Honey spot deployment optimization method, device, electronic device and storage medium

By acquiring honey spot detection information, calculating multi-dimensional evaluation of honey spot deployment value, and optimizing honey spot deployment, the problem of poor honey spot deployment accuracy is solved, and network defense effectiveness and resource utilization are improved.

CN120639507BActive Publication Date: 2025-10-28PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511087892.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-10-28
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

Existing technologies have poor accuracy in honeypot deployment optimization, resulting in limited improvement in threat detection effectiveness.

Method used

By acquiring honey-hunting information of the target network, we calculate the substitutability, honey-hunting repetition rate, and simulation efficiency of honey points, assign weight coefficient groups for weight adjustment, perform cluster analysis, remove unnecessary honey points, and optimize honey point deployment.

Benefits of technology

It improves the accuracy of honeypot deployment and enhances the defense capabilities and resource utilization efficiency of the target network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639507B_ABST
    Figure CN120639507B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, electronic device, and storage medium for optimizing honeypot deployment, belonging to the field of network security technology. The method includes: acquiring honeypot detection information of a target network; for each honeypot, determining substitutability information based on honeypot-detecting IP addresses with which the honeypot has a honeypot detection relationship, determining honeypot detection repetition rate information based on other honeypots with which the honeypot has a honeypot detection relationship, and determining simulation efficiency information based on attack threat tags; assigning negative weights to the substitutability information and honeypot detection repetition rate information, assigning positive weights to the simulation efficiency information, obtaining an initial weight coefficient set based on the negative and positive weights, and calculating an initial honeypot effect value based on the initial weight coefficient set; performing at least one weight adjustment on the initial weight coefficient set to obtain a target weight coefficient set; determining the updated target honeypot effect value based on the target weight coefficient set, and removing the corresponding honeypot when the target honeypot effect value is lower than a preset effect threshold.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a honeypot deployment optimization method, apparatus, electronic device, and storage medium. Background Technology

[0002] Honeypot technology is a proactive defense technique that enhances the protection of a target network by deploying fake systems or services as bait to lure attackers into intrusions and capture their attack behavior. Honeypoints are the core component of honeypot technology; they are nodes, probes, or other decoys deployed in the target network to monitor attack traffic in real time, capture attackers, and collect threat intelligence.

[0003] In target networks where honeypots have already been deployed, related technologies perform traffic statistics on the Internet Protocol Addresses (IP addresses) of the attacking honeypots, such as counting access frequency and connection counts, and use the traffic statistics results as a basis to adjust the deployment of honeypots on the target network. However, the basis obtained in this method is too one-sided, resulting in no significant improvement in the threat detection effect of the adjusted honeypots. In other words, the related technologies suffer from poor accuracy in optimizing the deployment of honeypots on the target network. Summary of the Invention

[0004] The main objective of this application is to provide a honeypot deployment optimization method, apparatus, electronic device, and storage medium, which aims to improve the accuracy of honeypot deployment optimization in a target network.

[0005] To achieve the above objectives, a first aspect of this application proposes a honeypot deployment optimization method, the method comprising:

[0006] Obtain honey trapping information of the target network. The target network has multiple honey traps pre-deployed for trapping attacks. The honey trapping information indicates the honey trapping IP address and attack threat tag corresponding to the honey trap that successfully traps the attack.

[0007] For each honeypot, substitutability information is determined based on the honeypot-kicking IP addresses that have a honeypot-kicking relationship with the honeypot, honeypot-kicking repetition rate information is determined based on other honeypots that have a honeypot-kicking relationship with the honeypot, and simulation efficiency information is determined based on attack threat tags.

[0008] Negative weights are assigned to substitutability information and honey repetition rate information, and positive weights are assigned to simulation efficiency information. An initial weight coefficient set is obtained based on the negative and positive weights. The initial honey point effect value is calculated based on the initial weight coefficient set, substitutability information, honey repetition rate information, and simulation efficiency information.

[0009] Cluster analysis is performed on all honey spots to obtain cluster analysis results that characterize the deployment effect of each honey spot group. Based on the cluster analysis results and the initial honey spot effect values, the initial weight coefficient group is adjusted at least once to obtain the target weight coefficient group.

[0010] The initial honeypot effect value is updated based on the target weight coefficient group to obtain the updated target honeypot effect value. When the target honeypot effect value corresponding to a honeypot is lower than the preset effect threshold, the corresponding honeypot is removed.

[0011] In some embodiments, determining substitutability information based on the IP addresses of those who have a honey-fighting relationship with the honey point includes:

[0012] Count the number of IP addresses that have a honey-fighting relationship with the current honey point, and obtain the total number of honey-fighting IPs corresponding to the current honey point;

[0013] From the honey-following IP addresses that have a honey-following relationship with the current honey point, count the number of honey-following IP addresses with non-unique honey-following characteristics to obtain the total number of non-unique honey-following IP addresses.

[0014] Substitutability information is obtained by comparing the ratio of the total number of non-unique honey-feeding IPs to the total number of honey-feeding IPs.

[0015] In some embodiments, determining the honey-feeding repetition rate information based on other honey points associated with a honey point includes:

[0016] Identify the IP addresses that have a honey-breaking relationship with the current honey point as associated honey-breaking IP addresses. For each associated honey-breaking IP address, identify other honey points besides the current honey point that has been broken into as associated honey points of the current honey point.

[0017] For each associated honeypot, determine the number of associated honeypot IP addresses that are simultaneously attacking the current honeypot and the associated honeypot, and obtain the first duplicate statistics for each associated honeypot.

[0018] The first duplicate statistics of each associated honeypot are accumulated to obtain the second duplicate statistics of the current honeypot. The duplicate rate information is obtained by calculating the ratio of the second duplicate statistics to the total number of honeypot-using IPs.

[0019] In some embodiments, determining simulation efficiency information based on attack threat labels includes:

[0020] For each associated honey-sniffing IP address, the threat level of all attack threat tags belonging to the associated honey-sniffing IP address is scored to obtain sub-threat level information;

[0021] The total threat level information is obtained by summing up the sub-threat level information of all associated honeybee-detecting IP addresses;

[0022] The simulation efficiency information is obtained by comparing the total threat level information with the total number of compromised IPs.

[0023] In some embodiments, threat level scores are performed on all attack threat tags belonging to the associated honeypot IP address to obtain sub-threat level information, including:

[0024] Obtain risk quantification standard information;

[0025] Based on risk quantification standard information, the threat level of each attack threat tag associated with the honey-fighting IP address is scored, and a single score is obtained for each attack threat tag.

[0026] The sub-threat level information is obtained by summing the individual scores of all attack threat tags belonging to the currently associated honeypot IP address.

[0027] In some embodiments, the negative weights include a first negative weight and a second negative weight;

[0028] Negative weights are assigned to substitutability information and honey-picking repetition rate information, while positive weights are assigned to simulation efficiency information. An initial weight coefficient set is obtained based on these negative and positive weights. Then, based on the initial weight coefficient set, substitutability information, honey-picking repetition rate information, and simulation efficiency information, the initial honey-point effect value is calculated, including:

[0029] Assign a first negative weight to substitutability information, a second negative weight to honey-picking repetition rate information, and a positive weight to simulation efficiency information.

[0030] The first negative weight is multiplied by the substitutability information to obtain the first multiplier value, and the second negative weight is multiplied by the honey-following repetition rate information to obtain the second multiplier value. The result of adding the first multiplier value and the second multiplier value is regarded as the negative value information.

[0031] The result of multiplying the positive weights and the simulation efficiency information is regarded as positive value information. The negative value information and the positive value information are superimposed to obtain the initial honey point effect value.

[0032] In some embodiments, based on clustering analysis results and initial honeypot effect values, the initial weight coefficient group is subjected to at least one weight adjustment process to obtain the target weight coefficient group, including:

[0033] Obtain the target optimization function and the preset initial learning rate. Based on the initial honeypot effect value and cluster analysis results, determine the first target optimization function value corresponding to the target optimization function.

[0034] Based on the objective optimization function and the initial learning rate, the initial weight coefficient group is adjusted to obtain the updated weight coefficient group. The updated honeypot effect value is determined based on the updated weight coefficient group. Based on the updated honeypot effect value and the cluster analysis results, the value of the second objective optimization function corresponding to the objective optimization function is determined.

[0035] If the value of the first objective optimization function is better than the value of the second objective optimization function, the initial weight coefficient set is retained, and the initial learning rate is updated to obtain the updated initial learning rate; otherwise, the updated honeypot effect value is used as the new initial honeypot effect value, and a new objective optimization function is determined based on the new initial honeypot effect value.

[0036] Based on the updated initial learning rate or the new objective optimization function and the new initial honeypot effect value, perform at least one more weight adjustment process until the preset iteration conditions are met, and use the last updated weight coefficient as the target weight coefficient group.

[0037] In some embodiments, an updated weight coefficient set is obtained by adjusting the initial weight coefficient set according to the objective optimization function and the initial learning rate, including:

[0038] Based on the objective optimization function, partial derivatives are taken with respect to the first negative weight, the second negative weight, and the positive weight to obtain the first negative gradient descent value, the second negative gradient descent value, and the positive gradient descent value.

[0039] The first negative weights are updated based on the initial learning rate and the first negative gradient descent value to obtain the optimized first negative weights. The second negative weights are updated based on the initial learning rate and the second negative gradient descent value to obtain the optimized second negative weights. The positive weights are updated based on the initial learning rate and the positive gradient descent value to obtain the optimized positive weights.

[0040] Determine the optimization of the first negative weight, the second negative weight, and the positive weight to update the weight coefficient group.

[0041] To achieve the above objectives, a second aspect of this application provides a honeypot deployment optimization apparatus, comprising:

[0042] The acquisition module is used to acquire honeypot information of the target network. The target network has multiple honeypots pre-deployed for trapping attacks. The honeypot information indicates the honeypot IP address and attack threat tag corresponding to the honeypot that successfully traps the attack.

[0043] The multi-dimensional evaluation information module is used to determine the substitutability information for each honeypot based on the honeypot-penetrating IP addresses that have a honeypot-penetrating relationship with the honeypot, determine the honeypot-penetrating repetition rate information based on other honeypots that have a honeypot-penetrating relationship with the honeypot, and determine the simulation efficiency information based on the attack threat label.

[0044] The honey spot effect value calculation module is used to assign negative weights to substitutability information and honey spot repetition rate information, and positive weights to simulation efficiency information. Based on the negative and positive weights, an initial weight coefficient set is obtained, and based on the initial weight coefficient set, substitutability information, honey spot repetition rate information and simulation efficiency information, the initial honey spot effect value is calculated.

[0045] The weight adjustment module is used to perform cluster analysis on all honey spots, obtain cluster analysis results that characterize the deployment effect of each honey spot group, and perform at least one weight adjustment process on the initial weight coefficient group based on the cluster analysis results and the initial honey spot effect values ​​to obtain the target weight coefficient group.

[0046] The honeypot deployment optimization module is used to update the initial honeypot effect value based on the target weight coefficient group, obtain the updated target honeypot effect value, and remove the corresponding honeypot when the target honeypot effect value is lower than the preset effect threshold.

[0047] To achieve the above objectives, a third aspect of the present application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the honeypot deployment optimization method of the first aspect.

[0048] To achieve the above objectives, a fourth aspect of the present application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the honeypot deployment optimization method of the first aspect.

[0049] This application proposes a method, apparatus, electronic device, and storage medium for optimizing honeypot deployment. It acquires honeypot detection information from a target network, where the target network pre-deploys multiple honeypots for decoy attacks. The detection information indicates the detection IP address and attack threat tag corresponding to the successfully detected honeypot. For each honeypot, substitutability information is determined based on the detection IP addresses associated with it, honeypot repetition rate information is determined based on other honeypots associated with it, and simulation efficiency information is determined based on the attack threat tag. These three indicators comprehensively evaluate the deployment value and optimization potential of the corresponding honeypot. Next, negative weights are assigned to substitutability and honeypot repetition rate information, and positive weights are assigned to simulation efficiency information. An initial weight coefficient set is obtained based on the negative and positive weights, and then... The initial honeypot effect value is calculated based on honeypot repetition rate information and simulation efficiency information. Negative and positive weights reflect the influence of different indicators on the honeypot value. Assigning different value weights guides the evaluation process to more accurately reflect potential threats and resource utilization. Next, cluster analysis is performed on all honeypots to obtain cluster analysis results representing the deployment effect of each honeypot group. Based on the cluster analysis results and the initial honeypot effect value, the initial weight coefficient group is adjusted at least once to obtain the target weight coefficient group. Finally, the initial honeypot effect value is updated based on the target weight coefficient group to obtain the updated target honeypot effect value. When the target honeypot effect value of a honeypot is lower than a preset effect threshold, the corresponding honeypot is removed to avoid unnecessary resource waste, thereby improving the accuracy of honeypot deployment optimization in the target network. Attached Figure Description

[0050] Figure 1 This is a schematic diagram of an optional implementation environment for the honeypot deployment optimization device provided in this application embodiment;

[0051] Figure 2 This is an optional flowchart of the honeypot deployment optimization method provided in the embodiments of this application;

[0052] Figure 3 yes Figure 2 Step 102 in the flowchart is an optional implementation.

[0053] Figure 4 yes Figure 2 Step 102 in the flowchart is another optional implementation.

[0054] Figure 5 yes Figure 2 Step 102 in the flowchart is another optional implementation.

[0055] Figure 6 yes Figure 5Step 102.3.1 is an optional implementation flowchart;

[0056] Figure 7 yes Figure 2 Step 103 is an optional implementation flowchart;

[0057] Figure 8 yes Figure 2 Step 104 in the flowchart is an optional implementation.

[0058] Figure 9 yes Figure 8 Step 104.1.2 is an optional implementation flowchart;

[0059] Figure 10 This is a schematic diagram of an optional device module of the honey spot deployment optimization device provided in the embodiments of this application;

[0060] Figure 11 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0062] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0063] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0064] First, let's analyze the terms used in this application:

[0065] An Internet Protocol (IP) address is a digital label assigned to each device connected to a computer network. IP addresses are used to uniquely identify a device in a network and help enable data transmission and communication between devices. IP addresses ensure that sent data accurately reaches the target device.

[0066] Next, the technical background related to the embodiments of this application will be introduced:

[0067] Honeypot technology is a proactive defense technique that enhances the protection of a target network by deploying fake systems or services as bait to lure attackers into intrusions and capture their attack behavior. Honeypoints are the core component of honeypot technology; they are nodes, probes, or other decoys deployed in the target network to monitor attack traffic in real time, capture attackers, and collect threat intelligence.

[0068] In target networks where honeypots have already been deployed, related technologies perform traffic statistics on the internet protocol addresses of the attacking honeypots, such as counting access frequency and connection counts, and use the traffic statistics results as a basis to adjust the deployment of honeypots on the target network. However, the basis obtained in this way is too one-sided, so the threat detection effect of the adjusted honeypots is not significantly improved. In other words, the related technologies suffer from poor accuracy in optimizing the deployment of honeypots on the target network.

[0069] Based on this, embodiments of this application provide a honeypot deployment optimization method, apparatus, electronic device, and storage medium, aiming to improve the accuracy of honeypot deployment optimization in a target network.

[0070] For example, such as Figure 1 As shown, Figure 1This is a schematic diagram of an optional implementation environment for the honeypot deployment optimization device provided in this application embodiment. The implementation environment includes a client 11 and a server 12 of the target network. Multiple clients 11 can access the target network at any time. The honeypot deployment optimization device (which can also be simply referred to as the "optimization device" for ease of description) is deployed on the server 12. After multiple clients 11 complete access to the target network, the server 12 obtains the honeypot detection information of the target network. The target network has multiple pre-deployed honeypots for trapping attacks. The honeypot detection information indicates the honeypot IP address and attack threat tag corresponding to the successfully targeted honeypot. For each honeypot, substitutability information is determined based on the honeypot IP addresses that have a honeypot detection relationship with the honeypot, honeypot repetition rate information is determined based on other honeypots associated with the honeypot, and simulation efficiency information is determined based on the attack threat tag. Negative weights are assigned to substitutability information and honeypot repetition rate information, and positive weights are assigned to simulation efficiency information. An initial weight coefficient set is obtained by summing positive weights. Based on the initial weight coefficient set, substitutability information, honeypot repetition rate information, and simulation efficiency information, the initial honeypot effect value is calculated. Cluster analysis is performed on all honeypots to obtain cluster analysis results characterizing the deployment effect of each honeypot group. Based on the cluster analysis results and the initial honeypot effect value, the initial weight coefficient set is adjusted at least once to obtain the target weight coefficient set. The initial honeypot effect value is updated based on the target weight coefficient set to obtain the updated target honeypot effect value. When the target honeypot effect value of a honeypot is lower than a preset effect threshold, the corresponding honeypot is removed. Thus, this application successfully obtains attackers' honeypot detection information by deploying multiple honeypots for decoy attacks in the target network. Based on the detection information, the substitutability, honeypot repetition rate, and simulation efficiency of the honeypots are analyzed, providing a multi-dimensional evaluation basis for the honeypot deployment effect. This allows for the timely removal of ineffective honeypots based on the target honeypot effect value, improving resource utilization efficiency while enhancing the overall defense capability of the target network.

[0071] The server 12 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. Additionally, the server 12 can also be a node server in a blockchain network. The client 11 can be a mobile phone, computer, smart voice interaction device, smart wearable device, smart home appliance, in-vehicle terminal, etc., but is not limited to these. The client 11 and the server 12 can be connected directly or indirectly through wired or wireless communication, which is not limited in this embodiment.

[0072] It should be noted that in this application embodiment, when information related to user characteristics, such as basic user information or user identity, is required, the user's permission or consent will be obtained first. Furthermore, the collection, use, and processing of this data will comply with relevant laws, regulations, and standards. In addition, when this application embodiment needs to obtain sensitive personal information of a user, the user's individual permission or consent will be obtained first. Only after obtaining the user's individual permission or consent will the necessary data for the normal operation of this application embodiment be obtained. For example, before obtaining honey-trapping information of a target network, this application embodiment will obtain the authorization or consent of relevant personnel; otherwise, the honey-trapping information cannot be used in this application embodiment. Furthermore, other relevant data obtained by the optimization device in this application are all authorized data, and will not be elaborated upon here.

[0073] In this application embodiment, the description will focus on the optimization device, which can be integrated into a computer device, such as a server. Figure 2 As shown, Figure 2 This is an optional flowchart of the honeypot deployment optimization method provided in the embodiments of this application. Figure 2 The method may include, but is not limited to, the following steps 101 to 105. When the optimization device executes the honey spot deployment optimization method, the specific process is as follows. It should be noted first that this embodiment... Figure 2 The order of steps 101 to 105 is not specifically limited. The order of steps can be adjusted or some steps can be reduced or added according to actual needs.

[0074] Step 101: Obtain the honey trapping information of the target network. The target network has multiple honeypots pre-deployed for trapping attacks. The honey trapping information indicates the honey trapping IP address and attack threat tag corresponding to the honeypot that successfully traps the attack.

[0075] Step 101 will be described in detail below.

[0076] The target network refers to the specific network environment where network security protection and threat intelligence gathering are to be carried out. For example, the target network can be an enterprise internal network, a data center, or an Internet of Things (IoT) device network (the target network can be specifically selected based on actual circumstances, and this application embodiment does not impose any limitations on this). It is understood that the target network is the actual location where this application embodiment deploys honeypots, lures attacks, and conducts monitoring. Thus, by setting up deceptive resources to attract and monitor the behavior of potential attackers to obtain honeypot detection information, it is helpful to subsequently optimize the current honeypot deployment based on the honeypot detection information, thereby enhancing the network security protection of the target network and improving the overall security posture.

[0077] In this context, a honeypot refers to a fake system, service, or network node pre-deployed within a target network to lure attackers. As sentinels within the target network, honeypots aim to attract attackers and collect threat intelligence by recording their behavior. This allows relevant personnel to issue early warnings about potential threats to the target network. Typically, multiple honeypots are deployed within a target network, forming a "honeypot network."

[0078] Here, "honey trapping information" refers to various data recorded after an attacker successfully interacts with a honeypot. Honey trapping information is a direct product of honeypot-luring attacks. It includes at least the attacker's source IP address (i.e., the honey trapping IP address) and the threat type or attack behavior tag involved in the attack (i.e., the attack threat tag). Of course, honey trapping information can be configured according to actual circumstances. Furthermore, it can also include more detailed log data such as attack time, attack port, attack payload, and damaged services. This application embodiment does not limit the specific content included in the honey trapping information.

[0079] For example, the honey-hunting information of a target network is shown in Table 1 below:

[0080] Table 1

[0081]

[0082] Among them, the "honeycomb IP address" refers to the IP address of the attacker who successfully interacts with the honeypot and triggers the trapping behavior. This information is a key identifier for identifying the source of the attack. It can be the attacker's real IP address or an IP address that has been used through a proxy or jump server. Attack threat tags refer to labels or identifiers that classify, describe, and characterize the attack behaviors captured by the honeypot. These tags indicate the type of attack (such as ransomware attacks, botnet attempts, etc.). Attack threat tags provide semantic descriptions of attack behaviors, assisting in subsequent threat analysis and assessment.

[0083] Furthermore, the optimization device can pre-obtain information about legitimate IP addresses and, from multiple IP addresses interacting with honeypots, identify those IP addresses that mimic legitimate IP addresses but are not actually legitimate IP addresses as honeypot-detecting IP addresses. For example, if a legitimate IP address is www.xxx.com, and the optimization device finds that an IP address interacting with any honeypot is www.xxx1.com, then it determines that www.xxx1.com is a honeypot-detecting IP address.

[0084] In Table 1, each attack threat label is associated with all the corresponding honeypots. For example, number (1) in Table 1 indicates that the honeypot IP address 1 triggered honeypots 1 and 2, and its attack behavior was marked as "network scan" and "regular network scan", indicating that "network attack" and "regular network attack" not only appeared on honeypot 1, but also on honeypot 2. Table 1 is a record of honeypot-attacking behaviors that occurred at different times. That is, number (1) and number (4) both indicate honeypot-attacking behaviors related to IP address 1. IP address 1 attacked honeypots 1, 2 and 4, which does not mean that the IP addresses of number (1) and number (4) are different IP addresses. In addition, the attack threat labels in Table 1 are explained as follows:

[0085] (1) Network scanning: refers to the attacker probing the target network to discover information such as active hosts, open ports, running services and their versions. This is a common step for attackers to collect information and conduct reconnaissance before launching an actual attack.

[0086] (2) Regular network scanning: refers to automated, large-scale network probing without immediate malicious intent. It is usually used to discover potential open ports or connectable hosts, and its purpose may be closer to extensive reconnaissance than immediate attack.

[0087] (3) Web Attack: refers to all attacks against websites, web applications or web servers. These attacks usually exploit vulnerabilities in web technologies and protocols to gain unauthorized access or disrupt web services.

[0088] (4) Botnet: A network of computers or devices that are infected with malware and remotely controlled by an attacker. These controlled devices (called “zombies” or “bots”) can be used to launch large-scale coordinated attacks, such as distributed denial-of-service (DDoS-like Malicious File Callback, DDoS) attacks, sending spam, or stealing data.

[0089] (5) Spam: refers to unauthorized or irrelevant information sent in bulk via email without the recipient's request, in order to achieve purposes such as advertising, phishing scams or spreading malicious software.

[0090] (6) Malicious scanning: Unlike regular network scanning, malicious scanning has an explicit malicious purpose. Attackers use this scanning behavior to discover exploitable vulnerabilities or weaknesses in the target system or service in order to prepare for subsequent intrusion or attack.

[0091] (7) Brute-force attack: Attackers systematically try all possible combinations of characters to guess the correct credentials (such as username and password) until they find the correct combination to gain unauthorized access.

[0092] (8) Internet of Things Attack (IoT attack): Attacks specifically targeting Internet of Things devices (such as smart home devices, wearable devices, industrial sensors, etc.). These attacks exploit security vulnerabilities, weak passwords, or insecure configurations that are common in Internet of Things devices to intrude into, control, or use them as a springboard for launching other attacks.

[0093] (9) DDoS attack: A network attack that sends a massive number of requests to a target server by controlling a large number of infected devices, exhausting resources and causing normal service interruption. Its core purpose is to paralyze the target system through distributed and coordinated attacks, making it unable to respond to legitimate user requests.

[0094] (10) Spam: In a broad sense, spam refers to unnecessary or harassing or fraudulent information that is sent in bulk without request. In addition to spam emails, it may also include spam text messages, advertisements or fraudulent information on social media, etc.

[0095] (11) A popular Web server and reverse proxy server attack (Nginx Server Attack, Nginx attack): refers to an attack specifically targeting Nginx servers. Such attacks usually exploit vulnerabilities or insecure configuration flaws in the Nginx software itself to achieve intrusion or damage to the server.

[0096] (12) Oracle Scanning: A network probing activity specifically targeting Oracle database systems. Attackers use this scan to discover open Oracle database service ports, identify database version information, find known vulnerabilities, or try default / weak credentials in preparation for subsequent attacks on the database.

[0097] (13) Brute-force cracker: usually refers to an automated tool or program used to perform brute-force attacks, which means that the attacker is trying to automate brute-force related traffic or behavior patterns.

[0098] (14) Hijacking: refers to a state in which a system, communication session, user account, or data traffic in a network is illegally controlled or taken over by an unauthorized third party. For example, session hijacking, domain hijacking, or browser hijacking. This is usually the result of an attacker successfully intruding or taking control.

[0099] (15) Automated program bots (Bots): are a component of "botnets". They specifically refer to remotely controlled computers or devices that will perform various malicious tasks according to the attacker's instructions, such as launching DDoS attacks, sending spam, or performing malicious scans.

[0100] It should be noted that the above is an example of the attack threat labels appearing in Table 1. In practice, different attack threat labels of attackers can be recorded according to the actual situation, and it does not mean that the attack threat labels in this application embodiment are limited to the example scope.

[0101] Step 102: For each honeypot, determine the substitutability information based on the honeypot-kicking IP addresses that have a honeypot-kicking relationship with the honeypot, determine the honeypot-kicking repetition rate information based on other honeypots that have a honeypot-kicking relationship with the honeypot, and determine the simulation efficiency information based on the attack threat label.

[0102] Step 102 is described in detail below.

[0103] In some embodiments, to evaluate the deployment effectiveness of each honeypot from multiple dimensions and to optimize the "honeypot network" subsequently, this application embodiment comprehensively evaluates the deployment value and optimization potential of each honeypot by calculating three indicators. These three indicators include substitutability information, honeypot redundancy rate information, and simulation efficiency information. By combining these three indicators, the effectiveness of honeypot deployment in the target network can be significantly improved, potential threats can be better captured, defense effectiveness enhanced, and resource waste reduced, achieving dynamic and precise management of network security.

[0104] Substitutability information is used to measure how easily a honeypot can be replaced by other honeypots. If the attackers attracted by a honeypot (the IP addresses that are "detecting" the honeypot) can also be attracted by other honeypots, then the substitutability of this honeypot is high. Conversely, if a honeypot attracts some unique attackers (that other honeypots do not attract), then its substitutability is low. In other words, honeypots with high substitutability may be removed or adjusted during the optimization process because other honeypots can perform similar functions.

[0105] The honeypot redundancy rate is used to measure whether there is functional overlap between one honeypot and other honeypots. If multiple honeypots attract the same attacker (honeypot IP address), then these honeypots have a high honeypot redundancy rate. In other words, a high honeypot redundancy rate means that these honeypots may be redundant, and some of them can be removed or merged to improve efficiency.

[0106] Simulation efficiency is used to measure the threat level of attacks attracted by a honeypot. A honeypot attracts attacks with higher threat levels, resulting in higher simulation efficiency. This means the honeypot has successfully attracted more dangerous attackers, providing more valuable threat intelligence. In other words, honeypots with high simulation efficiency are more likely to be retained during optimization, and their deployment may even be strengthened.

[0107] The following steps, 102.1.1 to 102.1.3, 102.2.1 to 102.2.3, and 102.3.1 to 102.3.3, will explain in detail the specific methods for determining these three indicators for each honey spot:

[0108] In some embodiments, such as Figure 3 As shown, Figure 3 yes Figure 2 Step 102, an optional implementation flowchart, determines substitutability information based on the IP addresses of those who have a relationship with the honeypot, including the following steps:

[0109] 102.1.1 Count the number of IP addresses that have a honeypot relationship with the current honeypot, and obtain the total number of honeypot IPs corresponding to the current honeypot;

[0110] 102.1.2 From the honey-following IP addresses that have a honey-following relationship with the current honey point, count the number of honey-following IP addresses with non-unique honey-following characteristics, and obtain the total number of non-unique honey-following IP addresses;

[0111] 102.1.3 Based on the ratio of the total number of non-unique honey-using IPs to the total number of honey-using IPs, substitutability information is obtained.

[0112] Steps 102.1.1 to 102.1.3 are described in detail below.

[0113] The total number of IPs that have interacted with the current honeypot and left a trace (i.e., the associated IP addresses in step 102.2.1) refers to the total number of unique IP addresses that have interacted with the current honeypot and left a trace. The total number of IPs that have interacted with the honeypot reflects the breadth of attacker IP sources attracted by the honeypot within a certain period of time, and is one of the most direct indicators for measuring the attack frequency and attractiveness of a honeypot.

[0114] The non-unique honey-feeding characteristic refers to the fact that a particular IP address is reused or associated with multiple honeypots, meaning that the IP address does not uniquely correspond to a specific honeypot, but rather has honey-feeding relationships with multiple honeypots. The total number of non-unique honey-feeding IPs refers to the total number of IP addresses that, among all IP addresses that have fed the current honeypot, have also fed at least one other honeypot in the target network. This total number reveals how many of the honey-feeding IP addresses associated with the current honeypot are shared with other honeypots in the target network, thus helping to assess the uniqueness and substitutability of the information captured by the current honeypot.

[0115] Furthermore, according to the following formula <1> Calculation yields substitutability information :

[0116] <1>

[0117] Furthermore, taking honeypot 1 in Table 1 as an example, the IP addresses that have a honeypot-breaking relationship with the current honeypot (honeypot 1) include IP address 1 and IP address 7, for a total of 2 honeypot-breaking IP addresses; among the honeypot-breaking IP addresses that have a honeypot-breaking relationship with honeypot 4, IP address 1 and IP address 7 both have non-unique honeypot-breaking characteristics, therefore the total number of corresponding non-unique honeypot-breaking IP addresses is 2; and then according to the formula... <1> The calculated substitutability information corresponding to honey spot 1 is 1.

[0118] In some embodiments, such as Figure 4 As shown, Figure 4 yes Figure 2 Step 102 in the flowchart is another optional implementation. It determines the honey-playing repetition rate information based on other honey points that are associated with the honey point, including the following steps:

[0119] 102.2.1 Identify the IP addresses that have a honey-breaking relationship with the current honey point as associated honey-breaking IP addresses. For each associated honey-breaking IP address, identify other honey points besides the current honey point that has been broken as associated honey points of the current honey point.

[0120] 102.2.2 For each associated honeypot, determine the number of associated honeypot IP addresses that are also attacking associated honeypots while attacking the current honeypot, and obtain the first duplicate statistics for each associated honeypot;

[0121] 102.2.3 The first duplicate statistics of each associated honey point are accumulated to obtain the second duplicate statistics of the current honey point. The duplicate rate information is obtained based on the ratio of the second duplicate statistics to the total number of honey-touching IPs.

[0122] Steps 102.2.1 to 102.2.3 are described in detail below.

[0123] Among them, associated honeypot-following IP addresses refer to honeypot-following IP addresses that have a honeypot-following relationship with the current honeypot, and these IP addresses not only involve the current honeypot but also have honeypot-following relationships with other honeypots. In other words, these IP addresses not only attack the current honeypot but also attack one or more different honeypots, which indirectly demonstrates the correlation and multi-point overlap of the attack behavior.

[0124] In this context, associated honeypots refer to other honeypots that have a honeypot-feeding relationship with the current honeypot through a specific associated honeypot-feeding IP address. In other words, in addition to the current honeypot, associated honeypots are also attacked by the same honeypot-feeding IP address, which represents the behavioral association between multiple honeypots by the attacker.

[0125] The first duplicate statistics refer to the number of IP addresses that simultaneously attack both the current honeypot and the associated honeypot for each associated honeypot. In other words, it determines the number of times two honeypots (the current honeypot and the currently specified associated honeypot) are attacked simultaneously from the same attack source (the attacking IP address). The first duplicate statistics help to measure the commonalities in the behavior of two honeypots and the continuity of the attack path.

[0126] The second repetition statistic refers to the sum of the first repetition statistics of all associated honeypots, which represents the total number of repetitions. The second repetition statistic reflects the degree of overlap in attack behavior between the current honeypot and associated honeypots, as well as the attacker's sustained attack behavior.

[0127] Furthermore, according to the following formula <2> Calculate the honey-collecting repetition rate information :

[0128] <2>

[0129] Furthermore, taking honeypot 4 in Table 1 as an example, the honeypot-kicking IP addresses (associated honeypot-kicking IP addresses) that have a honeypot-kicking relationship with the current honeypot (honeypot 4) include IP address 1, IP address 3, and IP address 5, for a total of 3 honeypot-kicking IP addresses; and, the associated honeypots of honeypot 4 include honeypot 1, honeypot 2, honeypot 5, honeypot 6, honeypot 7, and honeypot 8; for each associated honeypot-kicking IP address:

[0130] (1) Honey spot 1:

[0131] IP address 1 attacked both honeypot 4 and honeypot 1;

[0132] IP address 3 did not attack honeypot 1;

[0133] IP address 5 is not attacking honeypot 1;

[0134] Therefore, the first duplicate statistic for honeypot 1 is 1 (IP address 1).

[0135] (2) Honey spot 2:

[0136] IP address 1 attacked honeypots 4 and 2;

[0137] IP address 3 did not attack honeypot 2;

[0138] IP address 5 did not attack honeypot 2;

[0139] Therefore, the first duplicate statistic for honeypot 2 is 1 (IP address 1).

[0140] (3) Honey spot 5:

[0141] IP address 1 is not attacking honeypot 5;

[0142] IP address 3 attacked honeypots 4 and 5;

[0143] IP address 5 attacked honeypots 4 and 5;

[0144] Therefore, the first duplicate statistics for honeypot 4 are 2 (IP address 3, IP address 5).

[0145] (4) Honey spot 6:

[0146] IP address 1 is not attacking honeypot 6;

[0147] IP address 3 attacked honeypots 4 and 6;

[0148] IP address 5 does not have a honeypot for attacking 6;

[0149] Therefore, the first duplicate statistic for honeypot 6 is 1 (IP address 3).

[0150] (5) Honey spot 7:

[0151] IP address 1 is not attacking honeypot 7;

[0152] IP address 3 attacked honeypots 4 and 7;

[0153] IP address 5 attacked honeypots 4 and 7;

[0154] Therefore, the first duplicate statistics for honey spot 7 are 2 (IP address 3, IP address 5).

[0155] (6) Honey spot 8:

[0156] IP address 1 is not attacking honeypot 8;

[0157] IP address 3 is not attacking honeypot 8;

[0158] IP address 5 attacked honeypots 4 and 8;

[0159] Therefore, the first duplicate statistic for honeypot 8 is 1 (IP address 5).

[0160] Furthermore, by accumulating the first repeated statistical information of each associated honey point, the second repeated statistical information corresponding to honey point 4 is obtained as follows: 1(honey point 1) + 1(honey point 2) + 2(honey point 5) + 1(honey point 6) + 2(honey point 7) + 1(honey point 8) = 8; and according to the formula... <2> The honey-feeding repetition rate information corresponding to honey spot 4 was calculated. =8 / 3≈2.67.

[0161] In some embodiments, such as Figure 5 As shown, Figure 5 yes Figure 2 Step 102 in the flowchart is another optional implementation. It determines simulation efficiency information based on attack threat tags, including the following steps:

[0162] 102.3.1 For each associated honeypot IP address, the threat level of all attack threat tags belonging to the associated honeypot IP address is scored to obtain sub-threat level information;

[0163] 102.3.2 Accumulate the sub-threat level information of all associated honeybee-detecting IP addresses to obtain the total threat level information;

[0164] 102.3.3 Based on the ratio of the total threat level information to the total number of compromised IPs, the simulation efficiency information is obtained.

[0165] Steps 102.3.1 to 102.3.3 are described in detail below.

[0166] Specifically, by evaluating and quantifying all different attack threat tags under each associated honeypot IP address, the nature, intensity, and potential harm of these threats are analyzed to obtain sub-threat level information. This sub-threat level information reflects the severity and danger of the threats carried by the associated honeypot IP address, thus helping to determine the threat level of the attack behavior of that associated honeypot IP address.

[0167] The overall threat level information is derived by accumulating the sub-threat level information of all associated honeypot IP addresses, reflecting the overall threat level. This information is obtained by comprehensively evaluating attack threat tags associated with the current honeypot, quantifying the cumulative threat intensity or value of all attacks successfully attracted by the current honeypot within the measured time period. It reflects the overall performance of the current honeypot in capturing high-value threat intelligence.

[0168] Furthermore, according to the following formula <3> Calculate the honey-collecting repetition rate information :

[0169] <3>

[0170] Where n represents the total number of IPs that have been compromised by the current honeypot, and L i Let represent all attack threat tags under the i-th associated honeypot IP address, where l represents the l-th attack threat tag; severity(l) represents the severity score corresponding to the l-th attack threat tag. This represents the sub-threat level information corresponding to the i-th associated honeybee IP address. This indicates the overall threat level of the current honeypot.

[0171] Furthermore, the optimization device can score the severity of each attack threat tag through steps A.1 to A.3 to obtain sub-threat level information:

[0172] In some embodiments, such as Figure 6 As shown, Figure 6 yes Figure 5 Step 102.3.1, an optional implementation flowchart, involves scoring the threat level of all attack threat tags belonging to the associated honeypot IP address to obtain sub-threat level information, including the following steps:

[0173] A.1 Obtain risk quantification standard information;

[0174] A.2 Based on risk quantification standard information, the threat level of all attack threat tags associated with the relevant honey-detecting IP address is scored one by one to obtain the individual score corresponding to each attack threat tag;

[0175] A.3 Accumulate the individual scores of all attack threat tags belonging to the currently associated honeypot IP address to obtain sub-threat level information.

[0176] Steps A.1 to A.3 are described in detail below.

[0177] Among them, risk quantification standard information refers to specific standards, indicators or rules used to measure and assess the risks of various network threats. Risk quantification standard information includes parameters obtained by quantifying the degree of danger, potential impact, probability of occurrence, threat level, etc. of different types of attacks. Through risk quantification standards, the embodiments of this application transform complex threat information into comparable and analyzable values, thereby achieving an objective assessment of the degree of threat.

[0178] The individual score is a specific score obtained by quantifying and evaluating each independent, identified attack threat label (such as "brute force" or "network scanning"). The sub-threat information, on the other hand, is the overall threat assessment score of a specific associated honeypot IP address, obtained by summing or combining all these individual scores.

[0179] For example, the risk quantification standard information obtained includes three items: high risk, medium risk, and low risk. Each item specifically includes:

[0180] High risk (9 points): remote code execution, vulnerability exploitation, DDoS attack, hijacking, botnet;

[0181] Medium risk (5 points): Brute-force attacks, malicious scanning, web attacks, hacking, IoT attacks, botnet attacks, honeypot attacks, penetration testing;

[0182] Low risk (3 points): network scanning, spam, regular network scanning, open source intelligence, information gathering, BRUTE_FORCER.

[0183] It should be noted that the specific content included in high-risk, medium-risk, and low-risk can be set according to actual circumstances, and this application embodiment does not impose any limitations on this. In addition, the risk quantification standard information can also be refined according to actual needs, and is not limited to the three items of high-risk, medium-risk, and low-risk.

[0184] Step 103: Assign negative weights to substitutability information and honey repetition rate information, and assign positive weights to simulation efficiency information. Obtain an initial weight coefficient set based on the negative and positive weights, and calculate the initial honey point effect value based on the initial weight coefficient set, substitutability information, honey repetition rate information, and simulation efficiency information.

[0185] Step 103 will be described in detail below.

[0186] The negative and positive weights reflect the direction of influence of different indicators on the value of honeypots. By assigning different weights to different values, the evaluation process is guided to more accurately reflect potential threats and resource utilization. Next, an initial weight coefficient set is constructed based on the negative and positive weights allocated to each indicator. This initial weight coefficient set helps to reasonably determine the overall effectiveness value of honeypots by comprehensively considering various indicators. Furthermore, by scientifically quantifying the effectiveness of honeypot deployment, high-value and low-value honeypots can be effectively identified, facilitating efficient and accurate honeypot deployment optimization in the future.

[0187] In some embodiments, such as Figure 7 As shown, Figure 7 yes Figure 2 Step 103, an optional implementation flowchart, assigns negative weights to substitutability information and honey-picking repetition rate information, and assigns positive weights to simulation efficiency information. Based on the negative and positive weights, an initial weight coefficient set is obtained. Then, based on the initial weight coefficient set, substitutability information, honey-picking repetition rate information, and simulation efficiency information, the initial honey-point effect value is calculated, including the following steps:

[0188] 103.1.1 Assigns a first negative weight to substitutability information, a second negative weight to honey-tapping repetition rate information, and a positive weight to simulation efficiency information;

[0189] 103.1.2 Multiply the first negative weight and the substitutability information to obtain the first multiplier value, multiply the second negative weight and the honey repetition rate information to obtain the second multiplier value, and add the first multiplier value and the second multiplier value to obtain the negative value information;

[0190] 103.1.3 The result of multiplying the positive weight and the simulation efficiency information is regarded as positive value information. The negative value information and the positive value information are superimposed to obtain the initial honey point effect value.

[0191] Steps 103.1.1 to 103.1.3 are described in detail below.

[0192] In some embodiments, according to the following formula <4> The initial honey spot effect value was calculated. :

[0193] <4>

[0194] in, As positive weights, As the second negative weight, The first negative weight, the initial weight coefficient set is ; As substitute information, For honey-tasting repetition rate information, For simulation efficiency information; First multiplier value, The second multiplier value. This is negative value information; This is positive value information.

[0195] Furthermore, in this embodiment, both the positive and negative weights are within the range of [0,1], and the initial weight coefficient set is [0, 0, 1]. Of course, the actual range and initial values ​​of the initial weight coefficient set can also be set according to the actual situation, and this embodiment does not limit this.

[0196] Step 104: Perform cluster analysis on all honeypots to obtain cluster analysis results that characterize the deployment effect of each honeypot group. Based on the cluster analysis results and the initial honeypot effect values, perform at least one weight adjustment on the initial weight coefficient group to obtain the target weight coefficient group.

[0197] Step 104 is described in detail below.

[0198] In some embodiments, cluster analysis is performed on all honeypots to reveal the effect patterns and inherent laws of different honeypots in actual deployment, thereby identifying groups of honeypots with similar deployment effects (cluster analysis results). Next, unlike traditional methods that rely solely on preset static rules, this embodiment iteratively optimizes the initial weight coefficient set to achieve dynamic weight optimization, resulting in a target weight coefficient set. This target weight coefficient set strengthens the characteristics of valuable honeypots and weakens the characteristics of less valuable honeypots, thus enabling honeypot deployment optimization based on the target honeypot effect values ​​determined by the target weight coefficient set.

[0199] Furthermore, a three-dimensional vector is obtained for each honey spot based on its three indicators. The K-means clustering algorithm was used to perform cluster analysis on it. According to the following formula... <5> The cluster analysis results were obtained:

[0200] <5>

[0201] Where, formula <5> The cluster number is set to 2, which means that the honey points h are divided into two sets; μ1 and μ2 are used to represent the center points of the two clusters, respectively; according to the formula... <5> Clustering yields a set of high-value honey spots, C1, and a set of low-value honey spots, C2.

[0202] K-means clustering is a commonly used unsupervised clustering method. Its goal is to divide a dataset into K predefined clusters, minimizing the distance between sample points within each cluster and maximizing the distance between different clusters. K-means clustering works iteratively by first randomly initializing K centroids, then continuously updating the cluster and cluster centers for each data point until the cluster centers stabilize or a preset stopping condition is met, thus achieving data classification and grouping.

[0203] In some embodiments, such as Figure 8 As shown, Figure 8 yes Figure 2 Step 104, an optional implementation flowchart, involves performing at least one weight adjustment on the initial weight coefficient group based on the clustering analysis results and the initial honeypot effect values ​​to obtain the target weight coefficient group, including the following steps:

[0204] 104.1.1 Obtain the target optimization function and the preset initial learning rate. Based on the initial honeypot effect value and cluster analysis results, determine the first target optimization function value corresponding to the target optimization function.

[0205] 104.1.2 Based on the objective optimization function and the initial learning rate, the initial weight coefficient group is adjusted to obtain the updated weight coefficient group. The updated honeypot effect value is determined based on the updated weight coefficient group. Based on the updated honeypot effect value and the cluster analysis results, the value of the second objective optimization function corresponding to the objective optimization function is determined.

[0206] 104.1.3 If the value of the first objective optimization function is better than the value of the second objective optimization function, the initial weight coefficient set is retained, and the initial learning rate is updated to obtain the updated initial learning rate; otherwise, the updated honeypot effect value is used as the new initial honeypot effect value, and a new objective optimization function is determined based on the new initial honeypot effect value.

[0207] 104.1.4 Based on the updated initial learning rate or the new objective optimization function and the new initial honeypot effect value, perform at least one more weight adjustment process until the preset iteration conditions are met, and use the last updated weight coefficient as the target weight coefficient group.

[0208] Steps 104.1.1 to 104.1.4 are described in detail below.

[0209] In some embodiments, honeypots are divided into a high-value honeypot set C1 (containing m honeypots) and a low-value honeypot set C2 (containing n honeypots). Based on this clustering classification result, the initial weight coefficient set is further adjusted and optimized using an objective optimization function so as to achieve honeypot deployment optimization according to the final adjusted objective weight coefficient set.

[0210] Furthermore, according to the following formula <6> The initial set of weight coefficients is adjusted and optimized to determine the target set of weight coefficients:

[0211] <6>

[0212] in, The objective function is to optimize such that: honeypots with high overall honeypot performance values ​​belong entirely to the high-value honeypot set C1 in the cluster analysis, and honeypots with low overall honeypot performance values ​​belong entirely to the low-value honeypot set C2 in the cluster analysis; I(·) is an indicator function that returns 1 if the condition is true and 0 otherwise.

[0213] Furthermore, based on the formula <4> The calculated initial honey spot effect value, formula <5> The calculated cluster analysis results and formula <6> The objective optimization function is determined to be F. best =F(α new ,β new ,γ new The first objective function value represents the initial optimal objective function value.

[0214] Furthermore, the initial weight coefficient set is adjusted using the obtained initial learning rate to obtain the updated weight coefficient set [α]. new ,β new ,γ new (Detailed explanation will be provided in steps B.1 to B.3); and based on the formula <4> The updated honeypot effect value is determined by updating the weight coefficient group. Based on the updated honeypot effect value and the cluster analysis results, the value of the second objective optimization function F corresponding to the objective optimization function is determined. new =F(α new ,β new ,γ new If F new >F best (If the second objective function value is better), then the initial weight coefficient set is updated to the updated weight coefficient set [α]. new ,β new ,γ new ], and utilize [α new ,β new ,γ new Update the objective function. Conversely, if the first objective function value is better, leave the initial weight set unchanged and update the initial learning rate to obtain a new initial learning rate; in one feasible example, decrease the learning rate. Where factor represents the attenuation factor, which can be set to 0.8.

[0215] The iteration conditions can be: the number of weight adjustment processes reaches a preset value, the weight adjustment processing time reaches a preset value, or the iteration stops when the change in the target optimization function value is less than a preset value in several consecutive iterations. Of course, the iteration conditions can be set according to the actual situation, and this application embodiment does not limit them.

[0216] In some embodiments, such as Figure 9 As shown, Figure 9 yes Figure 8 Step 104.1.2, an optional implementation flowchart, involves adjusting the initial weight coefficient set based on the objective optimization function and the initial learning rate to obtain an updated weight coefficient set, including the following steps:

[0217] B.1 Based on the objective optimization function, the partial derivatives with respect to the first negative weight, the second negative weight, and the positive weight are obtained to obtain the first negative gradient descent value, the second negative gradient descent value, and the positive gradient descent value.

[0218] B.2 The first negative weights are updated according to the initial learning rate and the first negative gradient descent value to obtain the optimized first negative weights. The second negative weights are updated according to the initial learning rate and the second negative gradient descent value to obtain the optimized second negative weights. The positive weights are updated according to the initial learning rate and the positive gradient descent value to obtain the optimized positive weights.

[0219] B.3 Determine the first negative weight, the second negative weight, and the positive weight to update the weight coefficient group.

[0220] Steps B.1 to B.3 are described in detail below.

[0221] In some embodiments, according to the following formula <7> to <9> The initial weight coefficient set is adjusted and optimized to obtain the optimized first negative weight. Optimize the second negative weight Optimize positive weights :

[0222] <7>

[0223] <8>

[0224] <9>

[0225] Where, α old β old γ old These represent the positive weight, the second negative weight, and the first negative weight from the previous iteration, respectively; η is the initial learning rate. Characterization by partial derivatives; The first negative gradient descent value, This is the second negative gradient descent value. This represents the positive gradient descent value.

[0226] Step 105: Update the initial honey point effect value based on the target weight coefficient group to obtain the updated target honey point effect value, and remove the corresponding honey point when the target honey point effect value is lower than the preset effect threshold.

[0227] Step 105 is described in detail below.

[0228] In some embodiments, the final updated target honeypot effect value is determined based on the target weight coefficient group. If the target honeypot effect value is higher than the preset effect threshold, the honeypot is deployed. If the target honeypot effect value is lower than the preset effect threshold, the honeypot is removed from the target network deployment to avoid unnecessary resource waste.

[0229] Furthermore, after removing ineffective honeypots, new honeypots can be deployed in batches to obtain new deployment target networks. The honeypot deployment optimization method proposed in the embodiments of this application can then be applied to the deployment target networks again to further eliminate inefficient honeypots.

[0230] It is understood that the embodiments of this application can effectively improve the monitoring effect of honey spots, remove poorly performing honey spots in a timely manner, help reduce redundancy and unnecessary monitoring burden, improve the accuracy of honey spot deployment optimization in the target network, ensure the optimal utilization of system resources, and thus improve the efficiency and security of the overall system.

[0231] like Figure 10 As shown, Figure 10 This is a schematic diagram of an optional device module of the honeypot deployment optimization device provided in this application embodiment. The honeypot deployment optimization device may include the following modules 201 to 205:

[0232] The acquisition module 201 is used to acquire honey trapping information of the target network, wherein the target network has multiple honey trapping points pre-deployed, and the honey trapping information indicates the honey trapping IP address and attack threat tag corresponding to the honey trapping point that successfully captures the attack.

[0233] The multidimensional evaluation information module 202 is used to determine substitutability information for each honeypot based on the honeypot IP address that has a honeypot-kicking relationship with the honeypot, determine honeypot-kicking repetition rate information based on other honeypots that have a honeypot-kicking relationship with the honeypot, and determine simulation efficiency information based on the attack threat label.

[0234] The honey spot effect value calculation module 203 is used to assign negative weights to the substitutability information and the honey spot repetition rate information, assign positive weights to the simulation efficiency information, obtain an initial weight coefficient group based on the negative weights and the positive weights, and calculate the initial honey spot effect value of the honey spot based on the initial weight coefficient group, the substitutability information, the honey spot repetition rate information and the simulation efficiency information.

[0235] The weight adjustment module 204 is used to perform cluster analysis on all the honey spots to obtain cluster analysis results that characterize the deployment effect of each honey spot group, and to perform at least one weight adjustment process on the initial weight coefficient group based on the cluster analysis results and the initial honey spot effect value to obtain the target weight coefficient group.

[0236] The honeypot deployment optimization module 205 is used to update the initial honeypot effect value based on the target weight coefficient group to obtain the updated target honeypot effect value, and remove the corresponding honeypot when the target honeypot effect value corresponding to the honeypot is lower than a preset effect threshold.

[0237] This application proposes a method, apparatus, electronic device, and storage medium for optimizing honeypot deployment. It acquires honeypot detection information from a target network, where the target network pre-deploys multiple honeypots for decoy attacks. The detection information indicates the detection IP address and attack threat tag corresponding to the successfully detected honeypot. For each honeypot, substitutability information is determined based on the detection IP addresses associated with it, honeypot repetition rate information is determined based on other honeypots associated with it, and simulation efficiency information is determined based on the attack threat tag. These three indicators comprehensively evaluate the deployment value and optimization potential of the corresponding honeypot. Next, negative weights are assigned to substitutability and honeypot repetition rate information, and positive weights are assigned to simulation efficiency information. An initial weight coefficient set is obtained based on the negative and positive weights, and then... The initial honeypot effect value is calculated based on honeypot repetition rate information and simulation efficiency information. Negative and positive weights reflect the influence of different indicators on the honeypot value. Assigning different value weights guides the evaluation process to more accurately reflect potential threats and resource utilization. Next, cluster analysis is performed on all honeypots to obtain cluster analysis results representing the deployment effect of each honeypot group. Based on the cluster analysis results and the initial honeypot effect value, the initial weight coefficient group is adjusted at least once to obtain the target weight coefficient group. Finally, the initial honeypot effect value is updated based on the target weight coefficient group to obtain the updated target honeypot effect value. When the target honeypot effect value of a honeypot is lower than a preset effect threshold, the corresponding honeypot is removed to avoid unnecessary resource waste, thereby improving the accuracy of honeypot deployment optimization in the target network.

[0238] The specific implementation of the honey spot deployment optimization device is basically the same as the specific embodiment of the honey spot deployment optimization method described above, and will not be repeated here.

[0239] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described honeypot deployment optimization method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0240] like Figure 11 As shown, Figure 11 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device includes:

[0241] The processor 301 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0242] The memory 302 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 302 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 302 and is called and executed by the processor 301 using the honeypot deployment optimization method of the embodiments of this application.

[0243] Input / output interface 303 is used to implement information input and output;

[0244] The communication interface 304 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0245] Bus 305 transmits information between various components of the device (e.g., processor 301, memory 302, input / output interface 303, and communication interface 304);

[0246] The processor 301, memory 302, input / output interface 303, and communication interface 304 are connected to each other within the device via bus 305.

[0247] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the honeypot deployment optimization method described above.

[0248] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0249] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0250] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0251] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0252] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0253] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0254] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0255] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0256] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0257] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0258] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0259] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for optimizing honeypot deployment, characterized in that, include: Obtain honey trapping information of a target network, wherein the target network has multiple honey traps pre-deployed for trapping attacks, and the honey trapping information indicates the honey trapping IP address and attack threat tag corresponding to the honey trap that successfully traps the attack. For each honeypot, substitutability information is determined based on the honeypot-kicking IP addresses that have a honeypot-kicking relationship with the honeypot, honeypot-kicking repetition rate information is determined based on other honeypots that have a honeypot-kicking relationship with the honeypot, and simulation efficiency information is determined based on the attack threat tag. Negative weights are assigned to the substitutability information and the honey-feeding repetition rate information, and positive weights are assigned to the simulation efficiency information. An initial weight coefficient set is obtained based on the negative weights and the positive weights. Based on the initial weight coefficient set, the substitutability information, the honey-feeding repetition rate information, and the simulation efficiency information, the initial honey point effect value of the honey point is calculated. Cluster analysis is performed on all the honey spots to obtain cluster analysis results that characterize the deployment effect of each honey spot group. Based on the cluster analysis results and the initial honey spot effect values, the initial weight coefficient group is adjusted at least once to obtain the target weight coefficient group. The initial honeypot effect value is updated based on the target weight coefficient group to obtain the updated target honeypot effect value. When the target honeypot effect value corresponding to the honeypot is lower than the preset effect threshold, the corresponding honeypot is removed.

2. The honeypot deployment optimization method according to claim 1, characterized in that, The process of determining substitutability information based on the IP addresses of those that have a honey-fighting relationship with the honey point includes: The number of IP addresses that have a honey-discarding relationship with the current honey point is counted to obtain the total number of honey-discarding IPs corresponding to the current honey point; From the honey-following IP addresses that have a honey-following relationship with the current honey point, count the number of honey-following IP addresses with non-unique honey-following characteristics to obtain the total number of non-unique honey-following IP addresses. The substitutability information is obtained based on the ratio of the total number of non-unique honey-feeding IPs to the total number of honey-feeding IPs.

3. The honey spot deployment optimization method according to claim 2, characterized in that, The determination of honey-feeding repetition rate information based on other honey points associated with the honey-feeding point includes: The IP address that has a honey-breaking relationship with the current honey point is identified as the associated honey-breaking IP address. For each associated honey-breaking IP address, other honey points besides the current honey point that has been broken are identified as associated honey points of the current honey point. For each associated honeypot, determine the number of associated honeypot IP addresses that are also honeypotted while the current honeypot is being honeypotted, and obtain the first duplicate statistics for each associated honeypot. The first duplicate statistics of each associated honeypot are accumulated to obtain the second duplicate statistics of the current honeypot. The duplicate rate information is obtained based on the ratio of the second duplicate statistics to the total number of honeypot-touching IPs.

4. The honey spot deployment optimization method according to claim 3, characterized in that, The process of determining simulation efficiency information based on the attack threat label includes: For each associated honey-sniffing IP address, a threat level score is given for all attack threat tags belonging to the associated honey-sniffing IP address to obtain sub-threat level information; The total threat level information is obtained by summing the sub-threat level information of all the associated honey-detecting IP addresses; The simulation efficiency information is obtained based on the ratio of the total threat level information to the total number of honey-trapping IPs.

5. The honeypot deployment optimization method according to claim 4, characterized in that, The threat level score is calculated for all attack threat tags belonging to the associated honeypot IP address to obtain sub-threat level information, including: Obtain risk quantification standard information; Based on the risk quantification standard information, the threat level of each of the attack threat tags associated with the honey-detecting IP address is scored to obtain a single score for each attack threat tag. The sub-threat level information is obtained by accumulating the individual scores of all attack threat tags belonging to the currently associated honeypot IP address.

6. The honeypot deployment optimization method according to claim 1, characterized in that, The negative weights include a first negative weight and a second negative weight; The process involves assigning negative weights to the substitutability information and the honey-feeding repetition rate information, assigning positive weights to the simulation efficiency information, obtaining an initial weight coefficient set based on the negative and positive weights, and calculating the initial honey point effect value based on the initial weight coefficient set, the substitutability information, the honey-feeding repetition rate information, and the simulation efficiency information, including: Assign the first negative weight to the substitutability information, assign the second negative weight to the honey-feeding repetition rate information, and assign the positive weight to the simulation efficiency information; Multiply the first negative weight and the substitutability information to obtain a first multiplier value, multiply the second negative weight and the honey repetition rate information to obtain a second multiplier value, and add the first multiplier value and the second multiplier value to obtain negative value information; The result of multiplying the positive weight and the simulation efficiency information is regarded as positive value information. The negative value information and the positive value information are superimposed to obtain the initial honey spot effect value.

7. The honey spot deployment optimization method according to claim 6, characterized in that, The step of performing at least one weight adjustment on the initial weight coefficient group based on the clustering analysis results and the initial honeypot effect value to obtain the target weight coefficient group includes: Obtain the target optimization function and the preset initial learning rate, and determine the first target optimization function value corresponding to the target optimization function based on the initial honeypot effect value and the clustering analysis results; Based on the target optimization function and the initial learning rate, the initial weight coefficient group is adjusted to obtain an updated weight coefficient group. Based on the updated weight coefficient group, the updated honeypot effect value is determined. Based on the updated honeypot effect value and the clustering analysis results, the second target optimization function value corresponding to the target optimization function is determined. If the value of the first objective optimization function is better than the value of the second objective optimization function, the initial weight coefficient group is retained, and the initial learning rate is updated to obtain the updated initial learning rate; otherwise, the updated honeypot effect value is used as the new initial honeypot effect value, and a new objective optimization function is determined based on the new initial honeypot effect value. Based on the updated initial learning rate or the new target optimization function and the new initial honeypot effect value, perform at least one more weight adjustment process until the preset iteration condition is met, and use the last obtained updated weight coefficient as the target weight coefficient group.

8. The honeypot deployment optimization method according to claim 7, characterized in that, The step of adjusting the initial weight coefficient set according to the objective optimization function and the initial learning rate to obtain the updated weight coefficient set includes: Based on the objective optimization function, partial derivatives are taken with respect to the first negative weight, the second negative weight, and the positive weight to obtain the first negative gradient descent value, the second negative gradient descent value, and the positive gradient descent value. The first negative weight is updated according to the initial learning rate and the first negative gradient descent value to obtain an optimized first negative weight; the second negative weight is updated according to the initial learning rate and the second negative gradient descent value to obtain an optimized second negative weight; and the positive weight is updated according to the initial learning rate and the positive gradient descent value to obtain an optimized positive weight. The optimized first negative weight, the optimized second negative weight, and the optimized positive weight are determined as the updated weight coefficient group.

9. A honey spot deployment optimization device, characterized in that, include: The acquisition module is used to acquire honey trapping information of the target network, wherein the target network has multiple honey trapping points pre-deployed, and the honey trapping information indicates the honey trapping IP address and attack threat tag corresponding to the honey trapping point that successfully captures the attack. The multi-dimensional evaluation information module is used to determine substitutability information for each honeypot based on the honeypot-kicking IP addresses that have a honeypot-kicking relationship with the honeypot, determine honeypot-kicking repetition rate information based on other honeypots that have a honeypot-kicking association with the honeypot, and determine simulation efficiency information based on the attack threat label. The honey spot effect value calculation module is used to assign negative weights to the substitutability information and the honey spot repetition rate information, assign positive weights to the simulation efficiency information, obtain an initial weight coefficient group based on the negative weights and the positive weights, and calculate the initial honey spot effect value of the honey spot based on the initial weight coefficient group, the substitutability information, the honey spot repetition rate information and the simulation efficiency information. The weight adjustment module is used to perform cluster analysis on all the honey spots to obtain cluster analysis results that characterize the deployment effect of each honey spot group, and to perform at least one weight adjustment process on the initial weight coefficient group based on the cluster analysis results and the initial honey spot effect value to obtain the target weight coefficient group. The honeypot deployment optimization module is used to update the initial honeypot effect value based on the target weight coefficient group to obtain the updated target honeypot effect value, and remove the corresponding honeypot when the target honeypot effect value corresponding to the honeypot is lower than a preset effect threshold.

10. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the honeypot deployment optimization method according to any one of claims 1 to 8.

11. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the honey spot deployment optimization method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Honey point domain name optimization deployment method, system and device and storage medium

    CN117220968A

  • Adaptive honey point deployment method based on attack graph

    CN118101332A