Port proxy-based honeypot service system and method

By deploying HIDS plug-in in the device cluster to monitor network connection requests for business-independent ports, and combining data processing and intrusion detection systems, the problems of high cost and low coverage of traditional honeypot technology are solved, and low-cost and efficient attack detection and response are achieved, which is suitable for network security protection for small and medium-sized enterprises.

CN120528632APending Publication Date: 2025-08-22BEIJING CHENGSHI WANGLIN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510572994.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

Traditional honeypot technology has high deployment cost, complex maintenance, low coverage, and difficult to effectively detect attacks, and is not suitable for small and medium-sized enterprises.

Method used

The honeypot service system based on port proxy is adopted. By deploying the HIDS plug-in on the device to be monitored, it monitors network connection requests initiated by the target port that is unrelated to the service, and conducts abnormal behavior detection in combination with the data processing platform and intrusion detection system to output alarm information.

Benefits of technology

It realizes low-cost and high coverage attack detection and response, can promptly detect and defend against network attacks, protect information system security, and is suitable for real-time network security protection for device clusters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528632A_ABST
    Figure CN120528632A_ABST
Patent Text Reader

Abstract

The invention provides a honeypot service system and method based on a port agent. The system comprises a honeypot background, a data processing platform, an intrusion detection system and an HIDS plug-in deployed on to-be-monitored equipment. The honeypot background issues a port monitoring strategy to the HIDS plug-in of each to-be-monitored device; the HIDS plug-in monitors a network connection request initiated to a target port of the to-be-monitored equipment based on the port monitoring strategy and records request information corresponding to the network connection request, and the target port is a monitoring port irrelevant to a service operated by the to-be-monitored equipment; and the intrusion detection system receives the request information provided by the HIDS plug-in and transmitted by the data processing platform, performs abnormal behavior detection on the request information based on a preset rule, and outputs alarm information when an abnormal behavior is detected. According to the invention, real-time network security protection can be provided for the to-be-monitored equipment in the equipment cluster with low cost, high coverage rate and efficient attack detection and response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a honeypot service system and method based on port proxy. Background Art

[0002] Honeypot technology is a proactive defense measure in the field of network security. It uses simulated vulnerable systems or services as bait to lure attackers into the network and capture their attack behavior, thereby analyzing attack methods, collecting threat intelligence, and improving defense capabilities. Currently, honeypot technology is categorized into physical honeypots, virtual honeypots, and honeynets, all used to detect and defend against network attacks.

[0003] A physical honeypot, a tool used in network security defense technology, is a real, complete computer system running a real operating system and services. A virtual honeypot is a software-emulated honeypot system that uses virtualization technology to create one or more virtual computer environments. These environments appear to be real systems, but actually run on a virtualized platform. Virtual honeypots can simulate various operating systems, network services, and vulnerabilities to entrap attackers and collect attack information. A honeynet is an advanced network security defense system composed of multiple honeypots. By simulating one or more network environments to attract attackers, the system collects attack behavior data, analyzes attack patterns, and enhances overall network security protection capabilities.

[0004] Physical and virtual honeypots have the disadvantages of high deployment costs, complex maintenance, relatively low coverage, and ineffective attack detection, thus failing to achieve the desired results. Honeynet systems, on the other hand, require extensive hardware resources and involve large-scale resource management and technical investment, and are generally suitable for large enterprises or research institutions. For small and medium-sized enterprises, traditional honeypot solutions are often not practical. Summary of the Invention

[0005] In view of the above problems, embodiments of the present application provide a honeypot service system and method based on a port proxy that overcomes the above problems or at least partially solves the above problems.

[0006] In a first aspect, an embodiment of the present application provides a honeypot service system based on a port proxy, comprising: a honeypot backend, a data processing platform, an intrusion detection system, and a HIDS plug-in deployed on a device to be monitored, wherein the device to be monitored is a device that is screened out from a device cluster and needs to be monitored for abnormal behavior;

[0007] The honeypot backend sends the port monitoring strategy to the HIDS plug-in of each device to be monitored;

[0008] The HIDS plug-in monitors network connection requests initiated to a target port of the device to be monitored based on the port monitoring policy and records request information corresponding to the network connection request, wherein the target port is a monitoring port unrelated to the service run by the device to be monitored;

[0009] The intrusion detection system receives the request information provided by the HIDS plug-in and transmitted via the data processing platform, performs abnormal behavior detection on the request information based on preset rules, and outputs alarm information when abnormal behavior is detected.

[0010] In a second aspect, an embodiment of the present application provides a honeypot service method based on a port proxy, which is applied to a honeypot backend. The method includes:

[0011] Filter out the devices to be monitored for abnormal behavior in the device cluster;

[0012] After the HIDS plug-in is deployed on the device to be monitored, a port monitoring policy is issued to the HIDS plug-in of each device to be monitored, wherein the port monitoring policy is used to instruct the HIDS plug-in to monitor network connection requests initiated to the target port of the device to be monitored and record request information corresponding to the network connection request, where the target port is a monitoring port that is unrelated to the service running on the device to be monitored;

[0013] Among them, after the request information recorded by the HIDS plug-in is transmitted to the intrusion detection system via the data processing platform, the intrusion detection system performs abnormal behavior detection on the request information based on preset rules and outputs alarm information when abnormal behavior is detected.

[0014] In a third aspect, an embodiment of the present application provides a honeypot service method based on a port proxy, which is applied to an intrusion detection system. The method includes:

[0015] Receiving request information provided by a HIDS plug-in and transmitted via a data processing platform, the HIDS plug-in is deployed on a device to be monitored, the device to be monitored is a device that is screened out from a device cluster and needs to be monitored for abnormal behavior, and the HIDS plug-in monitors network connection requests initiated to a target port of the device to be monitored based on a port monitoring policy issued by a honeypot backend, and records request information corresponding to the network connection request, the target port being a monitoring port unrelated to the business run by the device to be monitored;

[0016] The received request information is subjected to abnormal behavior detection based on preset rules, and an alarm message is output when abnormal behavior is detected.

[0017] The technical solution of the embodiment of the present application, through HIDS plug-in deployment and port proxy technology, combined with effective analysis of data flow and intrusion detection system, can provide real-time network security protection for the monitored devices in the device cluster with low cost, high coverage and efficient attack detection and response, ensuring that attack behaviors can be discovered in time and effectively responded to through the linkage mechanism, making up for the problems of high cost, difficult maintenance and low coverage of traditional honeypot technology, and can help enterprises monitor and defend against network attacks in real time and protect the security of information systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of a honeypot service system based on a port proxy provided in an embodiment of the present application is shown;

[0019] Figure 2 A schematic diagram showing the working process of the honeypot service system based on port proxy provided by an embodiment of the present application;

[0020] Figure 3 Schematic diagram of the honeypot service method based on port proxy provided by the embodiment of the present application Figure 1 ;

[0021] Figure 4 Schematic diagram of the honeypot service method based on port proxy provided by the embodiment of the present application Figure 2 ;

[0022] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0023] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0024] It should be understood that references throughout this specification to "one embodiment" or "an embodiment" mean that a particular feature, structure, or characteristic associated with the embodiment is included in at least one embodiment of the present application. Therefore, the appearance of "in one embodiment" or "in an embodiment" throughout this specification does not necessarily refer to the same embodiment. Furthermore, these particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. The term "a plurality" in the embodiments of the present application may include two or more.

[0025] In the various embodiments of the present application, it should be understood that the size of the serial numbers of the following processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0026] The embodiment of the present application provides a honeypot service system based on port proxy, such as Figure 1 As shown, the system includes: a honeypot backend 100, a data processing platform 200, an intrusion detection system 300, and a HIDS plug-in 410 deployed on a device to be monitored 400. The device to be monitored 400 is a device that needs to be monitored for abnormal behavior and is screened out from a device cluster;

[0027] The honeypot backend 100 issues a port monitoring policy to the HIDS plug-in 410 of each monitored device 400; the HIDS plug-in 410 monitors network connection requests initiated to the target port of the monitored device 400 based on the port monitoring policy and records the request information corresponding to the network connection request. The target port is a monitoring port that is unrelated to the business running on the monitored device 400;

[0028] The intrusion detection system 300 receives the request information provided by the HIDS plug-in 410 and transmitted via the data processing platform 200, performs abnormal behavior detection on the request information based on preset rules, and outputs alarm information when abnormal behavior is detected.

[0029] The honeypot service system provided in the embodiment of the present application includes a honeypot backend 100, a data processing platform 200, an intrusion detection system 300 communicating with the data processing platform 200, and a HIDS plug-in 410 deployed on a device to be monitored 400.

[0030] The honeypot backend 100 communicates with the HIDS plug-in 410 to issue a port monitoring policy to the HIDS plug-in 410 deployed on the monitored device 400. The issued port monitoring policy specifies the target port to be monitored, and the target port is a monitoring port unrelated to the business running on the monitored device 400. Based on the port monitoring policy, the HIDS plug-in 410 dynamically monitors the target port using port proxy technology to implement the honeypot function, recording abnormal access by attackers to normally unopened ports to identify attack behavior.

[0031] Among them, HIDS (Host Intrusion Detection System) is used to monitor malicious activities on a single computer or server, and helps identify intrusion behavior by monitoring data such as file systems, logs, and running processes. By deploying a HIDS plug-in 410 on each device to be monitored 400, the embodiment of the present application can capture the attack behavior initiated by the attacker based on the network connection request based on the HIDS plug-in 410, and the honeypot's trapping work can be plug-in-based and lightweight deployed on multiple devices to monitor attack behavior on multiple devices.

[0032] Since different monitored devices 400 operate on different ports for different services, the corresponding target ports for different monitored devices 400 are also different. For each monitored device 400, the HIDS plug-in 410 deployed on the device obtains the corresponding port monitoring policy and, based on the target port specified by the port monitoring policy, monitors network connection requests initiated to the target port and records the request information corresponding to the network connection request.

[0033] After monitoring network connection requests and recording the corresponding request information, HIDS plug-in 410 provides the request information to data processing platform 200. In this embodiment, data processing platform 200 is, for example, the open-source streaming platform Kafka, which can process large-scale real-time data streams and can be used to efficiently transmit, store, and process massive amounts of data. By providing the request information corresponding to the network connection request to data processing platform 200, data processing platform 200 can be used to store and transmit the request information.

[0034] The data processing platform 200 is connected to the intrusion detection system (IDS) 300, and the data stream stored in the data processing platform 200 is transmitted to the intrusion detection system 300 for real-time analysis. The intrusion detection system 300 can analyze and monitor network traffic in real time and identify potential security threats and attack behaviors. After receiving the request information transmitted by the data processing platform 200 and provided by the HIDS plug-in 410, the intrusion detection system 300 performs abnormal behavior detection on the collected request information according to pre-set rules, and outputs alarm information when abnormal behavior is detected (such as scanning attacks, brute force cracking, etc.), notifies security personnel and takes corresponding defensive measures to respond to attacks through a linkage mechanism and achieve timely response to network security incidents.

[0035] The honeypot service system provided in the embodiment of the present application, through HIDS plug-in deployment and port proxy technology, combined with effective analysis of data flow and intrusion detection system, can provide real-time network security protection for the monitored devices in the device cluster with low cost, high coverage and efficient attack detection and response, ensuring that attack behaviors can be discovered in time and effectively responded to through the linkage mechanism, making up for the problems of high cost, difficult maintenance and low coverage of traditional honeypot technology, and can help enterprises monitor and defend against network attacks in real time and protect the security of information systems.

[0036] As an optional embodiment, port conflict detection needs to be performed when deploying port monitoring to avoid port conflicts and repeated monitoring and ensure system stability. Figure 2 As shown, for each device 400 to be monitored, the honeypot backend 100 obtains a port list corresponding to the device 400 to be monitored, identifies unoccupied ports of the device 400 to be monitored in the port list, and determines a target port from the identified ports;

[0037] The honeypot backend 100 generates a matching port monitoring policy based on the determined target port and sends it to the HIDS plug-in 410 of the device to be monitored 400. The HIDS plug-in 410 monitors the attack behavior launched on the target port;

[0038] Among them, the occupied ports in the port list are marked with an occupied symbol, and the target port is a port that meets the attack condition among the unoccupied ports.

[0039] For each device 400 to be monitored, the honeypot backend 100 needs to perform port conflict detection when determining the corresponding target port for the device 400 to be monitored. By detecting the opened ports and determining the port to be monitored from the unoccupied ports, port conflicts can be avoided, and repeated monitoring can be avoided to ensure system stability.

[0040] When the honeypot backend 100 detects and determines the target port of the device to be monitored 400 through port conflict detection, it identifies the port occupied by the device to be monitored 400 in the port list corresponding to the device to be monitored 400, and then selects the port that meets the attack condition from the unoccupied ports, and determines the selected port as the target port. The port list includes port identifiers corresponding to all ports of the device to be monitored 400, such as port numbers. The port numbers of occupied ports in the port list are marked with occupancy symbols. Based on the occupancy symbols, occupied ports and unoccupied ports can be quickly and effectively distinguished. Sensitive ports, such as ports that are easily attacked, are then further selected from the unoccupied ports, and the selected ports are determined as target ports to be monitored. The number of the selected target ports is one or more, and the target port can be determined based on a single or multiple screenings.

[0041] The ports occupied by the monitored device 400 include ports occupied by the running services and ports selected for monitoring. By identifying ports unrelated to the running services, monitoring of ports occupied by the services can be avoided, thereby preventing port conflicts. After the ports to be monitored are selected, they are marked as occupied, which prevents repeated selection of the port as a monitoring port, thereby avoiding repeated monitoring of the port.

[0042] After the honeypot backend 100 determines the target port for the device to be monitored 400, it generates a matching port monitoring policy based on the determined target port and sends it to the HIDS plug-in 410 of the device to be monitored 400. The HIDS plug-in 410 dynamically monitors the target port based on the port monitoring policy and captures the attack behavior launched by the attacker on the target port.

[0043] By identifying unoccupied ports based on the port list and selecting vulnerable ports from the identified unoccupied ports as target ports to be monitored, port conflicts can be avoided based on port conflict detection, and repeated monitoring can be avoided to ensure system stability.

[0044] In the embodiments of this application, Figure 2 As shown, the request information recorded by the HIDS plug-in 410 includes at least: a local IP (Internet Protocol) address, a local port number, a remote IP address, and a timestamp; the local IP address is the IP address of the local device; the local port number is the port number used by the local device, which is a digital label used to identify the process in communication; the remote IP address is the IP address of the remote device, which refers to the unique identifier of the device that initiates the network attack in the network.

[0045] The intrusion detection system 300 detects, based on the received request information, whether there is a first abnormal behavior in which the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first time period, and detects whether there is a second abnormal behavior in which the same local port receives network connection requests exceeding a second threshold within a second time period;

[0046] In response to detecting the first abnormal behavior, the intrusion detection system 300 outputs an alarm message indicating the presence of abnormal scanning behavior; and / or, in response to detecting the second abnormal behavior, the intrusion detection system 300 outputs an alarm message indicating the presence of brute force cracking behavior.

[0047] After receiving the request information provided by the HIDS plug-in 410, the intrusion detection system 300 detects, based on the request information, whether there is a first abnormal behavior in which the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first time period, and detects whether there is a second abnormal behavior in which the same local port receives network connection requests exceeding a second threshold within a second time period.

[0048] When detecting the first abnormal behavior, the intrusion detection system 300 detects, based on the local IP address and remote IP address carried in the request information, whether there is a first abnormal behavior in which the same remote IP address initiates more than, for example, five network connection requests to different local IP addresses within a short period of time (e.g., one second). When detecting the second abnormal behavior, the intrusion detection system 300 detects, based on the local port number carried in the request information, whether there is a second abnormal behavior in which the same local port receives more than, for example, five network connection requests within a short period of time (e.g., 0.5 seconds).

[0049] In response to detecting the first abnormal behavior, the intrusion detection system 300 determines that the attacker has launched a scanning attack on the local device and outputs an alarm message indicating the presence of abnormal scanning behavior. The alarm message may carry the remote IP address corresponding to the attacker who launched the scanning attack, and may also carry the local IP address that was attacked by the scanning attack. In response to detecting the second abnormal behavior, the intrusion detection system 300 determines that the local port has been attacked by a brute force attack launched by a remote device corresponding to one or more remote IP addresses, and outputs an alarm message indicating the presence of brute force attack. The alarm message may carry the port number corresponding to the local port of the monitored device 400 that was attacked, and may also carry the one or more remote IP addresses that launched the attack.

[0050] Based on the content carried in the request information, the intrusion detection system can detect whether the monitored device is subject to scanning attacks and whether the local port is subject to brute force cracking, so that when an attack is detected, timely measures can be taken to prevent further harm.

[0051] Among them, such as Figure 2 As shown, the request information also includes: the device identification of the device to be monitored 400;

[0052] In response to the device to be monitored 400 corresponding to at least two local IP addresses, the intrusion detection system 300, upon detecting that the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first time period, identifies whether the different local IP addresses correspond to the same device identifier;

[0053] In response to different local IP addresses corresponding to the same device identifier, it is determined that the device to be monitored 400 corresponding to the current device identifier is subject to a scanning attack.

[0054] In an embodiment of the present application, the request information recorded by the HIDS plug-in 410 also includes the device identification of the device to be monitored 400, such as a device ID (Identity document), which is used to distinguish different devices. For any device to be monitored 400, it can have one or more local IP addresses. When the intrusion detection system 300 performs the first abnormal behavior detection, in response to detecting that the same remote IP address initiates network connection requests exceeding the first threshold to different local IP addresses within a first time period, it further identifies whether the different local IP addresses correspond to the same device identification. If different local IP addresses correspond to the same device identification, it is determined that the attacker initiates a scanning attack on the device to be monitored 400 corresponding to the current device identification. At this time, the output alarm information carries the device identification of the device to be monitored 400 that is subjected to the scanning attack, so that the device under attack can be quickly located based on the device identification.

[0055] For the attack behavior of the same attacker scanning multiple local IP addresses, identify whether the device identifiers corresponding to the multiple local IP addresses under attack are the same. If multiple local IP addresses correspond to the same device identifier, determine that the monitored device corresponding to the device identifier is the attacked object. The attacked device can be quickly located based on the device identifier.

[0056] like Figure 2 As shown, the device cluster in the embodiment of the present application includes at least one of a first device from a production network and a second device from an office network, and the request information associated with the second device also includes a local operation account;

[0057] In response to detecting that the second target device from the office network is subjected to a scanning attack and / or a brute force attack, the intrusion detection system 300 locates the attacked object based on the local operation account corresponding to the second target device.

[0058] The device cluster includes a first device from a production network and / or a second device from an office network. The first device is, for example, a production network server, and the second device is, for example, a PC (Personal Computer). By deploying a HIDS plug-in 410 on the first device and / or the second device, a low-cost, high-efficiency honeypot service can be implemented on the production network and / or the office network to promptly detect and prevent further damage when the production network and / or the office network is attacked.

[0059] The second device, as a device in the office network, has a Local OA account (local operation account), based on which the specific person using the second device can be located. The request information associated with the second device recorded by the HIDS plug-in 410 also includes the local operation account.

[0060] When the intrusion detection system 300 detects that a second target device (any second device) originating from the office network is subjected to a scanning attack and / or a brute force attack, it can locate a specific person based on the local operation account included in the request information, and identify the device used by the person as the attacked device to quickly locate the attacked device.

[0061] In one embodiment of the present application, Figure 2 As shown, the HIDS plug-in 410 monitors the load and resource usage of the monitored device 400 and reports it to the honeypot backend 100;

[0062] In response to the load condition and / or resource usage of the device to be monitored 400 meeting the preset conditions, the honeypot backend 100 sends a shutdown instruction to the HIDS plug-in 410 of the device to be monitored 400 .

[0063] In addition to port monitoring, the HIDS plug-in 410 deployed on the device to be monitored 400 can also monitor the load and resource usage of the device to be monitored 400 and report it to the honeypot background 100. Based on the information reported by the HIDS plug-in 410, the honeypot background 100 understands the resource usage (such as CPU, memory, network bandwidth, etc.) of the device to be monitored 400 and the load of the device to be monitored 400 to monitor the device performance. If the load of the device to be monitored 400 is too large and / or the resources are used too much, the honeypot background 100 sends a shutdown command to the HIDS plug-in 410 of the device to be monitored 400, so that the HIDS plug-in 410 suspends port monitoring to reasonably utilize the resources of the device to be monitored 400 and reduce the load of the device to be monitored 400.

[0064] In one embodiment of the present application, Figure 2 As shown, the honeypot backend 100 obtains a device list corresponding to the device cluster, and the device list includes device identifiers corresponding to each device in the device cluster;

[0065] The honeypot backend 100 identifies a first device set corresponding to the device to be monitored 400 on which the HIDS plug-in 410 is deployed based on the device list, and identifies a second device set in which the HIDS plug-in 410 is in normal working state in the first device set based on the device list;

[0066] The honeypot backend 100 groups device assets based on the identified first device set, second device set, and device cluster;

[0067] In the device list, the device identifier corresponding to the monitored device 400 with the HIDS plug-in 410 deployed has a first marking symbol, and the device identifier corresponding to the monitored device 400 with the HIDS plug-in 410 in normal working state has a second marking symbol.

[0068] The device cluster corresponds to a device list, which includes the device identifier corresponding to each device in the device cluster, and in the device list, the device identifier corresponding to the monitored device 400 with the HIDS plug-in 410 deployed has a first marking symbol, and the device identifier corresponding to the monitored device 400 with the HIDS plug-in 410 in normal working condition has a second marking symbol. After obtaining the device list corresponding to the device cluster, the honeypot backend 100 identifies the first device set corresponding to the monitored device 400 with the HIDS plug-in 410 deployed in the device cluster based on the first marking symbol in the device list, and identifies the second device set in the first device set with the HIDS plug-in 410 in normal working condition based on the second marking symbol in the device list. The honeypot backend 100 groups device assets based on the first device set, the second device set, and the device cluster, so as to understand which devices in the device cluster are being monitored and which of the monitored devices have the HIDS plug-in 410 deployed thereon working normally, thereby managing device assets.

[0069] The above is the overall implementation plan of the honeypot service system based on port proxy provided in the embodiment of this application. It combines the port proxy with the production office environment, and performs real-time analysis through Kafka streaming data and preset rules. It can improve the accuracy and response speed of attack detection, detect and prevent further harm in time when an attack occurs, and achieve efficient honeypot services and security protection at a lower cost and with less resource investment. Compared with traditional honeypot technology, this solution has a wider coverage and is simpler to manage and maintain.

[0070] The embodiment of the present application also provides a honeypot service method based on port proxy applied to the honeypot background, such as Figure 3 As shown, the method includes:

[0071] Step 301: Filter out devices to be monitored that require abnormal behavior monitoring in a device cluster.

[0072] The device cluster in the embodiment of the present application includes at least one of a first device from a production network and a second device from an office network. The honeypot backend performs device screening in the device cluster to screen out devices that need to be monitored for abnormal behavior, so as to determine the devices to be monitored in the device cluster. The devices to be monitored include at least some of the devices in the device cluster.

[0073] Step 302: After the HIDS plug-in is deployed on the device to be monitored, a port monitoring policy is issued to the HIDS plug-in of each device to be monitored. The port monitoring policy is used to instruct the HIDS plug-in to monitor network connection requests initiated to the target port of the device to be monitored and record request information corresponding to the network connection request. The target port is a monitoring port that is unrelated to the business running on the device to be monitored. Among them, after the request information recorded by the HIDS plug-in is transmitted to the intrusion detection system via the data processing platform, the intrusion detection system performs abnormal behavior detection on the request information based on preset rules, and outputs alarm information when abnormal behavior is detected.

[0074] After the devices to be monitored are determined in the device cluster and the HIDS plug-in is deployed on the devices to be monitored, the honeypot backend sends a matching port monitoring policy to the HIDS plug-in of each device to be monitored. The port monitoring policy sent specifies the target port to be monitored. For each device to be monitored, the honeypot backend obtains the port list corresponding to the device to be monitored. The port list includes port identifiers corresponding to all ports of the device to be monitored, such as port numbers. The port numbers of occupied ports in the port list are marked with occupants. Based on the occupants, occupied ports and unoccupied ports can be quickly and effectively distinguished. The honeypot backend identifies unoccupied ports in the port list and determines the ports that meet the attack conditions as target ports among the identified ports.

[0075] After the honeypot backend sends the port monitoring policy to the HIDS plug-in of each device to be monitored, the HIDS plug-in dynamically monitors the corresponding target port based on the port monitoring policy to capture the attack behavior launched by the attacker on the target port.

[0076] After monitoring the attacker's network connection requests to the target port and recording the corresponding request information, the HIDS plug-in provides the request information to the data processing platform, which transmits the request information to the intrusion detection system for real-time analysis. When the intrusion detection system detects abnormal behavior (such as scanning attacks, brute force cracking, etc.), it outputs an alarm message, notifying security personnel and requiring them to take appropriate defensive measures. This response mechanism responds to attacks through a linkage mechanism, achieving a timely response to network security incidents.

[0077] As an optional implementation scheme, the honeypot backend can also receive the load status and resource usage of the monitored device reported by the HIDS plug-in. Based on the information reported by the HIDS plug-in, the honeypot backend understands the resource usage (such as CPU, memory, network bandwidth, etc.) of the monitored device and the load status of the monitored device. When it is determined that the load of the monitored device is too large and / or the resource usage is too much, the honeypot backend sends a shutdown command to the HIDS plug-in deployed on the monitored device, causing the HIDS plug-in to suspend port monitoring, so as to reasonably utilize the resources of the monitored device and reduce the load of the monitored device.

[0078] As another optional implementation scheme, the honeypot backend obtains a device list corresponding to the device cluster, which includes a device identifier corresponding to each device in the device cluster, and the device identifier corresponding to the device to be monitored with the HIDS plug-in deployed has a first marking symbol, and the device identifier corresponding to the device to be monitored with the HIDS plug-in in normal working condition has a second marking symbol. The honeypot backend can identify the first device set corresponding to the device to be monitored with the HIDS plug-in deployed based on the first marking symbol, and identify the second device set in the first device set with the HIDS plug-in in normal working condition based on the second marking symbol.

[0079] After identifying the first device set and the second device set, the honeypot backend groups the device assets based on the first device set, the second device set and the device cluster. Based on the grouping, it understands which devices in the device cluster are monitored and which HIDS plug-ins deployed on the monitored devices are working normally, thereby managing the device assets.

[0080] The above implementation scheme of the present application, by combining the port proxy with the existing production office environment and using preset rules to analyze attack behaviors, can improve the accuracy and response speed of attack detection, and can achieve efficient honeypot services and security protection at a lower cost and with less resource investment. Compared with traditional honeypot solutions, the honeypot service of this application has a wider coverage and is simpler to manage and maintain.

[0081] By understanding the resource usage and load of the monitored device, the HIDS plug-in can be controlled to suspend port monitoring when the load and / or resource usage of the monitored device are too large, thereby rationally utilizing the resources of the monitored device and reducing the load on the monitored device. By grouping devices in the device cluster, device assets can be effectively managed.

[0082] The embodiment of the present application also provides a honeypot service method based on port proxy applied to an intrusion detection system, such as Figure 4 As shown, the method includes:

[0083] Step 401: Receive request information provided by the HIDS plug-in and transmitted via the data processing platform. The HIDS plug-in is deployed on the device to be monitored. The device to be monitored is a device that is screened out in the device cluster and needs to be monitored for abnormal behavior. The HIDS plug-in monitors the network connection request initiated to the target port of the device to be monitored based on the port monitoring policy issued by the honeypot background and records the request information corresponding to the network connection request. The target port is a monitoring port that is unrelated to the business running on the device to be monitored.

[0084] The intrusion detection system communicates with the data processing platform, which in turn communicates with the HIDS plug-in deployed on the devices to be monitored. These devices are those selected from the device cluster for abnormal behavior monitoring. The HIDS plug-in monitors network connection requests initiated to the target port based on the port monitoring policy and records the corresponding request information. The HIDS plug-in then provides the recorded request information to the data processing platform, which then provides the request information to the intrusion detection system.

[0085] The port monitoring policy is provided by the honeypot backend. The policy specifies the target port to be monitored, and the target port is a monitoring port unrelated to the services running on the monitored device. For each device to be monitored, the honeypot backend identifies unoccupied ports and, among these identified unoccupied ports, determines the port that meets the attack criteria as the target port. Based on the target port, the port monitoring policy is issued to the corresponding HIDS plug-in.

[0086] Step 402: Perform abnormal behavior detection on the received request information based on preset rules, and output alarm information when abnormal behavior is detected.

[0087] After receiving the request information transmitted by the data processing platform and provided by the HIDS plug-in, the intrusion detection system detects abnormal behavior of the collected request information according to pre-set rules, and outputs alarm information when abnormal behavior is detected (such as scanning attacks, brute force cracking, etc.), notifies security personnel and takes corresponding defensive measures to respond to attacks through the linkage mechanism and achieve timely response to network security incidents.

[0088] The request information includes at least: a local IP address, a local port number, a remote IP address, and a timestamp; when abnormal behavior detection is performed on the received request information based on preset rules and an alarm message is output when abnormal behavior is detected, it includes:

[0089] Detecting, based on the received request information, whether there is a first abnormal behavior in which the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first duration, and detecting whether there is a second abnormal behavior in which the same local port receives network connection requests exceeding a second threshold within a second duration;

[0090] In response to detecting the first abnormal behavior, outputting an alarm message indicating the presence of abnormal scanning behavior; and / or, in response to detecting the second abnormal behavior, outputting an alarm message indicating the presence of brute force cracking behavior.

[0091] After receiving the request information provided by the HIDS plug-in, the intrusion detection system detects, based on the local IP address and remote IP address carried in the request information, whether there is a first abnormal behavior in which the same remote IP address initiates more than, for example, five network connection requests to different local IP addresses within a short period of time (e.g., one second). Furthermore, based on the local port number carried in the request information, the intrusion detection system detects whether there is a second abnormal behavior in which the same local port receives more than, for example, five network connection requests within a short period of time (e.g., 0.5 seconds).

[0092] When the first abnormal behavior is detected, it is determined that the attacker has launched a scanning attack on the local device, and an alarm message indicating the presence of abnormal scanning behavior is output. The alarm message may carry the remote IP address corresponding to the attacker who launched the scanning attack, and may also carry the local IP address that suffered the scanning attack. When the second abnormal behavior is detected, it is determined that the local port has suffered a brute force attack launched by a remote device corresponding to one or more remote IP addresses, and an alarm message indicating the presence of brute force attack is output. The alarm message may carry the port number corresponding to the local port of the monitored device that suffered the attack, and may also carry the one or more remote IP addresses that launched the attack.

[0093] Optionally, the request information also includes the device identification of the device to be monitored, such as a device ID, which is used to distinguish different devices. For any device to be monitored, it can have one or more local IP addresses. When performing the first abnormal behavior detection, the intrusion detection system further identifies whether different local IP addresses correspond to the same device identification. If different local IP addresses correspond to the same device identification, it is determined that the attacker has launched a scanning attack on the device to be monitored corresponding to the current device identification. At this time, the output alarm information carries the device identification of the device to be monitored that has suffered the scanning attack, so that the device under attack can be quickly located based on the device identification.

[0094] The device cluster in the embodiment of the present application includes a first device from a production network and / or a second device from an office network, where the first device is, for example, a production network server and the second device is, for example, a PC. The second device, as a device within the office network, has a Local OA account (local operation account), and the specific person using the second device can be located based on the local operation account. When the intrusion detection system detects that the second device from the office network is under a scanning attack and / or a brute force attack, it can locate the specific person based on the local operation account included in the request information, and determine the device used by the person as the attacked device, so as to quickly locate the attacked device.

[0095] The above-mentioned implementation scheme of the present application, by implementing low-cost, high-efficiency honeypot services on production network equipment and / or office network equipment, can detect attacks in a timely manner when they occur, and through real-time monitoring and multi-level alarm mechanisms, can effectively respond to common attack behaviors and prevent each attack through a linkage mechanism.

[0096] An embodiment of the present application also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and runnable on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned honeypot service method embodiment based on the port proxy are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0097] For example, Figure 5 FIG. 1 shows a schematic diagram of the physical structure of an electronic device. Figure 5 As shown, the electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540, wherein the processor 510, the communication interface 520, and the memory 530 communicate with each other via the communication bus 540. The processor 510 can call the logic instructions in the memory 530, and the processor 410 is used to execute the various processes of the honeypot service method based on the port proxy in the embodiment of the present application, which will not be elaborated one by one here.

[0098] In addition, the logic instructions in the above-mentioned memory 530 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.

[0099] The present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the various processes of the above-mentioned honeypot service method embodiment based on a port proxy are implemented, and the same technical effects are achieved. To avoid repetition, the details are not described here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0100] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0101] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0102] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A honeypot service system based on port proxy, characterized in that: include: Honeypot backend, data processing platform, intrusion detection system, and HIDS plug-in deployed on the devices to be monitored. The devices to be monitored are devices that need to be monitored for abnormal behavior selected from the device cluster; The honeypot backend sends the port monitoring strategy to the HIDS plug-in of each device to be monitored; The HIDS plug-in monitors network connection requests initiated to a target port of the device to be monitored based on the port monitoring policy and records request information corresponding to the network connection request, wherein the target port is a monitoring port unrelated to the service run by the device to be monitored; The intrusion detection system receives the request information provided by the HIDS plug-in and transmitted via the data processing platform, performs abnormal behavior detection on the request information based on preset rules, and outputs alarm information when abnormal behavior is detected.

2. The honeypot service system based on port proxy according to claim 1, characterized in that: For each device to be monitored, the honeypot backend obtains a port list corresponding to the device to be monitored, identifies unoccupied ports of the device to be monitored in the port list, and determines the target port from the identified ports; The honeypot backend generates a matching port monitoring policy according to the determined target port and sends it to the HIDS plug-in of the device to be monitored, and the HIDS plug-in monitors the attack behavior launched on the target port; The occupied ports in the port list are marked with an occupied symbol, and the target port is a port that meets the attack condition among the unoccupied ports.

3. The honeypot service system based on port proxy according to claim 1, characterized in that: The request information includes at least: local IP address, local port number, remote IP address and timestamp; The intrusion detection system detects, based on the received request information, whether there is a first abnormal behavior in which the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first time period, and detects whether there is a second abnormal behavior in which the same local port receives network connection requests exceeding a second threshold within a second time period; In response to detecting the first abnormal behavior, the intrusion detection system outputs an alarm message indicating the presence of abnormal scanning behavior; and / or, in response to detecting the second abnormal behavior, the intrusion detection system outputs an alarm message indicating the presence of brute force cracking behavior.

4. The honeypot service system based on port proxy according to claim 3 is characterized in that: The request information also includes: a device identifier of the device to be monitored; In response to the device to be monitored corresponding to at least two local IP addresses, the intrusion detection system, upon detecting that the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first time period, identifies whether the different local IP addresses correspond to the same device identifier; In response to the different local IP addresses corresponding to the same device identifier, it is determined that the device to be monitored corresponding to the current device identifier is subject to a scanning attack.

5. The honeypot service system based on port proxy according to claim 3 or 4, characterized in that: The device cluster includes at least one of a first device from a production network and a second device from an office network, and the request information associated with the second device further includes a local operation account; In response to detecting that a second target device from an office network is subjected to a scanning attack and / or a brute force attack, the intrusion detection system locates the attacked object based on a local operation account corresponding to the second target device.

6. The honeypot service system based on port proxy according to claim 1, characterized in that: The HIDS plug-in monitors the load and resource usage of the device to be monitored and reports it to the honeypot backend; In response to the load condition and / or resource occupancy of the device to be monitored meeting a preset condition, the honeypot backend sends a shutdown instruction to the HIDS plug-in of the device to be monitored.

7. The honeypot service system based on port proxy according to claim 1, characterized in that: The honeypot backend obtains a device list corresponding to the device cluster, wherein the device list includes a device identifier corresponding to each device in the device cluster; The honeypot backend identifies a first device set corresponding to the device to be monitored on which the HIDS plug-in is deployed based on the device list, and identifies a second device set in which the HIDS plug-in is in a normal working state in the first device set based on the device list; The honeypot backend performs device asset grouping based on the identified first device set, the second device set, and the device cluster; Among them, in the device list, the device identifier corresponding to the device to be monitored where the HIDS plug-in is deployed has a first marking symbol, and the device identifier corresponding to the device to be monitored where the HIDS plug-in is in normal working state has a second marking symbol.

8. A honeypot service method based on port proxy, applied to the honeypot background, characterized in that: The method comprises: Filter out the devices to be monitored for abnormal behavior in the device cluster; After the HIDS plug-in is deployed on the device to be monitored, a port monitoring policy is issued to the HIDS plug-in of each device to be monitored, wherein the port monitoring policy is used to instruct the HIDS plug-in to monitor network connection requests initiated to the target port of the device to be monitored and record request information corresponding to the network connection request, where the target port is a monitoring port that is unrelated to the service running on the device to be monitored; Among them, after the request information recorded by the HIDS plug-in is transmitted to the intrusion detection system via the data processing platform, the intrusion detection system performs abnormal behavior detection on the request information based on preset rules and outputs alarm information when abnormal behavior is detected.

9. A honeypot service method based on port proxy, applied to intrusion detection system, characterized in that: The method comprises: Receiving request information provided by a HIDS plug-in and transmitted via a data processing platform, the HIDS plug-in is deployed on a device to be monitored, the device to be monitored is a device that is screened out from a device cluster and needs to be monitored for abnormal behavior, and the HIDS plug-in monitors network connection requests initiated to a target port of the device to be monitored based on a port monitoring policy issued by a honeypot backend, and records request information corresponding to the network connection request, the target port being a monitoring port unrelated to the business run by the device to be monitored; The received request information is subjected to abnormal behavior detection based on preset rules, and an alarm message is output when abnormal behavior is detected.

10. The honeypot service method based on port proxy according to claim 9, characterized in that: The request information includes at least: local IP address, local port number, remote IP address and timestamp; The detecting abnormal behavior of the received request information based on preset rules and outputting alarm information when abnormal behavior is detected includes: Detecting, based on the received request information, whether there is a first abnormal behavior in which the same remote IP address initiates network connection requests exceeding a first threshold to different local IP addresses within a first duration, and detecting whether there is a second abnormal behavior in which the same local port receives network connection requests exceeding a second threshold within a second duration; In response to detecting the first abnormal behavior, outputting an alarm message indicating the presence of abnormal scanning behavior; And / or, in response to detecting the second abnormal behavior, outputting an alarm message indicating the presence of brute force cracking behavior.