying a large number of honey points around the protected system, the security threats faced by the system are actively perceived in an all-round and multi-level manner, thus breaking this disadvantage. The deployment strategy of honey points is the key to threat perception capabilities. However, if the honey points do not change for a long time, attackers can discover the honey points and design bypass strategies during the interaction with the system, making the honey points ineffective. The honey array provides strategic support for the management and deployment of each defense point, adjusts the type and location of the defense point in real time according to the system security situation, and establishes a dynamic change mechanism for active defense measures. At the same time, the defense effect is evaluated based on the expert knowledge base and historical attack data, the utility of the defense points is analyzed, the deployment strategy is iteratively optimized, the defense cost is reduced, and the defense capability is improved.
[0003] The existing honey array transformation scheme continuously monitors the defense effect through static configuration evaluation and dynamic evaluation based on log feedback. By presetting the scoring rules and dynamic evaluation time interval, the operation effect is regularly scored according to the honey log information when the array is running. When the operation effect of the array is lower than the preset threshold, the honey array transformation is triggered, the current array is discarded, and the roulette algorithm is used to regenerate the array, while ensuring that the newly generated array has a higher score than the original array.
[0004] However, in the honey array transformation process, the overall transformation of the running array diagram consumes more resources, and not all parts of the running array diagram need to be replaced. The honey points that can effectively perceive threats do not need to be replaced in this round of transformation. The present invention proposes a local honey array transformation strategy, which calculates the contribution of each honey point in the running array diagram to threat perception through the Shapley value, finds out the parts in the running array diagram that have no effect, performs local modifications to optimize the array diagram, and retains the effective honey points in the array diagram that can detect attacks. While reducing the resource consumption of the honey array transformation, the threat perception capability of the array diagram is better guaranteed. Summary of the invention
[0005] The purpose of the present invention is to find out the ineffective parts of the running array, make local modifications to optimize the array, and retain the effective honey spots in the array that can detect attacks. While reducing the resource consumption of honey array transformation, the threat perception ability of the array is better guaranteed.
[0006] In a first aspect, the present invention provides a local transformation method of a honey array based on Shapley value, comprising the following steps: A regular dynamic evaluation is performed on the running array diagram. When the running effect of the array diagram is lower than a preset threshold, a cooperative relationship between the honey points is established according to the array diagram and the Shapley value of each honey point in the array diagram is calculated. Several honey points with the lowest Shapley values are selected to form a sub-array diagram to be deleted. The parameters of the sub-array diagram to be regenerated are calculated according to the parameters of the sub-array diagram to be deleted. The array diagram engine generates a new array diagram according to the parameters of the sub-array diagram to be regenerated, the parameters of the sub-array diagram to be deleted and the original array diagram.
[0007] The honey array local transformation method based on Shapley value provided by the present invention has the technical effect of saving resources.
[0008] Optionally, when performing a regular dynamic evaluation on the running array diagram, the running effect is scored according to the preset scoring rules and the honey-stepping log information.
[0009] Optionally, when establishing a cooperative relationship between honey points, the honey points are regarded as players, the array formed by the honey points is regarded as an alliance, the dynamically evaluated scores are regarded as the benefits of cooperation, and the benefits of cooperation are distributed according to the size of the Shapley value.
[0010] Optionally, a Monte Carlo method is used to approximate the Shapley value of each honeypoint.
[0011] Optionally, when selecting several honey points with the lowest Shapley values to form the sub-array graph to be deleted, firstly sort the honey points from low to high according to the Shapley value of each honey point, and then select several honey points to be replaced in turn.
[0012] Optionally, when selecting several honey points with the lowest Shapley values to form the sub-array graph to be deleted, the number of honey points is determined according to a preset scoring rule.
[0013] Optionally, when the parameters of the sub-array graph to be regenerated are calculated according to the parameters of the sub-array graph to be deleted, the parameters of the sub-array graph to be deleted are the IPs and types of the honey points constituting the sub-array graph to be deleted.
[0014] Optionally, when the parameters of the sub-array diagram to be regenerated are calculated according to the parameters of the sub-array diagram to be deleted, the parameters of the regenerated sub-array diagram are confirmed by the preset industry characteristics and the parameters of the sub-array diagram to be deleted.
[0015] In a second aspect, the present invention provides a local transformation device of a honey array based on Shapley value, comprising: Dynamic evaluation module, used to score the operation effect according to the preset scoring rules and honey-stepping log information, and determine whether the honey array needs to be changed;
[0016] A local transformation device is used to establish a cooperative relationship based on the array diagrams below a preset threshold, identify the sub-array diagrams with poor performance, and calculate the parameters of the sub-array diagrams to be regenerated, and transmit the parameters of the sub-array diagrams to be regenerated, the parameters of the sub-array diagrams to be deleted, and the original array diagram to the array diagram engine; The array diagram engine is used to generate an array diagram according to the parameters of the sub-array diagram to be regenerated, the parameters of the sub-array diagram to be deleted and the original array diagram.
[0017] The dynamic evaluation module, the local transformation device, and the array engine are loop-connected in sequence. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is a flow chart of the operation of the honey array local transformation device provided by the present invention; Figure 2 It is a flow chart of the honey array local transformation method provided by the present invention. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be understood by people with general skills in the field to which the present invention belongs. "Including" and similar words used in this article mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects.
[0020] The embodiment of the present invention provides a local transformation method of a honey array based on Shapley value, comprising the following steps: S1. Perform regular dynamic evaluation on the running array diagram; S2. When the operation effect of the array diagram is lower than a preset threshold, establishing a cooperative relationship between the honey spots according to the array diagram; S3, calculating the Shapley value of each honey point in the array; S4, selecting several honey points with the lowest Shapley values to form a subarray graph to be deleted; S5, calculating the parameters of the subarray diagram to be regenerated according to the parameters of the subarray diagram to be deleted; S6. The array diagram engine generates a new array diagram according to the parameters of the sub-array diagram to be regenerated, the parameters of the sub-array diagram to be deleted, and the original array diagram.
[0021] The flowchart of the local transformation method of the honey array provided by the present invention is as follows: Figure 2 As shown: Through the incoming json file, the cooperative relationship between the honey points is first established, and then the Shapley value of each honey point in the array is calculated according to the preset scoring rules. The Shapley value means the contribution of each honey point in the array in the threat perception during this round of operation. After the calculation is completed, according to the set number of honey points n, the n honey points with the lowest contribution are selected, and their IP, type, etc. are obtained. Then, according to the industry characteristics preset by the user, the parameters of the regenerated sub-array are calculated. Finally, these parameters are converted into a json file and passed to the array engine, which generates a new array.
[0022] Here are the details to pay attention to in each step: When executing step S1, when performing a regular dynamic evaluation on the running array diagram, the running effect is scored according to the preset scoring rules and the honey-stepping log information.
[0023] When executing step S2, when establishing a cooperative relationship between honey points, the honey points are regarded as players, the array formed by the honey points is regarded as an alliance, the dynamically evaluated scores are regarded as the benefits of cooperation, and the benefits of cooperation are distributed according to the size of the Shapley value.
[0024] The Shapley value is a concept in cooperative game theory, which was proposed by Lloyd Shapley in 1951 and won the Nobel Prize in Economics. It is a method to measure the contribution of each participant in the cooperation to the overall victory. The core idea of the Shapley value is to distribute rewards or benefits according to the contribution of each participant to the entire cooperation process. The advantage of the Shapley value is that it can accurately measure the contribution of each participant to the entire cooperation process, so as to achieve the purpose of fair distribution of rewards or benefits. Weber proved that the Shapley value is the only attribution method with the following properties: 1) Symmetry: The distribution of cooperative profits does not change with the sign or order of each person in the cooperation. 2) Effectiveness: The sum of the profits of the cooperating parties is equal to the cooperative profit 3) Redundancy: If a member does not contribute to any cooperative alliance he participates in, he should not benefit from the overall cooperation. 4) Linearity: If the reward of a cooperation u satisfies u(S) = v(S) + w(S), where v and w are two other cooperations, then the Shapley value of each player i in u is the sum of the Shapley values of player i in cooperation v and w. The formula for calculating the Shapley value is as follows: ; Where V(i) represents the Shapley value of participant i, N represents the set of participants, |N| represents the number of elements in the set of participants, S is a subset of N, |S| is the number of subsets of N, and v(S) represents the value of the cooperative combination S. The calculation steps of the Shapley value are: 1) Consider all possible alliances: Alliances refer to different combinations of cooperative members, including subsets containing different members. 2) Calculation of marginal contribution: For each member i, Shapley Value calculates the marginal contribution of member i in the alliance. The marginal contribution represents the incremental contribution of member i to the overall alliance. 3) Weighted summation: Use the weight factor to perform weighted summation of the marginal contribution of each member.
[0025] When executing step S3, the Shapley value of each honey point is approximately estimated using the Monte Carlo method.
[0026] From the Shapley value calculation formula, we can see that the complexity of calculating the Shapley value is O(N*2N). It cannot be solved within the polynomial time complexity and is NP-hard. Therefore, it can only be solved when the network scale is small. In order to make this method applicable to networks of any size, this method uses the Monte Carlo method to approximate the Shapley value of each node. The specific estimation method is: random sampling X times, each sampling randomly generates a permutation, and calculates the marginal utility of each honey point in the permutation. Finally, the Shapley value of a node is the average of the marginal benefits obtained by each random sampling. For example, for a matrix containing 5 honey points, the permutation generated by a certain sampling is {1,5,4,3,2}, then the marginal utility of honey point 3 in the current permutation is v({1,5,4,3})-v({1,5,4}), where the sub-matrix performance evaluation function v() is returned by calling the dynamic evaluation module.
[0027] When executing step S4, when selecting several honey points with the lowest Shapley values to form the sub-array graph to be deleted, first sort the honey points from low to high according to the Shapley value of each honey point, and then select several honey points to be replaced in turn. The number of honey points is determined according to a preset scoring rule.
[0028] To identify the subarray graphs with poor performance, first sort the honey points from low to high according to the contribution of the Shapley value of each honey point to the honey point, and then select n honey points in sequence according to the preset number of honey points n that need to be replaced, and count the types of these honey points.
[0029] When executing step S5, the parameters of the sub-array diagram to be regenerated are calculated based on the parameters of the sub-array diagram to be deleted, and the parameters of the sub-array diagram to be deleted are the IP and type of the honey points constituting the sub-array diagram to be deleted. The parameters of the regenerated sub-array diagram are jointly confirmed by the preset industry characteristics and the parameters of the sub-array diagram to be deleted.
[0030] The parameters of the sub-array diagram that needs to be regenerated are confirmed based on the preset industry characteristics and the deleted honey spot information. For example, the preset industry rules are that the service mixing line, flow mixing line, and domain control mixing line each occupy p1, p2, and p3, and the total number of honey spots is sum. The number of service mixing lines, flow mixing lines, and domain control mixing lines in the sub-array diagram with poor performance is x1, x2, and x3 respectively. It is calculated that the types of honey spots that need to be generated in the sub-array diagram are sum*p1-x1, sum*p2-x2, and sum*p3-x3, and the proportions are (sum*p1-x1) / n, (sum*p1-x1) / n, (sum*p1-x1) / n. Finally, the retained sub-array diagram and the sub-array diagram parameters that need to be regenerated are passed to the array diagram generation module in the array diagram engine in the form of json.
[0031] The embodiment of the present invention provides a local transformation device of a honey array based on Shapley value, comprising: Dynamic evaluation module, used to score the operation effect according to the preset scoring rules and honey-stepping log information, and determine whether the honey array needs to be changed; A local transformation device is used to establish a cooperative relationship based on the array diagrams below a preset threshold, identify the sub-array diagrams with poor performance, and calculate the parameters of the sub-array diagrams to be regenerated, and transmit the parameters of the sub-array diagrams to be regenerated, the parameters of the sub-array diagrams to be deleted, and the original array diagram to the array diagram engine; The array diagram engine is used to generate an array diagram according to the parameters of the sub-array diagram to be regenerated, the parameters of the sub-array diagram to be deleted and the original array diagram.
[0032] The flowchart of the operation of the local transformation device of the honey array provided by the present invention is as follows: Figure 1 shown.
[0033] The dynamic evaluation module, the local transformation device, and the array engine are loop-connected in sequence.
[0034] Although the embodiments of the present invention are described in detail above, it is obvious to those skilled in the art that various modifications and variations can be made to these embodiments. However, it should be understood that such modifications and variations are within the scope and spirit of the present invention as described in the claims. Moreover, the present invention described herein may have other embodiments and may be implemented or realized in a variety of ways.
Claims
1. A honey array local transformation method based on Shapley value, characterized in that: The following steps are involved: A regular dynamic evaluation is performed on the running array diagram. When the running effect of the array diagram is lower than a preset threshold, a cooperative relationship between the honey points is established according to the array diagram and the Shapley value of each honey point in the array diagram is calculated. Several honey points with the lowest Shapley values are selected to form a sub-array diagram to be deleted. The parameters of the sub-array diagram to be regenerated are calculated according to the parameters of the sub-array diagram to be deleted. The array diagram engine generates a new array diagram according to the parameters of the sub-array diagram to be regenerated, the parameters of the sub-array diagram to be deleted and the original array diagram.
2. The local transformation method of honey array according to claim 1, characterized in that: When performing regular dynamic evaluation on the running array diagram, the running effect is scored according to the preset scoring rules and the honey-stepping log information.
3. The local transformation method of honey array according to claim 1, characterized in that: When establishing a cooperative relationship, the honey points are regarded as players, the array formed by the honey points is regarded as an alliance, the dynamically evaluated scores are regarded as the benefits of the cooperation, and the benefits of the cooperation are distributed according to the size of the Shapley value.
4. The local transformation method of honey array according to claim 1, characterized in that: The Monte Carlo method was used to approximate the Shapley value of each honey point.
5. The local transformation method of honey array according to claim 1, characterized in that: When selecting several honey points with the lowest Shapley values to form a subarray graph to be deleted, firstly sort the honey points from low to high according to the Shapley value of each honey point, and then select several honey points to be replaced in turn.
6. The local transformation method of honey array according to claim 1, characterized in that: When selecting several honey points with the lowest Shapley values to form a subarray graph to be deleted, the number of honey points is determined according to a preset scoring rule.
7. The local transformation method of honey array according to claim 1, characterized in that: When the parameters of the sub-array graph to be regenerated are calculated according to the parameters of the sub-array graph to be deleted, the parameters of the sub-array graph to be deleted are the IP and type of the honey points constituting the sub-array graph to be deleted.
8. The local transformation method of honey array according to claim 1, characterized in that: When the parameters of the sub-array diagram to be regenerated are calculated according to the parameters of the sub-array diagram to be deleted, the parameters of the regenerated sub-array diagram are confirmed by the preset industry characteristics and the parameters of the sub-array diagram to be deleted.
9. A device for local transformation of honey array based on Shapley value, characterized in that: include: Dynamic evaluation module, used to score the operation effect according to the preset scoring rules and honey-stepping log information, and determine whether the honey array needs to be changed; A local transformation device is used to establish a cooperative relationship between honey points according to the array diagrams below a preset threshold, identify the sub-array diagrams with poor performance, and calculate the parameters of the sub-array diagrams to be regenerated, and transmit the parameters of the sub-array diagrams to be regenerated, the parameters of the sub-array diagrams to be deleted, and the original array diagram to the array diagram engine; The array diagram engine is used to generate an array diagram according to the parameters of the sub-array diagram to be regenerated, the parameters of the sub-array diagram to be deleted and the original array diagram.
10. The device for local transformation of honey array based on Shapley value according to claim 9, characterized in that: The dynamic evaluation module, the local transformation device, and the array engine are loop-connected in sequence.
Citation Information
Patent Citations
Dynamic honey point deployment method and system based on attack graph and Shapley value
CN119182584A
Honey spot anti-aging method and system based on digital twinning
CN119402216A