Attack chain association analysis and tracing method based on RASP technology
By using RASP technology to implant probe codes in the power system, guiding attackers to the simulated honeypot and using terminal fingerprint information to form an attack chain, the problem of easy identification and difficult traceability of honeypots is solved, and highly simulated deception defense and accurate traceability are achieved.
Patent Information
- Application Number
- CN202510991943.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-09-19
AI Technical Summary
When existing technologies are used to defend against complex attack chains in power systems, honeypot systems are easily identified by attackers, have poor simulation, cannot provide global deception defense, and cannot track attacker behavior, making it difficult to achieve accurate tracing.
RASP technology is used to implant probe codes in the business system to guide attackers to the simulated honeypot system for deception defense. The terminal fingerprint information is used to associate attack behaviors to form an attack chain and achieve multi-dimensional traceability perception.
It improves the simulation degree of the honeypot system, realizes accurate tracing of attackers and global deception defense, can track attacker behavior and attributes, and enhance enterprise network security.
Smart Images

Figure CN120675799A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of business application technology of power business systems, and specifically to an attack chain correlation analysis and tracing method based on RASP technology. Background Art
[0002] In the current context of new power system construction, attack methods are emerging in an endless stream. With the spread of botnet worms, system zero-day threats, APT attacks, and social engineering attacks, companies are facing a wide variety of attack methods and difficult-to-prevent combined attack chains, making it difficult for traditional detection and defense technologies based on feature matching to effectively detect attacks.
[0003] Deception defense uses behavioral biases to trap attackers, placing multiple traps along their attack paths. While traditional rule-based security methods tend to generate high false positives, deception defense, based on behavioral biases, detects attack behavior with greater accuracy and virtually no false positives. Compared to the passive defenses of traditional security, deception defense is proactive and can effectively complement traditional security measures, building a more secure defense system for enterprises.
[0004] Currently, the industry mainly uses server-side management to configure honeypots to achieve basic deception defense capabilities, but there are still some limitations. The main ones include:
[0005] (1) The integration degree with the main and auxiliary business systems is not high, the business simulation degree is poor, the honeypot container is identified by the attacker, and the success rate of trapping is not high.
[0006] (2) The deception defense capability is single and lacks a three-dimensional global deception capability.
[0007] (3) After discovering the attacker, apart from tracing the source based on IP and phishing, it is impossible to conduct further tracking and analysis of the entire attack team's attack time cycle behavior.
[0008] To address the above issues, it is proposed to achieve the main-auxiliary integration of business applications and deception defense systems through bytecode instrumentation based on RASP technology, build a deception defense system suitable for business applications of power business systems, and achieve accurate threat tracing and attack forensics based on attack chain correlation analysis and tracing technology, helping companies to grasp the security threat situation. At the same time, it can capture unknown APTs, other unknown threats and ongoing attack behaviors in the network, avoid attacks on corporate business networks and services, prevent unknown security risks, and effectively protect the company's real assets. Summary of the Invention
[0009] In view of the deficiencies of the existing technology, the present invention provides an attack chain correlation analysis and tracing method based on RASP technology, which solves the problems.
[0010] To achieve the above objectives, the present invention is implemented through the following technical solutions: an attack chain correlation analysis and tracing method based on RASP technology, specifically comprising the following steps:
[0011] Step 1: Probe code is implanted in a specific location of the source program. RASP software probes are installed by replacing standard application libraries, JAR files, and even Java virtual machines to hijack calls to the underlying platform. When hackers attack real business systems, the probe code leads hackers to the simulated honeypot system for attack, while normal users are not affected and are directly released. When hackers are lured by bait or disguised agents, they are also directly guided to the simulated honeypot system for attack. The simulated honeynet system uses its internal simulation software to enable attackers to crack passwords, exploit vulnerabilities, and move attacks laterally in the honeypot system, completing deception defense, capturing attackers' behaviors, and analyzing their attack methods and strategies. In this process, the attackers' attack behaviors are recorded and attack warnings are processed, summarizing the hackers' threat intelligence.
[0012] Step 2: In step 1, the user sends an HTTP request through the browser, and the web server returns an HTML page with a fingerprint collection script. The browser automatically executes the JavaScript script to render the page, collecting browser information and uploading it to the designated server without the user's knowledge. The same fingerprint collection script will produce the same results when executed on the same device browser. The user is tracked through the fingerprint matching algorithm, and the user's behavior is analyzed. Based on the terminal fingerprint information obtained, the attacker's IP is associated, and multiple attack behaviors from different IPs are linked together to form a real attack chain. Through precise positioning, multi-dimensional aggregation, and restoration of the attack process, the attacker's attributes are further analyzed, achieving a comprehensive multi-dimensional traceability perception of the attacker;
[0013] Preferably, in step one, the RASP platform passively "sees" the application call to the supported function and applies rules when the request is intercepted.
[0014] The present invention also discloses an attack chain correlation analysis and tracing system based on RASP technology, including an insertion module, the insertion module is connected to a RASP traction probe module, the RASP traction probe module is connected to a dense network module and a behavior recording module, the dense network module is respectively connected to a bait perception module and a sandbox simulation module, the bait perception module is connected to a probe perception module, the behavior recording module is connected to an attack alarm module, the attack alarm module is connected to a threat intelligence module connected to the sandbox simulation module, the sandbox simulation module is connected to a deception defense module, the deception defense module and the threat intelligence module are jointly connected to a visualization module, and the visualization module is connected to a tracing countermeasure module.
[0015] Preferably, the traceability countermeasure module includes an embedded module connected to the visualization module and the insertion module respectively, the embedded module is connected to the download module, the download module is connected to the execution module, the support module is connected to the extraction module, the extraction module is respectively connected to the generation module and the rotation module, the rotation module is connected to the storage module, and the storage module is connected to the analysis module.
[0016] Preferably, the embedding module is used to embed the HTML page of the JS file link, and the downloading module is used to download the JS file.
[0017] Preferably, the extraction module is used to extract browser information, system platform information, device hardware information, network environment information, user setting information, and system platform information.
[0018] Preferably, the storage module is internally connected to an ElasticSearch module, and the generation module is used to generate a browser fingerprint.
[0019] Preferably, the deceptive code of the RASP traction probe module does not provide external access and file operation permissions.
[0020] Beneficial effects
[0021] This invention provides an attack chain correlation analysis and tracing method based on RASP technology. Compared with the existing technology, it has the following advantages:
[0022] (1) The attack chain correlation analysis and tracing method based on RASP technology sets up a RASP traction probe module in the system, integrates it with the business system through RASP technology bytecode insertion, and adds web paths that do not exist but are of interest to attackers under the real business domain name by forging responses. When the black party accesses these paths, the program jumps to the simulation page deployed in the honeypot, making it impossible for hackers to distinguish between authenticity and fakeness, thereby improving business simulation and solving the problem that the existing honeypot system is easily identified by attackers.
[0023] (2) The attack chain correlation analysis and tracing method based on RASP technology sets up a tracing countermeasure module in the system, and associates the attacker's IP based on the terminal fingerprint information obtained, and combines multiple attack behaviors from different IPs to form a real attack chain. Through precise positioning, multi-dimensional aggregation, and restoration of the attack process, the attacker's attributes are further analyzed, such as historical attack targets, key attack industries, and common attack methods, to achieve a multi-dimensional and comprehensive tracing perception of the attacker, which is convenient for the defense to conduct forensic investigation and tracing of the attacker.
[0024] (3) The attack chain correlation analysis and tracing method based on RASP technology sets a generation module in the system. The user sends an HTTP request through the browser, and the Web server returns an HTML page with a fingerprint collection script. The browser automatically executes the JavaScript script to render the page. The generation module generates the corresponding browser fingerprint information and collects the browser information without the user's knowledge and uploads it to the designated server. Since the same fingerprint collection script has the same execution result on the same device browser, the user is tracked through the fingerprint matching algorithm and the user's behavior is analyzed. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 This is a main principle block diagram of the present invention;
[0026] Figure 2 It is the main flow chart of the present invention;
[0027] Figure 3 This is a principle block diagram of the traceability countermeasure module in the present invention;
[0028] Figure 4 This is a flow chart of the traceability countermeasure module in the present invention;
[0029] Figure 5 This is a block diagram of the principles of browser fingerprint tracking in the present invention. DETAILED DESCRIPTION
[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0031] refer to Figure 1-5 The present invention discloses an attack chain correlation analysis and tracing method based on RASP technology, which specifically includes the following steps:
[0032] Step 1: Probe code is implanted in a specific location of the source program. RASP software probes are installed by replacing standard application libraries, JAR files, and even Java virtual machines to hijack calls to the underlying platform. When hackers attack real business systems, the probe code leads hackers to the simulated honeypot system for attack, while normal users are not affected and are directly released. When hackers are lured by bait or disguised agents, they are also directly guided to the simulated honeypot system for attack. The simulated honeynet system uses its internal simulation software to enable attackers to crack passwords, exploit vulnerabilities, and move attacks laterally in the honeypot system, completing deception defense, capturing attackers' behaviors, and analyzing their attack methods and strategies. In this process, the attackers' attack behaviors are recorded and attack warnings are processed, summarizing the hackers' threat intelligence.
[0033] Step 2: In step 1, the user sends an HTTP request through the browser, and the web server returns an HTML page with a fingerprint collection script. The browser automatically executes the JavaScript script to render the page, collecting browser information and uploading it to the designated server without the user's knowledge. The same fingerprint collection script will produce the same results when executed on the same device browser. The user is tracked through the fingerprint matching algorithm, and the user's behavior is analyzed. Based on the terminal fingerprint information obtained, the attacker's IP is associated, and multiple attack behaviors from different IPs are linked together to form a real attack chain. Through precise positioning, multi-dimensional aggregation, and restoration of the attack process, the attacker's attributes are further analyzed, achieving a comprehensive multi-dimensional traceability perception of the attacker;
[0034] In step one, the RASP platform passively “sees” application calls to supported functions and applies rules when requests are intercepted.
[0035] like Figure 1-5 As shown, the present invention also discloses an attack chain correlation analysis and tracing system based on RASP technology, including an instrumentation module, the instrumentation module is connected to a RASP traction probe module, the RASP traction probe module is connected to a dense network module and a behavior recording module, the dense network module is respectively connected to a bait perception module and a sandbox simulation module, the bait perception module is connected to a probe perception module, the behavior recording module is connected to an attack alarm module, the attack alarm module is connected to a threat intelligence module connected to the sandbox simulation module, the sandbox simulation module is connected to a deception defense module, the deception defense module and the threat intelligence module are jointly connected to a visualization module, and the visualization module is connected to a tracing countermeasure module;
[0036] The embedding module is used to embed HTML pages with JS file links, and the download module is used to download JS files. The extraction module is used to extract browser information, system platform information, device hardware information, network environment information, user settings information, and system platform information. Based on RASP technology, the software probe is integrated with the real business system, and traction rules and baits are set. For example, sensitive paths such as / admin, / upload, / database, and / bak that attackers are interested in are pulled to the fully interactive simulation honeypot system for analysis without the attacker's knowledge, while normal system users are directly released without being affected. Through the integration of RASP technology bytecode instrumentation with the business system, web paths that do not exist but are of interest to the attacker are added under the real business domain name by forging responses. When the hacker accesses these paths, the program jumps to the simulation page deployed in the honeypot, making it impossible for hackers to distinguish between authenticity and fakeness, thereby improving the business simulation degree.
[0037] The RASP traction probe module's heavy deception code does not provide external access and file operation permissions.
[0038] like Figure 1-4 The second embodiment shown is mainly different from the first embodiment in that:
[0039] The tracing and countermeasure module includes an embedding module connected to the visualization module and the instrumentation module respectively. The embedding module is connected to the download module, the download module is connected to the execution module, the support module is connected to the extraction module, the extraction module is connected to the generation module and the rotation module respectively, the rotation module is connected to the storage module, and the storage module is connected to the analysis module. Based on the acquired terminal fingerprint information, the attacker's IP address is associated, and multiple attack behaviors from different IP addresses are linked together. Through precise positioning, multi-dimensional aggregation, and restoration of the attack process, the attacker's attributes are further analyzed to achieve a comprehensive multi-dimensional tracing and perception of the attacker.
[0040] like Figure 1-5 The third embodiment shown is mainly different from the second embodiment in that:
[0041] The storage module is internally connected to the ElasticSearch module. The generation module is responsible for generating browser fingerprints. When a user issues an HTTP request through a browser, the web server returns an HTML page containing a fingerprinting script. The browser automatically executes a JavaScript script to render the page, and the generation module generates the corresponding browser fingerprint information. This information is collected without the user's knowledge and uploaded to a designated server. Because the same fingerprinting script produces the same results when executed on the same device's browser, a fingerprint matching algorithm is used to track users and analyze their behavior. As a distributed architecture, ElasticSearch offers full-text search, structured search, and aggregated analytics, and rapidly stores, searches, and analyzes massive amounts of data. Furthermore, ElasticSearch balances its workload across nodes, so a single node failure can paralyze the entire cluster. Compared to Lucene, ElasticSearch offers more than just full-text search capabilities; it can also search across individual fields of small data stored in ElasticSearch. If you need faster search capabilities and greater storage, simply add more ElasticSearch nodes. Furthermore, it can scale horizontally to hundreds or thousands of servers, processing petabytes of data.
[0042] At the same time, the contents not described in detail in this specification belong to the existing technology known to those skilled in the art, and the model parameters of each electrical appliance are not specifically limited, and conventional equipment can be used.
[0043] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0044] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. Attack chain correlation analysis and tracing method based on RASP technology, characterized by: The specific steps include: Step 1: Probe code is implanted in a specific location of the source program. RASP software probes are installed by replacing standard application libraries, JAR files, and even Java virtual machines to hijack calls to the underlying platform. When hackers attack real business systems, the probe code leads hackers to the simulated honeypot system for attack, while normal users are not affected and are directly released. When hackers are lured by bait or disguised agents, they are also directly guided to the simulated honeypot system for attack. The simulated honeynet system uses its internal simulation software to enable attackers to crack passwords, exploit vulnerabilities, and move attacks laterally in the honeypot system, completing deception defense, capturing attackers' behaviors, and analyzing their attack methods and strategies. In this process, the attackers' attack behaviors are recorded and attack warnings are processed, summarizing the hackers' threat intelligence. Step 2. In step 1, the user sends an HTTP request through the browser, and the web server returns an HTML page with a fingerprint collection script. The browser automatically executes the JavaScript script to render the page, and collects browser information and uploads it to the designated server without the user's knowledge. The same fingerprint collection script has the same execution results on the same device browser. The user is tracked through the fingerprint matching algorithm, and the user's behavior is analyzed. Based on the terminal fingerprint information obtained, the attacker's IP is associated, and multiple attack behaviors from different IPs are linked together to form a real attack chain. Through precise positioning, multi-dimensional aggregation, and restoring the attack process, the attacker's attributes are further analyzed to achieve a multi-dimensional and comprehensive traceability perception of the attacker.
2. The attack chain correlation analysis and tracing method based on RASP technology according to claim 1 is characterized by: In step one, the RASP platform passively “sees” application calls to supported functions and applies rules when requests are intercepted.
3. A RASP-based attack chain correlation analysis and tracing system, used to implement the RASP-based attack chain correlation analysis and tracing method according to claim 1, comprising an instrumentation module, characterized in that: The plug-in module is connected to the RASP traction probe module, the RASP traction probe module is connected to the dense network module and the behavior recording module, the dense network module is respectively connected to the bait perception module and the sandbox simulation module, the bait perception module is connected to the probe perception module, the behavior recording module is connected to the attack alarm module, the attack alarm module is connected to the threat intelligence module connected to the sandbox simulation module, the sandbox simulation module is connected to the deception defense module, the deception defense module and the threat intelligence module are jointly connected to the visualization module, and the visualization module is connected to the tracing countermeasure module.
4. The attack chain correlation analysis and tracing system based on RASP technology according to claim 3 is characterized by: The traceability countermeasure module includes an embedded module connected to the visualization module and the insertion module respectively, the embedded module is connected to the download module, the download module is connected to the execution module, the support module is connected to the extraction module, the extraction module is respectively connected to the generation module and the rotation module, the rotation module is connected to the storage module, and the storage module is connected to the analysis module.
5. The attack chain correlation analysis and tracing system based on RASP technology according to claim 4 is characterized by: The embedding module is used to embed the HTML page of the JS file link, and the downloading module is used to download the JS file.
6. The attack chain correlation analysis and tracing system based on RASP technology according to claim 4 is characterized by: The extraction module is used to extract browser information, system platform information, device hardware information, network environment information, user setting information, and system platform information.
7. The attack chain correlation analysis and tracing system based on RASP technology according to claim 4 is characterized by: The storage module is internally connected to an ElasticSearch module, and the generation module is used to generate a browser fingerprint.
8. The attack chain correlation analysis and tracing system based on RASP technology according to claim 3 is characterized by: The RASP traction probe module's deceptive code does not provide external access and file operation permissions.