Honeypot configuration method based on graph neural network

Through the honeypot configuration method based on graph neural network, the honeypot deployment strategy is dynamically adjusted, which solves the problem that existing honeypot systems are difficult to identify and deal with complex attacks in complex network environments, and achieves more efficient attack detection and defense effects.

CN120200848AInactive Publication Date: 2025-06-24GUANGZHOU UNIVERSITY

Patent Information

Application Number
CN202510662422.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-06-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When facing complex network environments, existing honeypot systems are difficult to effectively identify and deal with multi-stage, distributed or low-frequency hidden attacks, and traditional honeypot deployment methods cannot dynamically adjust strategies based on real-time network situations, resulting in attack detection lag and resource waste.

Method used

The honeypot configuration method based on graph neural network is adopted. By collecting network situation data, building network situation charts, and performing graph embedding processing, and inputting graph neural networks to classify and predict node security status, dynamically adjusting honeypot deployment strategies to deal with different attack situations.

Benefits of technology

It realizes the dynamic adaptation and intelligent configuration of honeypot system to complex network environments, improves the real-time and defense effects of attack detection, and enhances the efficiency of honeypot resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200848A_ABST
    Figure CN120200848A_ABST
Patent Text Reader

Abstract

The invention provides a honeypot configuration method based on a graph neural network. The honeypot configuration method comprises the following steps: collecting network situation data; calculating a node connection relation carried by edges of a network situation map according to the network situation data, and constructing a node feature vector to construct the network situation map; performing graph embedding processing to obtain a first feature matrix for representing node vectors in the graph; inputting the network situation map and the first feature matrix into a graph neural network, extracting node information and pooling feature expression of the node information by the graph neural network, reading node features obtained by each processing module, and splicing the node features obtained by the C processing modules to form a second feature matrix for performing security state classification and prediction on the nodes; and judging an attack situation according to the network situation maps at different time points, and generating a honeypot deployment strategy for the attack situation for adjusting honeypot resource configuration. By applying the method, the deployment strategy of the honeypot can be dynamically adjusted, and the change of a network environment and complex attack behaviors can be quickly responded.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a honeypot configuration method based on graph neural network. Background Art

[0002] With the rapid development of network technology, network space security issues have become increasingly prominent. The forms of network attacks have gradually shown a trend of complexity, concealment, and diversification. Traditional passive defense methods are difficult to effectively cope with the increasingly severe security threats. Against this background, the honeypot, as an active defense means, has been widely used in the network security protection system. Existing honeypots preset positions, types, and interaction methods during system initialization and basically do not adjust after deployment. However, the network environment is dynamically changing, and the intrusion paths, attack targets, and means of attackers are also constantly evolving. Moreover, modern attacks often adopt multi-stage, distributed, or low-frequency covert attacks. Since traditional honeypots cannot adjust strategies according to the real-time network situation, it leads to the lag and inefficiency of attack detection, and may even waste resources or increase the false alarm rate due to unreasonable deployment.

[0003] Although some machine learning methods have been adopted in the prior art to guide the arrangement of honeypots. However, the existing methods currently cannot effectively support the processing of complex network structures, especially in large-scale and multi-level networks, where the correlation relationships between nodes are complex and dynamically changing. Traditional data mining and machine learning methods are mostly linear models and cannot fully capture the non-linear relationships and high-order dependencies between nodes in the network topology. This limits the threat recognition ability and defense strategy optimization ability of existing honeypot systems when facing a highly complex network environment. Especially in a network with multiple attack paths and complex attack means, the protection effect of traditional honeypot systems often fails to meet expectations.

[0004] Therefore, it is necessary to provide a honeypot configuration method that enhances the adaptability and defense effect of honeypots to complex network environments. Summary of the Invention

[0005] The purpose of the present invention is to provide a honeypot configuration method based on graph neural network to enhance the adaptability and defense effect of honeypots to complex network environments.

[0006] In a first aspect, the honeypot configuration method based on a graph neural network provided by the present invention includes: collecting network situation data, where the network situation data includes network traffic data and server log data; calculating the node connection relationships carried by the edges of the network situation graph and constructing node feature vectors based on the network situation data for constructing the network situation graph; performing graph embedding processing on the network situation graph to obtain a first feature matrix for representing the node vectors in the graph; inputting the network situation graph and the first feature matrix into a graph neural network, where the graph neural network includes C processing modules, a readout module, and a merging module. The processing modules are used to extract node information according to the input content and pool the feature expressions of the node information. The readout module is used to read out the node features obtained by each processing module. The merging module is used to splice the node features obtained by the C processing modules to form a second feature matrix, and classify and predict the security states of the nodes according to the second feature matrix, where C is a positive integer; judging the attack situation according to the node security state classification and prediction results of the network situation graph at different time points and generating a honeypot deployment strategy for the attack situation to adjust the honeypot resource configuration.

[0007] The beneficial effects of the honeypot configuration method based on a graph neural network provided by the present invention are as follows: By collecting multi-dimensional information such as network topology, communication traffic, and node characteristics in real time and combining the powerful analysis ability of GNN, it is possible to dynamically adjust the honeypot deployment strategy to achieve a rapid response to changes in the network environment and complex attack behaviors. This dynamic and intelligent configuration not only overcomes the lag and limitations of existing honeypot deployment solutions, but also greatly improves the utilization efficiency of honeypot resources and the overall network defense ability.

[0008] In a possible embodiment, the nodes in the business network are defined as the nodes of the network situation graph; calculating the node connection relationships carried by the edges of the network situation graph and constructing node feature vectors based on the network situation data for constructing the network situation graph includes: calculating the communication frequency and traffic size between nodes within a preset time window range according to the network traffic data, and constructing the feature vector information of the nodes according to the server log data; the network situation graph within the preset time window range satisfies the following undirected graph representation: , where represents the network situation graph, represents the node set of the network situation graph, represents the network link set between nodes, represents the adjacency matrix of the nodes, including node connection relationships and node vector features.

[0009] In another possible embodiment, performing graph embedding processing on the network situation graph to obtain a first feature matrix for representing node vectors in the graph includes: defining parameters for controlling the random walk; performing a random walk on each node in the network situation graph to collect random walk path information, where the access probability to the next node during the random walk is calculated based on the parameters; learning a low-dimensional embedding representation of the nodes from the random walk paths to generate vector representations of the nodes, and generating a first feature matrix according to the vector representations of the nodes.

[0010] In other possible embodiments, the calculation of the access probability to the next node during the random walk satisfies the following formula: , where v represents the currently accessed node, x represents the hypothesized next node, represents the node to the node transition probability, represents the th node in the random walk, represents the normalization constant, and E represents the set of network links between nodes.

[0011] The processing module includes a graph convolutional layer for aggregating the features of nodes and their neighborhoods according to the input content to extract node information; the graph convolutional kernel of the graph convolutional layer satisfies the following formula: , where represents the product kernel of the graph convolution, represents the parameters learned during the neural network training process, represents the k-th order Chebyshev polynomial, and K represents the highest order of the Chebyshev polynomial; the node propagation formula satisfies: , where Z represents the feature representation output by the graph convolutional layer, represents the k-th order Chebyshev polynomial, and X represents the first feature matrix.

[0012] Judging the attack situation and generating a honeypot deployment strategy for the attack situation according to the node security status classification and prediction results of the network situation graph at different time points includes: when judging that the attack situation is an exploit attack, the generated honeypot deployment strategy for the attack situation is to redirect traffic to the honeypot to simulate the node state; when judging that the attack situation is scanning and sniffing, the generated honeypot deployment strategy for the attack situation is to increase monitoring and restrict access permissions.

[0013] In a second aspect, the present invention also provides a honeypot configuration device based on a graph neural network, including: a collection unit for collecting network situation data, where the network situation data includes network traffic data and server log data.

[0014] A network situation map construction unit is used to calculate the node connection relationship carried by the edges of the network situation map and construct node feature vectors based on network situation data, for constructing the network situation map.

[0015] A graph embedding processing unit is used to perform graph embedding processing on the network situation map to obtain a first feature matrix for representing node vectors in the graph.

[0016] A classification and prediction unit is used to input the network situation map and the first feature matrix into a graph neural network. The graph neural network includes C processing modules, a readout module, and a merging module. The processing modules are used to extract node information according to the input content and pool the feature expressions of the node information. The readout module is used to read out the node features obtained by each processing module. The merging module is used to splice the node features obtained by the C processing modules to form a second feature matrix, and classify and predict the security status of the nodes according to the second feature matrix, where C is a positive integer.

[0017] A honeypot configuration unit is used to judge the attack situation according to the node security status classification and prediction results of the network situation map at different time points and generate a honeypot deployment strategy for the attack situation to adjust the honeypot resource configuration.

[0018] In a third aspect, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned honeypot configuration method based on a graph neural network is implemented.

[0019] In a fourth aspect, the present invention also provides an electronic device, including: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory so that the electronic device executes the above-mentioned honeypot configuration method based on a graph neural network.

[0020] Regarding the beneficial effects of the above second to fourth aspects, reference can be made to the description of the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a flowchart of a honeypot configuration method based on a graph neural network provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of a solution of a honeypot configuration method based on a graph neural network provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of a graph embedding process provided by an embodiment of the present invention; Figure 4 It is a schematic diagram of a random walk strategy provided by an embodiment of the present invention; Figure 5 It is a schematic diagram of a graph neural network provided by an embodiment of the present invention; Figure 6 Schematic diagram of the network situation map analysis process provided by the embodiment of the present invention; Figure 7 Schematic diagram of a honeypot configuration device based on a graph neural network provided by the embodiment of the present invention; Figure 8 Schematic diagram of the structure of an electronic device provided by the embodiment of the present invention. Detailed implementation manners

[0022] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art in the field to which the present invention belongs. The words such as "including" used herein mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects.

[0023] This embodiment provides a method. Refer to Figure 1 and Figure 2 , the method includes: S101: Collect network situation data, where the network situation data includes network traffic data and server log data.

[0024] In a possible embodiment, the purpose of collecting network situation data is to collect and integrate multi-dimensional situation information in the network in real time, providing data support for subsequent analysis and dynamic configuration. The collected network situation data includes network traffic data and server log data.

[0025] Specifically, the network traffic data includes communication traffic data captured in real time in the service network, including information such as packet size, packet characteristics, and communication frequency between nodes. The network traffic data reflects the interaction behaviors between nodes in the network and can lay a foundation for subsequent analysis of network dynamic changes.

[0026] The server log data includes log data generated by servers and systems in the network, including access logs, abnormal behavior records, security event logs, etc. Through the server log data, the running states of network nodes and systems can be comprehensively understood, which is beneficial to help identify potential security hazards and attack behaviors in a timely manner.

[0027] Network traffic data and server log data have extensive applications and market demands in various network environments, and traffic and log data are involved in almost all network environments. In this application, these two modules are selected as the core data sources, which not only improves the versatility of the solution of the present invention but also ensures its high implementability in different network environments, ensuring the wide applicability of this technical solution in the market.

[0028] In a specific embodiment, the collected network traffic data and server log data will be aggregated into a database for centralized storage and unified management, so as to ensure the availability and consistency of the data and provide a basis for the subsequent construction and analysis of the network situation map.

[0029] S102: Calculate the node connection relationship carried by the edges of the network situation map and construct the node feature vector according to the network situation data for constructing the network situation map.

[0030] In a possible embodiment, the nodes in the business network are defined as the nodes of the network situation map. Calculating the node connection relationship carried by the edges of the network situation map and constructing the node feature vector according to the network situation data for constructing the network situation map includes: calculating the communication frequency and traffic size between nodes within a preset time window range according to the network traffic data, and constructing the feature vector information of the nodes according to the server log data; the network situation map within the preset time window range satisfies the following undirected graph representation: , where, represents the network situation map, represents the node set of the network situation map, represents the network link set between nodes, represents the adjacency matrix of the nodes, including the node connection relationship and the node vector feature.

[0031] In a specific embodiment, each network node, such as a server, a host, or other network devices, is defined as a vertex in the network situation map. The time range of the network situation map starts from the moment and ends at , representing the time window of the network situation analyzed by the current network situation map. The specific manifestation form of the network situation map satisfies the undirected graph , where, represents the network situation map, represents the node set of the network situation map, including servers, hosts, and network devices; represents the network link set between nodes; represents the adjacency matrix of the nodes, used to describe the connection relationship between nodes, specifically including the node connection relationship and the node vector feature.

[0032] When representing the network situation map in graphical form, the relationships between nodes are represented by the edges in the graph. Each edge not only reflects the connection relationship between nodes but also carries node vector feature information such as the communication frequency and data transmission volume (the size of communication traffic) between nodes.

[0033] The communication frequency represents the number of communications that occur between two nodes within a certain period of time. It can be calculated by counting the number of data packet exchanges between nodes: , where represents the number of communications between two nodes (i.e., the number of data packet exchanges or the number of connection requests), represents the time window, usually in seconds, minutes, or hours. For example, a time window of 1 minute, 1 hour, etc. can be used to count the communication frequency.

[0034] The traffic size represents the amount of data transmitted between two nodes within a certain period of time. It is calculated by counting the number of bytes of data packets: , where represents the total amount of data transmitted between two nodes within the time window (in bytes), represents the time window, which is the same as the communication frequency and is usually in seconds, minutes, or hours.

[0035] Exemplarily, if node A communicates with node B more than five times per minute or transmits 50 MB of data per minute, it is considered that there is an edge between the two nodes. The specific threshold can be set according to the current network environment. If the network communication volume is large, the threshold can be appropriately increased to reduce the complexity of the network situation map.

[0036] The weight of the edge can be dynamically adjusted according to the communication frequency and data transmission volume between nodes. Specifically, if the communication frequency between two nodes is high or the amount of data transmitted is large, the edge between them will have a large weight, and vice versa, the weight will be small.

[0037] The feature vectors of the nodes in the network situation map include data from various types of logs, such as application service program logs, operating system logs, and system security logs, etc. The application service program logs provide information about the services running on the nodes, such as the types of services running on the server (such as httpd, CySQL, etc.) and the open ports (such as port 80, port 3306, etc.). The operating system logs record more detailed system activities, including user operations, system calls, command executions, etc. All these can help the present invention understand the running state of the nodes. The feature vector of each node is constructed by mapping these log information. For example, if a certain node has been accessed by a certain user within a specific time period, or has executed a certain system command, or has a high CPU occupancy rate, these information will be quantified and represented as the corresponding columns in the feature vector. A value of 1 indicates that the behavior has occurred, and a value of 0 indicates that the behavior has not occurred.

[0038] S103: Perform graph embedding processing on the network situation map to obtain a first feature matrix for representing the node vectors in the graph.

[0039] In a possible embodiment, performing graph embedding processing on the network situation map to obtain a first feature matrix for representing the node vectors in the graph includes: defining parameters for controlling the random walk; performing random walk on each node in the network situation map to collect random walk path information, where the access probability to the next node during the random walk is calculated based on the parameters; learning the low-dimensional embedding representation of the nodes from the random walk paths to generate the vector representation of the nodes, and generating the first feature matrix according to the vector representation of the nodes.

[0040] See the attached Figure 3 to the specification. The goal of performing graph embedding processing on the network situation map is to convert each node in the network into a low-dimensional vector representation. The low-dimensional vector representation can not only retain the structural characteristics between the nodes, but also improve the efficiency of subsequent calculation tasks by converting the high-dimensional attribute information into a more easily processed form.

[0041] In a specific embodiment, the calculation of the access probability to the next node during the random walk satisfies the following formula: , where v represents the currently accessed node, x represents the hypothesized next node, represents the node to the node transition probability, represents the th node in the random walk, represents the normalization constant, and E represents the set of network links between the nodes.

[0042] In a specific embodiment, random walks are performed on each node in the network situation map to collect walk path information. The calculation of the access probability of the next node in the random walk process satisfies the following formula: , where v represents the currently visited node, x represents the hypothetical next node, represents the node to the node transition probability of, represents the th node in the random walk, represents the normalization constant, and E represents the set of network links between nodes. is defined as: , where, represents the node and the node the edge weight value between, represents the previous node, represents the node the next step walks to the node the reciprocal of the probability that may occur.

[0043] The settings of the random walk parameters are as follows: , where, represents the return parameter (Return ParaCeter), which controls whether the walk tends to return to the previous node (DFS), represents the in-out parameter (In-Out ParaCeter), which controls whether the walk is more inclined to explore new nodes (BFS).

[0044] Exemplarily, referring to the attached drawings of the specification Figure 4 , assuming that the current random walk passes through the node and then arrives at the node . Next, it is necessary to select the next node from the neighbors of . The selection probability is determined by the following rules: If (return to the previous node), the selection probability is higher (determined by ); if is a distant neighbor of, the selection probability is lower (determined by ); if is a direct neighbor of, the selection probability is moderate. Through this mechanism, it is ensured that the walk can capture both local features and global features. By and adjustment, the user can control the exploration mode of the walk.

[0045] After obtaining the walking paths through random walks, the low-dimensional embedding representation of nodes is learned from these random walk paths, and then the vector representation of each node is generated. This embedding representation not only effectively preserves the local neighborhood information of nodes, but also can maintain the global characteristics of the node structure in the network.

[0046] The low-dimensional node vectors obtained by the above method can be effectively used for downstream tasks, such as node classification, node security status prediction, etc. The generation of these low-dimensional vectors not only improves the efficiency of graph embedding, but also ensures the expressiveness and generalization ability of node features in practical applications, providing better input for subsequent dynamic network security defense. The embedding of the network situation graph not only realizes the efficient processing of complex node features, but also ensures that the embedding result can accurately reflect the structural characteristics of the network, providing strong support for tasks such as network situation analysis and security status prediction, and providing accurate data input for subsequent dynamic configuration and defense strategy optimization.

[0047] S104: Input the network situation graph and the first feature matrix into a graph neural network. The graph neural network includes C processing modules, a readout module and a merging module. The processing module is used to extract node information according to the input content and pool the feature expressions of the node information. The readout module is used to read out the node features obtained by each processing module. The merging module is used to splice the node features obtained by C processing modules to form a second feature matrix, and classify and predict the security status of nodes according to the second feature matrix, where C is a positive integer.

[0048] In a possible embodiment, see the appended Figure 5 description. The processing module includes a graph convolutional layer and a graph pooling layer. The graph neural network includes C processing modules to perform multi-channel graph convolutional operations. The features of nodes and their neighborhoods are gradually aggregated through multiple graph convolutional layers to extract the local and global information of nodes, and the feature expressions are optimized in combination with the graph pooling layer to reduce the computational complexity. The readout layer is used to integrate and update the global features, and finally the security status of each node can be classified and predicted through a fully connected layer. The design of the graph neural network of the present invention can effectively capture the relationships between nodes in the graph, integrate node features and topological structures, and provide an accurate classification basis for identifying the security status of unknown nodes.

[0049] Classifying and predicting the security status of nodes according to the second feature matrix includes: inputting the second feature matrix into a classifier, and the classifier predicts the security label of the node according to the feature vectors in the second feature matrix.

[0050] See the appended Figure 6 description. In a specific embodiment, since the scale of the network situation graph is usually large, the calculation for processing is large and complex, and the Chebyshev inequality is used to approximately simplify the calculation of graph convolution. Specifically, the graph convolution kernel of the graph convolutional layer satisfies the following formula: , where represents the product kernel of graph convolution, represents the parameters learned during the neural network training process, represents the k-th order Chebyshev polynomial, and K represents the highest order of the Chebyshev polynomial, which is usually selected according to the complexity of the model and the data characteristics, and generally takes values in the range of 1 to 5. The node propagation formula satisfies: , where Z represents the feature representation output by the graph convolution layer, represents the K-th order Chebyshev inequality, and X represents the first feature matrix. Through the convolution operation of the above graph convolution kernel and the node propagation operation, the information of the -th order neighborhood of the node can be captured, avoiding the large overhead of directly calculating the eigen-decomposition of the Laplacian matrix. Through the -th order neighborhood, the embedding vector of the node can combine the information of nodes at a farther distance.

[0051] C processing modules implement multi-channel graph convolution operations, and multiple convolution kernels can be used to capture different feature patterns. For the same node feature, multiple weight matrices are used for convolution operations: , where represents the -th channel's feature matrix at the -th layer, represents the activation function, represents the graph adjacency matrix with self-connection introduced, which is the degree matrix of the graph nodes, represents the -th layer's feature matrix, represents the -th channel's weight matrix at the -th layer. The outputs of different channels (processing modules) are concatenated to form the second feature matrix: , where represents the -th layer's feature matrix, represents the number of channels.

[0052] A non-linear activation function is added after each layer of convolution, enhancing the expressive power of the model, enabling non-linear changes to capture the complex graph structure characteristics, and making the embedding vector more discriminative. Exemplarily, the non-linear activation function can be the ReLU function.

[0053] Graph Neural Networks (GNNs) can classify nodes in a network. In this embodiment, node classification is mainly divided into two categories: secure nodes and suspicious nodes. Secure nodes refer to those network nodes that are operating normally without any abnormal behavior, usually including stable servers, hosts, and other network devices. Suspicious nodes, on the other hand, are those that may pose potential security risks. They may exhibit abnormal behaviors such as frequent connection requests or suspicious communication patterns. Although these nodes have not been clearly identified as attack nodes, their behaviors have raised alarms and require further monitoring and analysis. For the security status of nodes, GNNs can predict the future security status of network nodes and identify nodes that may be attacked or are already in a high-risk state.

[0054] In one possible embodiment, a weighted cross-entropy method is used to define the loss function of the graph neural network: , where represents the number of security status labels of a node, represents the nodes with security status labels, represents the status label of a node, represents the weight of the label category, which is proportional to the inverse frequency of category , represents the true label vector of node . If node belongs to category , then , otherwise it is 0. represents the probability that the model predicts node belongs to . This loss function can accurately measure the quality of the model prediction in the classification task of unknown node security status, help the model learn the feature distribution of nodes, and thus achieve efficient and accurate classification. Moreover, it can solve the problem of uneven class distribution caused by the fact that the number of secure nodes is usually much larger than that of suspicious nodes in the actual network environment, which is prone to overfitting.

[0055] S105: Determine the attack situation based on the node security status classification and prediction results of the network situation map at different time points, and generate a honeypot deployment strategy for the attack situation to adjust the honeypot resource configuration.

[0056] In one possible embodiment, determining the attack situation based on the node security status classification and prediction results of the network situation map at different time points and generating a honeypot deployment strategy for the attack situation includes: when it is determined that the attack situation is an exploit attack, the generated honeypot deployment strategy for the attack situation is to redirect traffic to the honeypot and simulate the node state; when it is determined that the attack situation is scanning and sniffing, the generated honeypot deployment strategy for the attack situation is to increase monitoring and restrict access permissions.

[0057] In a specific embodiment, the network situation map of the current time window is compared and analyzed with that of the previous time window, and key node information and change trends are extracted therefrom. Based on this, a dynamic honeypot deployment strategy for different attack postures is generated. Specifically, it includes: The result obtained by comparing and analyzing the network situation map of the current time window with that of the previous time window is and , represents the state of node v, and the possible values are normal state or attacked state. represents that node v is an attacker node, represents is the attacked node. The above results show that at moment, the state of node v is and state. At time t, the state of node v has become the attacker state, which indicates that node v has been attacked. Using the above results as judgment conditions, it can be concluded that the attack posture is a vulnerability exploitation attack, and then the honeypot deployment strategy for this attack posture is to redirect traffic to the honeypot and simulate the node state. The result obtained by comparing and analyzing the network situation map of the current time window with that of the previous time window is and the neighbor nodes are normal, indicating that the neighbor nodes of node v are all in normal states, but node v has suspicious behavior. Although node v has no attack behavior, it may have become a zombie or is in an attacked state. Using the above results as judgment conditions, it can be concluded that the attack posture is a vulnerability exploitation attack, and then the honeypot deployment strategy for this attack posture is to increase monitoring and restrict access permissions.

[0058] Extracting key node information and change trends from the network situation map of the current time window and that of the previous time window, and generating a dynamic honeypot deployment strategy for different attack postures based on this can not only adjust the resource configuration of the honeypot according to real-time network data, but also accurately redirect attack traffic and guide it to a virtualized environment, thereby effectively isolating the attack source and reducing the impact on real network resources. At the same time, the state of the node will also be disguised in real time according to network changes and attack patterns, enhancing the deception of the honeypot and making it more difficult for attackers to identify and bypass. Through this flexible dynamic configuration scheme, it has significant advantages in quickly responding to attacks, improving the defense effect, and optimizing resource utilization.

[0059] The honeypot configuration method based on graph neural network provided by the present invention can dynamically adjust the deployment strategy of the honeypot by collecting multi-dimensional information such as network topology, communication traffic, and node characteristics in real time, and combining the powerful analysis ability of GNN, so as to achieve rapid response to changes in the network environment and complex attack behaviors. This dynamic and intelligent configuration not only overcomes the lag and limitations of existing honeypot deployment solutions, but also greatly improves the utilization efficiency of honeypot resources and the overall network defense ability.

[0060] The present invention fully considers the complexity and diversity of the network security situation, and comprehensively reflects the dynamic changes of the network by integrating network situation information from multiple dimensions, such as network topology, communication data, node attributes, and system logs. This integrated analysis of multi-dimensional information can not only capture the characteristics of attack behaviors more accurately, improve the overall accuracy of network situation awareness, but also effectively reduce the risks of false positives and false negatives. By integrating these multi-dimensional data, the potential threats in the network can be comprehensively grasped, and then the deployment strategy of the honeypot can be optimized, making the defense system more targeted and efficient.

[0061] The feature extraction ability of GNN makes the network situation awareness more accurate, thus optimizing the resource allocation of the honeypot, ensuring effective coverage of key areas, and maximizing the defense effectiveness. This technical solution provides an economical and efficient solution for protection in large-scale complex network environments, and has significant advantages in dynamic response, intelligent deployment, and resource optimization.

[0062] See the appended Figure 7 description. In this embodiment, a honeypot configuration device based on graph neural network is further provided, and this device is used to implement the method embodiment described above. The device includes: A collection unit 201, configured to collect network situation data, where the network situation data includes network traffic data and server log data.

[0063] A network situation graph construction unit 202, configured to calculate the node connection relationship carried by the edges of the network situation graph and construct a node feature vector according to the network situation data for constructing the network situation graph.

[0064] A graph embedding processing unit 203, configured to perform graph embedding processing on the network situation graph to obtain a first feature matrix for representing the node vectors in the graph.

[0065] The classification prediction unit 204 is configured to input the network situation map and the first feature matrix into a graph neural network. The graph neural network includes C processing modules, a readout module, and a merging module. The processing modules are configured to extract node information according to the input content and pool the feature expressions of the node information. The readout module is configured to read out the node features obtained by each processing module. The merging module is configured to splice the node features obtained by the C processing modules to form a second feature matrix, and classify and predict the security status of the nodes according to the second feature matrix, where C is a positive integer.

[0066] The honeypot configuration unit 205 is configured to determine the attack situation according to the node security status classification and prediction results of the network situation map at different time points and generate a honeypot deployment strategy for the attack situation to adjust the honeypot resource configuration.

[0067] All relevant content of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules and will not be elaborated here.

[0068] In some other embodiments of the present application, embodiments of the present application disclose an electronic device, as Figure 8 shown. The electronic device 300 may include: one or more processors 301; a memory 302; a display 303; one or more applications (not shown); and one or more computer programs 304. The above devices may be connected through one or more communication buses 305. The one or more computer programs 304 are stored in the above memory and configured to be executed by the one or more processors 301. The one or more computer programs 304 include instructions, and the above instructions may be used to execute the steps in Figure 1 and the corresponding embodiments.

[0069] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of description, only the above division of each functional module is used as an example. In actual applications, the above functions may be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working processes of the systems, devices, and units described above may refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.

[0070] In each embodiment of the embodiments of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated units may be implemented in the form of hardware or in the form of software functional units.

[0071] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, magnetic disk, or optical disc.

[0072] As described above, the above is only the specific implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the embodiments of the present application should be covered by the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.

Claims

1. A honeypot configuration method based on graph neural network, characterized in that Including: Collecting network situation data, where the network situation data includes network traffic data and server log data; Calculating the node connection relationship carried by the edges of the network situation graph and constructing node feature vectors according to the network situation data for constructing the network situation graph; Performing graph embedding processing on the network situation graph to obtain a first feature matrix for representing the node vectors in the graph; Inputting the network situation graph and the first feature matrix into a graph neural network, where the graph neural network includes C processing modules, a readout module, and a merging module. The processing modules are used to extract node information according to the input content and pool the feature expressions of the node information. The readout module is used to read out the node features obtained by each processing module. The merging module is used to splice the node features obtained by the C processing modules to form a second feature matrix, and classify and predict the security status of the nodes according to the second feature matrix, where C is a positive integer; Judging the attack situation according to the node security status classification and prediction results of the network situation graphs at different time points and generating a honeypot deployment strategy for the attack situation to adjust the honeypot resource configuration.

2. The method according to claim 1, wherein Defining the nodes in the business network as the nodes of the network situation graph; Calculating the node connection relationship carried by the edges of the network situation graph and constructing node feature vectors according to the network situation data for constructing the network situation graph, including: Calculating the communication frequency and traffic size between nodes within a preset time window range according to the network traffic data, and constructing the feature vector information of the nodes according to the server log data; The network situation map within the preset time window range satisfies the following undirected graph representation: , where represents the network situation map, represents the node set of the network situation map, represents the network link set between nodes, represents the adjacency matrix of nodes, including node connection relationships and node vector features.

3. The method according to claim 1, wherein Performing graph embedding processing on the network situation graph to obtain a first feature matrix for representing the node vectors in the graph, including: Defining the parameters for controlling the random walk; Performing random walk on each node in the network situation graph to collect the random walk path information, where the access probability of the next node in the random walk process is calculated based on the parameters; Learning the low-dimensional embedding representation of the nodes from the random walk paths to generate the vector representation of the nodes, and generating the first feature matrix according to the vector representation of the nodes.

4. The method according to claim 3, wherein The calculation of the access probability to the next node in the random walk process satisfies the following formula: , where v represents the currently accessed node, x represents the hypothetical next node, represents the node to the node transition probability, represents the th node in the random walk, represents the normalization constant, and E represents the set of network links between nodes.

5. The method according to claim 1, wherein The processing module includes a graph convolutional layer for aggregating the features of the node and its neighborhood according to the input content and extracting the node information; The graph convolution kernel of the graph convolution layer satisfies the following formula: , where represents the product kernel of graph convolution, represents the parameters learned during the neural network training process, represents the k-th order Chebyshev polynomial, and K represents the highest order of the Chebyshev polynomial; The node propagation formula satisfies: , where Z represents the feature representation output by the graph convolutional layer, represents the k-th order Chebyshev inequality, and X represents the first feature matrix.

6. The method according to claim 1, characterized in that, Judging the attack situation according to the node security status classification and prediction results of the network situation graphs at different time points and generating a honeypot deployment strategy for the attack situation, including: When judging that the attack situation is a vulnerability exploitation attack, the generated honeypot deployment strategy for the attack situation is to redirect the traffic to the honeypot and simulate the node state; When judging that the attack situation is scanning and sniffing, the generated honeypot deployment strategy for the attack situation is to increase monitoring and restrict access permissions.

7. A honeypot configuration device based on a graph neural network, characterized in that, The device includes: A collection unit for collecting network situation data, where the network situation data includes network traffic data and server log data; A network situation graph construction unit for calculating the node connection relationship carried by the edges of the network situation graph and constructing node feature vectors according to the network situation data for constructing the network situation graph; A graph embedding processing unit for performing graph embedding processing on the network situation graph to obtain a first feature matrix for representing the node vectors in the graph; A classification prediction unit, configured to input the network situation graph and the first feature matrix into a graph neural network. The graph neural network includes C processing modules, a readout module, and a merging module. The processing modules are configured to extract node information according to the input content and pool the feature expressions of the node information. The readout module is configured to read out the node features obtained by each processing module. The merging module is configured to splice the node features obtained by the C processing modules to form a second feature matrix, and classify and predict the security states of the nodes according to the second feature matrix, where C is a positive integer; A honeypot configuration unit, configured to determine the attack situation according to the classification and prediction results of the node security states of the network situation graph at different time points and generate a honeypot deployment strategy for the attack situation to adjust the honeypot resource configuration.

8. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the honeypot configuration method based on a graph neural network according to any one of claims 1 to 7.

9. An electronic device, characterized in that, Comprising: A processor and a memory; The memory is configured to store a computer program; The processor is configured to execute the computer program stored in the memory, so that the electronic device executes the honeypot configuration method based on a graph neural network according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for predicting attack intention through graph neural network based on honeypot data

    CN114978708A

  • Self-adaption method for realizing active deception defense strategy based on security atlas neural network

    CN115913635A

  • Cloud security anomaly detection method based on graph neural network

    CN117650899A

  • Honeypot network security situation prediction method and system

    CN118540166A

  • GCN-based honey situation map analysis method

    CN119316238A

Cited By

  • Honey array situation map analysis method and device, medium and electronic equipment

    CN121125354A

  • A honeycomb situation map analysis method, device, medium and electronic equipment

    CN121125354B