A public network-oriented global threat perception method and system

By constructing sub-honey arrays of honey spots, honey gardens, and honey holes on the public internet, and combining them with camouflage and attribution techniques, the universality and performance issues of advanced persistent threat detection under different system architectures have been resolved, achieving low-intrusion, high-efficiency threat detection and countermeasures.

CN120834966BActive Publication Date: 2025-11-21GUANGZHOU UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511334015.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-11-21
Estimated Expiration
2045-09-18

AI Technical Summary

Technical Problem

Existing advanced persistent threat detection technologies vary greatly across different industry system architectures, which limits their versatility and functionality, and affects system performance and stability, thus weakening detection depth and accuracy.

Method used

Employing a comprehensive threat awareness approach, this method constructs sub-honey arrays by setting up honeypot devices, honey garden devices, and honey hole devices on the public internet. It performs low-intrusion detection and countermeasures, and combines spoofing and attribution techniques with anti-linking techniques to generate threat intelligence and update IP address resources.

Benefits of technology

It achieves highly universal and low-intrusive global threat detection, improving detection depth and accuracy without affecting the normal operation of the protected system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120834966B_ABST
    Figure CN120834966B_ABST
Patent Text Reader

Abstract

The application provides a public network-oriented global threat perception method and system, relates to the technical field of advanced persistent threat detection, and specifically discloses the following technical scheme: network stumbling lines and domain name stumbling lines of a public network are set to build a honeypot device, a honeynest device is built based on an IP address credit mechanism, a honeypot device is built based on a pseudo-tracing technology and a reverse chain technology, and a sub-honeynet is built based on the honeypot device, the honeynest device and the honeypot device; a honeypot template is generated based on the sub-honeynet to deploy the honeypot device, public network traffic is acquired based on the honeynest device in combination with the honeypot device, the public network traffic is detected to obtain a detection result; a countermeasure strategy of the honeypot device is formulated based on the detection result, the threat intelligence of an attacker is acquired, and IP address resources of the honeypot device and the honeynest device are updated based on the threat intelligence. The application establishes a low-intrusion threat exploration mechanism and a high-universal global threat perception system through four honeypot devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of advanced persistent attack threat detection technology, and in particular to a method and system for full-domain threat perception on the public network. Background Technology

[0002] Advanced Persistent Threat (APT) detection is a security strategy focused on identifying and responding to complex, long-term cyberattacks. Threat intelligence refers to security strategies that help organizations predict, prevent, and respond to potential attacks by collecting, analyzing, and interpreting information related to cybersecurity threats. APT detection identifies such attacks through multi-layered monitoring, behavioral analysis, threat intelligence, and abnormal traffic detection technologies.

[0003] Existing technologies are often limited by the protected systems, meaning that the system architectures and technology stacks vary significantly across different industries, requiring specific adaptations at the underlying technology level. This may limit their versatility and functionality. Furthermore, some critical areas have requirements regarding system performance and stability, forcing detection systems to make trade-offs at the underlying mechanism level to avoid affecting the normal operation of the system. This can weaken the depth and accuracy of their detection to some extent.

[0004] Therefore, there is an urgent need to develop a solution to the above problems. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for full-domain threat perception for public networks, which supplements and improves the existing technologies in terms of low-intrusion threat detection mechanisms and highly universal full-domain network threat detection mechanisms.

[0006] The present invention provides a technical solution employing the following approach:

[0007] Firstly, a method for comprehensive threat awareness on the public internet, specifically including:

[0008] Setting up public network tripwires and domain name tripwires to build honeypot devices involves: applying for a public IP pool from an operator; allocating the IP pool based on industry category importance; selecting the honeypot type to deploy based on the allocation results; generating honeypot domains based on the webpage information of the protected domain and existing subdomains; setting public network tripwires and domain name tripwires based on the honeypot type and the honeypot domain to obtain the honeypot devices; building honeycomb devices based on IP address reputation mechanisms; building honeyhole devices based on spoofing and tracing technologies and anti-linking technologies; and constructing a sub-honeypot array based on the honeypot devices, honeycomb devices, and honeyhole devices.

[0009] Honey point devices are deployed based on honey point templates generated by sub-honey arrays. Public network traffic is obtained by combining the honey point devices with the honey garden device front-end, and the public network traffic is detected to obtain the detection results.

[0010] Based on the attacker's behavior within the detection results, a countermeasure strategy for the honeyhole device is formulated, threat intelligence of the attacker is obtained, and the IP address resources of the honey point device and honey courtyard device are updated based on the threat intelligence.

[0011] The beneficial effects of the public network-oriented global threat perception method provided by this invention are as follows: by deploying four honeypot devices around the protected system, a joint defense and control protection mechanism is established. Simultaneously, because service simulation is performed only on the protected system or deployment is done in front of the service, the invasiveness to the target system is low. The underlying technology is highly decoupled from the specific system; the domain of the protected system does not affect the underlying technical principles of the detection mechanism, thus exhibiting high universality. Furthermore, the system combines sub-honeypot arrays with a central honeypot array to form a global threat perception system that combines local and global mobilization.

[0012] Optionally, a honeypot domain is generated based on the webpage information of the protected domain and existing subdomains, including:

[0013] The algorithm crawls web page information and existing subdomains of the protected domain. Based on a known domain brute-force dictionary, it designs a target domain generation algorithm, integrates the web page information and existing subdomains to obtain the characteristics of the subdomains, and simulates the generation of domains to obfuscate attackers to obtain honeypot domains.

[0014] Optionally, the detection results are obtained by detecting the public network traffic, including:

[0015] Based on the HoneyNet device, pre-detection is performed before public network traffic reaches the protected system. The public network is initially filtered, and gray IP addresses and behaviors that access the HoneyNet device are continuously monitored and actively redirected. When there is behavior that accesses the alias of the protected asset, it is regarded as a risky behavior and the detection result is output.

[0016] Optionally, a countermeasure strategy for the honeypot device is formulated based on the attacker's behavior within the detection results to obtain threat intelligence about the attacker. The countermeasure strategy includes:

[0017] When attackers intend to launch malware attacks and steal files, they can use different disguise techniques to package the source tracing script into different file types to obtain file honey holes. Based on the file honey holes, attackers are lured to trigger the online execution of the source tracing script, and threat intelligence is obtained by backlinking and tracing the attackers.

[0018] When an attacker intends to exploit a web vulnerability, the system can obtain a honeypot on a dynamic page by deploying the traceability source code. Based on the honeypot, the system can automatically scan the attacker's environment and status. The system can also collect the attacker's sensitive information by configuring the traceability source code. After the system is released and executed as a web browser plugin, the system can record the attacker's sensitive information in the browser to obtain threat intelligence.

[0019] When an attacker intends to use a remote control tool to connect to a website, a counter-honeymoon vulnerability is deployed on the vulnerable website to obtain the source code. Based on the counter-honeymoon vulnerability, the attacker's tool version is obtained, and open-source vulnerability detection is performed to generate a targeted source code tracing script. The attacker then reconnects to the counter-honeymoon vulnerability to gain control of the attacker's host and collect attacker information to obtain threat intelligence.

[0020] Optionally, the source tracing script can be packaged into different file types based on different camouflage techniques to obtain a file honeypot, wherein the file type packaging includes:

[0021] Sensitive data files are mapped to source tracing scripts via shortcuts, and the target path is configured to execute the source tracing scripts to perform backlinking and source tracing against attackers.

[0022] Business program files, based on Trojan programs for encrypted communication and traffic spoofing, achieve highly covert remote control;

[0023] An Office file, embedded with a VBA script, downloads and runs a source-tracing payload in the background without the attacker's knowledge.

[0024] Optionally, after the threat intelligence collected by the Honeyhole device is encrypted and transmitted to a relay server deployed on the public network for relay and back transmission, the attacker is tagged and profiled based on the threat intelligence to generate a specific job title. After the specific job title is analyzed, a deterrent message is sent, requiring the attacker to enter a mobile phone verification code and ID card information for double verification.

[0025] Optionally, based on threat intelligence, update the IP address resources of honeypot devices and honeyhouse devices, including:

[0026] A threat intelligence sharing center is built based on threat intelligence. Based on known security incidents, risk warning results provided by correlation analysis, and operator requirements, the IP address resources of Honey Point devices and Honey Court devices are allocated and updated.

[0027] Secondly, a public network-oriented, comprehensive threat awareness system specifically includes:

[0028] The device setup module is used to set up public network tripwires and domain name tripwires to build honeypot devices. The honeypot device setup includes: applying for a public IP pool from the operator; allocating the public IP pool based on industry category importance; selecting the honeypot type to deploy based on the allocation results; generating honeypot domains based on the webpage information of the protected domain and existing subdomains; setting up public network tripwires and domain name tripwires based on the honeypot type and the honeypot domain to obtain the honeypot device; building a honeycomb device based on an IP address reputation mechanism; building a honeyhole device based on spoofing and tracing technology and anti-linking technology; and constructing a sub-honeypot array based on the honeypot device, honeycomb device, and honeyhole device.

[0029] The sub-honey array detection module generates honey spot templates based on the sub-honey array and deploys honey spot devices. Based on the honey garden device front-end and combined with the honey spot devices, it obtains public network traffic and detects the public network traffic to obtain detection results.

[0030] The threat perception module formulates countermeasures for the honeypot device based on the attacker's behavior within the detection results, obtains threat intelligence from the attacker, and updates the IP address resources of the honeypot device and honey garden device based on the threat intelligence.

[0031] Optionally, the equipment building module can build the following equipment: honey spot equipment, honey garden equipment, honey cave equipment, and honey array equipment;

[0032] Honeydot devices consist of a lightweight threat-aware device that includes network tripwires and system tripwires. Deployed around the protected target, they are used to discover threats and collect threat information, providing adaptive simulation capabilities at the network and system levels, depending on the industry type of the protected asset.

[0033] The HoneyNet device consists of a security proxy device located at the front end of the protected system. It identifies abnormal situations in incoming traffic and proxy service requests based on an IP address reputation mechanism. It is used to obtain public network traffic in conjunction with the HoneyNet device and detect the public network traffic to obtain detection results.

[0034] Honeyhole devices consist of file honeyholes, web page honeyholes, and countermeasure honeyholes. They are used to specifically track malicious attackers, deploy various types of decoys, gradually collect system fingerprints, and accurately send code, thereby achieving continuous tracking and countermeasures against attackers.

[0035] The honey array device consists of sub-honey arrays and a central honey array. It is responsible for decision-making and control, and is used to aggregate threat intelligence information from honey point devices, honey garden devices, and honey hole devices to comprehensively assess the network security situation. It also uses IP reputation and threat intelligence to uniformly allocate and dynamically optimize deception defense resources.

[0036] The beneficial effects in the second aspect can be referred to the relevant description in the first aspect. Attached Figure Description

[0037] Figure 1 The present invention provides an overall flowchart of a public network-oriented, full-domain threat perception method. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art. The terms "comprising" and similar expressions used herein mean that the element or object preceding the word covers the element or object listed after the word and its equivalents, but does not exclude other elements or objects.

[0039] Definitions:

[0040] Threat intelligence is information collected, analyzed, and processed to identify and assess potential threats on the network. It encompasses the following areas: malware analysis (reverse engineering and analysis of new malware, viruses, Trojans, and other malicious code to reveal their propagation paths, attack methods, and potential impact); vulnerability information (collecting known and unknown system and application vulnerabilities to facilitate timely patching or application of defensive measures); malicious domains and IP addresses (collecting information such as malicious domains and IP addresses for blocking or monitoring at network boundaries); attacker behavior analysis (analyzing attacker behavior patterns and target selection on the network to help predict their next actions); and exploit intelligence (obtaining intelligence on the exploitation of known vulnerabilities, including attack tools and exploit code, to strengthen defenses against known vulnerabilities).

[0041] This invention provides a method for global threat awareness on the public internet, comprising the following steps:

[0042] S1. Setting up public network tripwires and domain name tripwires to build honeypot devices, wherein building honeypot devices includes: applying for a public network IP pool from the operator, allocating the public network IP pool based on the importance of industry categories, and selecting the honeypot type to be deployed based on the allocation results; generating honeypot domain names based on the web page information of the protected domain name and existing subdomains; setting up public network tripwires and domain name tripwires based on the honeypot type and the honeypot domain name to obtain the honeypot device; building honeypot devices based on IP address reputation mechanisms, and building honeypot devices based on spoofing and tracing technologies and anti-linking technologies.

[0043] S2. Construct a sub-honey array based on honey point devices, honey garden devices, and honey cave devices. Generate honey point templates based on the sub-honey arrays and deploy honey point devices. Use honey garden devices as a front-end to obtain public network traffic in conjunction with the honey point devices, and detect the public network traffic to obtain detection results.

[0044] S3. Based on the attacker's behavior in the detection results, formulate a countermeasure strategy for the honey hole device, obtain the attacker's threat intelligence, and update the IP address resources of the honey point device and honey courtyard device based on the threat intelligence.

[0045] In some embodiments, performing step S1 specifically includes:

[0046] S1-1. Set up public network tripwires and domain name tripwires to establish honeypot devices;

[0047] S1-2. Building a Honeycomb device based on an IP address reputation mechanism;

[0048] S1-3. Building a honey hole device based on camouflage tracing technology and anti-chain technology.

[0049] Specifically, in step S1-1, setting up public network tripwires and domain name tripwires to establish a honeypot device includes:

[0050] Apply for a public IP pool from the operator, allocate the IP budget from the public IP pool based on the importance of industry category, and determine the honeypot type to be deployed based on the allocation results;

[0051] Generate honeypot domains based on the webpage information of the protected domain and existing subdomains;

[0052] Based on the honeypot type and the honeypot domain name, a public network tripwire and domain name tripwire are set to obtain the honeypot device.

[0053] In fact, honeypot domains are generated based on the webpage information of the protected domain and existing subdomains, including:

[0054] The algorithm crawls web page information and existing subdomains of the protected domain. Based on a known domain brute-force dictionary, it designs a target domain generation algorithm, integrates the web page information and existing subdomains to obtain the characteristics of the subdomains, and simulates the generation of domains to obfuscate attackers to obtain honeypot domains.

[0055] Furthermore, honeypot devices are lightweight threat-aware devices comprised of network tripwires and system tripwires, strategically deployed around protected targets to detect threats early. Adaptive simulations can be performed at both the network and system levels, depending on the industry type of the protected assets.

[0056] Specifically, during steps S1-2, the HoneyNet device mainly performs pre-detection of user traffic before it comes into contact with the protected system, performs initial filtering of the traffic, and can be linked with the HoneyPoint device. While detecting the traffic, it can lure malicious traffic attacks to step on the honey, thereby improving the defense against attacks and collecting public network traffic.

[0057] Specifically, during the execution of steps S1-3, a honey hole device is built based on spoofing and tracing technology and anti-linking technology. The honey hole device mainly includes: file honey hole, web page honey hole and anti-honey hole.

[0058] File honeypots first use different disguise techniques to package the tracing script into different file types, such as sensitive data files, business programs, and office files, depending on the different business scenarios.

[0059] Furthermore, various methods can be used to reverse the connection with attackers. For sensitive data files, .lnk shortcuts can be used to map and execute scripts, while the target path can be configured to execute the source tracing script to reverse the connection and trace the source of the attacker. For business programs, CS Trojan programs can be used to achieve highly covert remote control through encrypted communication and traffic masquerading. For Office files, VBA scripts can be carried along to download and run the source tracing payload in the background without the attacker's knowledge.

[0060] It should be noted that, ultimately, through methods including but not limited to the three spoofing and tracing methods mentioned above, and by using obfuscation and encryption to lure attackers into going online, the attackers are able to conduct reverse linking and information collection.

[0061] Web page honeyholes are obtained by deploying traceable source code on dynamic pages. Based on the web page honeyholes, the attacker's environment is automatically scanned. The traceable source code is configured to collect the attacker's sensitive information. After the web browser plugin is released and executed, the attacker's sensitive information in the browser is recorded to obtain threat intelligence.

[0062] Furthermore, the collected information is encrypted and transmitted to a fake relay server deployed on the public network. The information is then relayed back to the threat intelligence center's profile database through the relay server. Attackers are tagged and profiled to generate specific job titles. After analysis and judgment, deterrent information is sent, and attackers are required to enter a mobile phone verification code and ID card information for double verification.

[0063] Counter-honeyholes are created by deploying counter-source code on vulnerable websites. The attacker's tool version is obtained from the counter-honeyhole, and open-source vulnerability detection is performed to generate a targeted source code script. The attacker then reconnects to the counter-honeyhole to gain control of the attacker's host and collect attacker information to obtain threat intelligence.

[0064] It should be noted that file honeyholes, web honeyholes, and counter-honeyholes utilize relay servers deployed on the public internet to receive threat intelligence, which is then encrypted and returned to the internal database of the threat intelligence center.

[0065] In some embodiments, performing step S2 includes:

[0066] S2-1. Construct a sub-honey array based on honey point devices, honey garden devices, and honey cave devices; generate honey point templates based on the sub-honey arrays and deploy the honey point devices accordingly.

[0067] S2-2. Based on the honey-themed device front-end combined with the honey-point device, public network traffic is obtained, and the public network traffic is detected to obtain the detection result;

[0068] Specifically, during step S2-1, the sub-honey array is used to locally control the deployment of honey point devices, honey garden devices, and honey hole devices on the public network, that is, to retrieve the corresponding parts of each device in different industries and regions for threat perception and defense.

[0069] Furthermore, HoneyPoint first applies for a public IP pool from the operator, allocates the IP budget of the public IP pool according to the importance of the industry category, and decides what type of HoneyPoint to deploy on the public network according to the industry category.

[0070] Specifically, during step S2-2, the public network traffic is detected to obtain the detection results, including:

[0071] Based on the HoneyNet device, pre-detection is performed before public network traffic reaches the protected system. The public network is initially filtered, and gray IP addresses and behaviors that access the HoneyNet device are continuously monitored and actively redirected. When there is behavior that accesses the alias of the protected asset, it is regarded as a risky behavior and the detection result is output.

[0072] In some embodiments, performing step S3 includes:

[0073] S3-1. Based on the attacker's behavior within the detection results, formulate a countermeasure strategy for the honeypot device and obtain threat intelligence from the attacker;

[0074] S3-2. Update the IP address resources of honeypot devices and honeyhouse devices based on threat intelligence.

[0075] Specifically, in step S3-1, when formulating a countermeasure strategy for the honeypot device based on the attacker's behavior within the detection results and obtaining threat intelligence from the attacker, the countermeasure strategy includes:

[0076] When attackers intend to launch malware attacks and steal files, they can use different disguise techniques to package the source tracing script into different file types to obtain file honey holes. Based on the file honey holes, attackers are lured to trigger the online execution of the source tracing script, and threat intelligence is obtained by backlinking and tracing the attackers.

[0077] When an attacker intends to exploit a web vulnerability, the system can obtain a honeypot on a dynamic page by deploying the traceability source code. Based on the honeypot, the system can automatically scan the attacker's environment and status. The system can also collect the attacker's sensitive information by configuring the traceability source code. After the system is released and executed as a web browser plugin, the system can record the attacker's sensitive information in the browser to obtain threat intelligence.

[0078] When an attacker intends to use a remote control tool to connect to a website, a counter-honeymoon vulnerability is deployed on the vulnerable website to obtain the source code. Based on the counter-honeymoon vulnerability, the attacker's tool version is obtained, and open-source vulnerability detection is performed to generate a targeted source code tracing script. The attacker then reconnects to the counter-honeymoon vulnerability to gain control of the attacker's host and collect attacker information to obtain threat intelligence.

[0079] In fact, by using different camouflage techniques, the source tracing script is packaged into different file types to obtain file honeypots. These file types include:

[0080] Sensitive data files are mapped to source tracing scripts via shortcuts, and the target path is configured to execute the source tracing scripts to perform backlinking and source tracing against attackers.

[0081] Business program files, based on Trojan programs for encrypted communication and traffic spoofing, achieve highly covert remote control;

[0082] An Office file, embedded with a VBA script, downloads and runs a source-tracing payload in the background without the attacker's knowledge.

[0083] Furthermore, the threat intelligence collected by the Honeyhole device is encrypted and transmitted to a relay server deployed on the public network for relay and transmission. Based on the threat intelligence, attackers are tagged and profiled to generate specific job titles. After analysis and judgment, deterrent information is sent, requiring attackers to enter mobile phone verification codes and ID card information for double verification.

[0084] Specifically, during step S3-2, the IP address resources of the honeypot device and honeyhouse device are updated based on threat intelligence, including:

[0085] A threat intelligence sharing center is built based on threat intelligence. Based on known security incidents, risk warning results provided by correlation analysis, and operator requirements, the IP address resources of Honey Point devices and Honey Court devices are allocated and updated.

[0086] Furthermore, for potentially vulnerable targets, more resources are allocated, namely, generating and transforming regional-level sensing honey arrays from a global perspective, and issuing instructions to sub-honey arrays to form joint defense and control.

[0087] This invention also provides a global threat awareness system for the public internet, comprising:

[0088] The device setup module is used to set up public network tripwires and domain name tripwires to build honeypot devices. Building honeypot devices includes: applying for a public IP pool from the operator; allocating the public IP pool based on industry category importance; selecting the honeypot type to deploy based on the allocation results; generating honeypot domains based on the webpage information of the protected domain and existing subdomains; setting up public network tripwires and domain name tripwires based on the honeypot type and the honeypot domain to obtain the honeypot device; building a honeycomb device based on an IP address reputation mechanism; building a honeyhole device based on spoofing and tracing technology and anti-linking technology; and constructing a sub-honeypot array based on the honeypot device, honeycomb device, and honeyhole device.

[0089] The sub-honey array detection module generates honey spot templates based on the sub-honey array and deploys honey spot devices. Based on the honey garden device front-end and combined with the honey spot devices, it obtains public network traffic and detects the public network traffic to obtain detection results.

[0090] The threat perception module formulates countermeasures for the honeypot device based on the attacker's behavior within the detection results, obtains threat intelligence from the attacker, and updates the IP address resources of the honeypot device and honey garden device based on the threat intelligence.

[0091] Specifically, the equipment building module builds the following equipment: honey spot equipment, honey garden equipment, honey cave equipment, and honey array equipment;

[0092] Honeydot devices consist of a lightweight threat-aware device that includes network tripwires and system tripwires. Deployed around the protected target, they are used to discover threats and collect threat information, providing adaptive simulation capabilities at the network and system levels, depending on the industry type of the protected asset.

[0093] The HoneyNet device consists of a security proxy device located at the front end of the protected system. It identifies abnormal situations in incoming traffic and proxy service requests based on an IP address reputation mechanism. It is used to obtain public network traffic in conjunction with the HoneyNet device and detect the public network traffic to obtain detection results.

[0094] Honeyhole devices consist of file honeyholes, web page honeyholes, and countermeasure honeyholes. They are used to specifically track malicious attackers, deploy various types of decoys, gradually collect system fingerprints, and accurately send code, thereby achieving continuous tracking and countermeasures against attackers.

[0095] The honey array device consists of sub-honey arrays and a central honey array. It is responsible for decision-making and control, and is used to aggregate threat intelligence information from honey point devices, honey garden devices, and honey hole devices to comprehensively assess the network security situation. It also uses IP reputation and threat intelligence to uniformly allocate and dynamically optimize deception defense resources.

[0096] Furthermore, starting from the sub-honeycomb arrays, local control is applied to various industries to collect threat intelligence from attackers and form local awareness. The central honeycomb array establishes a threat intelligence sharing center, links each local sub-honeycomb array, collects the acquired threat intelligence, and issues instructions for local control from a global perspective, forming joint defense and control between the sub-honeycomb arrays and the central honeycomb array. Ultimately, this achieves a method and system for full-domain threat awareness facing the public network that combines local and global approaches.

[0097] While embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations can be made to these embodiments. However, it should be understood that such modifications and variations fall within the scope and spirit of the invention as set forth in the claims. Furthermore, the invention described herein may have other embodiments and can be implemented or carried out in various ways.

Claims

1. A method for comprehensive threat perception over the public internet, characterized in that, include: Setting up public network tripwires and domain name tripwires to build honeypot devices involves: applying for a public IP pool from an operator; allocating the IP pool based on industry category importance; selecting the honeypot type to deploy based on the allocation results; generating honeypot domains based on the webpage information of the protected domain and existing subdomains; setting public network tripwires and domain name tripwires based on the honeypot type and the honeypot domain to obtain the honeypot devices; building honeycomb devices based on IP address reputation mechanisms; building honeyhole devices based on spoofing and tracing technologies and anti-linking technologies; and constructing a sub-honeypot array based on the honeypot devices, honeycomb devices, and honeyhole devices. Honey point devices are deployed based on honey point templates generated by sub-honey arrays. Public network traffic is obtained by combining the honey point devices with the honey garden device as a front-end, and the public network traffic is detected to obtain the detection results. Based on the attacker behavior within the detection results, a countermeasure strategy for the honeyhole device is formulated, threat intelligence of the attacker is obtained, and the IP address resources of the honey point device and honey courtyard device are updated based on the threat intelligence.

2. The method for comprehensive threat perception over the public network according to claim 1, characterized in that, Honeypot domains are generated based on the webpage information of the protected domain and existing subdomains, including: The algorithm crawls web page information and existing subdomains of the protected domain, designs a target domain generation algorithm based on a known domain brute-force dictionary, integrates the web page information and existing subdomains to obtain the characteristics of the subdomains, and simulates the generation of domains to obfuscate attackers to obtain honeypot domains.

3. The method for comprehensive threat perception over the public network according to claim 1, characterized in that, The detection results obtained by detecting the public network traffic include: Based on the HoneyNet device, pre-detection is performed before public network traffic reaches the protected system. The public network is initially filtered, and gray IP addresses and behaviors that access the HoneyNet device are continuously monitored and actively redirected. When there is behavior that accesses the alias of the protected asset, it is regarded as a risky behavior and the detection result is output.

4. The method for comprehensive threat perception over the public network according to claim 1, characterized in that, Based on the attacker's behavior within the detection results, a countermeasure strategy for the honeypot device is formulated to obtain threat intelligence from the attacker. The countermeasure strategy includes: When attackers intend to launch malware attacks and steal files, they can use different disguise techniques to package the source tracing script into different file types to obtain file honey holes. Based on the file honey holes, attackers are lured to trigger the online execution of the source tracing script, and threat intelligence is obtained by backlinking and tracing the attackers. When an attacker intends to exploit a web vulnerability, the system can obtain a honeypot on a dynamic page by deploying the traceability source code. Based on the honeypot, the system can automatically scan the attacker's environment and status. The system can also collect the attacker's sensitive information by configuring the traceability source code. After the system is released and executed as a web browser plugin, the system can record the attacker's sensitive information in the browser to obtain threat intelligence. When an attacker intends to use a remote control tool to connect to a website, a counter-honeymoon vulnerability is deployed on the vulnerable website to obtain the source code. Based on the counter-honeymoon vulnerability, the attacker's tool version is obtained, and open-source vulnerability detection is performed to generate a targeted source code tracing script. The attacker then reconnects to the counter-honeymoon vulnerability to gain control of the attacker's host and collect attacker information to obtain threat intelligence.

5. The method for comprehensive threat perception over the public network according to claim 4, characterized in that, By packaging the source tracing script into different file types using different camouflage techniques, file honeypots are obtained. These file types include: Sensitive data files are mapped to source tracing scripts via shortcuts, and the target path is configured to execute the source tracing scripts to perform backlinking and source tracing against attackers. Business program files, based on Trojan programs for encrypted communication and traffic spoofing, achieve highly covert remote control; An Office file, embedded with a VBA script, downloads and runs a source-tracing payload in the background without the attacker's knowledge.

6. The method for comprehensive threat perception over the public network according to claim 3, characterized in that, After the threat intelligence collected by the Honeyhole device is encrypted and transmitted to a relay server deployed on the public network for relay and back transmission, the attacker is tagged and profiled based on the threat intelligence to generate a specific job title. After the specific job title is analyzed, a deterrent message is sent, requiring the attacker to enter a mobile phone verification code and ID card information for double verification.

7. The method for comprehensive threat perception over the public network according to claim 1, characterized in that, And based on threat intelligence, update the IP address resources of honeypot devices and honeyhouse devices, including: A threat intelligence sharing center is built based on threat intelligence. Based on known security incidents, risk warning results provided by correlation analysis, and operator requirements, the IP address resources of Honey Point devices and Honey Court devices are allocated and updated.

8. A global threat awareness system for public networks, characterized in that, include: The device setup module is used to set up public network tripwires and domain name tripwires to build honeypot devices. The honeypot device setup includes: applying for a public IP pool from the operator; allocating the public IP pool based on industry category importance; selecting the honeypot type to deploy based on the allocation results; generating honeypot domains based on the webpage information of the protected domain and existing subdomains; setting up public network tripwires and domain name tripwires based on the honeypot type and the honeypot domain to obtain the honeypot device; building a honeycomb device based on an IP address reputation mechanism; building a honeyhole device based on spoofing and tracing technology and anti-linking technology; and constructing a sub-honeypot array based on the honeypot device, honeycomb device, and honeyhole device. The sub-honey array detection module generates honey spot templates based on the sub-honey array and deploys honey spot devices. Based on the honey garden device front-end and combined with the honey spot devices, it obtains public network traffic and detects the public network traffic to obtain detection results. The threat perception module formulates countermeasures for the honeypot device based on the attacker's behavior within the detection results, obtains threat intelligence from the attacker, and updates the IP address resources of the honeypot device and honey garden device based on the threat intelligence.

9. The public network-oriented global threat awareness system according to claim 8, characterized in that, The equipment construction module can construct the following equipment: honey spot equipment, honey garden equipment, honey cave equipment, and honey array equipment; Honeydot devices consist of a lightweight threat-aware device that includes network tripwires and system tripwires. Deployed around the protected target, they are used to discover threats and collect threat information, providing adaptive simulation capabilities at the network and system levels, depending on the industry type of the protected asset. The HoneyNet device consists of a security proxy device located at the front end of the protected system. It identifies abnormal situations in incoming traffic and proxy service requests based on an IP address reputation mechanism. It is used to obtain public network traffic in conjunction with the HoneyNet device and detect the public network traffic to obtain detection results. Honeyhole devices consist of file honeyholes, web page honeyholes, and countermeasure honeyholes. They are used to specifically track malicious attackers, deploy various types of decoys, gradually collect system fingerprints, and accurately send code, thereby achieving continuous tracking and countermeasures against attackers. The honey array device consists of sub-honey arrays and a central honey array. It is responsible for decision-making and control, and is used to aggregate threat intelligence information from honey point devices, honey garden devices, and honey hole devices to comprehensively assess the network security situation. It also uses IP reputation and threat intelligence to uniformly allocate and dynamically optimize deception defense resources.