A method for detecting attackers based on vulnerability forgery

By introducing data analysis and dynamic optimization management of the basic monitoring cycle into the attacker detection scheme, the problem of poor monitoring effect in the existing scheme is solved, more efficient local and overall monitoring effect is achieved, and the reliability of adaptive optimization management is enhanced.

CN120498823BActive Publication Date: 2025-12-02BEIJING WILLBOX TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510757318.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-12-02
Estimated Expiration
2045-06-09

AI Technical Summary

Technical Problem

Existing attacker detection solutions have poor local monitoring and overall application effects during implementation, and lack adaptive optimization management effectiveness.

Method used

By monitoring and analyzing the implementation process of attacker capture schemes based on a preset basic monitoring cycle, obtaining local active and passive monitoring data, integrating and analyzing the data, and dynamically optimizing management, adaptive optimization management of attacker capture schemes is achieved. This includes the following steps: 1) Data analysis based on the basic monitoring cycle, including: 1) Data classification and formula calculation, 2) Effect recognition model, 3) Dynamic optimization management.

Benefits of technology

It improves the local implementation and overall application effectiveness of attacker detection schemes, and enhances the reliability and completeness of adaptive optimization management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498823B_ABST
    Figure CN120498823B_ABST
Patent Text Reader

Abstract

This invention discloses an attacker capture method based on vulnerability forgery, belonging to the field of vulnerability detection technology. It uses a preset basic monitoring cycle to monitor and analyze the implementation process of the attacker capture scheme from different aspects. It integrates and analyzes locally active and locally passive monitoring data acquired within the basic monitoring cycle, and dynamically optimizes the subsequent implementation of the attacker capture scheme based on the local application effects. It monitors and analyzes the optimization effect of the attacker capture scheme after optimization management, and performs secondary optimization management based on the analysis results. This invention addresses the technical problems of poor local implementation monitoring and overall application effects, as well as poor adaptive optimization management effects in existing attacker capture schemes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vulnerability detection technology, and more specifically to a method for capturing attackers based on vulnerability forgery. Background Technology

[0002] Attacker capture based on vulnerability forgery typically refers to using deception techniques to detect and defend against cyberattacks. The core idea is to set traps or baits to attract attackers to interact, thereby revealing their attack behaviors, tools, and strategies.

[0003] Existing attacker detection schemes, during implementation, cannot monitor and analyze data from different aspects of the implementation process, determine the positive and negative effects of the attacker detection scheme, integrate and analyze the application effect of the attacker detection scheme based on the different effects obtained, and adaptively optimize and manage the attacker detection scheme based on the integrated analysis results. As a result, the local implementation monitoring effect and overall application effect of the attacker detection scheme are not good, and the adaptive optimization and management effect is not good. Summary of the Invention

[0004] The purpose of this invention is to provide an attacker capture method based on vulnerability forgery, which solves the technical problems of poor local implementation and overall application effects in the implementation process of existing attacker capture schemes, as well as poor adaptive optimization management effects.

[0005] The objective of this invention can be achieved through the following technical solutions:

[0006] An attacker capture method based on vulnerability forgery includes:

[0007] Based on a preset basic monitoring cycle, different aspects of the attacker capture scheme implementation process are monitored and data analysis is performed to obtain local active monitoring data and local passive monitoring data corresponding to the attacker capture scheme implementation process.

[0008] The data on active and passive implementation of the attacker detection scheme are integrated, processed, and analyzed during the basic regulatory cycle to determine the local application effect of the attacker detection scheme during the basic regulatory cycle. Based on the local application effect, the subsequent implementation of the attacker detection scheme is dynamically optimized and managed.

[0009] Monitor and analyze the effectiveness of the optimized attacker capture scheme after implementation and management, and maintain the optimized attacker capture scheme for continued implementation based on the analysis results, or conduct secondary optimization management of the optimized attacker capture scheme.

[0010] Preferably, when monitoring and statistically analyzing all capture data during the implementation of the attacker capture scheme based on a preset basic monitoring cycle, the attacked target, capture confirmation result, and capture resource value are obtained from different capture data; the capture confirmation result includes capture confirmation valid and capture confirmation invalid.

[0011] Based on the same valid capture confirmation results, all the capture data belonging to the same category are sorted and combined to obtain the first capture category data;

[0012] Furthermore, based on the same capture confirmation result that is invalid, all the capture data belonging to it are sorted and combined to obtain the second capture category data.

[0013] Preferably, when performing data analysis on different aspects based on the first capture classification data and the second capture classification data, the first capture classification data is analyzed using the local positive influence formula. Calculate and obtain the corresponding local active regulatory value JJ; where NZ is the total number of all capture data in the first capture classification data; and NY is the total number of all capture data in the second capture classification data.

[0014] Preferably, the second capture classification data is processed using the local negative impact formula. Calculate and obtain the corresponding local implementation negative regulatory value JX; where ZBi is the capture resource value associated with different capture data in the second capture category data; i is different capture data in the second capture category data, i = 1, 2, 3, ..., NY; ZB0 is the total capture resource value associated with all capture data within the basic regulatory period;

[0015] By associating and combining the values ​​of locally implemented positive supervision with the first capture classification data, we obtain the locally implemented positive supervision data corresponding to the basic supervision cycle. Similarly, by associating and combining the values ​​of locally implemented negative supervision with the second capture classification data, we obtain the locally implemented negative supervision data corresponding to the basic supervision cycle.

[0016] Preferably, the values ​​of locally implemented positive supervision in the locally implemented positive supervision data and the values ​​of locally implemented negative supervision in the locally implemented negative supervision data are combined using the formula... Calculate the local implementation supervision difference c; where η is the standard value of the local implementation supervision difference corresponding to the attacker's capture scheme in the basic supervision cycle;

[0017] Furthermore, the calculated local implementation monitoring difference is analyzed using a local implementation effect identification model, and the local application validity YX corresponding to the attacker capture scheme within the basic monitoring cycle is output; the local application validity includes a value of -1, 0 or 1.

[0018] Preferably, the expression for the local implementation effect recognition model is: In the formula, b represents the value of the local implementation of regulatory conditions.

[0019] Preferably, a local application validity value of -1 indicates that the attacker capture scheme is functioning normally in its local application within the basic monitoring period;

[0020] The local application validity value of 0 indicates that the attacker capture scheme has a slightly abnormal local application effect during the basic monitoring period, and the attacker capture scheme is subject to the first optimization management.

[0021] Based on the local application validity of 1, it is indicated that the local application effect of the attacker capture scheme is severely abnormal during the basic monitoring period, and a second optimization management is implemented for the attacker capture scheme.

[0022] Preferably, the attacker detection scheme after optimization management is implemented is obtained, and the local implementation positive monitoring value, local implementation negative monitoring value, and local implementation monitoring difference are obtained within the corresponding monitoring period, and then expressed by the formula. Calculate the local implementation optimization validity SYX after the implementation optimization management of the attacker capture scheme; where c′ is the local implementation supervision difference of the attacker capture scheme after implementation optimization management in the corresponding supervision period; K is a real number greater than 0 and less than 100; This is the floor function.

[0023] Preferably, data analysis is performed on the local implementation optimization validity. If the local implementation optimization validity is less than or equal to 0, it is determined that the attacker capture scheme after the implementation optimization management has a normal capture optimization effect, and the optimized attacker capture scheme is maintained and will continue to be implemented.

[0024] If the local implementation of optimization validity is greater than 0, it is determined that the attacker capture scheme after optimization management has an abnormal capture optimization effect, and the optimized attacker capture scheme is subject to secondary optimization management.

[0025] Preferably, when performing secondary optimization management, if the local implementation optimization validity is 1, then the attacker capture scheme after the implementation of optimization management will continue to be subject to the first optimization management.

[0026] If the local implementation of optimization validity is greater than 1, then the attacker capture scheme after optimization management will continue to be subject to second optimization management.

[0027] Compared to existing solutions, the beneficial effects achieved by this invention are:

[0028] This invention monitors and analyzes the implementation process of attacker capture schemes from different aspects based on a preset basic monitoring period. It can digitally process and classify the local implementation monitoring status of attacker capture schemes within the basic monitoring period from the dimensions of positive and negative implementation results. This provides reliable multi-dimensional local implementation monitoring analysis data support for the data analysis of the local application effects of attacker capture schemes within the subsequent basic monitoring period, thereby improving the local implementation monitoring effect of different aspects of the attacker capture scheme implementation process.

[0029] This invention integrates and analyzes the local active and passive regulatory data obtained in the early stages of the process to obtain the local application effects of the attacker capture scheme within the basic regulatory cycle. Based on the local application effects, it dynamically optimizes and manages the subsequent implementation of the attacker capture scheme. This enables the monitoring and analysis of the implementation effect of the attacker capture scheme from an overall perspective, as well as targeted optimization and management, thereby improving the overall application effect and adaptive optimization and management effect of different aspects of the attacker capture scheme implementation process.

[0030] This invention monitors and analyzes the optimization effect of the attacker capture scheme after implementation of optimized management, and performs secondary optimization management on the optimized attacker capture scheme based on the analysis results, thereby further improving the autonomous monitoring and self-improvement effect of the adaptive optimization management of the attacker capture scheme. Attached Figure Description

[0031] The invention will now be further described with reference to the accompanying drawings.

[0032] Figure 1 This is a flowchart of an attacker capture method based on vulnerability forgery according to the present invention.

[0033] Figure 2 This is a flowchart illustrating the data analysis of the local implementation optimization effectiveness in this invention. Detailed Implementation

[0034] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0035] like Figure 1 As shown, this invention is a method for capturing attackers based on vulnerability forgery, comprising:

[0036] Based on a pre-defined basic monitoring cycle, the implementation process of attacker detection schemes is monitored and analyzed from different aspects to obtain local active and passive monitoring data corresponding to the implementation process of attacker detection schemes; including:

[0037] When monitoring and statistically analyzing all captured data during the implementation of an attacker's capture scheme based on a preset basic monitoring period, the unit of the basic monitoring period is days, which can be 15 days or customized according to the actual application needs of the actual application scenario. This allows for the acquisition of the attacked target, capture confirmation results, and capture resource values ​​from different capture data.

[0038] The targets of the attack can specifically be several pre-faked vulnerabilities;

[0039] The capture confirmation result includes valid capture confirmation and invalid capture confirmation; the capture confirmation result can be determined by professional operation and maintenance personnel in this field;

[0040] The captured resource value can be either CPU utilization, which is the percentage of time the central processing unit spends processing the task of capturing the attacker; or total network bandwidth usage, which is the total network traffic generated from the start to the end of the capture process. It can be determined according to the actual application requirements of the actual application scenario.

[0041] Based on the same valid capture confirmation results, all the capture data belonging to the same category are sorted and combined to obtain the first capture category data;

[0042] Furthermore, based on the same capture confirmation result that is invalid, all the capture data belonging to it are sorted and combined to obtain the second capture category data;

[0043] In this embodiment of the invention, by processing and classifying all capture data that occurs within the basic regulatory cycle, reliable capture classification data support can be provided for subsequent data analysis in different aspects.

[0044] When performing different aspects of data analysis based on the first and second capture classification data, the first capture classification data is analyzed using the local positive influence formula. Calculate and obtain the corresponding local active regulatory value JJ; where NZ is the total number of all capture data in the first capture category data; NY is the total number of all capture data in the second capture category data;

[0045] And the second capture classification data is processed through the local negative impact formula. Calculate and obtain the corresponding local implementation negative regulatory value JX; where ZBi is the capture resource value associated with different capture data in the second capture category data; i is different capture data in the second capture category data, i = 1, 2, 3, ..., NY; ZB0 is the total capture resource value associated with all capture data within the basic regulatory period;

[0046] It should be noted that the values ​​for positive and negative local implementation of supervision are calculated from the dimensions of positive and negative implementation results, respectively, to digitally represent the local implementation status corresponding to different dimensions.

[0047] By associating and combining the local active regulatory values ​​with the first capture classification data, we obtain the local active regulatory data corresponding to the basic regulatory cycle; and by associating and combining the local negative regulatory values ​​with the second capture classification data, we obtain the local negative regulatory data corresponding to the basic regulatory cycle.

[0048] In this embodiment of the invention, different aspects of the attacker capture scheme implementation process are monitored and data analyzed based on a preset basic monitoring period. This allows for the digital processing and classification of the local implementation monitoring status of the attacker capture scheme within the basic monitoring period from both positive and negative implementation outcome dimensions. This provides reliable multi-dimensional local implementation monitoring analysis data support for the data analysis of the local application effects of the attacker capture scheme implementation within the subsequent basic monitoring period, thereby improving the local implementation monitoring effect of different aspects of the attacker capture scheme implementation process.

[0049] This involves integrating and analyzing both positive and negative regulatory data acquired during the basic regulatory cycle to determine the local application effectiveness of attacker detection strategies within that cycle. Based on these local application effectiveness, the subsequent implementation of attacker detection strategies will be dynamically optimized and managed. This includes:

[0050] The values ​​of partial active supervision and partial negative supervision in the partial active supervision data and the partial negative supervision data are combined using the formula... Calculate the local implementation supervision difference c; where η is the standard value of the local implementation supervision difference corresponding to the attacker capture scheme in the basic supervision cycle, which can be determined according to the design requirements data of the attacker capture scheme, or according to the early test data of the attacker capture scheme.

[0051] It should be noted that the partial implementation monitoring difference is used to calculate the partial implementation monitoring data of different dimensions corresponding to the attacker's capture scheme within the basic monitoring cycle, so as to digitally represent the corresponding partial implementation monitoring status.

[0052] In this embodiment of the invention, by integrating and calculating the monitoring and processing data of different aspects of the early attacker capture scheme implementation process, the monitoring data of the local implementation corresponding to different dimensions in the early stage can be expanded and utilized.

[0053] Furthermore, the calculated local implementation supervision difference is analyzed through a local implementation effect identification model, and the local application validity YX corresponding to the attacker capture scheme within the basic supervision period is output.

[0054] The expression for the local implementation effect recognition model is as follows: In the formula, b is the value of the local implementation monitoring condition, which can be determined according to the design requirements data of the attacker's capture scheme;

[0055] Local application validity includes values ​​of -1, 0, or 1;

[0056] A local application validity value of -1 indicates that the attacker capture strategy is effective in local application within the basic monitoring period;

[0057] A local application validity value of 0 indicates that the attacker capture strategy has a slightly abnormal local application effect within the basic monitoring period;

[0058] A local application validity value of -1 indicates that the local application effect of the attacker capture scheme is severely abnormal during the basic monitoring period;

[0059] The local application validity value of -1 indicates that the attacker capture scheme is effective in local applications within the basic monitoring period.

[0060] The local application validity value of 0 indicates that the attacker capture scheme has a slightly abnormal local application effect during the basic monitoring period, and the attacker capture scheme is subject to the first optimization management.

[0061] Based on the local application validity of 1, it is indicated that the local application effect of the attacker capture scheme is severely abnormal during the basic monitoring period, and a second optimization management is implemented for the attacker capture scheme.

[0062] The first optimization management specifically involves updating and improving the attack capture design rules for vulnerability forgery to reduce the impact of abnormal operations caused by false alarms; the specific attack capture design rules can be determined by combining existing honeypot and honeynet design rules.

[0063] The second optimization management specifically involves updating and improving the attack capture design rules for vulnerability forgery, and shortening the basic supervision cycle to implement targeted periodic supervision. The shortened period can be as long as 7 days; that is, optimizing management from both the capture implementation aspect and the capture implementation supervision aspect.

[0064] In this embodiment of the invention, by integrating and analyzing the local active and passive regulatory data obtained in the early processing, the local application effect of the attacker capture scheme implementation within the basic regulatory cycle is obtained. Based on the local application effect, the subsequent implementation of the attacker capture scheme is dynamically optimized and managed. This realizes the regulatory analysis and targeted optimization management of the implementation effect of the attacker capture scheme from the overall perspective, improving the overall application effect and adaptive optimization management effect of different aspects of the attacker capture scheme implementation process.

[0065] The optimized attacker detection scheme is monitored and analyzed to assess its effectiveness. Based on the analysis results, the optimized scheme is maintained for continued implementation, or secondary optimization is performed. This includes:

[0066] Obtain the local active monitoring value, local passive monitoring value, and local monitoring difference of the attacker capture plan within the corresponding monitoring period after the implementation of optimized management, and use the formula... Calculate the first local implementation optimization validity SYX after the implementation optimization management of the attacker capture scheme; where c′ is the local implementation supervision difference of the attacker capture scheme after implementation optimization management in the corresponding supervision period, which can be determined according to the design requirements data of the attacker capture scheme, or according to the previous test data of the attacker capture scheme; K is a real number greater than 0 and less than 100, and can be taken as 60. This is the floor function;

[0067] It should be noted that the local implementation optimization validity is used to calculate the periodic implementation monitoring data after the implementation and optimization management of the attacker capture scheme, so as to digitally represent the capture optimization effect of the implementation and optimization management of the attacker capture scheme.

[0068] Furthermore, the local implementation monitoring difference of the attacker capture scheme after optimization management within the corresponding monitoring period will be analyzed using a local implementation effect identification model, and the corresponding second local implementation optimization validity will be output.

[0069] Unlike existing technical solutions that only trace and analyze the optimization effect from a single aspect of the regulatory data, resulting in poor accuracy of the trace and analysis and poor reliability of the optimization management, this invention, through monitoring and processing the optimization effect data of the attacker capture scheme implemented after optimization management within the corresponding regulatory period, can effectively reduce the error of data processing and analysis, thereby improving the reliability and diversity of the secondary optimization management of the attacker capture scheme after optimization management.

[0070] like Figure 2As shown, data analysis is performed on the first part of the implementation optimization validity and the second part of the implementation optimization validity. If both the first part of the implementation optimization validity and the second part of the implementation optimization validity are less than or equal to 0, it is determined that the attacker capture scheme after the implementation optimization management has a normal capture optimization effect, and the optimized attacker capture scheme will continue to be implemented in the future.

[0071] If either the first part of the implementation optimization validity or the second part of the implementation optimization validity is greater than 0, then the attacker capture scheme after the implementation optimization management is judged to have an abnormal capture optimization effect, and the optimized attacker capture scheme is subject to secondary optimization management.

[0072] In the case of secondary optimization management, if the first part of the optimization validity and the second part of the optimization validity are both 1, then the attacker capture scheme after optimization management will continue to be subject to the first optimization management.

[0073] If the validity of the first part of the implementation optimization and the validity of the second part of the implementation optimization are both greater than 1, then the attacker capture scheme after the implementation optimization management will continue to be subject to the second optimization management.

[0074] Unlike existing technical solutions that do not trace and analyze the effects of optimized attacker capture schemes, this invention improves the self-monitoring and self-improvement effects of adaptive optimization management of attacker capture schemes by monitoring and analyzing the optimization effects of the optimized attacker capture schemes after implementation of optimization management, and by performing secondary optimization management on the optimized attacker capture schemes based on the analysis results.

[0075] Furthermore, the formulas mentioned above are all numerical calculations obtained by removing dimensions and using simulation software to obtain a formula that is closest to the real situation, based on the collection of a large amount of data.

[0076] In the several embodiments provided by this invention, it should be understood that the disclosed methods can be implemented in other ways. For example, the embodiments of the invention described above are merely illustrative; for instance, the division of modules is only a logical functional division, and there may be other division methods in actual implementation.

[0077] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0078] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or in the form of hardware plus software functional modules.

[0079] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the essential characteristics of the present invention.

[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for detecting attackers based on vulnerability forgery, characterized in that, include: Based on a preset basic monitoring cycle, different aspects of the attacker capture scheme implementation process are monitored and data analysis is performed to obtain local active monitoring data and local passive monitoring data corresponding to the attacker capture scheme implementation process. Among them, when monitoring and statistically analyzing all capture data during the implementation of the attacker's capture scheme based on a preset basic monitoring cycle, the attacked target, capture confirmation result, and capture resource value are obtained from different capture data; the capture confirmation result includes capture confirmation valid and capture confirmation invalid. Based on the same valid capture confirmation results, all the capture data belonging to the same category are sorted and combined to obtain the first capture category data; Furthermore, based on the same capture confirmation result that is invalid, all the capture data belonging to it are sorted and combined to obtain the second capture category data; When performing different aspects of data analysis based on the first and second capture classification data, the first capture classification data is analyzed using the local positive influence formula. Calculate and obtain the corresponding local active regulatory value JJ; where NZ is the total number of all capture data in the first capture category data; NY is the total number of all capture data in the second capture category data; The second capture classification data is processed using the local negative impact formula. Calculate and obtain the corresponding local implementation negative regulatory value JX; where ZBi is the capture resource value associated with different capture data in the second capture classification data; i is different capture data in the second capture classification data, i=1, 2, 3, ..., NY; ZB0 is the total capture resource value associated with all capture data within the basic regulatory period; By associating and combining the local active regulatory values ​​with the first capture classification data, we obtain the local active regulatory data corresponding to the basic regulatory cycle; and by associating and combining the local negative regulatory values ​​with the second capture classification data, we obtain the local negative regulatory data corresponding to the basic regulatory cycle. The data on active and passive implementation of the attacker detection scheme are integrated, processed, and analyzed during the basic regulatory cycle to determine the local application effect of the attacker detection scheme during the basic regulatory cycle. Based on the local application effect, the subsequent implementation of the attacker detection scheme is dynamically optimized and managed. Monitor and analyze the effectiveness of the optimized attacker capture scheme after implementation and management, and maintain the optimized attacker capture scheme for continued implementation based on the analysis results, or conduct secondary optimization management of the optimized attacker capture scheme.

2. The attacker capture method based on vulnerability forgery according to claim 1, characterized in that, The values ​​of partial active supervision and partial negative supervision in the partial active supervision data and the partial negative supervision data are combined using the formula... Calculate the local implementation supervision difference c; where η is the standard value of the local implementation supervision difference corresponding to the attacker's capture scheme in the basic supervision cycle; Furthermore, the calculated local implementation monitoring difference is analyzed using a local implementation effect identification model, and the local application validity YX corresponding to the attacker capture scheme within the basic monitoring cycle is output; the local application validity includes a value of -1, 0 or 1.

3. The attacker capture method based on vulnerability forgery according to claim 2, characterized in that, The expression for the local implementation effect recognition model is: In the formula, b represents the value of the local implementation of regulatory conditions.

4. The attacker capture method based on vulnerability forgery according to claim 2, characterized in that, The local application validity value of -1 indicates that the attacker capture scheme is effective in local applications within the basic monitoring period. The local application validity value of 0 indicates that the attacker capture scheme has a slightly abnormal local application effect during the basic monitoring period, and the attacker capture scheme is subject to the first optimization management. Based on the local application validity of 1, it is indicated that the local application effect of the attacker capture scheme is severely abnormal during the basic monitoring period, and a second optimization management is implemented for the attacker capture scheme.

5. The attacker capture method based on vulnerability forgery according to claim 4, characterized in that, Obtain the local active monitoring value, local passive monitoring value, and local monitoring difference of the attacker capture plan within the corresponding monitoring period after the implementation of optimized management, and use the formula... Calculate the local implementation optimization validity SYX after optimizing the management of the attacker capture scheme; where, The difference in local implementation of the optimized attacker detection scheme within the corresponding regulatory period; K is a real number greater than 0 and less than 100; This is the floor function.

6. The attacker capture method based on vulnerability forgery according to claim 5, characterized in that, Data analysis was conducted on the local implementation optimization validity. If the local implementation optimization validity was less than or equal to 0, it was determined that the attacker capture scheme after the implementation optimization management had a normal capture optimization effect, and the optimized attacker capture scheme was maintained for continued implementation. If the effectiveness of local implementation optimization is greater than 0, it is determined that the attacker capture scheme after implementation optimization management has abnormal capture optimization effect, and the optimized attacker capture scheme will be subject to secondary optimization management.

7. The attacker capture method based on vulnerability forgery according to claim 6, characterized in that, When performing secondary optimization management, if the local implementation optimization validity is 1, then the attacker capture scheme after the implementation of optimization management will continue to be subject to the first optimization management. If the local implementation of optimization validity is greater than 1, then the attacker capture scheme after optimization management will continue to be subject to second optimization management.

Citation Information

Patent Citations

  • Network vulnerability attack detection method and system based on power distribution network

    CN118300823A

  • Honey spot deployment optimization method

    CN119051894A