Automatic internet attack countering method and system based on scene strategy

Through the DLL dynamic loading and information sharing mechanism, combined with custom counter scenario strategies, the problems of concealment and automated response of the counter system are solved, and efficient and flexible Internet attack countermeasures are achieved.

CN120301618APending Publication Date: 2025-07-11INFORMATION CENT OF YUNNAN POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510203489.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing Internet attack countermeasures lack concealment and are easily monitored by attackers. The countermeasures and response strategies are not flexible enough, cannot be adjusted quickly, and lack an automated countermeasures mechanism, resulting in insufficient responses and poor consistency.

Method used

Integrate into the host program through the DLL dynamic loading mode to enhance the concealment of the counter client; establish an information sharing mechanism with security components, build a counter event database for collaborative countermeasures; custom counterscenario strategies for automated countermeasures, support multiple combination matching methods to filter attack events and automate countermeasures.

Benefits of technology

The concealment and detection resistance of the counter client are improved, efficient information sharing and coordinated countermeasures are realized with security components, ensuring the flexibility and timeliness of the countermeasure process, reducing human intervention, and improving countermeasure efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301618A_ABST
    Figure CN120301618A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to an automatic internet attack countering method and system based on a scene strategy, which enhances the concealment and anti-detection capability of a countering client, packages the countering client into a dynamic link library, and adopts multi-thread operation and TCP short connection encryption communication at random time intervals. The method does not depend on a third-party library, does not create file data, and interacts with a countering system to receive a shellcode and an executable program to perform countering action; enhancing information sharing with other security components, receiving attack event data information through a self-defined data mechanism and a format template, self-defining a countering scene strategy, and associating and sharing a countering result and attack event data to realize collaborative countering; attack events conforming to automatic countering are screened by supporting multiple combination matching modes, a countering event library is associated to configure an automatic countering process, and after an attacker downloads a countering client program and starts, a countering system is automatically connected to obtain a countering strategy to realize automatic countering.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to an automated Internet attack countermeasure method and system based on scenario strategies. Background Art

[0002] In current Internet attack countermeasure systems, there are usually problems such as the lack of concealment of countermeasure clients, which are easily monitored and identified by attackers; secondly, the flexibility of countermeasure response strategies is insufficient, and countermeasure measures cannot be adjusted quickly; the lack of an automated countermeasure mechanism results in a slow reaction, missing the best countermeasure plan, and affecting subsequent event analysis and protection strategy optimization.

[0003] The lack of concealment of countermeasure clients makes them easily monitored and discovered: Currently, the vast majority of countermeasure clients are independent processes bundled with host programs and are separate and independent processes from the host program. They are usually composed of open-source code libraries or code snippets of other known programs and are similar to known malware. Security software can easily identify these similarities through feature libraries. Since they are independent processes running in the system, they are likely to leave obvious traces, such as: suspicious process and file names, network connections of abnormal processes, lack of encryption in communication, regular network traffic, logging of log information, and high consumption of system resources, etc., which makes them easily discovered by attackers; these characteristics make the countermeasure clients easily monitored and discovered during operation, thus reducing their concealment and effectiveness.

[0004] The flexibility of countermeasure response strategies is insufficient and information sharing is insufficient: In the face of complex and ever-changing network attacks, countermeasure systems often lack flexible response strategies and cannot quickly adjust countermeasure measures according to real-time situations. In addition, in a multi-level security protection system, the communication and cooperation between countermeasure systems and other security components are usually not sufficient, resulting in poor information sharing and unable to achieve effective collaborative countermeasures.

[0005] The lack of an automated response countermeasure mechanism: The lack of automation in countermeasures will result in a slow reaction when an attack occurs. The attacker may cause greater damage or miss the countermeasure opportunity during this period. Manual countermeasure measures taken by humans may be inconsistent due to individual differences, resulting in inconsistent countermeasure handling methods for different attack events. Usually, it is not possible to completely record and comprehensively obtain attacker information, leading to difficulties in subsequent event analysis and summary and affecting the optimization of future protection strategies. Summary of the Invention

[0006] In view of the problems existing in the above-mentioned prior art, the present invention is proposed.

[0007] Therefore, the technical problems to be solved by the present invention are as follows: enhancing the concealment and anti-detection ability of the countermeasure client; integrating the countermeasure client into the host program in the form of DLL dynamic loading for concealed loading, and further improving the concealment and anti-detection ability by changing the communication interaction mode and running behavior mode of the countermeasure DLL; the countermeasure DLL itself does not perform countermeasures, but receives the shellcode and executable *.exe programs sent by the countermeasure system through interaction with the countermeasure system to perform countermeasure actions.

[0008] Strengthening information sharing with other security components and establishing a countermeasure event library for collaborative countermeasures: constructing an interface standard for the countermeasure system to clarify the format and fields of attack event data obtained by the countermeasure system from other security components (such as intrusion detection systems, security situation awareness systems, etc.), and at the same time obtaining security event information; customizing a countermeasure event policy database covering attacker information collection, file distribution, execution of *.exe programs and shellcode, etc., and realizing collaborative countermeasures within the countermeasure system through countermeasure information sharing.

[0009] Customizing countermeasure scenario strategies for automated countermeasures: the system supports multiple combination matching methods, including JSON, regular expressions, specific values, and range intervals, to filter attack events that meet the requirements of automated countermeasures, and associate the countermeasure event library with such attack events and configure the automated countermeasure process; when the attacker downloads the countermeasure client program, as long as the software is started, the countermeasure client will automatically connect to the countermeasure system to obtain countermeasure strategies, thus realizing automated countermeasures.

[0010] To solve the above technical problems, the present invention provides the following technical solutions. An automated Internet attack countermeasure method based on scenario strategies includes: enhancing the concealment and anti-detection ability of the countermeasure client; strengthening information sharing with security components and establishing a countermeasure event library for collaborative countermeasures; customizing countermeasure scenario strategies for automated countermeasures.

[0011] As a preferred solution of the automated Internet attack countermeasure method based on scenario strategies according to the present invention, among them: the enhancement of the concealment and anti-detection ability of the countermeasure client includes encapsulating the countermeasure client as a dynamic link library by using Windows native API functions to achieve multi-threaded operation.

[0012] As a preferred solution of the automated Internet attack countermeasure method based on scenario strategies according to the present invention, among them: the multi-threaded operation includes a network communication thread and a task processing thread. The host program dynamically loads the link library, packages the host program and the dynamic library into a self-extracting installation program, and changes the icon and signature to achieve the concealed loading and running of the countermeasure client; the host program calls the dynamic link library of the countermeasure client to start loading the dynamic link library to achieve the concealed loading and running of the countermeasure client.

[0013] As a preferred solution of an automated Internet attack countermeasure method based on scenario strategies according to the present invention, wherein: strengthening information sharing with security components and establishing a countermeasure event library for collaborative countermeasures includes implementing data reception methods for Http, Kafka, and Syslog through a custom data mechanism, and receiving attack event data information sent by security components through a custom data format template.

[0014] As a preferred solution of an automated Internet attack countermeasure method based on scenario strategies according to the present invention, wherein: the countermeasure event library includes attacker information collection, uploading countermeasure *.exe programs, uploading countermeasure shellcodes, and uploading files, and issuing policies through the countermeasure system. The countermeasure result information and attack event data information are associated and shared to achieve collaborative countermeasures within the countermeasure system.

[0015] As a preferred solution of an automated Internet attack countermeasure method based on scenario strategies according to the present invention, wherein: customizing the countermeasure scenario strategy for automated countermeasures includes supporting combined matching methods, including JSON, regular expressions, specific values, and range, screening network security attack events that meet the requirements of automated countermeasures, associating the attack events with the countermeasure event library, and configuring the scenario of the automated countermeasure process.

[0016] As a preferred solution of an automated Internet attack countermeasure method based on scenario strategies according to the present invention, wherein: configuring the automated countermeasure process includes automatically collecting host information, searching for sensitive file data of the host, issuing countermeasure programs, and countermeasure shellcodes; when the attacker downloads the countermeasure client program, the software is started, and the countermeasure client automatically connects to the countermeasure system to obtain countermeasure strategies to achieve automated countermeasures.

[0017] Another object of the present invention is to provide an intelligent Internet attack countermeasure and protection system based on scenario-based strategies, which can effectively improve the countermeasure efficiency and accuracy, quickly respond to and accurately deal with network attacks, and ensure the timeliness and effectiveness of network security protection by enhancing the concealment and anti-detection ability of the countermeasure client, strengthening information sharing with security components, and implementing automated countermeasures for customizing countermeasure scenario strategies.

[0018] To solve the above technical problems, the present invention provides the following technical solutions: an intelligent Internet attack countermeasure and protection system based on scenario-based strategies, including: a concealment enhancement module, a countermeasure event library module, and a scenario strategy automated countermeasure module;

[0019] The concealment enhancement module enhances the concealment and anti-detection ability of the countermeasure client;

[0020] The countermeasure event library module strengthens data information sharing with security components and establishes a countermeasure event library for collaborative countermeasures;

[0021] The scenario strategy automated countermeasure module customizes countermeasure scenario strategies for automated countermeasures.

[0022] A computer device includes a memory and a processor. The memory stores a computer program. It is characterized in that when the processor executes the computer program, the steps of an automated Internet attack countermeasure method based on scenario strategies as described above are implemented.

[0023] A computer-readable storage medium stores a computer program thereon. It is characterized in that when the computer program is executed by a processor, the steps of an automated Internet attack countermeasure method based on scenario strategies as described above are implemented.

[0024] The beneficial effects of the present invention: In terms of enhancing the concealment and anti-detection ability of the countermeasure client, it has the following advantages:

[0025] Stealth loading, by adopting the DLL dynamic loading mode and integrating it into the host program for stealth loading, makes it difficult for the countermeasure client to be easily detected. This way of hiding within the normal host program changes the situation that conventional countermeasure programs are easily discovered when they exist independently, increasing the difficulty for attackers to discover the countermeasure client, which is equivalent to putting a "cloak of invisibility" on the countermeasure work;

[0026] Improve communication and behavior concealment, change the communication interaction mode and running behavior mode of the countermeasure DLL, and further strengthen the concealment. Unusual communication and behavior patterns can effectively avoid some detection means based on conventional mode monitoring, enabling the countermeasure client to run in a more concealed state and avoiding being detected by the defense mechanism for countermeasure monitoring, ensuring that the countermeasure work can be carried out continuously and without interference;

[0027] Flexible source of countermeasure actions. The countermeasure DLL itself does not directly carry out countermeasures, but relies on interacting with the countermeasure system to receive shellcode and executable *.exe programs for countermeasure actions. Such a design makes the initiation of countermeasure actions more flexible, and corresponding countermeasures can be implemented according to the unified deployment and real-time decision-making of the countermeasure system. It also helps to disperse the logic of implementing countermeasure functions and improve concealment from the source because it is difficult to fully grasp the entire picture of its countermeasures by analyzing the DLL alone;

[0028] In terms of strengthening information sharing with other security components and establishing a collaborative countermeasure with a countermeasure event library, it has the following advantages:

[0029] Unify the data acquisition standard and build a countermeasure system. By formulating an interface standard, it clarifies the format and fields for obtaining attack event data from other security components (such as intrusion detection systems, security situation awareness systems, etc.). This helps to standardize the data interaction process. The data of each security component can be aggregated into the countermeasure system according to the unified standard, avoiding information chaos and integration difficulties caused by inconsistent data formats and other issues, enabling the countermeasure system to utilize the information provided by external security components more efficiently and accurately.

[0030] Comprehensive information acquisition and integration can obtain security event information simultaneously. This means that the countermeasure system can grasp the security situation and attack conditions in the network from multiple dimensions, fuse the monitoring perspectives of different security components to form a more comprehensive "intelligence network", thus providing sufficient basis for precise countermeasures, not missing any possible attack clues, and improving the pertinence and effectiveness of countermeasures.

[0031] Build the foundation for collaborative countermeasures. Customize the countermeasure event policy database, covering aspects such as attacker information collection, file distribution, execution of *.exe programs, and shellcode. Based on this, through countermeasure information sharing, achieve collaborative countermeasures within the countermeasure system. Different security components can leverage their respective advantages based on this shared database and unified information, cooperate with each other during the countermeasure process. For example, after the intrusion detection system discovers an attack, the countermeasure system makes auxiliary decisions through the security situation awareness system based on the shared attacker information, etc., and implements effective countermeasure measures, forming an organic countermeasure whole to improve the overall countermeasure efficiency and success rate.

[0032] Regarding automating countermeasures through customizing countermeasure scenario strategies, it has the following advantages:

[0033] Flexibly screen attack events. The system supports multiple combination matching methods, including JSON, regular expressions, specific values, and range intervals, to screen attack events that meet the requirements of automated countermeasures. This diverse matching method can handle complex and changeable network attack scenarios. Whether it is an attack event based on specific text formats, numerical ranges, or specific string characteristics, it can be screened out relatively accurately, ensuring that countermeasure resources can focus on the targets that truly need to be countered and avoiding ineffective countermeasure actions.

[0034] Automate the association strategy. For the screened attack events, associate the countermeasure event library and configure the automated countermeasure process to achieve an automated connection from discovering an attack to implementing countermeasures. Once an attack event that meets the conditions is identified, countermeasures can be quickly carried out according to the pre-configured strategy without excessive manual intervention, greatly improving the timeliness of countermeasures and being able to quickly respond before the attack behavior causes greater harm, effectively curbing the spread of the attack.

[0035] Convenient automated implementation. When an attacker downloads the countermeasure client program, as long as the software countermeasure client is started, it will automatically connect to the countermeasure system to obtain countermeasure strategies, thus achieving automated countermeasures. The whole process is very convenient for users, without the need for additional complex operation configurations, ensuring that the countermeasure mechanism can run reliably and automatically, reducing the possibility of countermeasure delays or failures caused by factors such as human operation errors, and improving the stability and operability of countermeasure work. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0037] Figure 1 It is a flowchart of an automated Internet attack countermeasure method based on scenario strategies provided by an embodiment of the present invention.

[0038] Figure 2 It is a working principle diagram of an automated Internet attack countermeasure method based on scenario strategies provided by an embodiment of the present invention.

[0039] Figure 3 It is an integration process diagram of the countermeasure client of an automated Internet attack countermeasure method based on scenario strategies provided by an embodiment of the present invention.

[0040] Figure 4 It is a process diagram of the countermeasure client starting and executing countermeasure tasks of an automated Internet attack countermeasure method based on scenario strategies provided by an embodiment of the present invention.

[0041] Figure 5 It is a countermeasure event library diagram of an automated Internet attack countermeasure method based on scenario strategies provided by an embodiment of the present invention.

[0042] Figure 6 It is a diagram of automating countermeasures using custom countermeasure scenario strategies of an automated Internet attack countermeasure method based on scenario strategies provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention with reference to the accompanying drawings of the specification. Obviously, the described embodiments are some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0044] Example 1, reference Figure 1 , is an embodiment of the present invention, which provides an automatic Internet attack countermeasure method based on scenario strategy, including:

[0045] S1: Enhance the concealment and anti-detection capabilities of the counter-client.

[0046] It should be noted that if Figure 1 As shown in S1, the concealment and anti-detection capability of the counter-attack client are enhanced: by using Windows native API functions, the counter-attack client is encapsulated as a dynamic link library (DLL) to achieve multi-threaded operation, including network communication threads and task processing threads. The host program can dynamically load the library, or package the host program and the dynamic library into a self-extracting installer, and change the icon and signature to achieve the concealed loading and operation of the counter-attack client; the counter-attack DLL is encapsulated using the C language native API to ensure that the file size is small and does not rely on any third-party library; during operation, the network communication between the counter-attack client and the server adopts the TCP short connection encryption method with random time intervals, does not create or write any file data, and occupies less system resources; the counter-attack DLL itself does not perform counter-attacks, but receives the shellcode and executable *.exe program issued by the counter-attack system through interactive communication with the counter-attack system to perform counter-attacks; thereby further improving its concealment and anti-monitoring capabilities.

[0047] Further steps to counter the hidden nature of client integration:

[0048] The counter-attack client DLL is written in C language, relying only on the Windows built-in library, not calling any third-party library, and encapsulated as a dynamic link library (*.DLL), with the entry function simplified to a single function. The counter-attack client must occupy as little system CPU and memory resources as possible, and not record any log information to enhance concealment;

[0049] For applications with source code, the counter-client DLL is called through dynamic loading to achieve application integration of the counter-client;

[0050] For applications without source code, static Hook of the countermeasure client.dll is achieved by modifying the system version.dll, and the startup call of the countermeasure client.dll is realized. The specific steps include: analyzing the countermeasure client.dll to determine function entry, parameters, and return value information; regenerating the version.dll and writing a proxy function identical to the countermeasure client.dll in the version.dll. When the version.dll is started and called, the entry address of the countermeasure client.dll is obtained, thus realizing the call of the countermeasure client.dll; creating a self-extracting software together with the application, the modified version.dll, and the countermeasure client.dll (self-extracting options include obtaining administrative privileges, extracting to a temporary file, hiding the directory, and completely forcibly overwriting) to achieve the application integration of the countermeasure client; the integrated countermeasure client needs to be signed and authenticated again to avoid being detected and intercepted by antivirus software.

[0051] Furthermore, the steps for the countermeasure client's anti-detection ability are as follows:

[0052] During the startup process of the application integrated with the countermeasure client, the entry thread of the countermeasure client DLL is called to start the countermeasure client.

[0053] The countermeasure client creates a TCP client connection to the countermeasure system at random intervals ([5, 30] minutes).

[0054] Data transfer between the countermeasure client and the countermeasure system is encrypted using a private communication protocol. The countermeasure client asks the countermeasure system to obtain countermeasure execution tasks.

[0055] If no imported countermeasure tasks are obtained, the network connection is disconnected.

[0056] If countermeasure tasks are obtained, countermeasure actions are performed according to the following countermeasure task types:

[0057] For information collection tasks, data is directly collected through the countermeasure client, such as collecting the attacker's computer IP, MAC, computer name, process list, disk file list, etc.

[0058] For ShellCode countermeasure tasks, ShellCode is executed through Windows API functions (the specific process is shown in the above figure, including: creating a puppet process through CreateProcessA; obtaining the thread context through GetThreadContext; reading the base address of the puppet process through ReadProcessMemory; writing the shellcode into the process memory through WriteProcessMemory; resuming thread execution through ResumeThread).

[0059] Process countermeasure tasks (downloaded together with the task list, downloaded directly into memory without storing on the local hard drive), and execute process countermeasure tasks through Windows API functions (the specific process is shown in the above figure, including: creating a puppet process through CreateProcessA; obtaining the function base address through GetProcAddress; obtaining the thread context through GetThreadContext; reading the memory of the puppet process through ReadProcessMemory; unloading the memory address of the puppet process through UnmapViewOfSection; reading the data of the file to be executed into memory; saving the entry point of the countermeasure program process to the Eax of the puppet process context; applying for the memory space size to be countered in the puppet process through VirtualAllocEx; mapping the HEADER of the countermeasure program to the puppet process through WriteProcessMemory; mapping the blocks of the countermeasure program to the puppet process through WriteProcessMemory; mapping the context of the countermeasure program to the puppet process through WriteProcessMemory; resuming thread execution through ResumeThread).

[0060] After the collection task is completed, feedback the execution status and result data of the countermeasure task to the countermeasure system.

[0061] The countermeasure client actively disconnects the network connection with the countermeasure system.

[0062] S2: After encapsulation, strengthen information sharing with security components and establish a countermeasure event library for collaborative countermeasures.

[0063] It should be noted that, as Figure 1 shown in S2, strengthen information sharing with other security components and establish a countermeasure event library for collaborative countermeasures: implement data reception methods such as Http, Kafka, and Syslog through a custom data mechanism, and receive attack event data information (such as attacker IP, Internet threat tags, attack sources, etc.) sent by other security components (such as intrusion detection systems, security situation awareness systems, etc.) through a custom data format template. Customize countermeasure scenario strategies within the countermeasure system, including attacker information collection, uploading countermeasure *.exe programs, uploading countermeasure shellcodes, uploading files and issuing policies through the countermeasure system, and associating and sharing countermeasure result information and attack event data information to achieve collaborative countermeasures within the countermeasure system.

[0064] Furthermore, by customizing rules, configure the calling rules for information sharing interfaces of other security components (including HTTP sources, HTTP request interfaces, request bodies, and feedback responses; Kafka / Syslog sources: configure data parsing formats) to generate an interface for calling information on security component attack events;

[0065] Through custom rules, obtain Internet attack events from a certain security component, configure a data acquisition interface, set Header Token information, request parameter templates, and feedback result templates to generate an interface for calling information on security component attack events;

[0066] Create 3 countermeasure events, namely information collection countermeasure event, shellcode countermeasure event, and process countermeasure event, the details are as follows:

[0067] Information collection countermeasure event: Configure a collection client to implement the collection of the local computer name, MAC, IP address, host process information, host file names, and upload them to the countermeasure server and other uploads to the countermeasure system, and store them in the countermeasure event;

[0068] Shellcode countermeasure event: Use tools such as Metasploit Framework, Cobalt Strike, Msfvenom, and Shellter to generate shellcode for countermeasures, upload it to the countermeasure system, and store it in the countermeasure event library;

[0069] Process countermeasure event: Upload an independent running.exe program with countermeasure capabilities (such as: VNC client) to the countermeasure system and store it in the countermeasure event library;

[0070] After an attack is initiated from Internet IP 4.5.6.7 and detected by the security component and diverted to the honeypot, and after the application integrating the countermeasure client is downloaded and run, the countermeasure client of 4.5.6.7 actively connects to the countermeasure platform, and then obtains the attack event information discovered by the security component through the interface. Different security personnel can select countermeasure events in the countermeasure event library in the system to carry out collaborative countermeasures against the attacker of 4.5.6.7.

[0071] S3: Customize countermeasure scenario strategies for automated countermeasures.

[0072] It should be noted that as Figure 1As shown in S3, customize the countermeasure scenario strategy for automated countermeasures: The system supports multiple combination matching methods, including JSON, regular expressions, specific values, and range, to filter attack events that meet the requirements of automated countermeasures, and associate the countermeasure event library for such attack events, and configure the automated countermeasure process, such as automatically collecting host information, searching for sensitive file data on the host, distributing countermeasure programs, countering shellcode, etc.; when the attacker downloads the countermeasure client program, as long as the software is started, the countermeasure client will automatically connect to the countermeasure system to obtain the countermeasure strategy, thus realizing automated countermeasures.

[0073] Further, an example of customizing the countermeasure source rule for attack events:

[0074] Rule-making objective: Detect and counter the common port scan attack behavior on the enterprise's core business server from a specific external network segment. The rule name is "Internet attack event countermeasure source 1".

[0075] Specific rule configuration:

[0076] Source IP address matching: Use the matching method of range, and set the source IP address range to 220.168.100.1 - 220.168.150.254, because through previous security monitoring, suspicious activities often occur in this network segment.

[0077] Target IP matching: Match by specific value, and set the target IP to the IP address 10.10.10.10 of the enterprise's core business server, which is the object that needs to be protected with key emphasis;

[0078] Attack method matching: Use regular expressions to match, and set the rule to.*port scan.*, which is used to filter out the attack method records containing relevant descriptions of "port scan" (port scan), so as to accurately locate the attack behavior of port scan;

[0079] The final generated countermeasure source rule logic for attack events is: From the attack event information obtained from the security component, filter out the attack events whose source IP address is in the range of 220.168.100.1 - 220.168.150.254, the target IP is 10.10.10.10, and the attack method description matches the regular expression.*port scan.*. These events will be regarded as attack events that meet the countermeasure conditions;

[0080] An example of customizing the countermeasure scenario strategy:

[0081] Select the attack event source with the name of "Internet attack event countermeasure source 1" as the attack event source;

[0082] Select information collection countermeasure events, Shellcode countermeasure events, and process (such as VNC client) countermeasure events from the countermeasure event library;

[0083] Generate attack countermeasure strategy A through the above steps.

[0084] Furthermore, automate the countermeasure process

[0085] The countermeasure system receives a connection request from the countermeasure client (which has been deployed at each key node within the enterprise), and then automatically calls the attack event information synchronization interface to interact with security components such as the intrusion detection system to synchronize and obtain the latest attack event information. The system automatically associates and filters out eligible attack events according to the pre-configured "Internet attack event countermeasure source 1", that is, it discovers an attack event record of port scanning (the attack method matches successfully) from 220.168.120.50 (within the set source IP range) to 10.10.10.10 (the core business server). And the automatic countermeasure system matches attack countermeasure strategy A and sends countermeasure tasks to the countermeasure client: information collection countermeasure events, Shellcode countermeasure events, process (such as VNC client) countermeasure events; after the countermeasure client obtains the countermeasure tasks, it automatically performs countermeasure actions such as information collection countermeasure events, Shellcode countermeasure events, and process (such as VNC client) countermeasure events, and feeds back the execution status to the countermeasure system.

[0086] The above is a schematic solution of an automated Internet attack countermeasure method based on scenario strategies in this embodiment. It should be noted that the technical solution of the system of the automated Internet attack countermeasure method based on scenario strategies belongs to the same concept as the technical solution of the above-mentioned automated Internet attack countermeasure method based on scenario strategies. For the details not described in detail in the technical solution of the intelligent Internet attack countermeasure protection system based on scenario strategies in this embodiment, reference can be made to the description of the technical solution of the above-mentioned automated Internet attack countermeasure method based on scenario strategies.

[0087] Example 2, refer to Figures 2 - 6 , this is an embodiment of the present invention. This embodiment provides an automated Internet attack countermeasure method based on scenario strategies, including:

[0088] By analyzing network attack events, the Internet attack threat traffic is transferred to the honeypot system through a load balancing device. Internet business software integrated with a countermeasure client, such as a VPN client, an enterprise WeChat client, etc., is placed in the honeypot system. When an attacker downloads and runs the software integrated with the countermeasure client, the countermeasure process is initiated. By enhancing the concealment and anti-detection capabilities of the countermeasure client, it is encapsulated as a dynamic link library (DLL), and uses multi-threaded operation and TCP short connection encrypted communication with random time intervals. It does not rely on third-party libraries and does not create file data, and receives shellcode and executable programs through interaction with the countermeasure system to perform countermeasure actions. At the same time, information sharing with other security components is strengthened. Attack event data information is received through a custom data mechanism and format template, and custom countermeasure scenario strategies are defined and the countermeasure results are associated and shared with the attack event data to achieve collaborative countermeasures. In addition, the system supports multiple combination matching methods to filter attack events that meet automated countermeasures, and configures the automated countermeasure process by associating with a countermeasure event library. When an attacker downloads and starts the countermeasure client program, it automatically connects to the countermeasure system to obtain countermeasure strategies to achieve automated countermeasures. The overall working principle is as follows Figure 2 as shown;

[0089] Enhance the concealment and anti-detection capabilities of the countermeasure client. The integration process of the countermeasure client is as follows Figure 3 as shown;

[0090] Write the countermeasure client DLL in C language, only rely on the libraries built into Windows, do not call any third-party libraries, and encapsulate it as a dynamic link library (*.DLL), and simplify the entry function to a single function. The countermeasure client should occupy as little system CPU and memory resources as possible and not record any log information to enhance concealment;

[0091] For application programs with source code, call the countermeasure client DLL through dynamic loading to achieve the application integration of the countermeasure client.

[0092] For applications without source code, static Hook of the countermeasure client.dll is achieved by modifying the system version.dll, and the startup call of the countermeasure client.dll is realized. The specific steps include: analyzing the countermeasure client.dll to determine function entry, parameters, and return value information; regenerating the version.dll, writing a proxy function identical to the countermeasure client.dll in the version.dll, and obtaining the entry address of the countermeasure client.dll when the version.dll is started, so as to realize the call of the countermeasure client.dll; creating a self-extracting software (self-extracting options include obtaining administrative privileges, extracting to a temporary file, hiding the directory, and completely forced overwrite) with the application, the modified version.dll, and the countermeasure client.dll to achieve the application integration of the countermeasure client; the integrated countermeasure client needs to be signed and authenticated again to avoid being detected and intercepted by antivirus software.

[0093] The process of the countermeasure client starting and executing countermeasure tasks is as follows Figure 4 as shown;

[0094] When the application with the integrated countermeasure client starts, it calls the entry thread of the countermeasure client DLL to start the countermeasure client;

[0095] The countermeasure client creates a TCP client connection to the countermeasure system at random intervals ([5, 30] minutes);

[0096] The countermeasure client and the countermeasure system use a private communication protocol for encrypted data transfer. The countermeasure client asks the countermeasure system to obtain countermeasure execution tasks;

[0097] If no imported countermeasure tasks are obtained, the network connection is disconnected;

[0098] If countermeasure tasks are obtained, countermeasure actions are performed according to the following countermeasure task types:

[0099] For information collection tasks, data is directly collected through the countermeasure client, such as collecting the attacker's computer IP, MAC, computer name, process list, disk file list, etc.;

[0100] For ShellCode countermeasure tasks, ShellCode is executed through Windows API functions (the specific process is shown in the above figure, including: creating a puppet process through CreateProcessA; obtaining the thread context through GetThreadContext; reading the base address of the puppet process through ReadProcessMemory; writing the shellcode into the process memory through WriteProcessMemory; resuming thread execution through ResumeThread);

[0101] Process countermeasure tasks (downloaded along with the task list, downloaded directly into memory without storing on the local hard drive), and execute process countermeasure tasks through Windows API functions (for the specific process, see the figure above, including: creating a puppet process through CreateProcessA; obtaining the function base address through GetProcAddress; obtaining the thread context through GetThreadContext; reading the memory of the puppet process through ReadProcessMemory; unloading the memory address of the puppet process through UnmapViewOfSection; reading the data of the file to be executed into memory; saving the entry point of the countermeasure program process to the Eax of the puppet process context; applying for the memory space size to be countered in the puppet process through VirtualAllocEx; mapping the HEADER of the countermeasure program to the puppet process through WriteProcessMemory; mapping the blocks of the countermeasure program to the puppet process through WriteProcessMemory; mapping the context of the countermeasure program to the puppet process through WriteProcessMemory; resuming thread execution through ResumeThread);

[0102] After the collection task is completed, feedback the execution completion status and result data of the countermeasure task to the countermeasure system;

[0103] The countermeasure client actively disconnects the network connection with the countermeasure system;

[0104] Strengthen information sharing with other security components, establish a countermeasure event library for collaborative countermeasures, as follows Figure 5 shown:

[0105] Through custom rules, configure the information sharing interface call rules of other security components (including HTTP source, HTTP request interface, request body, and feedback response; Kafka / Syslog source: configure the data parsing format), and generate the information call interface for security component attack events;

[0106] Create a countermeasure event library, select the countermeasure event type (shellcode countermeasure, process countermeasure, information collection), and configure the information of the countermeasure puppet process (disguised process) or configure the collection event information (host information, IP, MAC, process, file, etc.) by uploading shellcode or uploading the countermeasure program to generate a countermeasure event library;

[0107] After the countermeasure system receives the connection from the countermeasure client, synchronize and associate the attack event information through the information call interface of the security component attack event, select the countermeasure events in the countermeasure event library to issue countermeasure tasks, obtain the countermeasure results, and generate the attack countermeasure results.

[0108] Automatically counterattack using a custom countermeasure scenario strategy as follows Figure 6 as shown below

[0109] Customize the countermeasure source rules for attack events, select and match attack event fields such as source IP address, target IP, port, and attack method, etc. The rules support multiple combination matching methods, including JSON, regular expressions, specific values, and range; Generate countermeasure source rules for attack events to filter attack events that meet the countermeasure conditions;

[0110] Customize the countermeasure scenario strategy. By creating a custom countermeasure scenario strategy, select the countermeasure source rules for attack events, and select and add countermeasure events from the countermeasure event library to finally form an attack countermeasure strategy;

[0111] After the countermeasure system receives the connection from the countermeasure client, it automatically calls the attack event information synchronization interface to synchronize the attack event information obtained by the security component, automatically associates and configures the attack event countermeasure strategy to achieve automatic counterattack of the attack event, and generates an attack countermeasure result.

[0112] Example 3 is an embodiment of the present invention, which provides an intelligent Internet attack countermeasure protection system based on a scenario-based strategy, including: a concealment enhancement module, a countermeasure event library module, and a scenario strategy automatic counterattack module;

[0113] The concealment enhancement module enhances the concealment and anti-detection ability of the countermeasure client;

[0114] The countermeasure event library module strengthens data information sharing with the security component and establishes a countermeasure event library for collaborative counterattack;

[0115] The scenario strategy automatic counterattack module customizes the countermeasure scenario strategy for automatic counterattack.

[0116] This embodiment also provides a computing device applicable to a situation of an automatic Internet attack countermeasure method based on a scenario strategy, including:

[0117] A memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement an automatic Internet attack countermeasure method based on a scenario strategy as proposed in the above embodiment.

[0118] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by the processor, it implements an automatic Internet attack countermeasure method based on a scenario strategy as proposed in the above embodiment.

[0119] The storage medium proposed in this embodiment and the automated Internet attack countermeasure method based on scenario strategy proposed in the above embodiment belong to the same inventive concept. Technical details not described in detail in this embodiment can be referred to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.

[0120] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0121] Logic and / or steps described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0122] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiment, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following well-known technologies in the art can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.

[0123] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. An automated Internet attack countermeasure method based on scenario strategies, characterized in that: Including: Enhance the concealment and anti-detection ability of the countermeasure client; Strengthen information sharing with security components, establish a countermeasure event library for collaborative countermeasures; Customize countermeasure scenario strategies for automated countermeasures.

2. The automated Internet attack countermeasure method based on scenario strategy according to claim 1, wherein: The enhancement of the concealment and anti-detection ability of the countermeasure client includes encapsulating the countermeasure client as a dynamic link library by using Windows native API functions to achieve multi-threaded operation.

3. The automated Internet attack countermeasure method based on scenario strategy according to claim 2, characterized in that: The multi-threaded operation includes a network communication thread and a task processing thread. The host program dynamically loads the link library, packages the host program and the dynamic library into a self-extracting installer, and changes the icon and signature to achieve the hidden loading and running of the countermeasure client; the host program calls the dynamic link library of the countermeasure client to start loading the dynamic link library to achieve the hidden loading and running of the countermeasure client.

4. The automated Internet attack countermeasure method based on a scenario strategy according to claim 3, wherein: The strengthening of information sharing with security components and the establishment of a countermeasure event library for collaborative countermeasures include implementing Http, Kafka, and Syslog data reception methods through a custom data mechanism, and receiving attack event data information sent by security components through a custom data format template.

5. The automated Internet attack countermeasure method based on scenario strategy according to claim 4, characterized in that: The countermeasure event library includes attacker information collection, uploading countermeasure *.exe programs, uploading countermeasure shellcodes, and uploading files, and associating and sharing countermeasure result information and attack event data information through the countermeasure system to issue policies, achieving collaborative countermeasures within the countermeasure system.

6. The automated Internet attack countermeasure method based on a scenario strategy according to claim 5, characterized in that: The customization of countermeasure scenario strategies for automated countermeasures includes supporting combination matching methods, including JSON, regular expressions, specific values, and range, screening network security attack events that meet the requirements of automated countermeasures, and associating the attack events with the countermeasure event library to configure the scenario of the automated countermeasure process.

7. The automated Internet attack countermeasure method based on a scenario strategy according to claim 6, characterized in that: The configuration of the automated countermeasure process includes automatically collecting host information, searching for sensitive file data of the host, issuing countermeasure programs, and countermeasure shellcodes; when the attacker downloads the countermeasure client program and starts the software, the countermeasure client automatically connects to the countermeasure system to obtain countermeasure policies to achieve automated countermeasures.

8. A system for intelligent Internet attack countermeasure protection based on scenario-based strategies according to any one of claims 1-7, characterized in that: Including: A concealment enhancement module, a countermeasure event library module, and a scenario strategy automated countermeasure module; The concealment enhancement module enhances the concealment and anti-detection ability of the countermeasure client; The countermeasure event library module strengthens data information sharing with security components and establishes a countermeasure event library for collaborative countermeasures; The scenario strategy automated countermeasure module customizes countermeasure scenario strategies for automated countermeasures.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of a scenario strategy-based automated Internet attack countermeasure method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of a scenario strategy-based automated Internet attack countermeasure method according to any one of claims 1 to 7.