Attack analysis method based on mysqldump connection characteristic honeypot
By embedding attack vectors in the tool version information of the simulated MySQL server, building a honeypot server and collecting multi-dimensional attack behavior data, the problem of difficulty in efficiently collecting and analyzing attack behavior in the existing technology is solved, and more accurate attack analysis and stronger network security defense are achieved.
Patent Information
- Application Number
- CN202510534613.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-11
AI Technical Summary
In the face of cyber attacks, it is difficult to efficiently collect attacker behavior data, and the attack analysis results are inaccurate.
By embedding attack vectors in the tool version information of the simulated MySQL server, a honeypot server is built, to attract attackers and obtain multi-dimensional attack behavior data, and data collection is collected using network traffic probes, process monitoring modules, interaction interfaces and log management modules, and attack behavior analysis is performed in combination with various analysis methods.
Improve the accuracy of attack analysis, a comprehensive understanding of attackers' behavior, provides support for the formulation of effective defense strategies, and enhances the overall defense capabilities of network security.
Smart Images

Figure CN120301667A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to an attack analysis method based on the connection characteristics of mysqldump honeypot. Background Art
[0002] In the Internet environment, there are a large number of web crawlers and hacker attacks, and it is of crucial significance to observe their behaviors. MySQL Honeypot, as a key technology in the field of network security, is used to attract and detect malicious activities directed against MySQL databases. The honeypot system appears to be a real and vulnerable MySQL server, but in fact it is a trap. Once an attacker launches an attack on it, the honeypot can collect the attacker's behavior data, including key information such as attack means, tools used, and attack frequency. These data provide strong support for in-depth analysis of the attacker's behavior, and thus help to better defend against potential security threats.
[0003] Traditional methods for attack analysis based on honeypots have two problems. On the one hand, the honeypots used in traditional methods are usually low-interaction honeypots, high-interaction honeypots or medium-interaction honeypots. However, low-interaction honeypots only simulate surface behaviors and cannot deeply simulate database content. When an attacker interacts with them, it is easy to find anomalies, resulting in limited attack data collection; although high-interaction honeypots can provide a real interaction environment, they have high deployment and maintenance costs and there are certain risks. Once breached by an attacker, it may lead to the exposure of the real system; medium-interaction honeypots can neither fully meet the need for comprehensive monitoring of the attacker's behavior nor accurately locate the attacker. On the other hand, traditional methods only analyze a small part of the data collected by the honeypot, resulting in inaccurate analysis results. In summary, the existing technologies are difficult to efficiently collect the attacker's behavior data and the attack analysis results are inaccurate when facing network attacks. Summary of the Invention
[0004] In view of this, the present invention provides an attack analysis method based on the connection characteristics of mysqldump honeypot to solve the problem that it is difficult to efficiently collect the attacker's behavior data and the attack analysis results are inaccurate when facing network attacks.
[0005] In a first aspect, the present invention provides an attack analysis method based on the connection characteristics of mysqldump honeypot, and the method includes:
[0006] Obtain a simulation tool for the MySQL server, where the simulation tool is used to build an environment for simulating the MySQL server;
[0007] Embed an attack vector in the version information of the simulation tool, and build a honeypot server based on the simulation tool;
[0008] In response to an attacker connecting to the honeypot server via mysqldump, obtain the version information returned by the honeypot server;
[0009] Based on the returned version information, obtain the multi-dimensional attack behavior data of the attacker;
[0010] Based on the multi-dimensional attack behavior data, analyze the attacker's attack behavior to obtain an attack analysis result.
[0011] The present invention obtains a simulated tool to simulate a real MySQL server, and then embeds an attack vector in the version information of the simulated tool. When the attacker obtains the version information, the attack vector is a key means to implement honeypot counterattack and mark attack behavior. Thus, a honeypot server is constructed based on the simulated tool to attract attackers, avoid their attacks on the real system, and gain time for defense measures. When the attacker connects to the honeypot server via mysqldump, capture the attack behavior by obtaining the returned version information, obtain multi-dimensional attack behavior data and analyze it, improve the accuracy of attack analysis, help comprehensively and accurately understand the attacker's attack behavior, provide strong support for formulating effective defense strategies, effectively reduce the risk of network attacks, and enhance the overall defense ability of network security.
[0012] In an alternative embodiment, based on the returned version information, obtain the multi-dimensional attack behavior data of the attacker, including:
[0013] Determine whether there is a detection file in the returned version information, where the detection file is used to identify whether the attacker executes the attack vector in the version information of the honeypot server;
[0014] In the case where there is a detection file in the returned version information, obtain the multi-dimensional attack behavior data of the attacker.
[0015] The present invention can accurately identify whether the attacker executes the attack vector by determining whether there is a detection file in the returned version information. When the attacker executes the attack vector, it can not only obtain the multi-dimensional attack behavior data of the attacker to analyze the attacker's attack behavior, but also achieve countermeasures against the attacker's attack and enhance the defense ability of network security.
[0016] In an alternative embodiment, the honeypot server includes a network traffic probe, a process monitoring module, an interaction interface, and a log management module;
[0017] In the case where there is a detection file in the returned version information, obtain the multi-dimensional attack behavior data of the attacker, including:
[0018] In the case where there is a detected file in the returned version information, a network traffic probe is used to monitor the network environment of the honeypot server to obtain the first behavior data of the attacker;
[0019] A process monitoring module is used to monitor the processes of the honeypot server to obtain the second behavior data of the attacker;
[0020] An interaction interface is used to monitor the interaction process between the honeypot server and the attacker's attack tools to obtain the third behavior data of the attacker;
[0021] A log management module is used to parse the logs of the honeypot server to obtain the fourth behavior data of the attacker;
[0022] The first behavior data, the second behavior data, the third behavior data, and the fourth behavior data are used as the multi-dimensional attack behavior data of the attacker.
[0023] The present invention collects data of the attacker during the attack from different aspects through multiple modules of the honeypot server, which helps to comprehensively and accurately understand the attack behavior of the attacker.
[0024] In an optional implementation manner, based on the multi-dimensional attack behavior data, the attack behavior of the attacker is analyzed to obtain an attack analysis result, including:
[0025] Based on the multi-dimensional attack behavior data, behavior mapping is performed to construct an attack behavior map of the attacker;
[0026] A binary reverse engineering tool is used to parse and deduce based on the multi-dimensional attack behavior data to obtain the working conditions of the attack tools used by the attacker;
[0027] A time series analysis and logical association algorithm is used to analyze based on the multi-dimensional attack behavior data to obtain the attack behavior chain of the attacker;
[0028] A YARA rule engine is used to perform rule matching based on the multi-dimensional attack behavior data to obtain the attack situation of the attacker;
[0029] A time series prediction model is used to perform prediction based on the multi-dimensional attack behavior data to obtain the predicted attack result of the attacker;
[0030] The attack behavior map, the working conditions of the attack tools, the attack behavior chain, the attack situation, and the predicted attack result are used as the attack analysis result.
[0031] The present invention analyzes the multi-dimensional attack behavior data of the attacker from different perspectives by using various methods, which helps to comprehensively and accurately understand the attack behavior of the attacker.
[0032] In an alternative embodiment, a honeypot server is constructed based on a simulation tool, including:
[0033] Configure the simulation tool;
[0034] Obtain the programming code of the honeypot server;
[0035] Based on the configured simulation tool and the programming code, construct a honeypot server.
[0036] By configuring the simulation tool and programming code to construct a honeypot server, the present invention can create a highly deceptive and attractive entrapment environment, enabling the honeypot server to collect and analyze the attack behaviors of attackers, and improving the security protection level. Moreover, as a security buffer, the honeypot server diverts the attention of attackers from real servers, reducing the risk of real systems being attacked.
[0037] In an alternative embodiment, the method further includes:
[0038] Adjust the defense measures based on the attack behaviors of attackers.
[0039] By the attack behaviors of attackers, the present invention correspondingly adjusts the defense measures, effectively reducing the risk of network attacks and enhancing the overall defense ability of network security.
[0040] In a second aspect, the present invention provides an attack analysis device for a honeypot based on the connection characteristics of mysqldump. The device includes:
[0041] A first acquisition module, configured to acquire a simulation tool for the MySQL server, where the simulation tool is used to build an environment for simulating the MySQL server;
[0042] A construction module, configured to embed an attack vector in the version information of the simulation tool and construct a honeypot server based on the simulation tool;
[0043] A second acquisition module, configured to, in response to an attacker connecting to the honeypot server through mysqldump, acquire the version information returned by the honeypot server;
[0044] A third acquisition module, configured to acquire multi-dimensional attack behavior data of the attacker based on the returned version information;
[0045] An analysis module, configured to analyze the attack behaviors of the attacker based on the multi-dimensional attack behavior data to obtain an attack analysis result.
[0046] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the attack analysis method based on the mysqldump connection characteristic honeypot according to the first aspect or any corresponding embodiment thereof.
[0047] In a fourth aspect, the present invention provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to perform the attack analysis method based on the mysqldump connection characteristic honeypot according to the first aspect or any corresponding embodiment thereof.
[0048] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, and the computer instructions are used to cause a computer to perform the attack analysis method based on the mysqldump connection characteristic honeypot according to the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.
[0050] Figure 1 is a schematic flowchart of the attack analysis method based on the mysqldump connection characteristic honeypot according to an embodiment of the present invention;
[0051] Figure 2 is a schematic flowchart of another attack analysis method based on the mysqldump connection characteristic honeypot according to an embodiment of the present invention;
[0052] Figure 3 is a structural block diagram of the attack analysis device based on the mysqldump connection characteristic honeypot according to an embodiment of the present invention;
[0053] Figure 4 is a schematic hardware structure diagram of the computer device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0055] In the related art, it is difficult to efficiently collect the behavior data of attackers in the face of network attacks, and the attack analysis results are inaccurate. The present invention embeds attack vectors in the version information of the simulation tool to attract attackers, avoid their attacks on the real system, gain time for defense measures, and obtain multi-dimensional attack behavior data for analysis, which helps to comprehensively and accurately understand the attack behavior of attackers.
[0056] According to an embodiment of the present invention, an embodiment of an attack analysis method based on a mysqldump connection characteristic honeypot is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0057] In this embodiment, an attack analysis method based on a mysqldump connection characteristic honeypot is provided. Figure 1 is a flowchart of an attack analysis method based on a mysqldump connection characteristic honeypot according to an embodiment of the present invention, as Figure 1 shown, the process includes the following steps:
[0058] Step S101, obtain a simulation tool for the MySQL server, where the simulation tool is used to build an environment for simulating the MySQL server. Specifically, use the pip command to install the simulation tool, for example, pip install mysql-mimic. The mysql-mimic library is a tool for simulating the MySQL server in a Python environment. After installation, it can be used to build an environment similar to the real MySQL server. By building a simulation environment, it is to attract attackers and make them think that they are connecting to the real MySQL server, so as to induce attackers to initiate attack behaviors, providing basic conditions for subsequent collection of attack data and analysis of attack means.
[0059] Step S102: Embed an attack vector into the version information of the simulation tool and build a honeypot server based on the simulation tool. Specifically, in an actual network attack scenario, mysqldump is one of the commonly used tools by attackers. Attackers will use mysqldump to connect to and access the MySQL database for data backup, migration, or attempt to obtain sensitive data. When mysqldump connects to the MySQL server, it will actively obtain the version information. Based on this characteristic, making a honeypot using the connection feature of mysqldump can better attract attackers. The honeypot server simulates a real MySQL server. When an attacker uses mysqldump to connect, they will not be suspicious due to abnormal connection methods, thus increasing the success rate of the honeypot in trapping attackers. By embedding the attack vector into the version information, it is possible to rely on the connection feature of mysqldump to ensure that the attack vector is likely to be executed when the attacker uses mysqldump to connect to the honeypot server. If other information that is not obtained or processed by mysqldump during connection is modified, it cannot be guaranteed that the attack vector can be triggered by the attacker, and it will be difficult to mark and counterattack the attack behavior. More specifically, in the variables.py file in the simulation tool (such as the mysql-mimic library), modify the version information (version field) and embed the attack vector, such as touch / tmp / pwn. Embedding the attack vector into the version information is to mark the attack behavior and achieve counterattack. Then, building a honeypot server based on the simulation tool combines the simulation environment with the attack vector to make it a complete trapping system with the ability to interact with attackers and collect data.
[0060] Step S103: In response to the attacker connecting to the honeypot server via mysqldump, obtain the version information returned by the honeypot server. Specifically, when the attacker uses mysqldump -h (honeypot server address) | mysql to connect to the honeypot server, the honeypot server will return a response containing the version information. By obtaining the returned version information, it helps to determine whether the attack vector has been executed and provides support for subsequent collection of attack data.
[0061] Step S104: Based on the returned version information, obtain multi-dimensional attack behavior data of the attacker. Specifically, based on the returned version information, use the multi-dimensional monitoring system deployed by the honeypot server to collect multi-dimensional data of the attacker to comprehensively reflect the attacker's attack behavior, providing a rich and comprehensive information basis for in-depth analysis of the attack behavior, thereby improving the analysis accuracy.
[0062] Step S105: Analyze the attacker's attack behavior based on multi-dimensional attack behavior data to obtain an attack analysis result. Specifically, by applying a variety of analysis methods to process the multi-dimensional attack behavior data, the attacker's attack behavior can be accurately analyzed, which helps to formulate defense measures, improve network defense capabilities, and reduce potential security threats.
[0063] In the present invention, a simulation tool is used to simulate a real MySQL server, and then an attack vector is embedded in the version information of the simulation tool. When the attacker obtains the version information, the attack vector is a key means to implement honeypot counterattack and mark attack behavior. Thus, a honeypot server is constructed based on the simulation tool to attract the attacker and prevent it from attacking the real system, gaining time for defense measures. When the attacker connects to the honeypot server through mysqldump, the attack behavior is captured by obtaining the returned version information, and multi-dimensional attack behavior data is obtained and analyzed, improving the accuracy of attack analysis, helping to comprehensively and accurately understand the attacker's attack behavior, providing strong support for formulating effective defense strategies, effectively reducing the risk of network attacks, and enhancing the overall defense capabilities of network security.
[0064] In this embodiment, an attack analysis method based on a honeypot with mysqldump connection characteristics is provided. Figure 2 It is a flowchart of another attack analysis method based on a honeypot with mysqldump connection characteristics according to an embodiment of the present invention, as Figure 2 shown. This process includes the following steps:
[0065] Step S201: Obtain a simulation tool for the MySQL server, which is used to build an environment for simulating the MySQL server. For details, please refer to Figure 1 Step S101 of the embodiment shown here, which will not be elaborated further.
[0066] Step S202: Embed an attack vector in the version information of the simulation tool and construct a honeypot server based on the simulation tool.
[0067] Specifically, the above-mentioned step S202 of constructing a honeypot server based on the simulation tool includes:
[0068] Step S2021, configure the simulation tool. Specifically, in addition to modifying the version information, the simulation tool can be configured in multiple aspects to enhance the functions and trapping effects of the honeypot server. For example, in terms of network and connection configuration, set port and IP bindings to avoid conflicts with real services and simulate different environments; in authentication and permission configuration, create different users and assign permissions to simulate the real user system and permission vulnerabilities; in log and monitoring configuration, set the log level to record operation information and set monitoring metrics to grasp the status of the honeypot in real time; in response and behavior configuration, plan the query response method and exception handling strategy to simulate the behavior of a real database and respond to attacks. These configurations work together to make the honeypot server more attractive, collect more attack data, and effectively analyze attack behaviors. Optionally, the above configuration process is only an example, and the embodiments of the present invention do not limit this.
[0069] Step S2022, obtain the programming code of the honeypot server. Specifically, taking the mysql-mimic library as an example, the programming code of the honeypot server needs to implement the parsing of the MySQL protocol to handle operations such as connection, authentication, and query. Create a class (such as the MySession class) that inherits from the Session class in the mysql-mimic library and override the query method. In the query method, add code to print information such as the parsed syntax tree, the original SQL statement, query attributes, the current authenticated user, and the currently selected database to analyze the behavior of the attacker. At the same time, return data in the (columns, rows) format specified by the MySQL protocol to ensure normal data interaction. In addition, the programming code can also define a schema method as needed to provide database schema information to support INFORMATION_SCHEMA and SHOW queries. By obtaining the programming code, the honeypot server can effectively simulate the behavior of a real MySQL server and attract attackers to interact with it. At the same time, the information collection and processing functions implemented by the code provide a basis for subsequent attack analysis based on the data collected by the honeypot server.
[0070] Step S2023, build a honeypot server based on the configured simulation tool and programming code. Specifically, integrate the configured mysql-mimic library with the written code. In the if __name__ == "__main__" code block, create an instance of MysqlServer and specify session_factory as the custom MySession class. Finally, use asyncio.run(server.serve_forever()) to start the honeypot server.
[0071] Step S203, in response to the attacker connecting to the honeypot server through mysqldump, obtain the version information returned by the honeypot server. For details, please refer to Figure 1 Step S103 of the embodiment shown, which will not be elaborated here.
[0072] Step S204, based on the returned version information, obtain the multi-dimensional attack behavior data of the attacker.
[0073] Specifically, the above Step S204 includes:
[0074] Step S2041, determine whether there is a detection file in the returned version information. The detection file is used to identify whether the attacker executes the attack vector in the version information of the honeypot server. Specifically, after the honeypot server receives the request from the attacker to connect using mysqldump, it will monitor the version information of the attacker. Taking the example of embedding the touch / tmp / pwn attack vector in the version information before, the honeypot server will check whether the detection file corresponding to this attack vector, that is, the / tmp / pwn file, exists. If it is detected that the file exists, it means that the attacker has executed this attack vector, and at this time, data collection on the attacker's attack behavior can be performed.
[0075] Step S2042, when there is a detection file in the returned version information, obtain the multi-dimensional attack behavior data of the attacker. The honeypot server includes a network traffic probe, a process monitoring module, an interaction interface, and a log management module.
[0076] In some alternative embodiments, the above Step S2042 includes:
[0077] Step a1, when there is a detection file in the returned version information, use the network traffic probe to monitor the network environment of the honeypot server and obtain the first behavior data of the attacker. Specifically, the network traffic probe will capture and analyze all network traffic in the network environment where the honeypot server is located. It will collect the network connection information between the attacker and the honeypot server, including the attacker's IP address, the port number used, the connection timestamp, and the type of transmission protocol. At the same time, it will also record the size of the data packet, the transmission frequency, and the data content, etc. These information constitute the first behavior data of the attacker. By monitoring the network traffic, the network interaction situation between the attacker and the honeypot server can be understood.
[0078] Step a2: Use a process monitoring module to monitor the processes of the honeypot server and obtain the second behavior data of the attacker. Specifically, the process monitoring module will monitor all the processes running on the honeypot server in real time, record the new processes started by the attacker on the honeypot server, including the process name, startup parameters, parent process information of the process, etc. At the same time, it will also monitor the usage of system resources by the processes, such as CPU usage rate, memory occupancy rate, etc., and the interaction between the processes and the file system, such as the files and directories accessed by the processes. These data constitute the second behavior data of the attacker. By monitoring the processes, the specific operation behaviors of the attacker inside the honeypot can be understood.
[0079] Step a3: Use an interaction interface to monitor the interaction process between the honeypot server and the attacker's attack tool and obtain the third behavior data of the attacker. Specifically, the interaction interface will monitor the interaction process between the honeypot server and the attack tool used by the attacker in detail, record information such as SQL query statements sent by the attacker, executed system commands, various requests sent to the honeypot server, etc. At the same time, it will also record the response situation of the honeypot server to these requests. These interaction information constitute the third behavior data of the attacker. By monitoring the interaction process, the interaction behavior between the attacker and the honeypot server can be understood.
[0080] Step a4: Use a log management module to parse the logs of the honeypot server and obtain the fourth behavior data of the attacker. Specifically, the log management module will parse various types of log files generated by the honeypot server. These logs include system logs, access logs, application logs, etc. By parsing the logs, information related to the attacker is extracted, such as the attacker's login attempts (success or failure), modification operations on system configuration files, timestamps of key operations executed, etc. The information extracted from these logs is used as the fourth behavior data of the attacker. By parsing the logs, the operation records of the attacker can be obtained.
[0081] Step a5: Use the first behavior data, the second behavior data, the third behavior data, and the fourth behavior data as the multi-dimensional attack behavior data of the attacker. Specifically, integrate the behavior data obtained in the previous four steps to form the multi-dimensional attack behavior data of the attacker. The single-dimensional data in the related technologies cannot comprehensively reflect the attack behavior of the attacker. By integrating multi-dimensional data, it provides a rich and comprehensive information basis for subsequent in-depth analysis of attack behaviors and formulation of effective defense strategies.
[0082] Step S205: Analyze the attack behavior of the attacker based on the multi-dimensional attack behavior data to obtain an attack analysis result.
[0083] Specifically, the above step S205 includes:
[0084] Step S2051, based on the multi-dimensional attack behavior data, behavior mapping is performed to construct an attacker's attack behavior map. Specifically, the ATT&CK framework (Adversarial Tactics, Techniques, and Common Knowledge) is used to sort and classify the multi-dimensional attack behavior data, and data from different sources and types are associated. Then, according to the sequence and logical relationship of the attack behavior, these associated data are mapped into a graph structure. The nodes in the graph structure represent different attack behaviors, system components or attack tools, and the edges represent the associations between them, such as causal relationships, time sequence relationships, etc. By constructing an attacker's attack behavior map, the entire process of the attack and the connection between each link are intuitively displayed.
[0085] Step S2052, using a binary reverse tool, parse and deduce based on the multi-dimensional attack behavior data to obtain the working conditions of the attack tools used by the attacker. Specifically, extract binary files or code snippets related to the attack tools from the multi-dimensional attack behavior data. Use binary reverse tools (such as IDAPro, Ghidra, etc.) to disassemble, decompile and analyze these binary data. Through reverse engineering technology, parse the code structure, function call relationship, data processing flow, etc. of the attack tool, and deduce the working conditions of the attack tool, such as the working principle, functional characteristics, and possible vulnerability exploitation methods.
[0086] Step S2053, using time series analysis and logical association algorithm, analyze based on multi-dimensional attack behavior data to obtain the attacker's attack behavior chain. Specifically, the time series analysis method is used to process and analyze the timestamp information in the multi-dimensional attack behavior data. Arrange the attack behaviors in chronological order to find out the time intervals and sequence between the attack behaviors. At the same time, use the logical association algorithm to analyze the logical relationship between different attack behaviors. By combining time series analysis and logical association, the attacker's attack behavior chain can be sorted out, and the attacker's attack steps and strategies can be understood, providing a basis for formulating defense measures.
[0087] Step S2054: Use the YARA rule engine to perform rule matching based on multi-dimensional attack behavior data to obtain the attack situation of the attacker. Specifically, according to known attack characteristics and common attack patterns, write YARA rules. Then, use the YARA rule engine to scan and match the multi-dimensional attack behavior data. When a certain part of the data matches the characteristics in the YARA rules, it is considered that the data is related to a known attack type. By statistically analyzing the matching results, understand the attack situation used by the attacker, such as attack techniques, attack targets, and attack frequencies. By statistically analyzing the attack situation, it helps to adjust defense measures and improve network security.
[0088] Step S2055: Use a time series prediction model to perform predictions based on multi-dimensional attack behavior data to obtain the predicted attack results of the attacker. Specifically, use a time series prediction model, such as Long Short-Term Memory (LSTM), AutoRegressive Integrated Moving Average (ARIMA), etc. Take the time series information in the multi-dimensional attack behavior data as input and train the model. During the training process, the model learns the changing rules and patterns of attack behavior over time. After training, use the trained model to predict the future attack behavior of the attacker to obtain predicted attack results, including attack time, attack type, attack target, etc. By predicting the future attack behavior of the attacker, it helps to make early defense preparations, adopt proactive defense strategies, and improve network security.
[0089] Step S2056: Take the attack behavior graph, the working conditions of attack tools, the attack behavior chain, the attack situation, and the predicted attack results as the attack analysis results. Specifically, integrate the analysis results of the previous five steps to form the attack analysis results of the attacker and achieve in-depth analysis of the attacker's attack behavior.
[0090] In some alternative embodiments, if no detection file corresponding to the attack vector is detected, it indicates that the attacker has not executed the attack vector embedded in the version information, and continue the detection.
[0091] Step S206: Adjust the defense measures based on the attacker's attack behavior. Specifically, according to the analysis of the attacker's attack behavior in step S205, the key nodes and paths can be identified from the attack behavior graph, and the protection can be strengthened and the attack chain can be cut off; according to the working conditions of the attack tools, the detection rules can be updated, the vulnerabilities can be repaired, and the protection can be fortified; according to the attack behavior chain, an early warning mechanism and a blocking strategy can be established; for the attack situation, the rules can be optimized and the emergency response process can be improved; based on the predicted attack results, the resource allocation can be optimized and an active defense strategy can be formulated, so as to improve the network security protection ability. Optionally, the adjustment process of the above defense measures is only an example, and the embodiments of the present invention do not limit this.
[0092] The present invention obtains a simulation tool to simulate a real MySQL server, and then embeds an attack vector in the version information of the simulation tool. When the attacker obtains the version information, the attack vector is a key means to implement honeypot counterattack and mark attack behavior. Thus, a honeypot server is constructed based on the simulation tool to attract the attacker and prevent it from attacking the real system, gaining time for the defense measures. When the attacker connects to the honeypot server through mysqldump, the attack behavior is captured by obtaining the returned version information, and multi-dimensional attack behavior data is obtained and analyzed, improving the accuracy of attack analysis, helping to comprehensively and accurately understand the attacker's attack behavior, providing strong support for formulating effective defense strategies, effectively reducing the risk of network attacks, and enhancing the overall defense ability of network security.
[0093] In this embodiment, an attack analysis device based on the connection characteristics of mysqldump to the honeypot is also provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0094] This embodiment provides an attack analysis device based on the connection characteristics of mysqldump to the honeypot, as Figure 3 shown, including:
[0095] A first acquisition module 301, configured to acquire a simulation tool for the MySQL server, where the simulation tool is used to build an environment for simulating the MySQL server.
[0096] A construction module 302, configured to embed an attack vector in the version information of the simulation tool and build a honeypot server based on the simulation tool.
[0097] A second acquisition module 303, configured to obtain the version information returned by the honeypot server in response to the attacker connecting to the honeypot server through mysqldump.
[0098] A third acquisition module 304, configured to acquire multi-dimensional attack behavior data of an attacker based on the returned version information.
[0099] An analysis module 305, configured to analyze the attack behavior of the attacker based on the multi-dimensional attack behavior data to obtain an attack analysis result.
[0100] In some alternative embodiments, the third acquisition module 304 includes:
[0101] A judgment unit, configured to judge whether there is a detection file in the returned version information, where the detection file is used to identify whether the attacker executes the attack vector in the version information of the honeypot server.
[0102] An acquisition unit, configured to acquire the multi-dimensional attack behavior data of the attacker when there is a detection file in the returned version information.
[0103] In some alternative embodiments, the honeypot server includes a network traffic probe, a process monitoring module, an interaction interface, and a log management module;
[0104] The acquisition unit includes:
[0105] A first acquisition subunit, configured to monitor the network environment of the honeypot server by using the network traffic probe to acquire first behavior data of the attacker when there is a detection file in the returned version information.
[0106] A second acquisition subunit, configured to monitor the processes of the honeypot server by using the process monitoring module to acquire second behavior data of the attacker.
[0107] A third acquisition subunit, configured to monitor the interaction process between the honeypot server and the attack tool of the attacker by using the interaction interface to acquire third behavior data of the attacker.
[0108] A fourth acquisition subunit, configured to parse the logs of the honeypot server by using the log management module to acquire fourth behavior data of the attacker.
[0109] A fifth acquisition subunit, configured to use the first behavior data, the second behavior data, the third behavior data, and the fourth behavior data as the multi-dimensional attack behavior data of the attacker.
[0110] In some alternative embodiments, the analysis module 305 includes:
[0111] A first construction unit, configured to perform behavior mapping based on the multi-dimensional attack behavior data to construct an attack behavior graph of the attacker.
[0112] A parsing unit, which is used to parse and deduce based on multi-dimensional attack behavior data by using a binary reverse tool, so as to obtain the working conditions of the attack tools adopted by the attacker.
[0113] An analysis unit, which is used to analyze based on multi-dimensional attack behavior data by using time series analysis and logical association algorithms, so as to obtain the attack behavior chain of the attacker.
[0114] A matching unit, which is used to perform rule matching based on multi-dimensional attack behavior data by using a YARA rule engine, so as to obtain the attack situation of the attacker.
[0115] A prediction unit, which is used to perform prediction based on multi-dimensional attack behavior data by using a time series prediction model, so as to obtain the predicted attack result of the attacker.
[0116] A determination unit, which is used to use the attack behavior graph, the working conditions of the attack tools, the attack behavior chain, the attack situation, and the predicted attack result as the attack analysis result.
[0117] In some alternative embodiments, the construction module 302 includes:
[0118] A configuration unit, which is used to configure simulation tools.
[0119] A writing unit, which is used to obtain the writing code of the honeypot server.
[0120] A second construction unit, which is used to construct a honeypot server based on the configured simulation tools and the writing code.
[0121] In some alternative embodiments, the device further includes:
[0122] An adjustment module, which is used to adjust defense measures based on the attack behavior of the attacker.
[0123] The further function descriptions of the above-mentioned various modules and units are the same as those in the corresponding above-mentioned embodiments, and will not be elaborated here.
[0124] The attack analysis device based on the mysqldump connection characteristic honeypot in this embodiment is presented in the form of functional units. Here, the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and a memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0125] This embodiment of the present invention also provides a computer device having the above Figure 3 shown attack analysis device based on the mysqldump connection characteristic honeypot.
[0126] Please refer toFigure 4 , Figure 4 is a schematic structural diagram of a computer device provided by an alternative embodiment of the present invention. As shown in Figure 4 , the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including a high-speed interface and a low-speed interface. Each component communicates with each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some alternative embodiments, if needed, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (such as an array of servers, a set of blade servers, or a multi-processor system). Figure 4 In
[0127] FIG.
[0128] The processor 10 may be a central processing unit, a network processor, or a combination thereof. Among them, the processor 10 may further include a hardware chip. The above hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The above programmable logic device may be a complex programmable logic device, a field programmable gate array, a generic array logic, or any combination thereof.
[0129] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiments.
[0130] The memory 20 may include a storage program area and a storage data area. Among them, the storage program area may store an operating system and application programs required for at least one function; the storage data area may store data created according to the use of the computer device. In addition, the memory 20 may include a high-speed random access memory and may further include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some alternative embodiments, the memory 20 may optionally include a memory remotely provided with respect to the processor 10, and these remote memories may be connected to the computer device through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0131] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0132] An embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code that is originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.
[0133] A part of the present invention can be applied as a computer program product, such as computer program instructions, which when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should be able to understand that the forms of existence of computer program instructions in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Herein, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.
[0134] Although the embodiments of the present invention are described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. An attack analysis method based on the connection characteristics of mysqldump honeypot, characterized in that The method includes: Obtaining a simulation tool for the MySQL server, where the simulation tool is used to build an environment for simulating the MySQL server; Embedding an attack vector in the version information of the simulation tool, and building a honeypot server based on the simulation tool; In response to an attacker connecting to the honeypot server through mysqldump, obtaining the version information returned by the honeypot server; Based on the returned version information, obtaining multi-dimensional attack behavior data of the attacker; Based on the multi-dimensional attack behavior data, analyzing the attack behavior of the attacker to obtain an attack analysis result.
2. The method according to claim 1, characterized in that, The obtaining of the multi-dimensional attack behavior data of the attacker based on the returned version information includes: Judging whether there is a detection file in the returned version information, where the detection file is used to identify whether the attacker executes the attack vector in the version information of the honeypot server; When the detection file exists in the returned version information, obtaining the multi-dimensional attack behavior data of the attacker.
3. The method according to claim 2, wherein The honeypot server includes a network traffic probe, a process monitoring module, an interaction interface, and a log management module; The obtaining of the multi-dimensional attack behavior data of the attacker when the detection file exists in the returned version information includes: When the detection file exists in the returned version information, using the network traffic probe to monitor the network environment of the honeypot server to obtain the first behavior data of the attacker; Using the process monitoring module to monitor the processes of the honeypot server to obtain the second behavior data of the attacker; Using the interaction interface to monitor the interaction process between the honeypot server and the attacker's attack tool to obtain the third behavior data of the attacker; Using the log management module to parse the logs of the honeypot server to obtain the fourth behavior data of the attacker; Taking the first behavior data, the second behavior data, the third behavior data, and the fourth behavior data as the multi-dimensional attack behavior data of the attacker.
4. The method according to claim 1, characterized in that, The analyzing of the attack behavior of the attacker based on the multi-dimensional attack behavior data to obtain an attack analysis result includes: Performing behavior mapping based on the multi-dimensional attack behavior data to build an attack behavior graph of the attacker; Using a binary reverse engineering tool to parse and deduce based on the multi-dimensional attack behavior data to obtain the working conditions of the attack tool used by the attacker; Using a time series analysis and logical association algorithm to analyze based on the multi-dimensional attack behavior data to obtain the attack behavior chain of the attacker; Using a YARA rule engine to perform rule matching based on the multi-dimensional attack behavior data to obtain the attack situation of the attacker; Using a time series prediction model to perform prediction based on the multi-dimensional attack behavior data to obtain the predicted attack result of the attacker; Taking the attack behavior graph, the working conditions of the attack tool, the attack behavior chain, the attack situation, and the predicted attack result as the attack analysis result.
5. The method according to claim 1, characterized in that Constructing a honeypot server based on the simulation tool includes: Configuring the simulation tool; Obtaining the coding of the honeypot server; Constructing the honeypot server based on the configured simulation tool and the coding.
6. The method according to claim 4, wherein The method further includes: Adjusting defense measures based on the attack behavior of the attacker.
7. An attack analysis device based on the connection characteristics of mysqldump honeypot, characterized in that, The device includes: A first obtaining module, configured to obtain a simulation tool for a MySQL server, where the simulation tool is used to build an environment for simulating a MySQL server; A constructing module, configured to embed an attack vector in the version information of the simulation tool and construct a honeypot server based on the simulation tool; A second obtaining module, configured to obtain the version information returned by the honeypot server in response to an attacker connecting to the honeypot server through mysqldump; A third obtaining module, configured to obtain multi-dimensional attack behavior data of the attacker based on the returned version information; An analyzing module, configured to analyze the attack behavior of the attacker based on the multi-dimensional attack behavior data to obtain an attack analysis result.
8. A computer device, characterized in that, Including: A memory and a processor, where the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the attack analysis method of the honeypot based on the mysqldump connection characteristic according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, Computer instructions are stored on the computer-readable storage medium, and the computer instructions are used to cause a computer to execute the attack analysis method of the honeypot based on the mysqldump connection characteristic according to any one of claims 1 to 6.
10. A computer program product, characterized in that, Including computer instructions, and the computer instructions are used to cause a computer to execute the attack analysis method of the honeypot based on the mysqldump connection characteristic according to any one of claims 1 to 6.