Dynamic honeypot scheduling method based on attack attraction
By collecting and analyzing network traffic and log data in real time, calculating honeypot access priority and similarity scores, and dynamically scheduling honeypots, the problem of insufficient deceptiveness of the honeynet architecture and high risk recognition is solved, and the authenticity and security defense capabilities of the honeynet environment are improved.
Patent Information
- Application Number
- CN202510361833.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-10
AI Technical Summary
The existing honeynet architecture has problems such as static, blind configuration, complex deployment, difficult maintenance and insufficient deceptiveness, resulting in the honeypot being discovered and ineffective.
The dynamic honeypot scheduling method based on attack attraction is adopted, and the network traffic acquisition module, server and system log acquisition module collects traffic and log data in real time, extracts honeypot access frequency characteristics, calculates honeypot access priority, and uses hierarchical analysis method to calculate honeypot similarity scores to realize the dynamic scheduling and disguise of honeypots.
It improves the authenticity and adaptability of the honeynet environment, reduces the risk of honeypot being discovered, and enhances network security defense capabilities.
Smart Images

Figure CN120128408A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security defense, and in particular to a dynamic honeypot scheduling method based on attack attractiveness. Background Art
[0002] As network security is facing threats, cyber attacks have also changed from simple and single attack methods to complex, diverse and continuous attack methods. Cyber attacks on new power systems refer to attacks on the system by tracking the actions of communication systems and control systems without permission, with the purpose of destroying or reducing the functions of power CPS, and exploiting the security defects and loopholes in the power information communication network.
[0003] At present, honeynet technology has evolved to the third generation. Its overall development trend is from honeynets for a single attack type to honeynets that support multiple attack types; from physical honeynets to virtual honeynets; from static honeynets with passive interaction to dynamic honeynets that can change their state autonomously according to attacks and conduct active interaction. The essence of honeynets is to set up hosts with system vulnerabilities or traps to deceive attackers and induce attackers to attack. By monitoring and analyzing attack behaviors, the attackers' intentions and motivations are clarified, so as to update defense strategies in time and enhance the system's defense capabilities. Honeynets not only improve the ability to capture network attack data, but also expand the network's active defense range. However, as the offensive and defensive confrontation between honeynets and attackers continues to evolve and upgrade, the traditional honeynet architecture may cause the honeypot to be discovered and become invalid due to its static, blind configuration, complex deployment, difficult maintenance, and insufficient deception.
[0004] In terms of power system network security, due to the heterogeneity of the power system network, the diversity of business and the dynamic nature of the topology structure, the authenticity of the constructed honeynet environment is poor, and there are problems with the diversity, dynamics and authenticity of the power system bait environment.
[0005] Chinese patent "CN114915493A A trapping deployment method based on network attacks on power monitoring systems" discloses a trapping deployment method based on network attacks on power monitoring systems, including: building a network honeypot system for power monitoring systems based on honeypot technology; designing baits based on the honeypot system, and forming a honeynet by interconnecting honeypots through baits; analyzing and tracing attack events captured by the system, monitoring dangerous nodes in real time and forming system alarms. The present invention provides a method for trapping deployment based on network attacks on power monitoring systems, in which camouflaged information implemented by honeypot technology is mixed into information sources frequently used by attackers, inducing attackers to collect erroneous information in the preparation stage and target the attack at the honeypot. The present invention supports data push to realize message linkage, and can push the hacker threat data fields recorded by the honeypot platform to other security visualization platforms as needed, and can provide sufficient source logs for threat intelligence data analysis, realize the advantages of linkage with other third-party devices, and detect attacks and alarms in time.
[0006] The Chinese patent "CN114978731A A system and method for implementing a trapping honeypot based on diversity expansion" discloses a system and method for implementing a trapping honeypot based on diversity expansion, which can generate targeted virtual honeypots according to the attacker's intentions, avoiding the blindness and huge overhead of traditional honeypots. At the same time, in the case where the virtual honeypot and the attacking host are interrupted or the intruder sees through the virtual honeypot, multiple new virtual honeypots are expanded and generated by reinforcement learning, which improves the authenticity and diversity of the honeypot and re-entices the intruder to launch more attacks. The technical effect of the present invention is to improve the generation efficiency and authenticity of virtual honeypots, which helps to improve network security.
[0007] Chinese patent "CN111885067A A flow-oriented integrated honeypot threat data capture method" discloses a flow-oriented integrated honeypot threat data capture method, which consists of network-level capture and system-level capture; network-level capture is passive acquisition based on flow, and original flow data is obtained through various open-source tools. The original flow data mainly includes all network connections flowing into and out of the honeynet at the only connection point of the honeynet gateway, attack data that meets the intrusion characteristics, the operating system type of the attacker, and all network connections flowing into and out of the honeynet; system-level capture is active trapping, setting vulnerabilities to lure attackers to attack the machine where the honeypot is located, and then actively capturing the attacker's behavior on the honeypot host through open-source tools. The captured behavior includes system behavior data and keystroke records, and then the actively captured data is transmitted to the central control system. In the present invention, the passive acquisition based on flow is combined with active trapping to capture the attacker's attack methods, and the firewall is updated in time, thereby protecting the attacked PC. Summary of the invention
[0008] Aiming at the deficiencies of the prior art, the present invention provides a dynamic honeypot scheduling method based on attack attractiveness, which solves the problems raised in the above-mentioned background technology.
[0009] To achieve the above objectives, the present invention is realized through the following technical solutions: A dynamic honeypot scheduling method based on attack attractiveness, including the following specific steps:
[0010] Step 1: The network traffic collection module and the server and the system log collection module are deployed in the business network, and are respectively responsible for the real-time collection of traffic and the real-time collection of logs;
[0011] Step 2: After the real-time collection of traffic data is completed, the data is stored in the database. Based on the traffic data and the log data, feature extraction is carried out, and the extracted features are as follows:
[0012] The current access frequency fnow of the Nth honeypot within the unit time T n ;
[0013] The historical highest access frequency fhis of the Nth honeypot within the unit time T n ;
[0014] Note: The unit of T is min, and it is recommended that the value ≥ 60;
[0015] After extracting fnow n and fhis n features, the user defines the weight Wn and the priority decay rate Ln of the Nth honeypot, and calculates the priority Pn of the Nth honeypot;
[0016] The value range of Wn is (0, 1);
[0017] The value range of Ln is (0, 1);
[0018] Step 3: After calculating the honeypot access priority Pn, the honeypot configuration target is to make the state of the honeynet the same as the state of the business network when an attack is initiated currently, so that the network context states of the attacker before and after being migrated are similar, ensuring the camouflage ability of the honeynet. Therefore, a drainage decision algorithm needs to be used to calculate the honeypot similarity score Score(Hi), where the decision algorithm uses the analytic hierarchy process;
[0019] Step 4: In order to deceive the orchestration and lifecycle management of the environment, research deception environment perception and orchestration technologies suitable for the power business scenario, such as Figure 3 shown; This method first defines the model of the deception resources, and then generates a complete structure deception environment description package through template-based resource combination. Finally, a workflow mechanism is introduced to model the instantiation task of the orchestration object in the deception environment and the deception and induction business process;
[0020] Step Five: The honeynet further lures attackers to attack the honeynet through an active deception and false response mechanism, and simultaneously collects the attack data of the attackers.
[0021] Optionally, the data type in Step One is network traffic data, including source IP address (IP_src), destination IP address (IP_dst), source port number (Port_src), destination port number (Port_dst), transport protocol (Protocol), the IP address of the Nth honeypot (HPOTn_ip), and the port number of the Nth honeypot (HPOTn_port).
[0022] Optionally, fnow in Step Two n The calculation process is as follows:
[0023] a. Match the logs where IP_dst = HPOTn_ip and Port_dst = HPOTn_port from the traffic data;
[0024] b. Starting from the current time time, count the number of logs Lognum that meet the conditions in step a within the unit time T; time ;
[0025] c. fnow n = Lognum time / T / 60;
[0026] d. Record time and the corresponding fnow n fields in the database;
[0027] e. Take the maximum value of all fnow n in the database as fhis n .
[0028] Optionally, the calculation formula for the access priority Pn of the Nth honeypot in Step Two is as follows:
[0029]
[0030] Among them, both the honeypot weight Wn and the priority decay rate Ln are set by the system administrator; the honeypot weight Wn represents the degree of attention of the system administrator to different honeypots. Since fhis n will only increase and ≥ 0, the greater the Wn, the greater the impact on Pn when fhis n increases; the priority decay rate Ln represents the degree of reduction of the priority when the current access frequency of the decoy decreases. The higher the Ln, the greater the impact on Pn when fnow n decreases, and the decoy is more likely to be shut down by the scheduling algorithm.
[0031] Optionally, the calculation steps of the decision algorithm for drainage in step three are as follows:
[0032] (1) Impact factors; select the following impact factors as decision indicators:
[0033] (S_j): Similarity between the honeypot and the business system;
[0034] (R_i): Resource usage of the honeypot;
[0035] (T): Matching degree between the attack type and the honeypot;
[0036] (P): Matching degree between the attack port and the honeypot;
[0037] (F): Matching degree between the attack frequency and the honeypot;
[0038] (2) Construct a judgment matrix; it is necessary to construct a judgment matrix (A) for each impact factor. The matrix element (a_{ij}) represents the relative importance of the (i)-th factor and the (j)-th factor;
[0039] The general form of the judgment matrix (A) is as follows:
[0040]
[0041] (3) Calculate the eigenvector and the maximum eigenvalue; according to the judgment matrix (A), calculate its maximum eigenvalue (λ max ) and the corresponding eigenvector (w); the eigenvector (w) is the weight of each index;
[0042] Aw = λ max w
[0043] Assume that the eigenvector (w) after normalization is:
[0044]
[0045] (4) Consistency check. To ensure the rationality of the judgment matrix, a consistency check is required; first, calculate the consistency index (CI):
[0046]
[0047] Among them, (n) is the order of the judgment matrix, and here (n = 5);
[0048] Then calculate the consistency ratio (CR):
[0049]
[0050] Among them, (RI) is the random consistency index, and for different (n), its value is predetermined;
[0051] If (CR < 0.1), the consistency of the judgment matrix can be accepted; otherwise, the judgment matrix needs to be adjusted.
[0052] (5) Comprehensive scoring: Perform comprehensive scoring on each honeypot (H_i). The scoring formula is as follows:
[0053] Score(H i ) = w 1 S j + w 2 (1 - R i ) + w 3 T + w 4 P + w 5 F
[0054] Where:
[0055] (S_j): The similarity between the (i)-th honeypot and the business system (value range: [0, 1]);
[0056] (R_i): The resource usage of the (i)-th honeypot (value range: [0, 1]);
[0057] (T): The matching degree between the attack type and the honeypot (value range: [0, 1]);
[0058] (P): The matching degree between the attack port and the honeypot (value range: [0, 1]);
[0059] (F): The matching degree between the attack frequency and the honeypot (value range: [0, 1]);
[0060] The weights (w_1, w_2, w_3, w_4, w_5) are obtained from the eigenvector (w);
[0061] (6) Optimal honeypot for attack attractiveness: Select the honeypot (H_i) with the highest comprehensive similarity score and access priority as the optimal honeypot for attack attractiveness:
[0062] R n = argmax(score(H i ) * P n )
[0063] Where i = n, the honeypot with the maximum value of Rn is the optimal honeypot.
[0064] The present invention provides a dynamic honeypot scheduling method based on attack attractiveness, having the following beneficial effects:
[0065] This dynamic honeypot scheduling method based on attack attractiveness aims to utilize limited resources to reduce the subjectivity and randomness of bait setting in the honeynet, improve the system's deception ability, and reduce the risk of real hosts being attacked. It studies a virtualized honeypot dynamic deployment method based on signal game. According to the attack behavior and network environment changes, with the goal of maximizing the comprehensive benefit of the defender under resource constraints, it establishes a honeypot deployment optimization model that integrates multi-stage confrontation and heterogeneous honeypot function superposition, and obtains the deployment strategy through reinforcement learning to quickly respond to the strategic attack behavior of the attacker;
[0066] By collecting real-time traffic log data, extracting honeypot access frequency features based on the traffic data, calculating the honeypot access priority through the frequency features; calculating the honeypot similarity score through the analytic hierarchy process; based on the honeypot access priority and the honeypot similarity score, obtaining the drainage strategy of the highest priority honeypot, solving the problems of diversity, dynamics, poor environmental authenticity and environmental adaptability in the honeypot environment, and improving the authenticity of the constructed honeynet environment. Brief Description of the Drawings
[0067] Figure 1 It is the working flowchart of the dynamic trapping network in this invention;
[0068] Figure 2 It is the schematic diagram of the situation awareness model framework in this invention;
[0069] Figure 3 It is the schematic diagram of deception environment perception, construction and orchestration in this invention. Detailed Embodiments
[0070] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.
[0071] In the description of the present invention, unless otherwise specified, "a plurality of" means two or more; the orientation or positional relationship indicated by the terms "upper", "lower", "left", "right", "inner", "outer", "front end", "rear end", "head", "tail", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. In addition, the terms "first", "second", "third", etc. are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance.
[0072] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "connected" and "coupled" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0073] Please refer to Figures 1 to 3 , the present invention provides a technical solution: a dynamic honeypot scheduling method based on attack attractiveness, including the following specific steps:
[0074] Step 1: The network traffic collection module and the server and the system log collection module are deployed in the business network, and are respectively responsible for the real-time collection of traffic and the real-time collection of logs;
[0075] The data type is network traffic data: including source IP address (IP_src), destination IP address (IP_dst), source port number (Port_src), destination port number (Port_dst), transport protocol (Protocol), Nth honeypot IP address (HPOTn_ip), Nth honeypot port number (HPOTn_port);
[0076] Step 2: After the real-time collection of traffic data is completed, the data is stored in the database. Based on the traffic data and log data, feature extraction is performed, and the extracted features are as follows:
[0077] The current access frequency fnow of the Nth honeypot within the unit time T n ;
[0078] The historical highest access frequency fhis of the Nth honeypot within the unit time T n ;
[0079] Note: The unit of T is min, and the recommended value is ≥60;
[0080] fnow n The calculation process is as follows:
[0081] a. Match the logs with IP_dst = HPOTn_ip and Port_dst = HPOTn_port from the traffic data;
[0082] b. Starting from the current time time, count the number of logs Lognum that meet the conditions of step a within the unit time T time ;
[0083] c. fnow n = Lognum time / T / 60;
[0084] d. Record time and the corresponding fnow in the database n field;
[0085] e. Retrieve all fnow in the database n and take the maximum value as fhis n ;
[0086] After extracting fnow n and fhis n features, the user defines the weight Wn and the priority decay rate Ln of the Nth honeypot, and calculates the priority Pn of the Nth honeypot;
[0087] The value range of Wn is (0, 1);
[0088] The value range of Ln is (0, 1);
[0089] The calculation formula for the access priority Pn of the Nth honeypot is as follows:
[0090]
[0091] Among them, both the honeypot weight Wn and the priority decay rate Ln are set by the system administrator; the honeypot weight Wn represents the degree of attention of the system administrator to different honeypots. Since fhis n only increases and ≥0, the greater Wn is, the greater the impact on Pn when fhis n increases; the priority decay rate Ln represents the degree of priority reduction when the current access frequency of the decoy decreases. The higher Ln is, the greater the impact on Pn when fnow n decreases, and the decoy is more likely to be shut down by the scheduling algorithm;
[0092] Step 3: After calculating the access priority Pn of the honeypot, the honeypot configuration target is to make the state of the honeynet consistent with the state of the business network when an attack is initiated currently, so that the network context state of the attacker before and after being migrated is similar, ensuring the camouflage ability of the honeynet. Therefore, a drainage decision algorithm needs to be used to calculate the honeypot similarity score Score(Hi), and the analytic hierarchy process is used for the decision algorithm;
[0093] The calculation steps of the drainage decision algorithm are as follows:
[0094] (1) Influence factors; Select the following influence factors as decision indicators:
[0095] (S_j): Similarity between the honeypot and the business system;
[0096] (R_i): Resource usage of the honeypot;
[0097] (T): Matching degree between the attack type and the honeypot;
[0098] (P): Matching degree between the attack port and the honeypot;
[0099] (F): Matching degree between the attack frequency and the honeypot;
[0100] (2) Construct the judgment matrix; we need to construct the judgment matrix (A) for each influencing factor, and the matrix element (a_{ij}) represents the relative importance of the (i)-th factor and the (j)-th factor;
[0101] The general form of the judgment matrix (A) is as follows:
[0102]
[0103] (3) Calculate the eigenvector and the maximum eigenvalue; according to the judgment matrix (A), calculate its maximum eigenvalue (λ max ) and the corresponding eigenvector (w); the eigenvector (w) is the weight of each index;
[0104] Aw = λ max w
[0105] Assume that the eigenvector (w) after normalization is:
[0106]
[0107] (4) Consistency test. To ensure the rationality of the judgment matrix, a consistency test is required; first, calculate the consistency index (CI):
[0108]
[0109] where (n) is the order of the judgment matrix, and here (n = 5);
[0110] Then calculate the consistency ratio (CR):
[0111]
[0112] where (RI) is the random consistency index, and for different (n), its value is predetermined;
[0113] If (CR < 0.1), the consistency of the judgment matrix is acceptable, otherwise, the judgment matrix needs to be adjusted;
[0114] (5) Comprehensive scoring. Conduct a comprehensive scoring for each honeypot (H_i), and the scoring formula is:
[0115] Score(H i ) = w 1 S j +w 2 (1 - Ri ) + w 3 T + w 4 P + w 5 F
[0116] Wherein:
[0117] (S_j): Similarity between the (i)-th honeypot and the business system (value range: [0, 1]);
[0118] (R_i): Resource usage of the (i)-th honeypot (value range: [0, 1]);
[0119] (T): Matching degree between the attack type and the honeypot (value range: [0, 1]);
[0120] (P): Matching degree between the attack port and the honeypot (value range: [0, 1]);
[0121] (F): Matching degree between the attack frequency and the honeypot (value range: [0, 1]);
[0122] The weights (w_1, w_2, w_3, w_4, w_5) are obtained from the feature vector (w);
[0123] (6) Optimal honeypot for attack attraction, select the honeypot (H_i) with the highest comprehensive similarity score and access priority as the optimal honeypot for attack attraction:
[0124] R n = argmax(score(H i ) * P n )
[0125] Where i = n, the honeypot with the maximum Rn value is the optimal honeypot;
[0126] Specific implementation steps of the algorithm:
[0127] 1. Construct a judgment matrix: Construct a judgment matrix (A) through methods such as expert scoring, and calculate its eigenvector and maximum eigenvalue;
[0128] 2. Calculate weights: Calculate the weights (w_1, w_2, w_3, w_4, w_5) of each index;
[0129] 3. Consistency check: Conduct a consistency check to ensure that the judgment matrix is reasonable;
[0130] 4. Calculate the comprehensive score: Calculate the comprehensive score of each honeypot according to the values of the influencing factors;
[0131] 5. Select the optimal honeypot for attack attraction: Select the most suitable honeypot for diversion according to the comprehensive score;
[0132] Step 4: To deceive the environment's orchestration and lifecycle management, research deception environment perception and orchestration technologies suitable for the power business scenario, such as Figure 3 shown; this method first defines the model of the deception resources, then generates a deception environment description package with a complete structure through template-based resource combination, and finally introduces a workflow mechanism to model the instantiation tasks of the orchestration objects in the deception environment and the deception and induction business processes;
[0133] Step 5: The honeynet further lures attackers to attack the honeynet through an active deception and false response mechanism, and at the same time collects the attack data of the attackers.
[0134] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and should be covered by the protection scope of the present invention.
Claims
1. A dynamic honeypot scheduling method based on attack attractiveness, characterized in that: The specific steps include: Step 1: The network traffic collection module and the server and system log collection module are deployed in the business network and are responsible for real-time traffic collection and log collection respectively; Step 2: After the real-time collection of traffic data is completed, the data is stored in the database. Based on the traffic data and log data, feature extraction is performed. The extracted features are as follows: The current access frequency fnow of honeypot N in unit time T n ; The historical highest access frequency fhis of honeypot N in unit time T n ; Note: T is in min, and the recommended value is ≥60; Extraction completed fnow n With fhis n After the features are obtained, the user defines the weight Wn and priority decay rate Ln of the N honeypots, and calculates the priority Pn of the N honeypots; The value range of Wn is (0, 1); The value range of Ln is (0, 1); Step 3: After completing the calculation of the honeypot access priority Pn, the honeypot configuration goal is to make the state of the honeynet consistent with the state of the business network when the attack is launched, so that the attacker's network context state before and after being migrated is similar, ensuring the camouflage ability of the honeynet. Therefore, it is necessary to use the diversion decision algorithm to calculate the honeypot similarity score Score (Hi), in which the decision algorithm adopts the hierarchical analysis method; Step 4: To orchestrate and manage the lifecycle of the deception environment, we study the deception environment perception and orchestration technology suitable for the power business scenario. We first define the deception resource model, then generate a complete deception environment description package through template-based resource combination, and finally introduce a workflow mechanism to model the orchestration object instantiation tasks and deception and inducement business processes in the deception environment. Step 5: The honeynet further lures attackers to attack the honeynet through active deception and false response mechanisms, and collects the attackers' attack data at the same time.
2. A dynamic honeypot scheduling method based on attack attractiveness according to claim 1, characterized in that: The data type in step one is network traffic data including source IP address, target IP address, source port number, target port number, transport protocol, honeypot IP address No. N, and honeypot port number No. N.
3. A dynamic honeypot scheduling method based on attack attractiveness according to claim 1, characterized in that: In step 2, fnow n The calculation process is as follows: a. Match the logs where IP_dst = HPOTn_ip and Port_dst = HPOTn_port in the traffic data; b. Starting from the current time, count the number of logs that meet step a within the unit time T Lognum time ; c.fnow n =Lognum time / T / 60; d. Record time and corresponding fnow in the database n Fields; e. Get all fnow in the database n The maximum value of fhis n .
4. A dynamic honeypot scheduling method based on attack attractiveness according to claim 1, characterized in that: The calculation formula for the access priority Pn of the Nth honeypot in step 2 is as follows: Among them, the honeypot weight Wn and priority decay rate Ln are set by the system administrator; the honeypot weight Wn represents the importance that the system administrator attaches to different honeypots. n It will only increase and ≥ 0, so the larger Wn is, the larger fhis n The greater the impact on Pn, the higher the priority decay rate Ln represents the degree of reduction in priority when the current access frequency of the bait decreases. The higher Ln, the greater the impact on fnow n The greater the impact on Pn when it is reduced, the easier it is for the decoy to be shut down by the scheduling algorithm.
5. The dynamic honeypot scheduling method based on attack attractiveness according to claim 1 is characterized by: The calculation steps of the decision algorithm for diversion in step 3 are as follows: (1) Impact factor; The following influencing factors are selected as decision indicators: (S_j): similarity between the honeypot and the business system; (R_i): resource usage of the honeypot; (T): the matching degree between the attack type and the honeypot; (P): Matching degree between attack port and honeypot; (F): Matching degree between attack frequency and honeypot; (2) Construct a judgment matrix. A judgment matrix (A) is constructed for each influencing factor, and the matrix element (a_{ij}) represents the relative importance of the (i)th factor and the (j)th factor. The general form of the judgment matrix (A) is as follows: (3) Calculate the eigenvector and the maximum eigenvalue; Based on the judgment matrix (A), calculate its maximum eigenvalue (λ max ) and the corresponding eigenvector (w); the eigenvector (w) is the weight of each indicator; Aw = λ max w Assume that the eigenvector (w) is normalized as: (4) Consistency check: To ensure the rationality of the judgment matrix, a consistency check is required; First calculate the consistency index (CI): Where, (n) is the order of the judgment matrix, here (n = 5); Then calculate the consistency ratio (CR): Where (RI) is the random consistency index, and its value is predetermined for different (n); If (CR<0.1), the consistency of the judgment matrix is acceptable, otherwise the judgment matrix needs to be adjusted; (5) Comprehensive scoring: Each honeypot (H_i) is comprehensively scored, and the scoring formula is: Score(H i )=w1S j +w2(1-R i )+w3T+w4P+w5F in: (S_j): the similarity between the (i)th honeypot and the business system (value range: [0, 1]); (R_i): resource usage of the (i)th honeypot (value range: [0, 1]); (T): the matching degree between the attack type and the honeypot (value range: [0, 1]); (P): Matching degree between the attack port and the honeypot (value range: [0, 1]); (F): Matching degree between attack frequency and honeypot (value range: [0, 1]); The weights (w_1, w_2, w_3, w_4, w_5) are obtained from the feature vector (w); (6) The honeypot with the best attack attractiveness is selected as the honeypot with the highest comprehensive similarity score and access priority (H_i): R n =argmax(score(H i )*P n ) Among them, i=n, and the honeypot with the maximum value of Rn is the optimal honeypot.
Citation Information
Patent Citations
Traffic-oriented integrated honeypot threat data capture method
CN111885067A
Trapping deployment method based on power monitoring system network attack
CN114915493A
Trapping honeypot implementation system and method based on diversity expansion
CN114978731A
Cited By
System and method for detecting abnormal traffic of credential server based on edge computing
CN121217490A