Network security defense method, system, equipment and medium

By evaluating the defense value and traffic data of network nodes, dynamically selecting honeypot deployment points, solving the problem of unreasonable honeypot deployment in the existing technology, and achieving resource optimization and attack recognition effects of network security defense.

CN120342745APending Publication Date: 2025-07-18CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510645681.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the existing network security defense technology, honeypot deployment strategy fails to fully consider the dynamic differences and risk distribution characteristics of network nodes, resulting in resource waste and defense blind spots coexisting, and the attack recognition effect is poor.

Method used

By obtaining the network topology structure, evaluating the defense value and traffic data of network nodes, calculating the honeypot deployment probability, dynamically selecting key nodes to deploy honeypots, and using honeypots for active defense.

Benefits of technology

Under the constraints of limited resources, optimizing honeypot deployment strategies has improved the execution efficiency of network security defense, reduced resource requirements, and improved attack recognition effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342745A_ABST
    Figure CN120342745A_ABST
Patent Text Reader

Abstract

The invention provides a network security defense method and system, electronic equipment and a storage medium to solve the problems that a network security defense mode is passive and the attack recognition effect is poor, and the method comprises the steps of obtaining a network topology structure; determining a point attribute value of the network node according to the defense value of the network node for the network, and determining an edge attribute value of each edge related to the network node in the topological structure according to the flow data related to the network node; according to the point attribute value of the network node and the edge attribute value of each edge related to the network node, calculating the selection probability of each network node as the network node of the honeypot to be deployed, and determining the network node of the honeypot to be deployed according to the selection probability of each network node; deploying the honeypot for the determined network node of the to-be-deployed honeypot; and performing security defense on the network based on the honeypot. The key nodes in the network can be selected to deploy the honeypot, the defense effect is ensured, the execution efficiency is improved, and the resource demand is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technologies, and in particular, to a network security defense method, a network security defense system, an electronic device, and a computer-readable storage medium. Background Art

[0002] With the rapid development of Internet technologies, the network has been applied to various scenarios. With the complexity and scale of network attack means, traditional network security defense technologies, such as using antivirus software to defend against attacks, gradually expose problems such as low resource utilization rate and obvious defense lag. In the prior art, as an active defense means, honeypots usually adopt a uniform deployment or a deployment strategy based on fixed rules. However, such methods fail to fully consider the dynamic differences and risk distribution characteristics of network nodes, resulting in coexistence of resource waste and defense blind spots. In addition, most of the existing node importance evaluations adopt a single index (such as connectivity or data sensitivity), lacking a multi-dimensional comprehensive modeling of the whole, resulting in poor attack recognition effect.

[0003] Under this background, there is an urgent need for a dynamic and intelligent defense solution to maximize the overall network security efficiency under the constraint of limited resources. Summary of the Invention

[0004] In order to at least solve the problems in the prior art that the network security defense method is relatively passive and the attack recognition effect is poor. The present disclosure provides a network security defense method, a network security defense system, an electronic device, and a computer-readable storage medium. By evaluating the importance of each node in the network based on the defense value and traffic data of the network of each node in the network, and based on the importance, key nodes in the network are selected to deploy honeypots, which improves the execution efficiency of the network security defense solution while ensuring the defense effect and reduces the resource requirements.

[0005] In a first aspect, the present disclosure provides a network security defense method, the method comprising:

[0006] Obtain a network topology structure;

[0007] Determine the point attribute value of a network node according to the defense value of the network node for the network, and determine the edge attribute value of each edge related to the network node in the topology structure according to the traffic data related to the network node;

[0008] Calculate the selection probability of each network node as a network node to which a honeypot is to be deployed according to the point attribute value of the network node and the edge attribute values of the respective edges related thereto, and determine the network nodes to which the honeypot is to be deployed according to the selection probability of each network node;

[0009] Deploy a honeypot for the determined network nodes to which the honeypot is to be deployed;

[0010] Perform security defense on the network based on honeypots.

[0011] Furthermore, determining the point attribute value of a network node according to the defense value of the network node for the network includes:

[0012] Determine the device type corresponding to the network node, and determine the attack probability value of the network node according to the device type;

[0013] Determine the security value corresponding to the network node according to the environment where the network node is located and the data stored;

[0014] Determine the risk value corresponding to the network node;

[0015] Determine the point attribute value of the network node according to the following formula:

[0016]

[0017] where AN i is the point attribute value of network node i, P i is the attack probability value of network node i, A i is the security value of network node i, Risk i is the risk value of network node i.

[0018] Furthermore, determining the risk value corresponding to the network node includes:

[0019] Obtain the traffic data, performance data, and attack data of network node i;

[0020] Determine the risk value of network node i according to the obtained data and the following formula;

[0021]

[0022] where is the total amount of abnormal traffic data in the traffic data of network node i, Flow i is the total amount of traffic data of network node i, is the total amount of data in the performance data of network node i that is higher than the highest performance security threshold, Fun i is the total amount of performance data of network node i, Att i is the number of times network node i is attacked within a preset time period.

[0023] Furthermore, determining the edge attribute value of each edge related to the network node in the topological structure according to the traffic data related to the network node includes:

[0024] Obtain the traffic data between network node i and the related node j connected by its edge within a preset time period, where j is the point identifier directly connected to network node i;

[0025] Among all the traffic data at point i, determine the ratio of the data volume with the destination IP being the IP of point j to the total data volume The ratio of the data volume with the source IP being the IP of point j to the total data volume

[0026] Among all the traffic data at point j, determine the ratio of the data volume with the destination IP being the IP of point i to the total data volume The ratio of the data volume with the source IP being the IP of point i to the total data volume

[0027] Determine the edge attribute value AL of the direct edge between network node i and node j according to the following formula ij :

[0028]

[0029] Furthermore, calculating the selection probability of each network node as the network node for deploying the honeypot according to the point attribute value of the network node and the edge attribute values of each related edge includes:

[0030] Calculate the selection probability of the network node as the network node for deploying the honeypot according to the following formula:

[0031]

[0032] where, PSe i is the selection probability of network node i, NN i is the degree of network node i, that is, the number of other nodes directly connected to network node i, NN j is the degree of node j, and NN is the maximum degree of nodes in the topological structure.

[0033] Furthermore, determining the network nodes for deploying the honeypot according to the selection probability of each network node includes:

[0034] Arrange the selection probabilities of each node from large to small in sequence, and use the top N nodes with the sorted selection probabilities as the network nodes for this deployment of the honeypot;

[0035] where,

[0036] N ALL is the total number of nodes in the network nodes, is the normalized average value of the performance data of each node obtained within the preset time period, is the total amount of abnormal traffic data in the traffic data of network node i obtained, Flow i is the total amount of traffic data of network node i obtained.

[0037] Further, deploying honeypots on the network nodes of the to-be-deployed honeypots determined includes:

[0038] Deploy a honeypot for each selected node, obtain the image of its corresponding node through the honeypot, and for any node i, its corresponding honeypot i has the same attributes as the device corresponding to node i. During the operation of device i, honeypot i obtains all the data of device i in an image manner;

[0039] Use the image obtained through the honeypot of its corresponding node as a decoy node for network decoying.

[0040] Further, the network security defense based on honeypots includes:

[0041] Obtain all the features in the feature library, including:

[0042] Obtain the attack logs of each node, and determine the features of each attack based on the attack logs of each node;

[0043] Obtain the features of each attack released by the security department;

[0044] Use the features obtained by combining the features of each attack determined from the attack logs and the features of each attack released by the security department as the final feature library;

[0045] Reorganize the features in the feature library to obtain different combinations, where x is the total number of features in the feature library and y is the number of features selected each time;

[0046] Compare the data obtained by each honeypot with all the groups of features obtained by reorganization. If similar features are found, it is considered that the device corresponding to the honeypot is under attack, and perform preset measures.

[0047] Further, the method further includes:

[0048] Obtain the traffic data and performance data of each node within a preset time period at preset intervals;

[0049] Update the point attribute values and edge attribute values in the topological structure according to the newly obtained data, and re-determine the network nodes of the to-be-deployed honeypots.

[0050] In a second aspect, the present disclosure provides a network security defense system, and the system includes:

[0051] An acquisition module configured to acquire a network topological structure;

[0052] A determination module, configured to determine the point attribute value of a network node according to the defense value of the network node for the network, and determine the edge attribute value of each edge associated with the network node in the topological structure according to the traffic data associated with the network node;

[0053] A selection module, configured to calculate the selection probability of each network node as a network node for deploying a honeypot according to the point attribute value of the network node and the edge attribute values of the edges associated therewith, and determine the network nodes for deploying the honeypot according to the selection probability of each network node;

[0054] A deployment module, configured to deploy a honeypot for the determined network nodes for deploying the honeypot;

[0055] A defense module, configured to perform security defense on the network based on the honeypot.

[0056] In a third aspect, the present disclosure provides an electronic device, including a memory and a processor, where a computer program is stored in the memory, and when the processor runs the computer program stored in the memory, the processor executes the network security defense method according to any one of the first aspects.

[0057] In a fourth aspect, the present disclosure provides a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the network security defense method according to any one of the first aspects is implemented.

[0058] Advantageous effects:

[0059] The network security defense method, network security defense system, electronic device and storage medium provided by the present disclosure; characterize the defense value of a node for the network through network point attributes, and the edge attributes characterize the interaction of the two devices corresponding to the edge in the data stream, determine the value of the edge for the network, and then calculate the selection probability of each network node as a network node for deploying a honeypot according to the point attribute value of the network node and the edge attribute values of the edges associated therewith. Through this selection probability, key nodes in the network can be selected to deploy honeypots, optimize the honeypot deployment strategy by accurately quantifying the node defense value, and maximize the overall network security efficiency under limited resource constraints; while ensuring the defense effect, improve the execution effect of the network security defense solution and reduce resource requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 It is a schematic flowchart of a network security defense method provided by Embodiment 1 of the present disclosure;

[0061] Figure 2 It is a schematic diagram of a network topology provided by an embodiment of the present disclosure;

[0062] Figure 3It is an architecture diagram of a network security defense system provided in the second embodiment of the present disclosure;

[0063] Figure 4 It is an architecture diagram of an electronic device provided in the third embodiment of the present disclosure. Detailed implementation manners

[0064] To enable those skilled in the art to better understand the technical solutions of the present disclosure, the present disclosure will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments and drawings described herein are only for explaining the present invention, rather than limiting the present invention.

[0065] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence; moreover, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other arbitrarily.

[0066] Among them, the terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and are not intended to limit the present disclosure. The singular forms "a", "the", and "said" used in the embodiments of the present disclosure and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0067] In subsequent descriptions, the suffixes such as "module", "component", or "unit" used to represent elements are only for the convenience of explaining the present disclosure, and have no specific meaning in themselves. Therefore, "module", "component", or "unit" can be used interchangeably.

[0068] The technical solutions of the present disclosure and how the technical solutions of the present disclosure solve the technical problems existing in the prior art will be described in detail below with specific embodiments. It can be understood that in the embodiments of the present application, the execution subject can execute some or all of the steps in the embodiments of the present application. These steps or operations are only examples, and the embodiments of the present application can also execute other operations or various deformations of the operations. In addition, the various steps can be executed in different orders presented in the embodiments of the present application, and it is possible not to execute all the operations in the embodiments of the present application. Moreover, the following several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0069] Figure 1 It is a flowchart of a network security defense method provided in the first embodiment of the present disclosure, as Figure 1 shown, the method includes:

[0070] Step S101: Obtain a network topology structure;

[0071] Step S102: Determine the point attribute value of the network node according to the defense value of the network node for the network, and determine the edge attribute value of each edge related to the network node in the topological structure according to the traffic data related to the network node;

[0072] Step S103: Calculate the selection probability of each network node as the network node where the honeypot is to be deployed according to the point attribute value of the network node and the edge attribute values of each edge related to it, and determine the network node where the honeypot is to be deployed according to the selection probability of each network node;

[0073] Step S104: Deploy a honeypot to the determined network node where the honeypot is to be deployed;

[0074] Step S105: Perform security defense on the network based on the honeypot.

[0075] The purpose of the embodiments of the present disclosure is a dynamic honeypot deployment method based on network topology and traffic characteristics. Through intelligent network node (abbreviated as node) evaluation and probabilistic deployment strategies, accurate placement of active defense resources and effective induction of attacker behavior are achieved. Network nodes, connection relationships, and traffic data are collected in real time through traffic probes and topology scanning tools. Quantitative analysis is carried out by combining node defense value (such as business criticality, risk level, security level, probability of being attacked, etc.) and edge characteristics (traffic abnormality, path importance). Through node defense value evaluation, calculate the selection probability of each network node as the network node where the honeypot is to be deployed, give priority to protecting network nodes in urgent need of protection such as business critical nodes (such as database servers) and highly vulnerable nodes, and realize the transformation from passive protection to attacker induction through the honeypot, and discover hidden threats in advance.

[0076] In the embodiments of the present disclosure, honeypots are not deployed to all nodes in the network because some nodes have a low risk, and deploying honeypots to them is a waste of honeypot resources. Therefore, honeypots are only deployed to important nodes.

[0077] First, it is necessary to determine the network nodes where the honeypots are to be deployed, including:

[0078] 1. Obtain the network topology structure

[0079] The network topology structure represents the connection relationship between network nodes, which is composed of points and edges.

[0080] Each device in the network is a point in the network topology graph. If communication can be carried out between two points, then a line is connected between the corresponding points of the two points in the network topology graph. For example Figure 1 A network topology graph shown in. The points in the topology graph have point attribute values, and the edges have edge attribute values.

[0081] Determine the point attribute value of a network node according to the defense value of the network node for the network, and determine the edge attribute values of each edge related to the network node in the topology according to the traffic data related to the network node; the point attribute characterizes the defense value of the node for the network, and the edge attribute characterizes the value of the edge for the network. The greater the value, the greater the possibility of being attacked.

[0082] The defense value of a network node for the network can be comprehensively considered through the business characteristics of the node device (based on the criticality of the carried service), vulnerability (its own security performance), degree centrality, probability of being attacked, etc. The edge attribute is comprehensively considered through the traffic characteristics, anomaly index, risk propagation coefficient, etc. on this edge. The point attribute value and the edge attribute value can be calculated according to the corresponding evaluation rules set according to the actual situation.

[0083] After determining the point attribute value and the edge attribute values of each edge related to it, the selection probability of each network node as a network node for deploying a honeypot can be calculated through a weight calculation formula. The greater the point attribute value (the greater the value), the greater the possibility of being attacked. The greater the edge attribute value, the greater the data interaction volume, which is also not safe and requires key attention.

[0084] Determine the network nodes for deploying honeypots according to the selection probability, deploy honeypots for these network nodes, and based on the security defense of the honeypots, actively lure attackers, collect threat intelligence, and protect real assets, shifting from passive protection to active entrapment, while reducing resource consumption, significantly delaying attackers, and protecting key assets.

[0085] In the embodiments of the present disclosure, the network point attribute characterizes the defense value of the node for the network, and the edge attribute characterizes the interaction situation of the two devices corresponding to the edge in the data stream, determining the value of the edge for the network. Then, according to the point attribute value of the network node and the edge attribute values of each edge related to it, calculate the selection probability of each network node as a network node for deploying a honeypot. Through this selection probability, key nodes in the network can be selected to deploy honeypots, optimize the honeypot deployment strategy by accurately quantifying the node defense value, and maximize the overall network security efficiency under the constraint of limited resources; while ensuring the defense effect, improve the execution effect of the network security defense solution and reduce resource requirements.

[0086] Further, the determining the point attribute value of the network node according to the defense value of the network node for the network includes:

[0087] Determine the device type corresponding to the network node, and determine the attack probability value of the network node according to the device type;

[0088] According to the environment where the network node is located and the data storage situation, determine the security value corresponding to the network node;

[0089] Determine the risk value corresponding to the network node;

[0090] Determine the point attribute value of the network node according to the following formula:

[0091]

[0092] where, AN i is the point attribute value of network node i, P i is the attack probability value of network node i, A i is the security value of network node i, Risk i is the risk value of network node i.

[0093] The process of determining the point attribute value of the network node includes:

[0094] (1) Determine the device type corresponding to the point, such as terminal, server, switch, etc. The type information is determined during device deployment.

[0095] (2) Determine the attack probability value of the device type corresponding to the point.

[0096] The attack probabilities of different types of devices are different. For example, if the device is a server and it stores a large amount of useful information, it is more likely to be attacked. Therefore, users will, based on experience values, or through big data analysis solutions, analyze a large number of historical attack situations as samples to obtain the attack probabilities of various types and store them as the relationship between device types and attack probabilities. Thus, the attack probability corresponding to each point device type can be obtained.

[0097] (3) Determine the security value of the device corresponding to the point

[0098] When the device is deployed, according to its location environment, such as internal network, external network, etc., and the data it will store, such as only used to store encrypted data, etc., a security value will be determined for the device. This security value is determined as the security value of the node. The more a device itself requires a secure environment, the higher its security value.

[0099] (4) Determine the risk value corresponding to the point

[0100] This value characterizes the network situation of the point within a certain period of time. By obtaining the traffic data, performance data, and attack data of the node and analyzing these data, the risk value of the network node can be obtained; if the abnormal traffic data increases, the performance data is larger, and the number of attacks received is more, it indicates that the risk value of this node is higher.

[0101] (5) Determine the point attribute of node i

[0102] where, P i is the attack probability value of node i, Ai is the security value of node i.

[0103] The node attribute characterizes the security condition of the device corresponding to the node. The larger the node attribute value, the less secure it is.

[0104] By calculating each index layer by layer, such as the attack probability, security value, and dynamic risk value, the limitations of a single index are avoided. By integrating the inherent attributes of the device (type, security value) and real-time status (traffic, performance, number of attacks), the node attribute value of the node is determined, which can reflect the current security status of the node in real time and better reflect the defense value of the node to the network.

[0105] Furthermore, the determination of the risk value corresponding to the network node includes:

[0106] Obtain the traffic data, performance data, and attack data of network node i;

[0107] Determine the risk value of network node i according to the obtained data and the following formula;

[0108]

[0109] where is the total amount of abnormal traffic data in the traffic data of network node i, Flow i is the total amount of traffic data of network node i, is the total amount of data in the performance data of network node i that is higher than the highest performance security threshold, Fun i is the total amount of performance data of network node i, Att i is the number of times network node i is attacked within a preset time period, and the preset time period can be set according to the actual situation, such as one month or half a year, etc.

[0110] Taking any node i as an example, the process of determining its risk value is as follows:

[0111] a. Obtain the traffic data, performance data, and attack data of node i

[0112] Among them, the traffic data is the traffic data in the recent period of time. In specific implementation, it can be refined into bandwidth data, uplink traffic data, downlink traffic data, etc. for the convenience of description in this step, it is collectively referred to as traffic data.

[0113] The performance data is the device performance data of node i in the recent period of time. In specific implementation, it can be refined into CPU (Central Processing Unit) occupancy rate, memory occupancy rate, etc. for the convenience of description in this step, it is collectively referred to as performance data.

[0114] The attack data is the attack situation that node i has suffered in a recent period of time, which can be obtained from the attack log.

[0115] b. Determine the risk value of node i:

[0116]

[0117] Or, confirm it through the following formula:

[0118] To smooth the impact of the number of attacks.

[0119] The more abnormal node i is, the larger the part in its risk calculation formula, and then the smaller it is, and the larger the result of the entire risk value calculation formula.

[0120] The more times node i is attacked, the larger the value of max(Att i ,1). When the degree of traffic and performance anomalies is fixed, the result of the risk value calculation formula will also be larger, indicating an increase in risk.

[0121] In summary, when the number of attacks on node i increases and the degree of anomalies in its traffic and performance data increases, its risk value Risk i will increase accordingly.

[0122] By comprehensively considering traffic, performance, and attack data, and comprehensively considering the risk value of the node, the evaluation is made more comprehensive, avoiding the one-sidedness of a single indicator, and covering the common dimensions of threat detection (abnormal traffic, resource abuse, attack frequency). By integrating multi-dimensional data, it is suitable for quickly evaluating the abnormal state of the node, with lightweight calculation. And it can truly reflect the security risk status of the node.

[0123] Furthermore, the determination of the edge attribute values of each edge related to the network node in the topological structure according to the traffic data related to the network node includes:

[0124] Obtain the traffic data within a preset time period between network node i and its directly connected related node j, where j is the point identifier directly connected to network node i;

[0125] Among all the traffic data at point i, determine the ratio of the data volume with the destination IP being the IP of point j to the total data volume The ratio of the data volume with the source IP being the IP of point j to the total data volume

[0126] Among all the traffic data at point j, determine the ratio of the data volume with the destination IP being the IP of point i to the total data volume The ratio of the data volume with the source IP being the IP of point i to the total data volume

[0127] Determine the edge attribute value AL of the direct edge between network node i and node j according to the following formula ij :

[0128]

[0129] The calculation process of the edge attribute value includes:

[0130] Obtain the traffic data of the two points (such as point i and point j) connected by the edge in the preset time period (in the recent period, such as one month or half a year, etc.); generally, the data traffic log is large, and in this step, the traffic log within a period of time can be obtained, and the full volume log is not required.

[0131] By counting the source / destination IP ratio in the traffic log, through Determine the frequency of point i actively sending data to point j, which may map data leakage or attack behavior; Reflect the proportion of data received by point j from point i, which may map the dependence or potential control of point i on point j; then calculate the edge attribute value of the edge between the two nodes through the formula. The larger the value, the more frequent the traffic interaction between i and j; the edge attribute characterizes the interaction of the two devices corresponding to the edge in the data stream. The larger the edge attribute value, the greater the data interaction volume and the less secure.

[0132] By calculating the two-way traffic ratio (i→j and j→i), the data interaction mode between devices can be captured. Using the traffic ratio can reduce the impact of the absolute scale of high-traffic nodes on the result and make it comparable between devices of different scales. Only count the source / destination IP ratio in the traffic log, and there is no need to process the full volume of data, making the calculation lightweight.

[0133] Furthermore, calculating the selection probability of each network node as the network node where the honeypot is to be deployed according to the point attribute value of the network node and the edge attribute values of each edge related to it includes:

[0134] Calculate the selection probability of the network node as the network node where the honeypot is to be deployed according to the following formula:

[0135]

[0136] Among them, PSe i is the selection probability of network node i, NN i is the degree of network node i, that is, the number of other nodes directly connected to network node i, NN j is the degree of node j, and NN is the maximum degree of nodes in the topological structure.

[0137] Taking any node i as an example, the calculation process of its selection probability is:

[0138]

[0139] The interaction intensity of all neighbors of node i. The larger this value, the less secure it is, the more honeypots need to be deployed, and the greater the selection probability.

[0140] The security situation of node i. The larger this value, the less secure it is, and the more honeypots need to be deployed.

[0141] The larger it is, the more it indicates that both the neighbors and itself are insecure, that is, the higher the degree of threat to node i, and the more honeypots need to be deployed.

[0142] A i is the security situation of node i itself, while A i is the security environment required by the device itself. For nodes with high security requirements, the selection probability needs to be reduced to ensure the security of these devices. is the possible situation after node i withstands threats under its own security situation. The larger this value, the more it indicates that node i remains secure after being threatened. The smaller this value, the more it indicates that node i is compromised after being threatened. Therefore, PSe i The larger the value, the more honeypots need to be deployed. Finally, select the nodes with larger PSe i values to deploy honeypots. Attract attackers away from real assets.

[0143] NN is the maximum degree of nodes in the topology structure, that is, the degree of the node that connects the most nodes. In this way indicates the ratio of the degree of node i to the maximum degree. The more degrees, the more it indicates that node i connects to other nodes, and the possibility of being attacked will increase. Therefore the larger it is, the greater the risk.

[0144] Furthermore, the network nodes for which honeypots are to be deployed according to the selection probability of each network node include:

[0145] Arrange the selection probabilities of each node from largest to smallest, and take the top N nodes with the sorted selection probabilities as the network nodes for this deployment of honeypots;

[0146] Among them,

[0147] N ALL is the total number of nodes in the network nodes, is the normalized average value of the performance data of each node obtained within a preset time period, is the total amount of abnormal traffic data in the traffic data of network node i obtained, Flow i is the total amount of traffic data of network node i obtained.

[0148] By It shows that the better the device performance, the higher the performance data, and the fewer honeypots deployed. This solution deploys honeypots when the network is normal to defend against network attacks during network operation. If the current network has been attacked, the network attack needs to be handled first, and after the network returns to normal, the subsequent operation can be defended by honeypots. At this time, if the network performance is stronger and the security level of the network itself is relatively high, fewer honeypots can be deployed to reduce the resource consumption of honeypot deployment.

[0149] Arrange the selection probabilities of nodes from large to small, and dynamically select the number of network nodes for this honeypot deployment according to the network conditions. When the abnormal traffic ratio is high or the performance is low, increase N and deploy more honeypots to cope with potential threats. Automatically balance anomaly detection and resource occupancy (for example, reduce the honeypot load when the performance is poor). Performance mean After normalization, the influence of dimensional differences of different metrics (CPU, memory, etc.) is avoided. And N ALL As the upper limit, it can be set according to the actual situation to prevent over-deployment (especially when the abnormal traffic surges) and protect resources. Through the dynamic adjustment of the number of honeypots, combined with traffic and performance data, it is suitable for rapid response to changes.

[0150] Furthermore, deploying a honeypot for the determined network nodes to be deployed with honeypots includes:

[0151] Deploy a honeypot for each selected node, obtain the mirror of its corresponding node through the honeypot, and for any node i, its corresponding honeypot i has the same attributes as the device corresponding to node i. During the operation of device i, honeypot i obtains all the data of device i in the form of a mirror.

[0152] Take the mirror obtained through the honeypot of its corresponding node as a decoy node for network decoying.

[0153] The honeypot has the same attributes as the device corresponding to the node, such as: the same name, the same identifier, the same configuration, etc.

[0154] Keep the honeypot and the real node exactly the same in terms of attributes and data through mirror synchronization; when an attacker accesses the honeypot, they are guided to the mirror node instead of the real asset to achieve the decoy function; the honeypot runs independently and is logically isolated from the real node to achieve data isolation.

[0155] The honeypot has the same attributes as the device corresponding to the node, such as: the same name, the same identifier, the same configuration, etc. The honeypot is exactly the same as the real node in terms of configuration, services, logs, etc., making it difficult for attackers to distinguish between the two through fingerprint recognition and significantly improving the success rate of entrapment. Through dynamic data synchronization, real-time mirroring of data (such as user sessions, file updates) enables the honeypot status to be synchronized with the real node, avoiding the exposure of timestamps or content differences due to static mirroring.

[0156] Through attacker behavior capture, the honeypot can record the complete operation chain of the attacker on the mirrored node (such as vulnerability exploitation, lateral movement), providing high-value data for security analysis through refined analysis. And the attack traffic is diverted to the honeypot, and the real node is not directly affected, ensuring business continuity.

[0157] The honeypot can quickly replicate node images based on container or virtual machine templates, realizing automated image generation, which is suitable for dynamically adjusting the honeypot layout in large-scale networks.

[0158] Furthermore, the security defense of the network based on the honeypot includes:

[0159] Obtain all the features in the feature library, including:

[0160] Obtain the attack logs of each node, and determine the features of each attack based on the attack logs of each node;

[0161] Obtain the features of each attack released by the security department;

[0162] Combine the features of each attack determined from the attack logs and the features of each attack released by the security department, and use the combined features as the final feature library;

[0163] Recombine the features in the feature library to obtain different combinations, where x is the total number of features in the feature library and y is the number of features selected each time;

[0164] Compare the data obtained from each honeypot with all the groups of features obtained by recombination. If similar features are found, it is considered that the device corresponding to the honeypot is under attack, and preset measures are executed.

[0165] By combining internal actual attack data with external authoritative threat intelligence, covering known attacks and localized threats, reducing false negatives, and making the feature coverage comprehensive; generating a large number of combinations through feature recombination, theoretically covering attack variants; the honeypot acts as an "attack decoy" to capture unknown attacks, dynamically updating the feature library, and forming a detection-feedback closed loop. Automatically execute preset measures (such as alarm, network disconnection, interception) after matching, shortening the attack response time.

[0166] Furthermore, the method further includes:

[0167] Obtain the traffic data and performance data of each node within a preset time period at every preset cycle;

[0168] Update the point attribute values and edge attribute values in the topological structure according to the obtained new data, and re-determine the network nodes where honeypots are to be deployed.

[0169] When constructing the topological structure, data within a period of time during construction is obtained, and after the construction is completed, data within a period of time is obtained again at every preset cycle, so as to update the point attribute values and edge attribute values in the topological structure. When deploying honeypots, data within a period of time is obtained. This period of time has no relation to the topological structure construction time, and they may overlap or not, and the lengths of time may also be the same or different. Generally, the honeypot deployment time will be later than the time when the topological structure obtains data. The preset cycle can update the point and edge attributes once every six months. It can also update the point and edge attributes once a month, which is determined according to the network security situation. If the network is relatively secure (such as an intranet), the preset cycle can be relatively longer.

[0170] Through a dynamic update mechanism, perform periodic data collection: collect the traffic data (such as total traffic volume, proportion of abnormal traffic) and performance data (such as CPU utilization rate, memory occupancy rate) of each node at every preset cycle (such as one week, one month or half a year, which can be set according to requirements); and update topological attributes: map the latest data to the point attributes (node security status, resource load) and edge attributes (communication frequency between nodes, traffic direction) of the network topology. Implement the decision-making for re-deploying honeypots: based on the updated topological attributes, recalculate the selection probability of nodes, and select the N nodes with the highest probability to deploy honeypots.

[0171] Through real-time threat response, dynamically track node anomalies (such as sudden DDoS (Distributed denialservice attacks) traffic, abnormal CPU load), and timely deploy honeypots in hot spots to improve the attack capture rate; for example, if the SQL (Structured Query Language) injection attack traffic of a certain node suddenly increases → give priority to deploying honeypots in the next cycle and record the attack Payload. Through elastic resource allocation, when the node performance deteriorates, reduce the number of honeypots deployed on it to avoid the failure of honeypots caused by resource exhaustion. After the node recovers, it is automatically re-included in the candidates to maintain the defense coverage rate. Moreover, continuous update can achieve network situation awareness, and the continuously updated topological attributes can generate a real-time security heat map to assist the administrator in locating vulnerable areas.

[0172] In the embodiments of the present disclosure, by evaluating the security level, the probability of being attacked, and the risk level of each node in the network to determine the importance of each node, the defense value of the node to the network is characterized by the node attributes, and the interaction situation of the two devices corresponding to the edge in the data stream is characterized by the edge attributes to determine the value of the edge to the network. Then, according to the node attribute values of the network nodes and the edge attribute values of each edge related thereto, the selection probability of each network node as a network node for deploying a honeypot is calculated. Through this selection probability, key nodes in the network can be selected to deploy honeypots, and by accurately quantifying the node defense value, the honeypot deployment strategy is optimized, and the overall security efficiency of the network is maximized under the constraint of limited resources; while ensuring the defense effect, the execution effect of the network security defense solution is improved, and the resource requirements are reduced.

[0173] Embodiment 2 of the present disclosure further provides a network security defense system, as Figure 3 shown, the system includes:

[0174] An acquisition module 11, which is configured to acquire a network topology structure;

[0175] A determination module 12, which is configured to determine the node attribute value of the network node according to the defense value of the network node to the network, and determine the edge attribute values of each edge related to the network node in the topology structure according to the traffic data related to the network node;

[0176] A selection module 13, which is configured to calculate the selection probability of each network node as a network node for deploying a honeypot according to the node attribute value of the network node and the edge attribute values of each edge related thereto, and determine the network nodes for deploying a honeypot according to the selection probability of each network node;

[0177] A deployment module 14, which is configured to deploy a honeypot for the determined network nodes for deploying a honeypot;

[0178] A defense module 15, which is configured to perform security defense on the network based on the honeypot.

[0179] Further, the determination module 12 is specifically configured to:

[0180] Determine the device type corresponding to the network node, and determine the attack probability value of the network node according to the device type;

[0181] Determine the security value corresponding to the network node according to the environment where the network node is located and the data stored;

[0182] Determine the risk value corresponding to the network node;

[0183] Determine the node attribute value of the network node according to the following formula:

[0184]

[0185] Among them, AN i is the point attribute value of network node i, P i is the attack probability value of network node i, A i is the security value of network node i, Risk i is the risk value of network node i.

[0186] Furthermore, the determining module 12 determining the risk value corresponding to the network node includes:

[0187] Obtain the traffic data, performance data, and attack data of network node i;

[0188] Determine the risk value of network node i according to the obtained data and the following formula;

[0189]

[0190] Among them, is the total amount of abnormal traffic data in the traffic data of network node i, Flow i is the total amount of traffic data of network node i, is the total amount of data in the performance data of network node i that is higher than the highest performance security threshold, Fun i is the total amount of performance data of network node i, Att i is the number of times network node i is attacked within a preset time period.

[0191] Furthermore, the determining module 12 is specifically set as:

[0192] Obtain the traffic data within a preset time period between network node i and the related node j connected to it by an edge, where j is the point identifier directly connected to network node i;

[0193] Among all the traffic data of point i, determine the ratio of the amount of data with the destination IP being the IP of point j to the total amount of data The ratio of the amount of data with the source IP being the IP of point j to the total amount of data

[0194] Among all the traffic data of point j, determine the ratio of the amount of data with the destination IP being the IP of point i to the total amount of data The ratio of the amount of data with the source IP being the IP of point i to the total amount of data

[0195] Determine the edge attribute value AL of the direct edge between network node i and node j according to the following formula ij :

[0196]

[0197] Furthermore, the selecting module 13 is specifically set as:

[0198] Calculate the selection probability of a network node as a honeypot to be deployed according to the following formula:

[0199]

[0200] where PSe i is the selection probability of network node i, NN i is the degree of network node i, that is, the number of other nodes directly connected to network node i, NN j is the degree of node j, and NN is the maximum degree of nodes in the topology structure.

[0201] Furthermore, the selection module 13 is specifically set as:

[0202] Arrange the selection probabilities of each node in descending order, and use the top N nodes with the highest selection probability as the network nodes for this honeypot deployment;

[0203] where

[0204] N ALL is the total number of nodes in the network nodes, is the normalized average value of the performance data of each node obtained within a preset time period, is the total amount of abnormal traffic data in the traffic data of network node i obtained, Flow i is the total amount of traffic data of network node i obtained.

[0205] Furthermore, the deployment module 14 is specifically set as:

[0206] Deploy a honeypot for each selected node, obtain the image of its corresponding node through the honeypot, and for any node i, its corresponding honeypot i has the same attributes as the device corresponding to node i. During the operation of device i, honeypot i obtains all the data of device i through the mirroring method;

[0207] Use the image of its corresponding node obtained through the honeypot as a trap node for network trapping.

[0208] Furthermore, the defense module 15 is specifically set as:

[0209] Obtain all the features in the feature library, including:

[0210] Obtain the attack logs of each node, and determine the features of each attack based on the attack logs of each node;

[0211] Obtain the features of each attack released by the security department;

[0212] The features obtained by combining the features of each attack determined from the attack logs and the features of each attack released by the security department are used as the final feature library;

[0213] Reorganize the features in the feature library to obtain different combinations, where x is the total number of features in the feature library and y is the number of features selected each time;

[0214] Compare the data obtained from each honeypot with all the groups of features obtained by reorganization. If similar features are found, it is considered that the device corresponding to the honeypot is under attack, and preset measures are executed.

[0215] Furthermore, the system further includes an update module 16;

[0216] The update module 16 is set to obtain the traffic data and performance data of each node within a preset time period every preset cycle; and,

[0217] Update the point attribute values and edge attribute values in the topological structure according to the newly obtained data, and enable the selection module 13 to re-determine the network nodes for deploying honeypots.

[0218] The network security defense system of the embodiments of the present disclosure is used to implement the network security defense method in the first embodiment of the method, so the description is relatively simple. For specific details, reference can be made to the relevant descriptions in the previous method embodiments, and details will not be repeated here.

[0219] In addition, as Figure 4 shown, the third embodiment of the present disclosure further provides an electronic device, including a memory 100 and a processor 200. A computer program is stored in the memory 100. When the processor 200 runs the computer program stored in the memory 100, the processor 200 executes the above various possible methods.

[0220] Among them, the memory 100 is connected to the processor 200. The memory 100 can adopt flash memory, read-only memory or other memories, and the processor 200 can adopt a central processing unit or a single-chip microcomputer.

[0221] In addition, the embodiments of the present disclosure further provide a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by the processor to perform the above various possible methods.

[0222] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, computer program modules, or other data. The computer-readable storage medium includes, but is not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), digital versatile disc (DVD, Digital Video Disc) or other optical disc storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.

[0223] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present disclosure. However, the present disclosure is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present disclosure, and these modifications and improvements are also regarded as the protection scope of the present disclosure.

Claims

1. A network security defense method, characterized in that, The method includes: Obtaining a network topology structure; Determining the point attribute value of a network node according to the defense value of the network node for the network, and determining the edge attribute value of each edge related to the network node in the topology structure according to the traffic data related to the network node; Calculating the selection probability of each network node as a network node for deploying a honeypot according to the point attribute value of the network node and the edge attribute values of the edges related to it, and determining the network nodes for deploying the honeypot according to the selection probability of each network node; Deploying a honeypot for the determined network nodes for deploying a honeypot; Performing security defense on the network based on the honeypot.

2. The method according to claim 1, wherein The determining the point attribute value of the network node according to the defense value of the network node for the network includes: Determining the device type corresponding to the network node, and determining the attack probability value of the network node according to the device type; Determining the security value corresponding to the network node according to the environment where the network node is located and the data stored; Determining the risk value corresponding to the network node; Determining the point attribute value of the network node according to the following formula: Among them, AN i is the node attribute value of network node i, P i is the attack probability value of network node i, A i is the security value of network node i, Risk i is the risk value of network node i.

3. The method according to claim 2, wherein The determining the risk value corresponding to the network node includes: Obtaining the traffic data, performance data, and attack data of network node i; Determining the risk value of network node i according to the obtained data and the following formula; Among them, is the total amount of abnormal traffic data in the traffic data of network node i, Flow i is the total amount of traffic data of network node i, is the total amount of data in the performance data of network node i that is higher than the highest performance security threshold, Fun i is the total amount of performance data of network node i, Att i is the number of times network node i is attacked within a preset time period.

4. The method according to claim 3, characterized in that The determining the edge attribute value of each edge related to the network node in the topology structure according to the traffic data related to the network node includes: Obtaining the traffic data within a preset time period between network node i and its directly connected related node j, where j is the point identifier directly connected to network node i; Among all the traffic data at point i, determine the ratio of the data volume with the destination IP being the IP of point j to the total data volume The ratio of the data volume with the source IP being the IP of point j to the total data volume Among all the traffic data at point j, determine the ratio of the data volume with the destination IP being the IP of point i to the total data volume The ratio of the data volume with the source IP being the IP of point i to the total data volume Determine the edge attribute value AL of the direct edge between network node i and node j according to the following formula ij :

5. The method according to claim 4, characterized in that, The calculating the selection probability of each network node as a network node for deploying a honeypot according to the point attribute value of the network node and the edge attribute values of the edges related to it includes: Calculating the selection probability of the network node as a network node for deploying a honeypot according to the following formula: Among them, PSe i is the selection probability of network node i, NN i is the degree of network node i, that is, the number of other nodes directly connected to network node i, NN j is the degree of node j, and NN is the maximum degree of nodes in the topological structure.

6. The method according to claim 1, wherein The determining the network nodes for deploying a honeypot according to the selection probability of each network node includes: Arranging the selection probabilities of each node from large to small in sequence, and taking the top N nodes with the sorted selection probabilities as the network nodes for deploying the honeypot this time; Among them, N ALL is the total number of nodes in the network node, is the normalized average of the performance data of each node obtained within the preset time period, is the total amount of abnormal traffic data in the traffic data of the network node i, Flow i is the total amount of traffic data of the network node i obtained.

7. The method according to claim 1, wherein The deploying a honeypot for the determined network nodes for deploying a honeypot includes: Deploying a honeypot for each selected node, obtaining an image of its corresponding node through the honeypot, and for any node i, its corresponding honeypot i has the same attributes as the device corresponding to node i. During the operation of device i, honeypot i obtains all the data of device i in an image manner; Using the image obtained through the honeypot of its corresponding node as a decoy node for network decoying.

8. The method according to claim 1, wherein The performing security defense on the network based on the honeypot includes: Obtaining all the features in the feature library, including: Obtaining the attack logs of each node, and determining the features of each attack based on the attack logs of each node; Obtaining the features of each attack released by the security department; Taking the features obtained by combining the features of each attack determined from the attack logs and the features of each attack released by the security department as the final feature library; Recombine the features in the feature library to obtain different combinations, where x is the total number of features in the feature library and y is the number of features selected each time; Comparing the data obtained by each honeypot with all the recombined group features. If similar features are found, it is considered that the device corresponding to the honeypot is under attack, and a preset measure is executed.

9. The method according to claim 1, wherein The method further includes: Obtain the traffic data and performance data of each node within a preset time period at every preset cycle; Update the point attribute values and edge attribute values in the topology structure according to the obtained new data, and re-determine the network nodes where honeypots are to be deployed.

10. A network security defense system, characterized in that, The system includes: An obtaining module configured to obtain a network topology structure; A determining module configured to determine the point attribute values of network nodes according to the defense value of the network nodes to the network, and determine the edge attribute values of each edge related to the network nodes in the topology structure according to the traffic data related to the network nodes; A selecting module configured to calculate the selection probability of each network node as a network node where a honeypot is to be deployed according to the point attribute values of the network nodes and the edge attribute values of each edge related to it, and determine the network nodes where honeypots are to be deployed according to the selection probability of each network node; A deploying module configured to deploy honeypots for the determined network nodes where honeypots are to be deployed; A defense module configured to perform security defense on the network based on the honeypots.

11. An electronic device, characterized in that, It includes a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the network security defense method according to any one of claims 1-9.

12. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, it implements the network security defense method according to any one of claims 1-9.